IT Aduit & Assessment - Case 3

A hospital providing holistic healthcare to patients in Hong Kong
 
Size200 staffs

Service
IT Audit and Assessment with Follow-up Services

Challenge
With a number of 100+ hospitals and clinics in diverse locations, the company has been struggling for many years to centrally manage the information security and to standardize the operation procedures. Due to the lack of resource, hardly can the company spot out the potential vulnerability without regular review mechanism. Therefore, Ringus engaged to perform an one-off and in-depth assessment, and pinpoint improvement areas within the information system.

After the on-site assessment, Ringus identified large amount of security vulnerabilities and operational deficiencies, in which IT Team might not have sufficient resource to fix the problem in the short run.
 

Solution

  • Identified network security vulnerabilities and provided technical recommendations
  • Evaluated and commenced internal and external security controls
  • Provided one-year implementation plan: Document Management System and Workflow System enhancement 
  • Provided project management consultation, including project progress, budget, and timeframe.

Result
Through a series of on-site interviews, our security experts have tailor-made a one-year step-by-step implementation plan for the company to perform remediation actions, along with continuous advisory from Ringus. High-priority risk items have been addressed with appropriate corrective actions to prevent the company from security risk exposure in the short run.

In the long run, to reduce the workload of the IT Team, Ringus not only provided suggestions and alternatives for the companies to consider, but also helped integrate the Information Security Management System into the operational workflow in diverse locations.
 
Follow-up
After the assessment, Ringus has consistently updated the remediation process with the company and continually provide implementation advisory mentioned in the assessment report.
An introduction of the standardized policies and procedures has been brought to ensure appropriate security level of information handling in the daily operation.

Benefit 
The one-year implementation roadmap is embedded in the assessment report in a manner that our client can easily follow the remediation plan according to the severity level assigned.

Our team continues to work closely with our client, providing the best managerial and technical implementations advisory that are in line with clientโ€™s missions and visions.
 

More Updates

Further reading

๐—œ๐—ฆ๐—ข ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ ๐—ถ๐˜€๐—ป'๐˜ ๐—ฎ ๐—ด๐˜‚๐—ฎ๐—ฟ๐—ฎ๐—ป๐˜๐—ฒ๐—ฒ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ถ๐—ป๐—ณ๐—ผ๐—ฟ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ถ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐˜€

In 2026, with cyber threats evolving faster than ever โ€” from AI-amplified attacks and supply chain compromises to credential abuse. No framework can promise 100% invulnerability. Certified organizations still face breaches.A point-in-time compliance snapshots can't stop every zero-day, insider mistake, or sophisticated adversary.Yet that's exactly why ISO 27001 remains essential. The standard transforms security from reactive firefighting to systematic risk management.๐Ÿ” ๐—–๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ผ๐˜‚๐˜€ ๐—ฅ๐—ถ๐˜€๐—ธ ๐—”๐˜€๐˜€๐—ฒ๐˜€๐˜€๐—บ๐—ฒ๐—ป๐˜The standard requires organizations to regularly identify, analyze, evaluate, and treat information security risks using a formal, documented process. This ensures threats are spotted and addressed proactivelyโ€”long before they turn into exploitable vulnerabilitiesโ€”rather than discovering them only during or after an incident.๐Ÿ”„๐—–๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ผ๐˜‚๐˜€ ๐—œ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ (๐—ฃ๐——๐—–๐—”)As its core, ISO 27001 follows the Plan-Do-Check-Act (PDCA) cycle, requiring regular reviews, internal audits, management involvement, and updates to the ISMS. This keeps security practices alive and adaptive, so controls improve over time as new threats emerge, lessons are learned from incidents or near-misses, and the business environment changes.๐Ÿšจ๐—ฆ๐˜๐—ฟ๐—ผ๐—ป๐—ด๐—ฒ๐—ฟ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒThe framework requires clear incident management processes, including defined roles, responsibilities, communication plans, and regular testing through exercises or simulations. When something does happen, the organization can detect it earlier, contain it more effectively, coordinate the response smoothly, and recover with less confusion and operational disruption.๐Ÿ›ก๐— ๐—ฒ๐—ฎ๐—ป๐—ถ๐—ป๐—ด๐—ณ๐˜‚๐—น ๐—ฅ๐—ถ๐˜€๐—ธ ๐—ฅ๐—ฒ๐—ฑ๐˜‚๐—ฐ๐˜๐—ถ๐—ผ๐—ปBy embedding risk-based thinking, better visibility across the organization, prioritized controls, and adaptive processes, ISO 27001 helps lower the chances of incidents occurring in the first place and limits their potential impact when they do. It creates genuine resilience through structured prevention, early detection, and effective response โ€” rather than relying on luck or hoping threats never find a way in.๐Ÿ’ก๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐˜€๐—ป'๐˜ ๐—ฎ ๐—บ๐—ฎ๐—ด๐—ถ๐—ฐ ๐˜€๐—ต๐—ถ๐—ฒ๐—น๐—ฑ; ๐—ถ๐˜'๐˜€ ๐—ต๐—ถ๐—ด๐—ต-๐—พ๐˜‚๐—ฎ๐—น๐—ถ๐˜๐˜† ๐—ฎ๐—ฟ๐—บ๐—ผ๐—ฟ. It equips organization to take hits, contain damage more effectively, recover with less chaos, and show you're prepared to handle the reality of today's threats.

