We’re exhibiting at

TribalNet 2026

September 20-24, 2026

Dallas, TX

Booth #320

Healthcare Sector

Three Real-World Purple Team Engagements  |  Fully Anonymised  |  ISO 17025 Accredited Methodology

ISO 17025 Accredited  ·  MITRE ATT&CK v15  ·  All engagements conducted under explicit written authorisation

Sector

Healthcare

Engagement

Purple Team Exercise

ATT&CK Tactics

MITRE ATT&CK v15

Location

Southeastern United States

About These Case Studies

The following case studies describe real purple team engagements conducted by GLI Secure across healthcare sector organisations. All identifying details — organisation names, locations, system names, and personnel — have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.

 

All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.

State & Local Government

Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.

Case Studies Healthcare about

Case Study HC-CS-01

EHR Ransomware Simulation — Regional Hospital Network

Testing whether a 12-hospital system could detect and contain a ransomware attack before clinical operations were disrupted

Organisation

A 12-hospital regional health system operating across three US states (anonymised)

Sector

Healthcare — Acute care, outpatient, and specialist services

Location

Southeastern United States

Engagement

Purple Team Exercise — EHR Ransomware Emulation

Duration

6 weeks (3-week planning, 2-day exercise, 1-week remediation validation)

Frameworks

HIPAA Security Rule §164.308 | HITRUST CSF v11 | MITRE ATT&CK Enterprise v15 | NHS DSPT Objective D (UK-aligned subsidiary)

The Situation

The health system had experienced a near-miss ransomware event 18 months prior. A Conti affiliate had gained access through a compromised vendor VPN account and remained inside the network for 23 days before a routine audit flagged unusual activity. The CISO was honest with the board: they had been lucky, not good.

 

Following the incident, the organisation invested significantly in EDR tooling, a new SIEM, and a dedicated SOC team. Eighteen months later, the board wanted independent evidence that the investment had actually improved detection capability — not just documentation that the tools were in place.

 

The organisation had never conducted a purple team exercise. Annual penetration tests and quarterly vulnerability scans told them whether attackers could get in — not whether the SOC could catch them when they did.

Core Challenge

Determine whether 18 months of security investment had produced measurable improvement in the ability to detect ransomware precursor activity — specifically the lateral movement and backup targeting techniques that preceded the prior near-miss.

What GLI Secure Did

We began with a threat intelligence review identifying the specific MITRE ATT&CK techniques used by Conti and BlackCat affiliates against hospital networks of similar size, producing a scenario grounded in the actual threat the organisation faced.

 

Phase 1 tested detection of initial access and lateral movement across the administrative network. Phase 2 tested ransomware precursor activity: credential harvesting, backup enumeration, and simulated encryption of isolated test file shares.

 

Our red team operated in full transparency: every technique was announced before execution, the detection hypothesis documented in advance. This allowed the blue team to test detections, identify specifically why missed ones failed, and begin tuning during the exercise.

The Purple Team Approach

Threat Intelligence Scoping

Mapped the 12 MITRE ATT&CK techniques most used by Conti and BlackCat affiliates against US hospital networks based on FBI IC3 2025 healthcare threat data. Selected 8 techniques for the exercise based on the Epic Hyperspace EHR environment and network architecture.

Detection Hypothesis Documentation

Before any technique was executed, the blue team documented the expected detection: which tool, which alert, within what timeframe. This exposed 3 techniques for which no detection rule existed — before the exercise began.

Phase 1 — Initial Access and Lateral Movement

Executed 4 techniques across initial access and lateral movement stages. Red team used a simulated compromised vendor credential, then moved laterally using SMB and RDP techniques consistent with the prior near-miss incident.

Phase 2 — Ransomware Precursor Activity

Executed 4 techniques simulating ransomware staging: credential dumping from LSASS, shadow copy enumeration, backup server access, and simulated encryption of isolated test shares. Each technique was executed, detection measured, and SOC response time recorded.

Real-Time Detection Tuning

For the 3 techniques that failed to generate alerts, detection engineers wrote new SIEM rules during the exercise. Two new rules were validated and confirmed functional before the exercise concluded.

Re-Test Validation

5 days after remediation, we re-executed all 8 techniques. Results were compared against the initial exercise to produce a measurable before/after improvement metric.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1566.001 Spear Phishing Attachment Detected

Alert fired in 4 minutes. Within target.

