Over 200 findings traced back to four kinds of exposure.
A group-commissioned assessment returned more than 200 findings at a manufacturing subsidiary. The list was not 200 problems.

The medical-device engagement separated infrastructure dependencies, product delivery and release evidence without interrupting the imaging workflow.
A corporate group commissioned an independent security assessment of one of its manufacturing subsidiaries, covering external resources, exposed endpoints and public data. It returned more than 200 findings, ordered the way the tooling produced them, with no indication of which ones shared a cause.
Nobody at the subsidiary could act on it
Security there was not a department. It was one long-serving employee carrying the responsibility alongside another job, with no additional headcount. The report named what was wrong. It did not say what any single item meant for this company, which of them were the same problem seen from different angles, or where to start.
One session established what was underneath
Every finding traced back to four kinds of exposure. Each one had been generating dozens of separate entries in the report.
- 01
Production equipment reachable from the internet
Machinery that was never intended to have a route to or from the public internet had one.
- 02
Email authentication misconfigured
Records were in place but configured so that mail from the company domain could still be spoofed — to its customers, its suppliers and its own staff.
- 03
A web server past its support life
Still serving, and carrying the long tail of publicly known issues that comes with it.
- 04
Internal tooling exposed outside its boundary
Several tools built for an internal network were reachable from outside it.
The list was not 200 problems. It was four, counted 200 times.
Remediation ran on four different clocks
Email authentication took hours. Separating the production equipment from the internet was a planned change with downtime, agreed around a manufacturing schedule. Treating those two as one backlog is what had kept the list frozen.
- Delivered entirely remotely — no site visit, no travel cost, no scheduling around one.
- For changes the subsidiary could make itself, the work was to state precisely what to change and why.
- For the rest, the client granted remote access and the changes were made directly.
Everything in scope closed. What was deliberately accepted was written down with a reason rather than left open, so the next assessment starts from a decision instead of a gap.
What each side got
The group got a subsidiary it could sign off. The subsidiary got its first explanation of what the findings meant and where the requirements came from. That is the part that decides whether the same list returns next year.
The wider pattern
The conditions that produced this — software as the product, requirements set by someone else, consequences beyond the bug tracker — are not specific to medical devices. What a buyer asks for, and which instrument creates the duty, is set out separately.
Regulated product software