๐—Ÿ๐—ผ๐˜„-๐—–๐—ผ๐—ฑ๐—ฒ ๐˜ƒ๐˜€. ๐—ก๐—ผ-๐—–๐—ผ๐—ฑ๐—ฒ ๐—ถ๐—ป ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ

Two years ago, a client came to us excitedly. They'd built their entire customer portal using a popular ๐—ป๐—ผ-๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ฝ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ. Zero developer needed. Launched in weeks. It felt like a win.Then the business started to scale.Suddenly, their no-code tool couldn't handle custom API integrations. Pricing ballooned with user volume. Worst of all โ€” they were completely locked into a vendor ecosystem they couldn't escape without rebuilding from scratch.Sound familiar?๐—ง๐—ต๐—ฒ ๐—ฅ๐—ฒ๐—ฎ๐—น ๐——๐—ถ๐—ณ๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ก๐—ผ-๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐˜ƒ๐˜€ ๐—Ÿ๐—ผ๐˜„-๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ถ๐—ป ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ๐Ÿ”น ๐—ก๐—ผ-๐—–๐—ผ๐—ฑ๐—ฒNo-Code is brilliant for ๐˜€๐—ฝ๐—ฒ๐—ฒ๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ถ๐—ฐ๐—ถ๐˜๐˜†. Business users can spin up forms, workflows, and dashboards without touching a single line of code. Perfect for internal tools, MVPs, and non-technical teams moving fast.๐Ÿ”น ๐—Ÿ๐—ผ๐˜„-๐—–๐—ผ๐—ฑ๐—ฒLow-Code is where serious projects live. It gives developers a ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ๐—ฑ ๐—ฑ๐—ฒ๐˜ƒ๐—ฒ๐—น๐—ผ๐—ฝ๐—บ๐—ฒ๐—ป๐˜ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ while dramatically reducing repetitive boilerplate work.Developers retain full control over architecture, integrations, security, and scalability โ€” without starting from zero.This makes low-code the preferred choice for ๐—ฒ๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ-๐—ด๐—ฟ๐—ฎ๐—ฑ๐—ฒ ๐—ฎ๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜๐—ต๐—ฎ๐˜ ๐—บ๐˜‚๐˜€๐˜ ๐—ฒ๐˜ƒ๐—ผ๐—น๐˜ƒ๐—ฒ ๐—ผ๐˜ƒ๐—ฒ๐—ฟ ๐˜๐—ถ๐—บ๐—ฒ.๐—ง๐—ต๐—ฒ ๐—–๐—ผ๐—บ๐—บ๐—ผ๐—ป ๐— ๐—ถ๐˜€๐˜๐—ฎ๐—ธ๐—ฒChoosing no-code for problems that need low-code. They optimise for launch speed and pay the price during growth.The smartest organisations today use ๐—ฏ๐—ผ๐˜๐—ต ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ด๐—ถ๐—ฐ๐—ฎ๐—น๐—น๐˜† โ€” โšกNo-code for rapid experimentation, โš™Low-code for production-grade systems that need to last.๐Ÿ’ก๐—ž๐—ป๐—ผ๐˜„ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜๐—ผ๐—ผ๐—น. ๐—ž๐—ป๐—ผ๐˜„ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜€๐—ฐ๐—ฎ๐—น๐—ฒ. ๐—•๐˜‚๐—ถ๐—น๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—ถ๐—ป๐˜๐—ฒ๐—ป๐˜๐—ถ๐—ผ๐—ป.