T1078 Valid Accounts (Vendor VPN) PARTIAL

Alert fired at 47 minutes. Exceeded 15-minute target.

T1021.002 SMB/Windows Admin Shares NOT DETECTED

No rule existed for this lateral movement technique.

T1003.001 LSASS Memory Credential Dump DETECTED

EDR alert in 2 minutes. Excellent result.

T1490 Inhibit System Recovery (Shadow Copies) Not Detected

Logging not enabled on backup servers.

T1486 Data Encrypted for Impact (Test Share) Detected

Ransomware behavioural detection in 3 minutes.

T1083 File and Directory Discovery Not Detected

No UEBA baseline for file enumeration volume.

T1021.001 Remote Desktop Protocol PARTIAL

Alert fired but required manual correlation. MTTD 38 minutes.

Key Findings

Medium

Detection Coverage:

5 of 8 techniques detected (62.5%) before tuning — improved to 87.5% after same-day tuning and remediation.

Critical

Critical Gap: Backup Server Logging:

Backup servers had no log forwarding to the SIEM. An attacker targeting backup infrastructure would have been completely invisible — the most critical ransomware precursor activity.

High

Vendor Account Monitoring:

Vendor VPN credential alert fired at 47 minutes — far too slow. Alert threshold was set too conservatively for the exact technique used in the prior near-miss incident.

Critical

SMB Lateral Movement Gap:

No detection rule existed for SMB-based lateral movement — the primary technique used in 73% of healthcare ransomware attacks per FBI IC3 2025.

Medium

EDR Strength:

EDR performed excellently on endpoint-level techniques. LSASS dump and ransomware behavioural detection were both sub-5-minute. The gap was network-level detection, not endpoint.

Measurable Outcomes

Detection Coverage Before 62.5% — 5 of 8 techniques detected
Detection Coverage After 87.5% — 7 of 8 techniques detected
Mean MTTD Before 24.4 minutes average
Mean MTTD After 8.1 minutes — 67% improvement
Critical Gaps Closed 3: backup logging, SMB detection, vendor MTTD
New SIEM Rules Written 6 rules validated during and after exercise
HITRUST CSF Evidence §09.ab control evidence accepted by assessor

Regulatory Impact

The exercise produced direct evidence for three HIPAA Security Rule requirements frequently cited in OCR audit findings: §164.308(a)(5) Security Awareness and Training, §164.308(a)(6) Security Incident Procedures, and §164.308(a)(7) Contingency Plan.

 

The discovery that backup server logging was not configured — despite being documented as complete in the HITRUST CSF assessment — highlighted the gap between self-attestation and operational reality. Addressing it proactively provides a demonstrably stronger HIPAA compliance position than the prior documentation-only approach.

 

The exercise report was accepted by the organisation’s HITRUST assessor as supporting evidence for Control Category 09.ab (Monitoring System Use), reducing the evidence burden for the next annual HITRUST cycle.

We spent 18 months and significant budget building what we thought was a mature detection programme. The purple team exercise showed us that we had excellent tools pointed in slightly the wrong direction. The backup server logging gap — invisible to every prior audit — would have given an attacker complete freedom to destroy our recovery capability. Finding that in a controlled exercise rather than during an actual ransomware attack was worth every dollar we spent.

— CISO, Regional Health System (anonymised)

Key Takeaways

Ready to test your Healthcare security defences?

Case Study HC-CS-02

IoMT Lateral Movement — Academic Medical Centre

Testing whether clinical network segmentation prevented pivot from IT to Internet of Medical Things infrastructure

Case Studies Healthcare hc cs 02

Organisation

A 900-bed academic medical centre with 14,000 connected devices (anonymised)

Sector

Healthcare — Academic medical centre, Level 1 trauma, research hospital

Location

Midwest United States

Engagement

Purple Team Exercise — IoMT Lateral Movement and Clinical Network Segmentation

Duration

8 weeks (4-week planning including device inventory, 3-day exercise, 1-week remediation)

Frameworks

HIPAA Security Rule §164.312 | FDA Pre-Market Cybersecurity Guidance 2023 | IEC 62443-4-2 | MITRE ATT&CK Enterprise v15 | DTAC (UK subsidiary)

The Situation

The medical centre’s biomedical engineering team had found that of 14,000 connected devices operating across the hospital network, only 3,200 appeared in the IT security team’s asset register. The remaining 10,800 devices — infusion pumps, patient monitors, imaging systems, nurse call systems — were connected to the network but invisible to the security operations centre.

