12-month penetration testing program for ING Bank Śląski
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.
Case study · IT Security
A network of 30 medical clinics, where 72 doctors see 3,200 patients a month in person and online, now meets the requirements of the NIS2 directive. We delivered MediMed software in the cloud, encrypted production data and Veeam backups, and doctors sign in over VPN with Fortinet MFA. We run the servers and SOC 24/7/365.
The client runs a network of 30 medical clinics and employs 72 doctors who see around 3,200 patients a month, both in the clinics and in online consultations. Every day it processes medical records and special-category data under the GDPR. Healthcare providers belong to the health sector, which the NIS2 directive lists among sectors of high criticality. The client’s name is covered by a non-disclosure agreement.
With the NIS2 directive and the amended Polish National Cybersecurity System Act (KSC), the client had to show that it manages risk, protects data and is ready to handle an incident within the statutory deadlines. An environment spread across 30 locations, plus online visits run from outside the clinics, made it hard to control who connects to the systems and from where. Nor was there certainty that backups could be restored after a ransomware attack. Medical data ruled out ad hoc fixes: the client needed a single partner to take over security, infrastructure and the medical software, and to watch over them around the clock.
Data on around 3,200 patients a month is protected under one NIS2-aligned security standard, across all 30 clinics and in online consultations. Each of the 72 doctors works over VPN with MFA, so a stolen password is not enough to take over an account. Medical data is encrypted both in production systems and in backups, and the immutable copy plus automated restore tests prove that Veeam backups can be recovered even after a ransomware attack. The SOC and administrators watch the environment 24/7/365, so an incident is detected and reported within the deadlines NIS2 requires. The MediMed software, cloud, infrastructure and security sit with one partner, which simplifies board oversight and answering auditors’ questions.
Does your healthcare organisation need to meet NIS2? Let’s talk about implementation.
Yes. The health sector, including healthcare providers, is listed in Annex I of the NIS2 directive. Medium-sized and large clinics and clinic networks are generally in scope. In Poland, NIS2 is implemented through the amended National Cybersecurity System Act (KSC).
It depends on the number of locations, the systems in use and the starting point. We begin with a gap analysis that shows what needs to be done and in what order, and build the implementation schedule from it.
A compromised password is one of the most common ways in. A VPN encrypts the connection to the clinic’s systems, and MFA requires a second confirmation for each sign-in, so a password alone grants no access. NIS2 explicitly lists multi-factor authentication among the recommended measures.
It is the regular, automatic restoration of backups in an isolated environment, with a check that the systems boot. That way you know backups will work after a ransomware attack before you actually need them.
The directive provides for fines of up to EUR 10 million or 2% of worldwide turnover for essential entities, and up to EUR 7 million or 1.4% for important entities. Management bodies are also accountable for overseeing cybersecurity.
Other projects
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.
A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.
How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.