Bowtie — Ransomware on a Hospital Network
Flat-dialect bowtie for encryption of clinical systems at an acute trust, where credential stuffing rather than phishing drives 64% of the top event and conditional access ranks as the most critical barrier.
Make it your own.
# Flat dialect: barriers attach to the threat above them, escalation
# factors to the barrier above them, controls to the escalation factor.
title "Ransomware encrypts clinical systems — acute trust"
hazard "Clinical systems holding live patient records across 4 sites"
top "Clinical systems encrypted by ransomware"
unit "/yr"
threat "Phishing email opened by a member of clinical staff" likelihood: 4.0
barrier "Mail gateway detonation of attachments and links" effectiveness: 0.8 type: detection
escalation "Detonation bypassed for a trusted supplier domain"
control "Quarterly review of the allow list with the SOC"
barrier "Phishing simulation and reporting culture" effectiveness: 0.4 type: detection
barrier "Application allow-listing on clinical workstations" effectiveness: 0.75 type: control
threat "Unpatched internet-facing remote access appliance" likelihood: 0.6
barrier "30-day patch SLA on edge devices" effectiveness: 0.7 type: control
escalation "Change freeze during the winter surge"
control "Emergency change route retained for critical CVEs"
barrier "Multi-factor authentication on all remote access" effectiveness: 0.85 type: control
threat "Compromised imaging supplier with a persistent VPN" likelihood: 0.35
barrier "Supplier access brokered through a jump host" effectiveness: 0.7 type: control
barrier "Just-in-time approval for supplier sessions" effectiveness: 0.55 type: control
threat "Credential stuffing against the staff portal" likelihood: 2.5
barrier "Password blocklist and breach credential checking" effectiveness: 0.6 type: control
barrier "Conditional access with impossible-travel blocking" effectiveness: 0.65 type: detection
consequence "Emergency department diverts to neighbouring trusts" severity: 5
barrier "Network segmentation between clinical and corporate" effectiveness: 0.75 type: control
barrier "Business continuity plan with paper pathways" effectiveness: 0.6 type: recovery
barrier "Mutual aid agreement with the regional network" effectiveness: 0.45 type: recovery
consequence "Loss of access to imaging and pathology results" severity: 4
barrier "Immutable offline backups tested quarterly" effectiveness: 0.8 type: recovery
escalation "Restore never rehearsed at full trust scale"
control "Annual full-scale restore exercise with the vendor"
barrier "Read-only results archive on separate infrastructure" effectiveness: 0.5 type: recovery
consequence "Patient data published on a leak site" severity: 4
barrier "Egress monitoring on large outbound transfers" effectiveness: 0.5 type: detection
barrier "Regulatory notification and patient support plan" effectiveness: 0.35 type: recovery
consequence "Regulatory action and public inquiry" severity: 3
barrier "Documented cyber assurance framework submission" effectiveness: 0.4 type: recovery