 

The CISO had invested in network segmentation between administrative and clinical VLANs following a prior security assessment, but nobody had ever tested whether that segmentation actually held under a realistic attack scenario. The specific concern was a Lazarus Group attack pattern documented by CISA in 2024: IT workstation compromise, lateral movement to clinical network via misconfigured firewall rules, then access to medical device control interfaces.

 

The medical centre wanted to know whether their environment was vulnerable to this specific attack chain.

Core Challenge

Verify whether an attacker who compromised the administrative IT network could reach and interact with clinical IoMT devices, and whether any such movement would be detected by existing security monitoring.

What GLI Secure Did

We began with a three-week device discovery phase, working with biomedical engineering to enumerate all connected devices. This produced the first complete device inventory: 14,200 devices across 47 VLANs, with 62 running end-of-life operating systems.

 

The exercise tested the segmentation boundary between IT and clinical networks, simulating an attacker who had compromised an IT workstation attempting to pivot to clinical infrastructure — using Lazarus Group healthcare attack techniques.

 

An isolated test PLC was used for all demonstrations of device interaction impact. No production medical devices were ever interacted with — patient safety was the absolute constraint around which every testing decision was made.

The Purple Team Approach

Device Inventory and Risk Classification

Catalogued all 14,200 devices by risk tier: 62 end-of-life devices with critical CVEs in Tier 1, 847 unmonitored devices with no logging in Tier 2. First complete IoMT asset register the organisation had ever possessed.

Segmentation Architecture Review

Reviewed all firewall rules between administrative and clinical VLANs. Identified 7 legacy rules creating unintended connectivity — created years earlier for operational convenience and never reviewed.

Lateral Movement Simulation

From a simulated compromised IT workstation, tested whether the 7 legacy firewall rules permitted lateral movement to clinical VLANs. Four of seven permitted connectivity; three were exploitable for lateral movement.

Clinical Network Enumeration

Once across the segmentation boundary, tested whether the clinical network could be enumerated. Result: 10,800 previously unknown devices became visible to the simulated attacker.

Test Device Interaction (Isolated Environment)

Using an isolated test infusion pump outside the production network, demonstrated access level achievable. Interaction was limited to reading device configuration — no parameters were modified.

Detection Validation

Tested whether lateral movement, enumeration, or clinical network access activities generated any alerts. Result: zero alerts for any activity after the initial IT workstation compromise.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1046 Network Service Scanning Not Detected

No anomaly detection for internal scanning traffic.

T1021.001 Remote Desktop Protocol Detected

EDR alert on IT workstation. MTTD 6 minutes.

T0812 Default Credentials (ICS) Not Detected

No credential monitoring on clinical devices.

T1190 Exploit Public-Facing Application PARTIAL

WAF detected but did not block. Alert not actioned.

T1135 Network Share Discovery Not Detected

No alerting on clinical VLAN enumeration.

T0866 Exploitation of Remote Services (ICS) Not Detected

Clinical network has no security monitoring.

Key Findings

Critical

Zero Clinical Network Monitoring:

The clinical network — 14,200 connected devices — had no security monitoring infrastructure. An attacker who reached the clinical network could operate indefinitely without generating any alert.

Critical

4 Exploitable Firewall Misconfigurations:

Four legacy firewall rules permitted lateral movement from the administrative network to clinical VLANs. These rules had never been reviewed and were not visible in current network documentation.

High

10,800 Unregistered Devices:

62% of connected clinical devices were absent from the security team’s asset register. You cannot monitor or protect assets you do not know exist.

High

62 End-of-Life Devices with Critical CVEs:

Cannot be patched due to FDA clearance constraints — requiring compensating controls aligned to IEC 62443-4-2.

medium

WAF Alert Not Actioned:

A WAF alert generated during the exercise was not reviewed by the SOC for over 4 hours — an alert management process gap, not a detection tool gap.

Measurable Outcomes

Firewall Rules Remediated 4 exploitable rules removed; 3 reviewed and scoped
Clinical Network Monitoring OT security monitoring deployed within 60 days
Asset Register Complete clinical device inventory: 14,200 devices documented
End-of-Life Devices Compensating controls applied to all 62 EOL devices within 30 days
Detection Coverage After Clinical network monitoring now covers 78% of device categories
FDA Evidence Package IoMT security assessment accepted as pre-market cybersecurity evidence

Regulatory Impact

The HIPAA §164.312 implication is direct: technical security measures must guard against unauthorised access to ePHI transmitted over electronic communications networks. An unmonitored clinical network containing patient monitoring data does not satisfy this requirement.

 

The IoMT security documentation was structured to align with the FDA’s 2023 Pre-Market Cybersecurity Guidance — supporting both the organisation’s internal security programme and engagement with device manufacturers on patch management.

 

The exercise highlighted the emerging IEC 62443-4-2 gap in healthcare IoMT: clinical devices that cannot be patched due to FDA clearance constraints require compensating controls — a compliance pathway the organisation’s prior documentation had not addressed.

We had passed HIPAA assessments for years and genuinely believed our clinical network segmentation was secure. The purple team exercise found four firewall rules — created years ago by people who no longer work here — that gave an attacker a clear path from our administrative network to 14,200 clinical devices, none of which generated a single alert. That finding alone justified everything we spent on this engagement.

— Vice President of Information Security, Academic Medical Centre (anonymised)

Key Takeaways

Ready to test your Healthcare security defences?

Case Study HC-CS-03

Third-Party Supplier Compromise — NHS Trust Supply Chain

Simulating the Advanced Computer Software Group attack pattern against a regional NHS Trust’s IT supplier ecosystem

Case Studies Healthcare hc cs 03

Organisation

A mid-sized NHS acute trust serving a population of approximately 500,000 (anonymised)

Sector

Healthcare — NHS acute trust, United Kingdom

Location

England, United Kingdom

Engagement

Purple Team Exercise — Third-Party Supplier Access and Supply Chain Attack Simulation

Duration

5 weeks (2-week scoping, 1.5-day exercise, 1.5-week remediation and reporting)

Frameworks

UK GDPR / DPA 2018 | NHS DSPT Version 8 (Category 1) | ICO Advanced Enforcement Decision March 2025 | NHS England Supplier Security Charter May 2025 | NCSC CAF Objective C | MITRE ATT&CK Enterprise v15

The Situation

In March 2025, the ICO fined Advanced Computer Software Group £3.07 million for the 2022 ransomware attack that disrupted NHS 111 services — the first-ever fine against a data processor under UK GDPR. The Trust’s CISO recognised their own supplier landscape looked uncomfortably similar to Advanced’s pre-attack configuration.

 

The Trust had 47 third-party suppliers with active access to NHS systems or patient data. Of these, 31 had not been security-assessed in over 18 months. MFA was not enforced for all supplier remote access sessions. And the Trust had no real-time monitoring of supplier connection behaviour.

 

Following the ICO enforcement action and publication of the NHS England Supplier Security Charter in May 2025, the board commissioned an independent assessment: could a compromised supplier account reach patient data — and would anyone notice?

Core Challenge

Determine whether a compromised NHS IT supplier credential would allow an attacker to access patient data, escalate privileges, and operate undetected — mirroring the exact attack vector responsible for the Advanced incident.

What GLI Secure Did

We conducted a full supplier access audit — reviewing all 47 third-party supplier accounts, their access permissions, the systems they could reach, and monitoring in place on their sessions. This produced the Trust’s first complete supplier access register, a direct DSPT Version 8 requirement.

 

The exercise simulated a compromised Advanced-style supplier account: an IT support company with legitimate remote access to clinical administration systems. We used the supplier’s actual access pathway and tested whether that access could be extended to reach patient data repositories.

 

We also tested the Trust’s ability to detect and respond to the specific techniques used in the Advanced attack — credential abuse, lateral movement via legitimate RMM tools, and data staging.

The Purple Team Approach

Supplier Access Audit

Reviewed all 47 supplier accounts. Found: 23 without MFA, 8 with access broader than contracted scope, 5 accounts for suppliers whose contracts had expired.

High-Risk Supplier Identification

Identified 3 suppliers with access profiles most similar to the Advanced attack vector: remote IT support companies with broad administrative access, limited session monitoring, no just-in-time access controls.

