Showcase of ThreatMirror integration with Imperial Global Singapore’s AutoPatch to Chairman of Singapore’s NRF
Finding a vulnerability on a medical device is only half the story. The question that healthcare providers need to ask is:
Can an attacker actually exploit that vulnerability to cause harm to a patient?
Vulnerabilities are aplenty on devices in a system. Without a way to connect the dots between individual findings and real-world attack paths, security teams often need to treat every vulnerability with the same urgency, which leads to alert fatigue and misallocated remediation effort.
This case study describes how our ThreatMirror platform was used with AutoPatch, an AI pentesting tool developed by Imperial Global Singapore, to answer that question concretely for a connected medical device environment.
The Environment
The case study centres on the following medical devices commonly found in clinical settings:
- A body monitor – this was the device where vulnerabilities were identified by AutoPatch
- An infusion pump – network connected to the body monitor as part of the same wireless OT subnet
The architecture diagram is shown below where the OT subnet is separated from the IT subnet which stores the Electronic Health Records (EHR) of patients. Doctors can remotely access virtual machines that tunnel the connection through the local workstation in order to access the EHR and disseminate commands directly to the pump controller.
The Approach
Step 1: Pentesting the Body Monitor
Imperial Global Singapore’s pentesting tool, AutoPatch, actively probes the patient monitor for vulnerabilities and misconfigurations using AI technologies, the result of which can be used for further analysis.
Step 2: Structuring Findings as Input
ThreatMirror is able to ingest structured pentesting outputs (as well as vulnerability assessments) directly as shown below.
Step 3: Building the Attack Graph
ThreatMirror mapped the imported vulnerabilities into an attack graph representing the full clinical network environment and the potential access vectors that an attacker could utilize. By combining the concrete, verified vulnerabilities from the pentest with the broader network and device relationships in the threat model, ThreatMirror determined viable attack paths that exploit the body monitor’s vulnerabilities in order to compromise the infusion pump and control the dosage administered to a patient.
In particular, the found vulnerability – an open debug port interface – would allow an attacker direct, unauthenticated access to the body monitor’s control functions. With that foothold, the attacker could then pivot to the body monitor gateway as the gateway extends implicit trust to any traffic originating from the body monitor. The attacker could then spoof sensor values from the body monitor or package malicious data to the gateway, causing the infusion pump to be tricked or compromised into performing the wrong actions.
The Outcome
The analysis confirmed multiple plausible attack paths that allow the healthcare system security team and device manufacturer to prioritize a subset of the recommended remediations. This result is far more actionable than a traditional vulnerability report as it shifts the conversation from “we found N vulnerabilities” to “here is the specific way an attacker can compromise the system and here is where we can break that chain most effectively”.
The case study was demonstrated during CREATE Symposium 2026, where it was viewed by Mr. Heng Swee Keat, chairman of Singapore’s National Research Foundation (NRF), highlighting the growing importance of medical device cybersecurity and threat modelling at the intersection of healthcare policy and national security. The demonstration illustrated not just the technical workflow, but the broader point that healthcare cybersecurity increasingly requires collaboration – between threat modelling and pentesting vendors, and between manufacturers and hospitals.
Why This Matters for Healthcare Security
Vulnerability findings are most useful when they’re contextualized within the network they live in. By combining structured pentesting output with attack graph-based threat modelling grounded in MITRE ATT&CK techniques, security teams can move beyond reactive vulnerability management toward a proactive understanding of real attacker paths – helping prioritize remediation where it matters most: protecting patients.





