Annual Pentesting and Phishing Simulation for a Healthcare IT Provider

Annual Pentesting and Phishing Simulation for a Healthcare IT Provider

Industry
Software products, Healthcare, Information Technology

Summary

A US-based healthcare software and IT services company places special emphasis on regulatory compliance and cybersecurity and runs annual security testing of its IT infrastructure. As a long-term partner, INNERLUXES performed the company's annual vulnerability assessment, black-box penetration testing, and phishing simulation in just five days — surfacing fixable issues and confirming both an improved security posture on retest and the high vigilance of the company's employees.

About the Client

The Client is a US-based company specializing in healthcare software and IT services. With deep experience in the domain, the Client has helped hundreds of healthcare providers optimize their clinical information systems.

Healthcare IT vendor looking for cybersecurity experts

Working in the healthcare domain, the Client places special emphasis on regulatory compliance and cybersecurity. To perform annual security testing of its IT infrastructure and assets, the company was looking for a reliable cybersecurity provider with expertise in healthcare IT.

Long-term partnership to uphold solid cyber defenses

With deep experience in cybersecurity and healthcare IT, INNERLUXES fully met the Client's criteria for a long-term partner. Since the start of our cooperation, INNERLUXES has completed a cybersecurity risk assessment of the Client's IT infrastructure, conducted three pentests, and implemented Microsoft Defender for endpoint protection against advanced persistent threats. Satisfied with the service quality, the Client enlisted INNERLUXES's ethical hackers for the fourth annual pentest and a social engineering attack simulation.

Vulnerability assessment

INNERLUXES's pentesters started with automated scanning of the Client's web application and external network to identify as many vulnerabilities as possible, followed by manual validation of the detected issues to exclude false positives.

Black-box penetration testing

At this stage, the goal was to attempt to exploit the weaknesses and gain unauthorized access to the Client's IT infrastructure and data. INNERLUXES's team conducted penetration testing — including input data manipulation and brute forcing — according to the PTES, OWASP Web Security Testing Guide, and NIST 800-115 methodologies.

INNERLUXES revealed issues such as unencrypted data, security misconfigurations, software with known vulnerabilities, and an outdated software component. To fix these, our team recommended:

  • Encrypting the data stored in the ViewState parameter of ASP.NET — to avoid potential sensitive information disclosure.
  • Implementing the missing security headers — to enhance protection against XSS, clickjacking, and other attacks.
  • Installing the latest version of the remote web server (Microsoft IIS) — to replace the version with known vulnerabilities and mitigate the risk of confidential information disclosure and DoS attacks.
  • Updating the outdated software to the latest version — to avoid the risks associated with unsupported software that no longer receives security updates.

Social engineering testing

INNERLUXES's team examined publicly available information about the company and, based on the collected data, prepared and ran several phishing attack scenarios against the gathered employee email addresses.

The first attempt revealed that the Client's email security controls effectively protected users against phishing. The second simulation started after the Client manually whitelisted our IPs to let the attacks pass through the filters. Our pentesters sent emails with malicious URLs as well as fake invitations and forms — but the Client's employees followed safety precautions and did not open the unknown links.

Improved cybersecurity posture and confidence in employee vigilance

  • Thanks to prior knowledge of the Client's IT environment, our team performed the vulnerability assessment, penetration testing, and social engineering testing in just five days.
  • The Client received a comprehensive report on the vulnerabilities identified in its web app and external network, classified by severity in line with the OWASP Top 10 and NIST CVSS standards.
  • The report featured detailed remediation recommendations to reduce the risks of sensitive data disclosure and attacks like XSS, clickjacking, and DoS; after implementing them, the Client improved its cybersecurity posture, confirmed during a retest.
  • The social engineering simulation proved the high vigilance of the Client's employees, and the Client plans to continue engaging INNERLUXES for annual security checkups.

Technologies and Tools

Metasploit, Nessus, Burp Suite, Acunetix, Nmap, DirB, SSLScan, TLSSLed, Python, C, Perl.