Start with the attack paths that actually get used
Most hospital ransomware doesn't begin with exotic zero-days. It begins with a phished credential, an exposed remote-access service without multi-factor authentication, or a vulnerable internet-facing system. Closing these common doors — MFA everywhere, especially on remote access; disciplined patching of external systems; and phishing-resistant authentication — removes the majority of easy entries.
- Enforce MFA on all remote access and privileged accounts — the single highest-leverage control.
- Inventory and patch or isolate internet-facing systems continuously.
- Segment the network so a foothold in one area can't reach everything.
Assume breach — and plan for spread
The most damaging hospital attacks are the ones that spread. An intruder who lands on one workstation and then moves laterally to the file shares, the backups, and the clinical systems is what turns an incident into a shutdown. Microsegmentation and continuous access verification limit how far an attacker can travel once inside.
This is where prevention and resilience meet: you assume something will eventually get in, and you architect so that it can't become everything.
Protect the medical devices you can't patch
Hospitals run tens of thousands of connected devices that can't take a security agent and often can't be patched. These are frequently the attacker's entry point and hiding place. Protecting them requires network-level visibility and containment rather than endpoint software — the ability to see and quarantine a compromised device without shutting it off mid-procedure.
Make recovery a first-class control
Backups are only a defense if they survive the attack and can be restored fast and clean. That means immutable, air-gapped recovery points that ransomware can't reach or encrypt, tested regularly, and a restoration process that brings systems back in clinical priority order — not an untested tape in a drawer.
This is the piece most prevention-focused programs underinvest in, and it's the one that decides whether you can refuse to pay.
Where Immune fits
Immune is built around the assume-breach reality of hospitals. It detects ransomware behavior in seconds, contains it with automatic isolation and microsegmentation gated for patient safety, protects agentless medical devices at the network boundary, and self-heals affected systems from immutable backups in clinical order. It's the layer that turns a strong prevention program into genuine resilience.
Sources
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
