Skip to main content
All customer stories
Healthcare — hospitals and diagnostics

External Estate Reconciliation for a Multi-Country Hospital Group

Client: A private hospital and diagnostics group running 14 hospitals and 63 diagnostic centres across three markets in the Gulf and South Asia, with around 11,000 staff and a central security function of nine people · details anonymised

The Challenge

An inventory accurate on the day it was signed off, and decaying in both directions from that moment

The security team was repeatedly asked a question it could not answer from any single source: what of ours is reachable from the internet right now, and who owns it? It had an ITSM CMDB, rebuilt eighteen months earlier during a service-management consolidation by asking each operating entity's IT lead to submit what they ran. It had a commercial vulnerability scanner whose target list was generated from those records. What it did not have was any independent view of what actually responded — so it had no way to detect either kind of drift, and no way to tell a genuinely undocumented system from the fifth front door onto an application already recorded.

The Solution

Discovery first, reconciliation against the customer's own record, and validation only where it was safe and authorised

ShadowMap ingested the group's CMDB export as one input to reconciliation rather than as the scope boundary, then ran external discovery for nineteen days before any active validation was enabled. The output was not a list of assets. It was a list of governance failures, categorised by type: never recorded, recorded but no longer responding, recorded on one domain only, and duplicate front door onto a known application. Ownership of anything ShadowMap could not attribute was routed to the group rather than assumed.

The Results

The inventory stopped being a snapshot and became a control

At the ninety-day review the group had withdrawn 530 access paths from public reachability, closed 505 stale records, opened 422 new ones with named owners, and moved the matched share of its live external estate from 69% to 96%. The vulnerability scanner's target list grew by 422 hostnames — the same scanner, the same licence, now pointed at the estate rather than at the record of it. The group's Security Rating moved from C to B over the quarter, with the score history in the platform showing which remediation step moved the number.

Full Case Study

· 5 min read

The question neither instrument could answer

The group owned both tools in the question. Its ITSM platform held 1,430 records for externally facing systems, rebuilt eighteen months earlier during a service-management consolidation by asking each operating entity's IT lead to submit what they ran. A commercial vulnerability scanner ran weekly against a target list generated from those records and reported coverage in the high nineties.

Reconciling that record against what actually responded from outside produced two numbers running in opposite directions. 505 of the 1,430 records — 35% — described systems that did not resolve, or did not respond at any point in a nineteen-day observation window. At the same time, 422 hostnames that did respond had no record in the CMDB at all — roughly a third of everything found live. The inventory was inflated and incomplete simultaneously, and neither error is detectable from inside, because both are defined against ground truth the inventory has no access to. The scanner inherited that blind spot exactly. It was scanning the list it had been handed, correctly, and that list was a third dead and missing a third of the estate. Its coverage figure was a measure of the paperwork.

That is the delta. A CMDB is a record of intent, populated at provisioning and decaying from the moment it is signed off. A scanner is an instrument of execution against a list somebody else maintains. Neither is a source of truth about reachability, and no amount of discipline inside the organisation produces one.

Why this estate had drifted

The sprawl was not carelessness; it was the shape of the business. Nine of the fourteen hospitals joined by acquisition over eleven years. Each arrived with its own domains, its own appointment and report-retrieval portals, and its own IT team, and every consolidation programme had reasonably prioritised clinical systems over the public estate. Two acquired diagnostic brands were still serving patient-facing report downloads on their original domains, under their original certificates.

On top of that sat two faster-moving layers. Teleconsultation and home-collection booking were built in weeks during 2020–21 by whichever team could move first, largely outside the provisioning route the CMDB records. And the group's medical-tourism business commissions per-source-market landing pages, consultant microsites and agent portals through marketing agencies, at a rate the change-advisory board never sees.

What discovery returned

Across the observation window ShadowMap found 1,347 responsive hostnames presenting 2,410 distinct access paths. Of those hostnames, 925 matched a CMDB record and 422 did not — 46% more live systems than the documented and still-responding portion of the inventory.

