01The challenge
A flat network connected everything from MRI machines to visitor Wi-Fi across 14 sites. One ransomware incident at a peer hospital group made the board's risk appetite very clear — but clinical systems can't take maintenance windows, and 30% of connected devices ran operating systems too old to patch.
02The approach
We rolled out zero-trust site by site: identity-based access first, then network segmentation that isolates clinical devices without touching them, then continuous device posture monitoring. Legacy equipment that couldn't be patched was fenced behind microsegments. Every change was rehearsed on a shadow network before it touched production.
14 SITES · SHARED BLAST RADIUS
03The result
The group passed its next insurance security audit with no exceptions, and our monitoring team still watches the estate around the clock under a managed SLA.