Case Study · Healthcare / Clinical

Cybersecurity Remediation and Hardening After a Close Call

A near-miss phishing incident prompted a Northern Ontario clinic to have us rebuild its security baseline. The result: MFA, conditional access, EDR, email security, immutable backups, and documented controls built with PHIPA considerations and cyber-insurance requirements in mind.

Industry
Healthcare / Clinical
Size
Multi-site clinical practice
Region
Northern Ontario

Client name and confidential details have been omitted. Specifics generalized to protect the business.

The Challenge

  • Phishing email harvested a credential; the account was used briefly before being noticed
  • No MFA on Microsoft 365; legacy authentication still enabled
  • Endpoint protection was the default Windows tool with no central management
  • Backups configured but never test-restored and not isolated from production credentials
  • Cyber-insurance renewal questionnaire could not be answered accurately

Environment

  • Microsoft 365 tenant used for email and files
  • Mixed clinical workstations across sites
  • Existing backup solution without immutability or isolated credentials
  • Environment with PHIPA considerations and cyber-insurance requirements

Assessment

  • Conducted incident triage: scoped account access, reset credentials, reviewed sign-in logs
  • Performed a Microsoft 365 tenant security review (Secure Score and manual control review)
  • Reviewed endpoint coverage and patch status across clinic workstations
  • Reviewed backup configuration and retention against PHIPA considerations and ransomware scenarios

The Solution

  • Enabled MFA tenant-wide and rolled out conditional access policies
  • Disabled legacy authentication and tightened external-sharing defaults
  • Deployed centrally managed endpoint protection (EDR) on workstations and servers
  • Implemented advanced email filtering and anti-impersonation policies
  • Redesigned backup using a business-grade backup solution with an immutable cloud repository and isolated credentials
  • Documented controls in a single security baseline document to support insurance and PHIPA review discussions

Results

Enhanced security posture

MFA and conditional access enforced across staff, contractors, and admins.

Reduced operational risk

Legacy authentication disabled and email filtering strengthened against impersonation.

Increased resilience

Backup redesigned with immutable retention and isolated credentials.

Standardized

Security controls documented in a single baseline to support insurance and PHIPA review discussions.

Technologies Used

  • Microsoft 365
  • Conditional Access
  • Centrally managed endpoint protection (EDR)
  • Business-grade backup with immutable retention
  • Email security

Supported technologies in this project

See what we support around each platform on our supported technologies hub.

Facing something similar?

Book a free 30-minute consultation. Serving Greater Sudbury, Northern Ontario, and surrounding communities. Remote support available throughout Ontario.

Keep exploring

Related services, industries, and resources

Helpful resources