Content fingerprinting then collapsed the 2,410 access paths onto 690 unique logical applications. Much of the duplication was structural rather than accidental: one shared appointment platform was served under fourteen hospital-branded hostnames plus three legacy acquisition domains, and each of those seventeen front doors carried its own certificate, its own edge configuration and its own patch state. Hosts returning redirects, errors or empty bodies were counted rather than discarded — a host that serves nothing still publishes a certificate whose subject alternative names disclose further estate, and several of the undocumented hostnames were found that way.

291 access paths — 12% — were explicitly non-production: UAT, staging, sandbox, demo and, distinctively for this sector, 84 clinical training instances of patient-facing systems, the class most likely to have been seeded with copied production data.

Making 2,410 access paths into a week of work

Of the 422 undocumented hostnames, 275 fingerprinted back to applications the group already recorded — campaign domains, marketing redirects, mirrors — and were correctly downgraded rather than escalated. That left 147 genuinely unattached to any recorded system. Applying a stated signal test, 38 either served real content or carried a name indicating a sensitive function, resolving to 31 logical applications surfaced for action. From 2,410 discovered access paths to 31 things to do: roughly 78:1.

The test is documented in the report rather than applied silently, so the group can audit what was excluded. AI Review's low-value results sit in a Filtered by AI queue that stays fully visible and reviewable; nothing is deleted.

A separate bucket of 62 hostnames referenced the group's brands but was registered to third parties — consultants' private practice sites, medical-tourism facilitators, one franchised collection centre. ShadowMap does not adjudicate ownership. These were routed to the group to confirm as authorised or act on. They were surfaced, not dismissed.

Among the 31: a tele-radiology image viewer from a 2021 pilot, reachable without the group's SSO; a clinical-trials document-exchange server run by the research office; a biomedical vendor's remote-support host for an infusion-pump fleet; a staff rostering application for one country's operation; a print-queue management console at two sites; two hosts still offering plaintext file transfer for nightly billing files to an insurance clearing house.

What was validated, and what deliberately was not

CART was not enabled at go-live. Discovery and enumeration ran first; validation was introduced from week five, with every host tagged clinical or medical-device-adjacent excluded by configuration.

Within that scope, the print-management console was confirmed to accept a default credential pair — a real authenticated response, evidence retained, nothing modified, and the request carrying an audit identifier so the group could reconcile the activity in its own logs. A suspected default on the rostering application was tested and confirmed not working; the finding was demoted but kept, because the console should not have been publicly reachable either way.

The radiology viewer was not tested. ShadowMap confirmed the login interface was reachable and did not enforce the group's SSO, and stated plainly that no authentication attempt was made and no studies were enumerated, with a request that the group verify internally. In the same window, the Data Exposure module's object-storage and open-database checks returned zero findings for the group — reported explicitly, because a module that finds nothing still evidences that it looked.

What changed

Non-production reachability was withdrawn in three change windows, removing 291 access paths at once. The radiology viewer went behind SSO in eleven days. The plaintext transfers were replaced. Three legacy acquisition domains were retired and their duplicate front doors collapsed. 505 stale records were closed and 422 opened with named owners.

At ninety days: publicly reachable access paths down from 2,410 to 1,880; the live estate matched to inventory up from 69% to 96%; median time from first observation of a new undocumented host to a named owner, four days. The Security Rating moved from C to B.

The governance change outlasts the numbers. Reconciliation now runs continuously against the ServiceNow CMDB, so drift is a ticket rather than an audit finding. Assets are tagged by operating entity, so each hospital CIO receives their own inventory, their own open-exposure count and their own rating trend — and the group's rating is computed from what responds, not from what was recorded. A rating derived from an inventory is a rating of the record. This one is a rating of the estate.

Related to

CMDB reconciliation external attack surface management asset inventory drift shadow IT discovery unknown internet-facing assets healthcare attack surface management vulnerability scanner coverage gap external asset discovery hospital group cyber security non-production environment exposure

Ask what ShadowMap would find on your assets.

A 30-minute live walk-through with a ShadowMap engineer on your own domains. We map you live; you keep the report whether or not you choose to engage.