Download PDF
Horizon3.ai > Case Studies > Enhancing Security in Medical Clinic with NodeZero
Horizon3.ai Logo

Enhancing Security in Medical Clinic with NodeZero

Technology Category
  • Cybersecurity & Privacy - Endpoint Security
  • Cybersecurity & Privacy - Intrusion Detection
Applicable Industries
  • Healthcare & Hospitals
  • National Security & Defense
Applicable Functions
  • Quality Assurance
Use Cases
  • Intrusion Detection Systems
  • Tamper Detection
Services
  • Testing & Certification
The Challenge

A medical clinic with over 120 providers was facing a significant security challenge. Despite using best-in-class endpoint detection and response (EDR) software, the clinic was still vulnerable to cyber threats. NodeZero, a security solution, was able to identify a device’s Local Security Authority Subsystem Service Process (LSASS), dump and crack user credentials, move laterally, and gain Windows Domain Administrator privileges. This resulted in full domain rights, a situation that should have been detected and blocked by the EDR. Upon investigation, it was discovered that the EDR solution was misconfigured on several devices. Additionally, the clinic had neglected to purchase an add-on module designed to alert on lateral movement. The clinic also faced challenges in patch management. While they recognized the urgency to install updates to their infrastructure, understanding what to patch, what to defer, and ensuring that patches remediate weaknesses was a complex task.

About The Customer

The customer in this case study is a medical clinic with over 120 providers. The clinic was using best-in-class endpoint detection and response (EDR) software to protect their systems from cyber threats. However, they were still vulnerable to attacks due to misconfigurations and a lack of certain add-on modules. The clinic also faced challenges in patch management, struggling to understand what to patch, what to defer, and how to ensure that patches effectively remediate weaknesses. Despite their best efforts, the clinic was unable to fully secure their systems, leading them to seek out the services of NodeZero.

The Solution

The clinic turned to NodeZero to address these security challenges. NodeZero is an autonomous penetration testing solution that identifies exploitable weaknesses in perimeter and/or internal systems. It does this even when vulnerability scanners and patch management systems show that security updates have been successful. NodeZero automates the process of penetration testing, which is typically expensive and manual. It is a 'self-service' offering that is safe to run in production and requires no persistent or credentialed agents. NodeZero assesses systems as would a manual pentester, but faster, more completely, and with more actionable results. By using NodeZero, the clinic was able to identify and address vulnerabilities in their system, enhancing their overall security posture.

Operational Impact
  • The implementation of NodeZero resulted in a more secure system for the medical clinic. The solution was able to identify and address vulnerabilities that the clinic's previous EDR solution had missed. This included identifying a device’s Local Security Authority Subsystem Service Process (LSASS), dumping and cracking user credentials, moving laterally, and gaining Windows Domain Administrator privileges. NodeZero also helped the clinic better manage their patching process, identifying what needed to be patched, what could be deferred, and ensuring that patches effectively remediated weaknesses. Overall, NodeZero enhanced the clinic's security posture, providing a more robust defense against cyber threats.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.