๐—ช๐—ต๐—ฒ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐˜€ ๐— ๐—ฎ๐—ธ๐—ฒ ๐—›๐—ฒ๐—ฎ๐—ฑ๐—น๐—ถ๐—ป๐—ฒ๐˜€: ๐—” ๐—ฅ๐—ฒ๐—บ๐—ถ๐—ป๐—ฑ๐—ฒ๐—ฟ ๐—ณ๐—ผ๐—ฟ ๐—˜๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ข๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป

A recent ransomware incident reported in Hong Kong serves as a timely reminder that cybersecurity threats continue to evolve โ€” and no organization is immune.According to public reports, the incident involved unauthorized access to an internal network where certain stakeholder data such as employee information, contact details, marketing contacts, and supplier records were exposed.  Fortunately, operational systems were reported to be ๐˜€๐—ฒ๐—ด๐—ฟ๐—ฒ๐—ด๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐˜‚๐—ป๐—ฎ๐—ณ๐—ณ๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ, highlighting the importance of ๐—ป๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐˜€๐—ฒ๐—ด๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป in protecting critical infrastructure.While the exact root cause of the breach is still under investigation, common entry points for ransomware attacks often include:โš   ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—ฒ๐—บ๐—ฎ๐—ถ๐—น๐˜€ targeting employeesโš   Exploitation of ๐˜‚๐—ป๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต๐—ฒ๐—ฑ ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ in internet-facing systemsโš   ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ๐—ฑ ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€ used for remote accessโš   ๐—ง๐—ต๐—ถ๐—ฟ๐—ฑ-๐—ฝ๐—ฎ๐—ฟ๐˜๐˜† ๐—ผ๐—ฟ ๐˜€๐˜‚๐—ฝ๐—ฝ๐—น๐˜† ๐—ฐ๐—ต๐—ฎ๐—ถ๐—ป ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ๐˜€This incident is a reminder that cybersecurity is not just about responding to attacks โ€” it is about ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ณ๐˜†๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ฑ๐—ฑ๐—ฟ๐—ฒ๐˜€๐˜€๐—ถ๐—ป๐—ด ๐—ฝ๐—ผ๐˜๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ด๐—ฎ๐—ฝ๐˜€ ๐—ฏ๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ฑ๐—ผ.Organizations can strengthen their defenses through several proactive measures:โœ” ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—”๐˜€๐˜€๐—ฒ๐˜€๐˜€๐—บ๐—ฒ๐—ป๐˜๐˜€ to identify technical weaknesses earlyโœ” ๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด to simulate real-world attack scenariosโœ” ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฎ๐˜„๐—ฎ๐—ฟ๐—ฒ๐—ป๐—ฒ๐˜€๐˜€ ๐˜๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด to reduce phishing risksโœ” ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐˜€๐—ฒ๐—ด๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—น๐—ฒ๐—ฎ๐˜€๐˜ ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ to limit impactโœ” ๐—ฆ๐˜๐—ฟ๐—ผ๐—ป๐—ด ๐—ฏ๐—ฎ๐—ฐ๐—ธ๐˜‚๐—ฝ ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ด๐—ถ๐—ฒ๐˜€ to ensure recovery in ransomware scenariosCyber resilience is not built during an incident โ€” it is built through preparation.The question for every organization is simple:๐—œ๐—ณ ๐—ฎ๐—ป ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ ๐˜๐—ฒ๐˜€๐˜๐—ฒ๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฑ๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฐ๐—ฒ๐˜€ ๐˜๐—ผ๐—ฑ๐—ฎ๐˜†, ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€ ๐—ฏ๐—ฒ ๐—ฟ๐—ฒ๐—ฎ๐—ฑ๐˜†?