All case studies
Healthcare
Internal Network Penetration Testing

Internal network assessment for a hospital group with legacy medical systems

A carefully constrained internal assessment achieved domain administrator access in under two days through legacy credential reuse, without disrupting a single clinical system.

Client
Hospital group operating 6 sites and 4,000 endpoints
Duration
3 weeks, tightly scheduled around clinical hours
Headline issue
Domain administrator via unconstrained delegation and reused local admin passwords
Sector
Healthcare

The challenge

Medical devices could not tolerate aggressive scanning, and testing windows were limited to overnight periods with clinical staff on standby.

Our approach

  • Agreed strict rules of engagement: no active exploitation on clinical VLANs, passive discovery only during clinical hours.
  • Focused on identity: Active Directory misconfiguration, credential hygiene and delegation paths.
  • Provided a live escalation channel with the IT duty manager throughout testing.

Outcome

  • Domain-wide credential reuse eliminated with a tiered administration model.
  • Legacy service accounts rotated and constrained delegation removed.
  • Zero clinical service disruption across the engagement.