How Segmentation Contains a Hospital OT Ransomware Attack
A hospital’s cybersecurity purview stretches far beyond its clinical and IT systems. The badge readers that control who enters a ward, the ventilation that holds an operating room at the right pressure, the elevators that move patients between floors: all of it depends on networked equipment that most security programs never inventory. When that equipment goes down, the building stops behaving like a hospital, even when every clinical application stays online.
That is close to what unfolded this week at Winnipeg’s Health Sciences Centre (HSC), Manitoba’s largest hospital, operated by Shared Health. The organization confirmed a ransomware incident affecting certain facility maintenance systems, including door access, heating, ventilation, and air conditioning, along with elevators. Shared Health said clinical services continued uninterrupted and that its investigation had found no indication patients were affected. No group has publicly claimed responsibility, and the initial access method has not been disclosed.
A network intrusion reaches whatever the network allows it to reach. Ransomware landed on the doors and the ventilation because nothing stopped it from moving there once it was inside. Segmentation is the control that determines how far an attacker can get by keeping building systems, clinical devices, and IT on a single open plane where anything can talk to anything. It does not stop the initial compromise. It determines whether that compromise remains contained or spreads to the parts of the hospital that keep the building running.
What The Incident Actually Shows
Ransomware has historically gone after files, email, and the systems that store them. What makes the HSC incident notable is where it landed: operational technology (OT) that runs the physical building. Access control, HVAC, and elevators are not back-office IT. They are safety-relevant systems that sit on the same converged networks as everything else, and attackers reached them.
Two takeaways follow from that. First, an attacker who can touch building systems can create physical consequences without ever touching a medical record. In the article from Healthcare Info Security, Darlene Jackson, president of the Manitoba Nurses Union, pointed to the obvious risk of doors that will not stay secured, in a building where unauthorized entry was already a documented safety concern. The blast radius of a network intrusion is measured by whatever a flat network lets the attacker reach, not by the count of encrypted servers.
Second, these systems are almost always in scope for the attacker and almost never in scope for the security program. John Strand of Black Hills Information Security, commenting on the incident, argued that operational and facilities systems have too often been treated as outside the boundary of cybersecurity. The Winnipeg attack is a direct argument that the boundary was drawn in the wrong place.
Related: How Poor Device Visibility Undermines Segmentation in Connected Environments
You Cannot Defend What You Never Counted
Every containment strategy starts with knowing what is on the network. Building management controllers, badge readers, and HVAC systems rarely accept a software agent for monitoring, so the tools built for laptops and servers miss them by design. That is exactly how facilities equipment ends up unmonitored on a network that also carries clinical and administrative traffic. That’s why the industry term “unmanaged devices” came into being.
The starting point is a single, authoritative inventory of every connected device, captured agentlessly and without disrupting operations, across IoT, OT, IoMT, and IT. Deep packet inspection and multi-source correlation fill in the detail, including services, connections, and firmware versions, but the point is the outcome: nothing on the network is invisible to the people responsible for defending it. A door controller you have never seen cannot be part of a segmentation plan.
The Reason Segmentation Stalls Is Not Technical
Most healthcare organizations already own a network access control (NAC) platform such as Cisco ISE, Aruba ClearPass, or Arista with the intention of disabling lateral movement to critical OT systems. But very few have operationalized their NACs for segmentation. The gap between a NAC that is deployed and a NAC that is actually enforcing policy is where incidents like this one live.
The reason is rarely a lack of will. It is the fear of breaking something that a hospital cannot afford to break. Clinical engineering, facilities, and IT all hold an effective veto over any change that could interrupt uptime, and they are right to. A segmentation policy that isolates the wrong flow can take down a nurse call system or an air handler, and in a hospital that is not an acceptable way to find out you made a mistake.
This is the objection that has to be answered before segmentation moves. Policy Simulation answers it by validating a policy against real, observed network traffic before anything is applied, showing exactly which devices and connections would be affected. Teams see the impact of a change against how the network actually behaves, not an estimate, and deploy only once the result is understood.
Related: Segmentation Orchestration
Segmentation Is Not A One-Time Project
Even organizations that segment well tend to treat it as a project with an end date. Networks do not cooperate. Devices are patched, decommissioned, added, and moved; IP assignments change, and firmware versions shift underneath the policy that was written for last quarter’s environment. Devices that can be moved to a different room and ethernet port will be moved.A control that was correct on the day it was deployed drifts out of alignment, and enforcement falls behind the reality on the network.
Containing the next incident depends on policy that tracks the current state of the network rather than a snapshot. Continuous Segmentation monitors whether policies still match what is actually connected and adapts as the environment changes, so the segmentation that limits a blast radius on Monday is still doing its job months later.
Reducing Risk and Preventing the Next Incident
Asimily’s Segmentation Orchestration is the intelligence and policy layer that sits on top of the NAC a hospital already owns. The NAC remains the enforcement point. Asimily supplies the device context, the risk prioritization, the policy, the simulation, and the ongoing management that turn a deployed NAC into working segmentation. It addresses the problem in order: see every device, prioritize the ones that matter using ATT&CK Analysis to confirm what is genuinely exploitable in your environment, create policy in the correct NAC-native format, simulate it against live traffic, apply it, and keep it aligned as the network changes.
The Winnipeg incident is a reminder that a network intrusion reaches whatever the network allows it to reach. The doors, the ventilation, and the elevators were reachable. Segmentation puts targets out of reach.
See how Segmentation Orchestration works: asimily.com/product/segmentation-orchestration
Secure Every IoT Device.
Automatically.
Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.