A healthcare software provider initially believed its security measures were sufficient, having put significant resources into various protections across a distributed workforce. Solutions included separated developer environments, segmented cloud resources, and strict management of administrative access, enhanced by widespread multifactor authentication (MFA), regular vulnerability scans, and annual penetration tests.
However, a penetration test focused on insider threats, executed with NodeZero®, revealed alarming vulnerabilities: a single compromised developer credential could lead to swift lateral movement within the network and potentially compromise critical cloud infrastructure.
“It owned our network in a matter of minutes,” the organization's IT operations leader remarked, illustrating the urgency that emerged from the findings. The realization that merely protecting endpoints and servers wasn't enough triggered a shift in security focus.
Instead of relying on traditional, periodic assessments like annual penetration tests, the provider recognized the need for a more holistic approach to security: one that emphasizes continuous validation and operational management of exposure.
Outcomes at a Glance
- Addressed internal exposure from 16 vulnerabilities affecting four hosts that led to AWS compromises and sensitive data risks.
- Downscaled AWS vulnerabilities to two low-severity weaknesses, which weren't linkable to significant business impacts.
- Removed excessive local-administrator access after NodeZero demonstrated the potential for rapid lateral movement and privilege escalation.
- Implemented new privileged access approval workflows and broadened MFA usage.
- Established a reliable monthly routine for testing, remediation, and validation.

Image 1: Initial testing unveiled 16 vulnerabilities across four hosts, contributing to AWS compromises and exposure of sensitive data.
Understanding the Impact
The security team had thought their defenses were robust. But the penetration test revealed that comprehending what an attacker could achieve once inside the network was crucial. The focus shifted from identifying individual weaknesses to understanding how those vulnerabilities could combine to enable an attack.
Operating with a widely dispersed workforce, diverse developer access needs, hybrid infrastructure, and increasing cloud reliance mirrored challenges faced by many software providers. Before implementing NodeZero, traditional vulnerability scanning and annual tests were the norm. Lessons learned from the first use of NodeZero illustrated the significant gaps in assumptions about their network security.
“An annual penetration test really just gives a snapshot in time,” the IT operations leader pointed out. “Technology doesn’t remain static; it continuously evolves.”
The team initially conducted a phishing impact test integrated with their Microsoft 365 environment, but none of the employees fell for the phishing attempt. Instead of assuming their workforce was impervious to such attacks, the organization opted for a more realistic approach by asking three employees—namely a developer, an HR personnel, and a support staff member—to intentionally provide credentials during the phishing test. This allowed the team to analyze the consequences of different access levels during a breach scenario.
This adjustment made evident where vulnerabilities were most significant. While the HR and support accounts proved to be relatively secure, the developer account’s compromise allowed NodeZero to swiftly expand its attack path, crack password hashes, escalate privileges, and navigate across segmented environments toward AWS-linked resources.
“We’re fully segmented,” the operations leader emphasized. “We thought we’d be secure in isolation, yet NodeZero easily traversed those segments.”
The rapidity of compromise was eye-opening, but understanding the path taken by the attack mattered even more. The environment became vulnerable at a single point—one developer system with elevated privileges enabled attackers to traverse the entire landscape.
This pivotal realization reframed their approach to security. The organization moved from assessing scattered vulnerabilities to managing overall exposure and recognizing that one vulnerable credential could initiate widespread issues.

Image 2: NodeZero illustrated how one compromised developer path could lead to rapid compromises within segmented environments.
To discover strategies for effective mitigation and remediation efforts, click here.
Reframing Security Priorities
“Our ultimate aim is to ensure our staff have jobs to come to every day,” stated the IT operations leader, indicating a transformation in the security mindset. Rather than viewing the issue as merely compliance-oriented or vulnerability management, the focus shifted to the ongoing obligation of ensuring an adversary couldn’t navigate their environment undetected.
For insights into Horizon3.ai and NodeZero, click here.