Healthcare Security in Focus: Applying Lessons from Real-World Penetration Tests
Автор: BreakPoint Labs
Загружено: 2026-02-06
Просмотров: 35
Описание:
Standard vulnerability scans often miss the high-impact risks that lead to real-world breaches. In this collaborative webinar with Health-ISAC, Andrew McNicol of Breakpoint Labs shares actionable insights from 16 years of "hacking hospitals" to help healthcare leaders move beyond compliance and toward true resiliency.
This session explores how attackers bypass traditional defenses by exploiting application logic, misconfigured Active Directory environments, and human error. Andrew also discusses five key takeaways developed in coordination with HHS OIG to help hospitals secure their most critical, life-supporting systems.
Key Moments & Timestamps
00:00 – Introductions: Healthcare Security in Focus
03:47 – Phase 1: Planning a Pen Test for Life-Supporting Systems
07:43 – The Hybrid Approach: Why Purple Teaming is Essential
10:13 – Reducing Risk: The "Assumed Breach" Scenario
15:00 – How a Pen Test Mirrors Real Adversary Behavior
18:30 – Beyond CVEs: Why Attackers Abuse Application Logic
21:30 – The Help Desk Backdoor: Bypassing MFA with a Single Call
26:19 – Brute-Forcing "Secret Questions" with AI Assistance
30:52 – Active Directory Hazards: Why "Disabled" Accounts Can Still Be Abused
37:38 – Network Shares & Snaffler: Finding Exposed Sensitive Data
39:53 – Physical Security Bypass: Using Compressed Air to Unlock Doors
46:00 – AI in Healthcare: Governance, Procurement, and Feature Abuse
49:12 – 5 Key Takeaways for Resilient Security (Developed with HHS OIG)
52:45 – Q&A: Corporate Entity Risks and Medical Device Segmentation
Resources:
Visit our Blog & Video Hub: Explore deep dives on Active Directory security and technical attack walkthroughs at https://breakpoint-labs.com/blog/ https://breakpoint-labs.com/videos/
Presented by Andrew McNicol: Cybersecurity expert, penetration tester, and security strategist. Andrew specializes in uncovering the hidden risks in business processes and physical security layers that leave organizations vulnerable to real-world attacks.
#HealthcareSecurity #HealthISAC #PenetrationTesting #CISORisk #HHS
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: