HEALTHCARE

Ransomware contained
in 39 seconds.

A 14-hospital system stopped a ransomware canary before a single clinical system blinked — agentless, across 12,400 connected devices.

INDUSTRY
Hospital network
SIZE
14 hospitals · 12,400 devices
DEPLOYMENT
US private cloud
REGION
US
RANSOMWARE CONTAINMENT39s
BEFOREhours
WITH THREATDEFENDR39s
canary quarantined · 0 care impact
THE CHALLENGE

You can't reboot a cath lab.

Helix couldn't put agents on FDA-certified devices, and its EDR was blind to everything from infusion pumps to imaging. A ransomware crew only needed one unpatched pump to pivot toward the EHR — and the SOC had no way to isolate a device without risking a patient.

WHERE IT HURT
  • Agents barred from certified medical devices
  • Infusion pumps and imaging invisible to EDR
  • Isolating a device risked interrupting care
  • No shared view of IT and clinical networks
THE APPROACH

Watch everything, touch nothing.

threatDefendr fingerprinted every connected device passively — no agents, no certification risk — and modeled normal behavior per device class. When a canary tripped, gated containment quarantined the segment, not the patient.

It quarantined the canary in thirty-nine seconds and never touched a bedside device. My nurses never knew there was an incident.
PR
Priya Raman
VP Security, Helix Health
WHAT CHANGED

The outcome, measured.

39s
CANARY TO CONTAINMENT

A ransomware canary on a legacy pump was quarantined at the segment before it could enumerate the EHR.

0
PATIENT IMPACT

No clinical system went offline; the care floor never saw an alert.

12,400
DEVICES MAPPED

Every connected device is now inventoried and behaviorally baselined without an agent.

// HEALTHCARE

Ransomware contained
in 39 seconds.

A 14-hospital system stopped a ransomware canary before a single clinical system blinked — agentless, across 12,400 connected devices.

INDUSTRY
Hospital network
SIZE
14 hospitals · 12,400 devices
DEPLOYMENT
US private cloud
REGION
US
// RANSOMWARE CONTAINMENT39s
BEFOREhours
WITH THREATDEFENDR39s
canary quarantined · 0 care impact
// THE CHALLENGE

You can't reboot a cath lab.

Helix couldn't put agents on FDA-certified devices, and its EDR was blind to everything from infusion pumps to imaging. A ransomware crew only needed one unpatched pump to pivot toward the EHR — and the SOC had no way to isolate a device without risking a patient.

WHERE IT HURT
  • Agents barred from certified medical devices
  • Infusion pumps and imaging invisible to EDR
  • Isolating a device risked interrupting care
  • No shared view of IT and clinical networks
// THE APPROACH

Watch everything, touch nothing.

threatDefendr fingerprinted every connected device passively — no agents, no certification risk — and modeled normal behavior per device class. When a canary tripped, gated containment quarantined the segment, not the patient.

It quarantined the canary in thirty-nine seconds and never touched a bedside device. My nurses never knew there was an incident.
PR
Priya Raman
VP Security, Helix Health
// WHAT CHANGED

The outcome, measured.

39s
CANARY TO CONTAINMENT

A ransomware canary on a legacy pump was quarantined at the segment before it could enumerate the EHR.

0
PATIENT IMPACT

No clinical system went offline; the care floor never saw an alert.

12,400
DEVICES MAPPED

Every connected device is now inventoried and behaviorally baselined without an agent.