WhitepaperRansomware Readiness: A Field Playbook for East African Enterprises
The decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
Clinical continuity first. We secure patient records, hospital information systems and connected medical devices without introducing risk to the care being delivered around them.

Patient records are the most sensitive data you hold.
Healthcare carries a constraint most sectors do not: the systems that most need securing are the ones that cannot be interrupted, and the consequence of getting it wrong is clinical rather than commercial. A scan that takes an imaging modality offline is not an acceptable cost of an assessment.
It also carries the most sensitive data category in the Act. Health records are sensitive personal data, which raises the bar on lawful basis, access control, retention and onward disclosure — to laboratories, insurers, third-party administrators and national claims platforms alike.
Our healthcare work is passive and clinically-aware by default. We map the estate from traffic and configuration rather than active probing, run any active testing against non-production systems or inside agreed windows, and prioritise the two things that most reliably protect patients: the ability to keep operating through a ransomware event, and control over who can reach patient records.
In a hospital the impact is not data loss but the loss of the systems care is delivered through — records, orders, results, scheduling. Documented downtime procedures and a measured restore time are patient-safety controls, not IT ones.
Modalities, monitors and the systems that store and distribute images frequently run unpatchable software on flat networks, sometimes reachable from general staff areas. Segmentation and monitoring carry these assets where patching cannot.
Credential sharing on wards is a response to real workflow pressure — a clinician cannot stop to re-authenticate mid-procedure. The answer is authentication designed for the workflow, not a policy telling staff to work slower.
Bulk export capability inside hospital information systems, often held by a wider group than anyone intends, is the most direct path to a large personal data breach. Export should be constrained, logged and alerted on.
Finance and procurement functions in hospitals are targeted the same way as anywhere else, with the added consequence that a compromised mailbox in a clinical organisation usually contains patient information.
Laboratories, pharmacies, referral partners, insurers and claims platforms all exchange patient data with you. Each interface needs its own authentication, its own minimum-necessary data scope and its own breach-notification route back to you.
The sequence below is what a healthcare engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Healthcare teamPassive network discovery, configuration review and interviews come first. Anything active is scoped, scheduled and authorised separately, with clinical engineering involved in the decision rather than informed of it.
We verify that a backup copy exists which production credentials cannot delete, rehearse a restore of a clinical system, measure how long it actually takes, and write the downtime procedures that cover the gap.
Medical devices move into their own zones with explicitly permitted flows, so an unpatchable modality stops being an open route into the record system and becomes a monitored, contained asset.
A data map covering every system holding health data, retention rules that are enforced rather than documented, a working process for data subject requests, and a notification runbook that meets the seventy-two-hour clock.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperThe decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Threat AdvisoryObject storage left world-readable remains one of the most common causes of data exposure we find. The detection and prevention controls are inexpensive and rarely switched on.