Skip to content
Bowtie risk templates

Bowtie — Ransomware on a Hospital Network

Flat-dialect bowtie for encryption of clinical systems at an acute trust, where credential stuffing rather than phishing drives 64% of the top event and conditional access ranks as the most critical barrier.

Template previewBowtie risk
Ransomware encrypts clinical systems — acute trustHAZARDClinical systems holding live patient records acro…THREATSPREVENTIVE BARRIERSRECOVERY BARRIERSCONSEQUENCESDetonation bypassed for a trustedsupplier domainQuarterly review of the allowlist with the SOCMail gateway detonation ofattachments and links80% · detectionPhishing simulation andreporting culture40% · detectionApplication allow-listingon clinical workstations75% · controlChange freeze during the wintersurgeEmergency change routeretained for critical CVEs30-day patch SLA on edgedevices70% · controlMulti-factor authenticationon all remote access85% · controlSupplier access brokeredthrough a jump host70% · controlJust-in-time approval forsupplier sessions55% · controlPassword blocklist andbreach credential checking60% · controlConditional access withimpossible-travel blocking65% · detectionNetwork segmentationbetween clinical andcorporate75% · controlBusiness continuity planwith paper pathways60% · recoveryMutual aid agreement withthe regional network45% · recoveryRestore never rehearsed at fulltrust scaleAnnual full-scale restoreexercise with the vendorImmutable offline backupstested quarterly80% · recoveryRead-only results archiveon separate infrastructure50% · recoveryEgress monitoring on largeoutbound transfers50% · detectionRegulatory notification andpatient support plan35% · recoveryDocumented cyber assuranceframework submission40% · recoveryPhishing email openedby a member ofclinical staff4/yr → 0.12/yrUnpatchedinternet-facing remoteaccess appliance0.6/yr → 0.027/yrCompromised imagingsupplier with apersistent VPN0.35/yr → 0.0473/yrCredential stuffingagainst the staffportal2.5/yr → 0.35/yrEmergency departmentdiverts toneighbouring trustssev 5 · risk 0.1497Loss of access toimaging and pathologyresultssev 4 · risk 0.2177Patient data publishedon a leak sitesev 4 · risk 0.7075Regulatory action andpublic inquirysev 3 · risk 0.9796Clinicalsystemsencrypted by…0.5442/yrtop-event frequencyTop event0.5442/yrinherent 7.45/yrResidual risk2.05inherent 119Risk reduction98.3%threat side 92.7%Barriers174 threats · 4 consequencesDominant threatCredential stuffing against the staff p…64.3% of the top eventResidual risk 2.05 against an inherent 119 — the barriers remove 98.3% of it. 1 thing is probably not what was meant — every path and every escalation factor was checked.Barrier criticality — residual risk if that one barrier were removed1. Conditional access with impossible-travel blocking+2.45 ×2.22. Password blocklist and breach credential checking+1.98 ×23. Mail gateway detonation of attachments and links+1.81 ×1.94. Application allow-listing on clinical workstations+1.36 ×1.75. Immutable offline backups tested quarterly+0.8708 ×1.46. Egress monitoring on large outbound transfers+0.7075 ×1.3FindingsConsequence "Regulatory action and public inquiry" rests on ONE barrier. Defence in depth is the claim a bowtie is drawn to make, and a single barrier is a single point of failure: the day it fails is the day the consequence lands in full. Add a s…Each of the 4 consequences is credited the full top-event frequency of 0.5442/yr — the model here is that one top event produces all of them, so the residual score of 2.05 adds 4 outcomes to one event. That is right when they happen together and u…

Make it your own.

# Flat dialect: barriers attach to the threat above them, escalation
# factors to the barrier above them, controls to the escalation factor.
title "Ransomware encrypts clinical systems — acute trust"
hazard "Clinical systems holding live patient records across 4 sites"
top "Clinical systems encrypted by ransomware"
unit "/yr"

threat "Phishing email opened by a member of clinical staff" likelihood: 4.0
  barrier "Mail gateway detonation of attachments and links" effectiveness: 0.8 type: detection
    escalation "Detonation bypassed for a trusted supplier domain"
      control "Quarterly review of the allow list with the SOC"
  barrier "Phishing simulation and reporting culture" effectiveness: 0.4 type: detection
  barrier "Application allow-listing on clinical workstations" effectiveness: 0.75 type: control

threat "Unpatched internet-facing remote access appliance" likelihood: 0.6
  barrier "30-day patch SLA on edge devices" effectiveness: 0.7 type: control
    escalation "Change freeze during the winter surge"
      control "Emergency change route retained for critical CVEs"
  barrier "Multi-factor authentication on all remote access" effectiveness: 0.85 type: control

threat "Compromised imaging supplier with a persistent VPN" likelihood: 0.35
  barrier "Supplier access brokered through a jump host" effectiveness: 0.7 type: control
  barrier "Just-in-time approval for supplier sessions" effectiveness: 0.55 type: control

threat "Credential stuffing against the staff portal" likelihood: 2.5
  barrier "Password blocklist and breach credential checking" effectiveness: 0.6 type: control
  barrier "Conditional access with impossible-travel blocking" effectiveness: 0.65 type: detection

consequence "Emergency department diverts to neighbouring trusts" severity: 5
  barrier "Network segmentation between clinical and corporate" effectiveness: 0.75 type: control
  barrier "Business continuity plan with paper pathways" effectiveness: 0.6 type: recovery
  barrier "Mutual aid agreement with the regional network" effectiveness: 0.45 type: recovery

consequence "Loss of access to imaging and pathology results" severity: 4
  barrier "Immutable offline backups tested quarterly" effectiveness: 0.8 type: recovery
    escalation "Restore never rehearsed at full trust scale"
      control "Annual full-scale restore exercise with the vendor"
  barrier "Read-only results archive on separate infrastructure" effectiveness: 0.5 type: recovery

consequence "Patient data published on a leak site" severity: 4
  barrier "Egress monitoring on large outbound transfers" effectiveness: 0.5 type: detection
  barrier "Regulatory notification and patient support plan" effectiveness: 0.35 type: recovery

consequence "Regulatory action and public inquiry" severity: 3
  barrier "Documented cyber assurance framework submission" effectiveness: 0.4 type: recovery