Immune — Self Heal, an iStudio Technologies product

Containment & Microsegmentation

Stop ransomware from spreading across the hospital

An attack that reaches one system is an incident. An attack that spreads to hundreds is a catastrophe. Immune's containment stands between the two — isolating threats and segmenting the network the moment an attack is confirmed, so a foothold never becomes a hospital-wide shutdown.

Immune contains confirmed threats in seconds through automatic host isolation and network microsegmentation — blocking lateral movement while gating any patient-care-impacting action behind human approval.

< 30sto contain a confirmed event
Patient-safecare-impacting actions gated
Fail-securekeeps enforcing if isolated

Why spread is the difference between an incident and a disaster

The reason a ransomware attack can close an entire hospital is rarely that the first system was so important. It is that the attacker was able to move from that first system to everything else. Hospital networks are often flat and densely interconnected, which is convenient for clinical workflows and disastrous for security, because it means a single compromised workstation can reach file shares, servers, imaging archives, and the systems that hold the backups. The attacker's entire strategy depends on this freedom of movement — the lateral spread from a small foothold to the whole environment.

Containment is the discipline of taking that freedom away. If a compromised system cannot reach its neighbors, the attack has nowhere to go. It stalls in a tiny corner of the network while the rest of the hospital keeps running. This is why containment, and the microsegmentation that underpins it, is arguably the single most important control for surviving a ransomware attack: it is what turns a potential disaster back into a manageable incident.

See it in action

The containment console shows every segment, its posture, and active isolation actions — with patient-care-impacting decisions gated behind one-click approval.

app.immuneselfheal.com
Immune containment and microsegmentation console — live isolation actions

Features

What containment provides

Host isolation

Separates a compromised system from the network so it can't be used to reach others.

Network microsegmentation

Divides the network into controlled zones that block lateral movement at the boundaries.

Malicious-source blocking

Cuts off the attacking identity, device, or address at the network boundary.

Credential revocation

Revokes compromised credentials and their active sessions to close the attacker's access.

Device quarantine

Isolates agentless medical devices at the network layer without powering them down.

Boundary auto-tightening

Reduces permitted sources and narrows segments automatically when a threat is confirmed.

How it works

How containment works

1

Receive the verdict

The detection engine confirms a threat with a confidence score and identifies the affected systems.

2

Choose the safest action

Immune selects the least disruptive actions that will stop the spread, based on your policy.

3

Act autonomously where safe

Low-risk actions — blocking a malicious source, isolating a non-clinical host — run immediately.

4

Gate care-impacting actions

Anything that could interrupt live patient care awaits a one-click human approval, while the source stays blocked.

5

Preserve continuity

A continuity mode keeps safe, read-only record access alive where possible, then hands off to recovery.

Advantages

The advantages of automatic containment

Contained blast radius

An attack is confined to a small zone instead of reaching critical systems.

Seconds, not hours

Confirmed encryption events are contained fast enough to actually matter.

Patient-safety first

Care-impacting actions are always gated behind human approval.

Safe for devices

Medical devices are quarantined, never shut down, preserving patient safety.

Fail-secure

The boundary keeps enforcing even if the control plane is unreachable.

Clean handoff to recovery

Once contained, self-healing restores exactly what was affected.

Use cases

Where containment matters

Halting lateral spread

Stop a compromised workstation from reaching servers, shares, and archives.

Isolating a compromised host

Separate an infected system while the rest of the hospital keeps running.

Quarantining a device

Cut a medical device off the network without interrupting its clinical function.

Cutting off the attacker

Block the malicious source and revoke its credentials in seconds.

Fast, but never reckless

Automatic where it's safe, human-approved where it counts

Speed matters enormously in containment — every second a threat spreads adds cost and risk — but speed cannot come at the expense of patient safety. A security system that automatically shut down a server in the middle of a surgery would be causing harm in the name of preventing it. Immune acts autonomously on the actions that are clearly safe and low-risk, because waiting on those would only help the attacker. For any action that could interrupt live patient care, it pauses and presents the security team with a clear, one-click decision — while continuing to block the malicious source in the meantime. The goal is to shrink the attack's footprint to the smallest possible size while keeping the hospital functioning.

Common questions

Containment and microsegmentation, answered

+How does microsegmentation stop ransomware?

Microsegmentation divides the network into tightly controlled zones so that a compromised system cannot freely reach others. When ransomware tries to spread, the segmentation boundaries block its lateral movement, containing the attack to a small area instead of letting it reach the whole hospital.

+What is ransomware containment?

Containment is the set of actions that stop a confirmed attack from spreading: isolating affected hosts, blocking the malicious source, revoking compromised credentials, and tightening network boundaries. Immune performs these automatically for low-risk actions and with human approval for anything that could affect patient care.

+Will automatic containment disrupt patient care?

Immune gates any containment action that could affect live care behind a one-click human approval, and quarantines medical devices at the network layer rather than shutting them down. Low-risk actions, like blocking a malicious source, run automatically; higher-impact ones wait for a human decision.

+How fast does Immune contain an attack?

Immune aims to contain a confirmed encryption event within about thirty seconds of the triggering signal, subject to the approval rules you configure — fast enough to stop the spread before it reaches critical systems.

+What is a continuity mode?

During containment, Immune can hold the environment in a continuity mode that preserves safe, read-only access to critical records where possible, so clinicians are not left completely without information while the response plays out.

+Does containment work for agentless devices?

Yes. Medical devices that cannot host an agent are contained by network quarantine — isolating their connectivity without powering them down — so an attack path is severed while the device stays safe for the patient.

Keep one compromised system from becoming a hospital-wide shutdown

Book a demo and see how Immune isolates threats and segments the network in seconds — safely, with patient care always in mind.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.