A 14-hospital system stopped a ransomware canary before a single clinical system blinked — agentless, across 12,400 connected devices.
39s Canary to quarantine | 0 Care disruptions | 12,400 Devices, agentless | 99.99% Uptime held |
Helix couldn’t put agents on FDA-certified devices, and its EDR was blind to everything from infusion pumps to imaging. One unpatched pump was all a ransomware crew needed to pivot toward the EHR — and isolating a device risked a patient.
threatDefendr fingerprinted every connected device passively — no agents, no certification risk — and modeled normal behavior per device class. When a canary tripped, gated containment quarantined the segment, not the patient.
A ransomware canary on a legacy pump was quarantined at the segment in 39 seconds, before it could enumerate the EHR. No clinical system went offline; the care floor never saw an alert.
“It quarantined the canary in thirty-nine seconds and never touched a bedside device. My nurses never knew there was an incident.”