Simulated Supplier Credential Compromise

Using a test supplier account mirroring a real high-risk supplier's access level, simulated an attacker operating from a compromised credential. Tested whether access could reach clinical administration systems.

Lateral Movement via Legitimate Tools

Tested the Advanced-documented technique: abusing legitimate remote monitoring and management tools for lateral movement. Found the Trust's environment had two RMM platforms both accessible from supplier accounts.

Patient Data Access Attempt

Tested whether the compromised supplier account could reach patient data repositories. Direct database access was blocked, but indirect access via a shared reporting system was possible.

Detection and Response Timing

Recorded time from initial simulated compromise to first alert. Tested the Trust's ability to revoke supplier access — measuring time from detection to complete access termination.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1199 Trusted Relationship (Supplier Access) Not Detected

No behavioural monitoring on supplier VPN sessions.

T1078 Valid Accounts (Supplier Credential) Not Detected

No anomaly detection on supplier account activity.

T1021.001 Remote Desktop Protocol (via RMM Tool) PARTIAL

Tool usage logged but not monitored. No alert generated.

T1543 Create or Modify System Process (Persistence) Not Detected

No monitoring on system process creation from supplier context.

T1530 Data from Cloud Storage (Reporting System) PARTIAL

Access logged but volume threshold not configured. No alert.

T1048 Exfiltration over Alternative Protocol DETECTED

DLP alert on data staging after 34 minutes.

Key Findings

Critical

Zero Supplier Session Monitoring:

No behavioural monitoring existed on any of the 47 supplier VPN sessions. An attacker using a legitimate supplier credential could operate indefinitely — the exact scenario of the Advanced attack.

Critical

5 Active Accounts for Expired Contracts:

Five supplier accounts remained active after contracts had expired — uncontrolled access pathways with no business justification.

High

Indirect Patient Data Access via Reporting System:

A shared reporting system accessible from supplier accounts contained patient-identifiable data in aggregate form. This access pathway was undocumented in the Trust’s data flow mapping or DPIA.

High

Access Revocation Speed:

From detection to complete supplier access revocation took 3 hours 47 minutes — a documented liability under NHS Supplier Security Charter Principle 6.

medium

23 Supplier Accounts Without MFA:

NHS Supplier Security Charter Principle 1 and the ICO Advanced enforcement decision both specifically address MFA as a minimum requirement. 23 of 47 accounts did not enforce MFA.

Measurable Outcomes

Supplier Accounts Without MFA 23 reduced to 0 within 21 days
Expired Contract Accounts 5 accounts terminated within 48 hours
Supplier Access Register First complete register created — DSPT v8 assertion evidence
Session Monitoring Supplier session behavioural monitoring deployed within 30 days
Access Revocation Time 3h 47m reduced to 23 minutes after process improvement
ICO Compliance Position Advanced-pattern controls documented per ICO enforcement requirements

Regulatory Impact

The exercise produced direct evidence relevant to the ICO’s March 2025 enforcement action. The ICO found that Advanced’s failure to enforce MFA and monitor privileged access was the proximate cause of the breach. The Trust’s identical risk profile — 23 accounts without MFA, zero supplier session monitoring — represented exposure that would be extremely difficult to defend before the ICO in the event of a breach.

 

The undocumented patient-identifiable data in the reporting system created a UK GDPR Article 35 DPIA gap. UK GDPR requires DPIAs for processing likely to result in high risk to individuals. Patient data accessible through a supplier-accessible, unmonitored system is precisely this category.

 

For DSPT Version 8, the exercise produced evidence for three supply chain security assertions the Trust had previously marked as ‘Standards Met’ on the basis of policy documentation. The exercise demonstrated operational reality did not match documentation.

The ICO fined Advanced £3.07 million because an NHS supplier failed to secure its access to NHS systems. When we looked at our own supplier landscape after reading that enforcement decision, we recognised we had the same problems. The purple team exercise confirmed it. More importantly, it gave us a documented remediation programme we could take to the board, to NHS England, and — if we ever needed to — to the ICO.

— Head of Information Governance, NHS Trust (anonymised)

Key Takeaways

Book a Free Healthcare Purple Team Discovery Call

GLI Secure | ISO 17025 Accredited

Strengthen your cybersecurity posture today.

Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.

Font Resize