24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Healthcare · 2026
Healthcare · Case 2026

Cryptomining botnet on MR/CT devices at a 300-bed hospital · ICU monitors protected

At a 300-bed public hospital, IT noticed packet delay on ICU monitors from the medical device network. 47 devices (MR, CT, biochemistry) were cryptomining with a Mirai variant + Monero miner. DSET isolated the medical device VLAN, secured the ICU; after IEC 80001 + ISO 27799 compliance, 24 months clean, and the Ministry of Health awarded a "model hospital" title.

Duration
2 hours of containment · 90 days of IEC 80001 compliance
Scope
47 infected medical devices · 300 beds · 0 packet loss in the ICU
Customer Satisfaction
★★★★★

01 The Challenge

An IT analyst saw in Wireshark that the medical device VLAN was generating 78% CPU (normal 15%). Packet delay on the ICU monitors = a vital monitoring risk. 47 devices infected (Hikvision firmware exploit + Monero miner XMRig). Attack vector: device default credentials (admin/12345) + a medical VLAN ↔ IT VLAN bridge. One patient in critical condition experienced a monitoring problem (was saved).

02 DSET's Approach

01

T+0 · VLAN isolation

The medical device VLAN was isolated immediately, the network split. ICU monitor packet delay recovered and patient safety was ensured.

02

T+4h · USOM coordination

Ministry of Health notification + USOM coordination. Within 4 hours 3 other hospitals were diagnosed with a similar situation and national coordination began.

03

T+24h · Manufacturer support

Coordination with GE Healthcare + Siemens + Hikvision. Firmware reset per device 90 min × 47 devices = 70 hours of workload.

04

T+1 week · Medical IDS

DSET installed a medical device IDS (like Imperva Medigate). A separate SIEM for the medical VLAN, data leakage monitoring.

05

T+45 days · IEC 80001 architecture

DSET healthcare-sector security architecture: IEC 80001 + ISO 27799 compliance. Medical device segmentation + zone & conduit.

06

T+90 days · Ministry audit

The Ministry of Health "Critical Infrastructure Cyber Security" audit was successful. The KVKK "health data protection" special audit was also passed.

07

T+24 months · Certification

DSET 24-month annual audit + quarterly tabletop. The Ministry of Health awarded a "model hospital" title. Insurance premium 30% discount.

03 Results in Numbers

0
ICU packet loss
2 hours
Containment time
Full
IEC 80001 compliance
0
KVKK penalty
Model hospital
Ministry title
30% discount
Insurance premium

04 Customer Testimonial

"

With a patient's life under threat, DSET's decision to isolate the VLAN in 2 hours saved us. Thanks to the IEC 80001 architecture we passed the Ministry of Health audit as a model.

Chief Physician
300-bed Public Hospital
★★★★★

05 Key Takeaways

The medical device VLAN must be physically separated from IT; logical segmentation is insufficient
Default credentials (admin/12345) are still common on medical devices and must be changed in the procurement contract
USOM coordination + manufacturer support is possible within 24 hours for an attack; a hospital should not solve it alone
IEC 80001 compliance is the gold standard for Ministry of Health + KVKK audits

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms