EmberKat
Experience/Medical device manufacturing

Over 200 findings traced back to four kinds of exposure.

A group-commissioned assessment returned more than 200 findings at a manufacturing subsidiary. The list was not 200 problems.

A medical imaging product connects a tangled infrastructure base to a separated delivery and evidence path.
Engagement record

The medical-device engagement separated infrastructure dependencies, product delivery and release evidence without interrupting the imaging workflow.

A corporate group commissioned an independent security assessment of one of its manufacturing subsidiaries, covering external resources, exposed endpoints and public data. It returned more than 200 findings, ordered the way the tooling produced them, with no indication of which ones shared a cause.

Nobody at the subsidiary could act on it

Security there was not a department. It was one long-serving employee carrying the responsibility alongside another job, with no additional headcount. The report named what was wrong. It did not say what any single item meant for this company, which of them were the same problem seen from different angles, or where to start.

One session established what was underneath

Every finding traced back to four kinds of exposure. Each one had been generating dozens of separate entries in the report.

  1. 01

    Production equipment reachable from the internet

    Machinery that was never intended to have a route to or from the public internet had one.

  2. 02

    Email authentication misconfigured

    Records were in place but configured so that mail from the company domain could still be spoofed — to its customers, its suppliers and its own staff.

  3. 03

    A web server past its support life

    Still serving, and carrying the long tail of publicly known issues that comes with it.

  4. 04

    Internal tooling exposed outside its boundary

    Several tools built for an internal network were reachable from outside it.

The list was not 200 problems. It was four, counted 200 times.

Remediation ran on four different clocks

Email authentication took hours. Separating the production equipment from the internet was a planned change with downtime, agreed around a manufacturing schedule. Treating those two as one backlog is what had kept the list frozen.

  • Delivered entirely remotely — no site visit, no travel cost, no scheduling around one.
  • For changes the subsidiary could make itself, the work was to state precisely what to change and why.
  • For the rest, the client granted remote access and the changes were made directly.

Everything in scope closed. What was deliberately accepted was written down with a reason rather than left open, so the next assessment starts from a decision instead of a gap.

What each side got

The group got a subsidiary it could sign off. The subsidiary got its first explanation of what the findings meant and where the requirements came from. That is the part that decides whether the same list returns next year.

The wider pattern

The conditions that produced this — software as the product, requirements set by someone else, consequences beyond the bug tracker — are not specific to medical devices. What a buyer asks for, and which instrument creates the duty, is set out separately.

Regulated product software

Related engagement

Findings Translation Sprint

10 business days. Findings grouped by root cause, with owners, priorities and closure criteria. Starting at €6,500 excl. VAT.

View engagement