Cybersecurity & Protection

Crisis Simulation Shows How Fast a Hospital Cyberattack Becomes a Stress Test

Sep 18, 2026 6 min read
All articles

What initially sounds like a routine IT security incident can turn into an existential crisis for a hospital within a matter of hours. At the anniversary conference of German hospital IT directors in Berlin, Professor Sebastian Schinzel and Nico Brüggemann from Fraunhofer SIT demonstrated how to make that moment tangible. One of their goals was to find out whether a hospital stays capable of acting once its IT fails.

Schinzel, who has worked in IT security for more than 20 years and previously worked as a penetration tester himself, says he has never experienced this kind of dynamic before. Looking ahead, he considers it plausible that malware could tap into a language model and adapt itself on the fly. In that case, the classic countermeasure of cutting the internet connection might no longer work, for instance if attackers find an internal GPU they can use to run a small model. Security concepts therefore need to be updated regularly.

The attack starts unremarkably

Such an attack rarely begins with an old piece of medical equipment, but with completely ordinary standard IT. In the simulation, the attack starts with open-source research: the attacker visits the hospital's website and collects published email addresses, names, roles, and hints about external systems, using any number of freely available tools. That research forms the basis for a tailored phishing email. In the scenario, an IT staff member with admin rights falls for it, and the attacker uses their VPN access to scan the network, find an Exchange server, and grab credentials there. From that point on, according to Brüggemann, the entire Active Directory essentially counts as compromised. What follows are suspicious logs, data exfiltration, and failing systems such as the hospital information system, radiology, and lab systems, until finally a ransom note arrives. Security researchers see this pattern again and again in cyberattacks on hospitals.

When the crisis team comes under pressure

Emergency plans look convincing in calm times, but a real crisis changes the dynamics completely. Once the crisis is real, Schinzel says, adrenaline runs high and old conflicts resurface. He knows this from personal experience: in 2022, as a professor of IT security, he lived through the ransomware attack on FH Münster, and heard from other affected universities how crises can spiral out of control, for example through suspended IT directors or departments that stop talking to each other exactly when communication matters most. What matters is whether alerting, communication, and decision-making hold up under time pressure.

In one of the conference's workshops, 23 participants took on twelve roles at a fictional, typical German hospital, including IT, management, medical leadership, nursing, information security, and the crisis team. The simulation was organizational rather than technical, using realistic firewall excerpts along with matching names, domains, and networks. What worked well was the escalation chain from the admin through IT leadership and the information security officer up to management, along with clear baseline decisions, such as refusing to pay ransom and disconnecting the hospital from the internet. The path back proved harder: the crisis team turned into a one-way street, with information flowing in but barely flowing back out, leaving IT staff at times unaware of decisions that had already been made. A crisis team must not be a one-way street, Brüggemann says; it needs people who constantly move between rooms keeping everyone up to date.

Documentation, and the question of shutting down

The exercise also included calls from chief physicians, restless wards, and media inquiries, such as a reporter standing at the door wanting to know whether a cyberattack is underway and whether patient care is secure. External communication often still works, but things get harder internally once email, Teams, and phone systems go down, especially across networks with multiple locations. One key finding from the exercise concerned documentation: at one point, someone asked about a measure that had long since been decided, but nobody had written it down. A crisis team therefore needs fixed roles, ideally with backups, for who documents decisions, who maintains the list of measures, and who informs people internally and externally.

Shutting everything down immediately is the typical reflex, according to Brüggemann, but it isn't always the right call: it's often unclear which systems are urgently needed at that moment or which doctor is currently operating with what, and an uncontrolled shutdown also destroys forensic evidence. Targeted network segmentation is usually the better move. When IT fails, invisible processes break down too, covering things like admissions, findings, image archives, medication, duty rosters, and food supply. The exercise therefore also dealt with courier runs, shift changes, and salary payments, for which the group pragmatically decided to simply repeat the previous month's amounts.

Recovery often takes months

Teams often estimate a return to normal operations within days, but weeks to months is more realistic. A case from the Frankfurt area that Brüggemann knows of took about a year to get back to its original state, even though nothing had actually been encrypted there, just the Active Directory had been compromised. Backups remain indispensable, but they don't solve the problem of a compromised infrastructure. Fraunhofer SIT evaluates the simulations scientifically and is looking for more hospitals to take part in the study, with each hospital's IT environment factored in beforehand through a questionnaire while keeping the scenarios comparable.