1000 Ways to Die: The Convergence of IT/OT in Hospitals
Hospitals are a perfect example of a complex System of Systems. Their infrastructure is like a small city, with multiple, independent, operationally distinct systems that interact to deliver healthcare services to users at the end of the day. No single system controls the whole, instead, clinical services emerge from the coordinated behavior of clinical, administrative, and logistical subsystems.
This also mean multiple single points of failure. And the convergence of IT and OT in this small cities we call hospitals is ramping up their cascading risk profiles. In this talk, we will explore 1000 ways do die, from delayed surgeries caused by a ransomware attack on the scheduling software to patient evacuation from HVAC systems, from infusion pumps being manipulated to target kills to medical data exfiltration to some country in Asia, from backup generator damage to DICOM clinical image manipulation.
We will marathon through many different scenarios, protocols and technologies, highlights as much as possible about the challenges hospitals face in this world where everything seems connected, online and at the reach of a button.
Modern hospitals are much more than just medical facilities: they are hyper-connected "small cities" functioning as a complex System-of-Systems. I want invite the audience to think about this system of systems concept and the potential cascading failures that can happen (and examples of failures that did happen). It all started when a close relative had to be transported by taxi from the biggest hospital in Antwerp in Belgium to Brussels because... ransom. Taxi, yes, they were out of ambulances.
While the convergence of Information Technology (IT) and Operational Technology (OT) has revolutionized patient care, it has simultaneously expanded the attack surface into a lethal playground of cascading risks. In this session, we explore the terrifying reality of a world where everything is online and a single button press can have fatal consequences.
We will dissect a "thousand ways to die" in the modern clinical environment, moving beyond simple data breaches to high-consequence physical scenarios. Attendees will journey through a mix of academic and real world scenarios like:
The Logistical Collapse: How ransomware on a scheduling app can paralyze a surgical wing.
The Infrastructure Sabotage: Forcing patient evacuations via HVAC manipulation or damaging backup generators.
The Targeted Strike: Manipulation of infusion pump dosages and the surgical alteration of DICOM clinical images.
The Geopolitical Shadow: The reality of medical data exfiltration and foreign state actors.
I will present results for internet wide scans in IT, OT and BMS protocols throughout the entire 2025, presenting examples of some of the more intriguing examples of exposures found in the wild.
Through a rapid-fire exploration of protocols, legacy vulnerabilities, and interconnected dependencies, this talk highlights the invisible "single points of failure" that threaten the resilience of global healthcare. This talk will highlight the friction between connectivity and safety, where the goal is very different from conventional "uptime". The goal is survival.
Pedro Umbelino holds the position of Principal Research Scientist at Bitsight and co-chairs the FIRST Time Security SIG.
His eclectic curiosity has led to the uncovering of vulnerabilities spanning a variety of technologies, highlighting critical issues in multiple devices and software, ranging from your everyday smartphone to household smart vacuums, from the intricacies of HTTP servers to the nuances of NFC radio frequencies, from vehicle GPS trackers to blowing up gas stations ATGs.
Pedro is committed to advancing cybersecurity knowledge and somehow help fixing Y2K38.
He has shared his findings at prominent conferences, including Bsides Lisbon, BruCON, Critical Effect, DEFCON, FIRST, Hack.lu, RSAC or Underground Economy.