Case study: Securing patient data with ISO 27001 in healthcare

Date

25 May 2026

Author

Share

When a regional hospital in Belgium reviewed its cybersecurity posture, the conclusion was clear: the systems supporting patient care were far more exposed than they should be.

With thousands of employees, hundreds of connected medical devices, and sensitive patient data flowing continuously across systems, the organisation was operating in a high-risk environment without the structure needed to manage it effectively.

At the same time, regulatory pressure was increasing. As an essential entity under the NIS2 Directive, the hospital faced strict cybersecurity requirements and a clear deadline to achieve CyFun Essential verification.

What followed was not just a compliance project, but a full transformation of how the organisation approached security, and in this case study, we’re going to explore how that transformation was achieved.

Where it started: complexity without control

Like many healthcare organisations, the hospital had grown its digital infrastructure over time. Electronic health records, imaging systems, medical devices, and administrative platforms were all interconnected, but not always governed consistently.

A closer look revealed critical issues:

  • Fragmented governance – Security responsibilities were spread across teams with no clear ownership or dedicated Information Security Officer.
  • Shadow IT – Staff used unapproved cloud tools, creating uncontrolled flows of sensitive patient data.
  • Legacy devices – Around 35% of medical devices ran unsupported systems, connected to the main network without segmentation.
  • Weak incident response – No formal plan was in place; a previous ransomware attempt was handled manually without clear procedures or escalation.
  • Misalignment of GDPR and security – Privacy and information security operated separately, with no integrated risk approach.

These gaps became impossible to ignore after a ransomware attempt exposed the organisation’s reliance on individual effort rather than structured processes.

Our approach: From fragmentation to structure

Rather than addressing issues in isolation, a structured and phased approach was implemented, combining ISO/IEC 27001 and CyberFundamentals (CyFun) Essential into one aligned strategy.

Phase 1 Discovery and gap analysis (Weeks 1–6)

A full asset inventory uncovered 47 previously undocumented shadow IT applications, followed by a CyFun self-assessment across all core controls. A unified gap analysis aligned ISO 27001, CyFun, and GDPR into a single roadmap, revealing a baseline maturity of 1.8/5, well below the required target of 3.5/5.

Phase 2 ISMS design and risk treatment (Weeks 7–18)

A formal governance structure was introduced, alongside a comprehensive risk assessment identifying 142 risks, including 38 high or critical. A structured treatment plan was developed, driving the implementation of 93 prioritised controls, supported by a complete set of policies and procedures.

Phase 3 Technical implementation (Weeks 12–28)

Key security measures were implemented, including network segmentation, stronger access controls, monitoring capabilities, and secure backup and data protection mechanisms, significantly reducing the organisation’s exposure by up to 85%.

Phase 4 Training and culture Training, Awareness and Culture Change (Continuous)

Security was embedded into daily operations through training of 2,800 employees, supported by phishing simulations and an internal network of security champions.

Phase 5 Internal audit, management review and certification (Weeks 29–40)

The approach was validated through internal audits, management review, and progression toward ISO 27001 certification and CyFun conformity assessment.

From the outset, the focus was not just on meeting requirements, but on building a system that works in daily operations: structured, scalable, and aligned with real risk.

Turning structure into action

The transformation began with governance.

A dedicated Information Security Officer was appointed, reporting directly to leadership. A Security and Privacy Committee was established, bringing together key stakeholders across departments.

From there, the organisation moved into understanding and controlling its environment:

  • A full asset inventory revealed previously unknown systems and tools
  • 47 shadow IT applications were identified and addressed
  • A comprehensive risk assessment identified 142 risks, prioritised based on impact

At the same time, policies and procedures were formalised, creating clarity where there had previously been ambiguity.

On the technical side, critical improvements were introduced:

  • Medical devices were isolated through network segmentation
  • Multi-factor authentication was implemented for sensitive access
  • Monitoring and detection capabilities were established
  • Backup and recovery processes were strengthened
  • Data protection controls reduced the risk of information leakage

Step by step, security became structured, visible, and manageable.

Making security part of everyday work

One of the most significant changes was cultural.

Security was no longer treated as an isolated IT responsibility. Instead, it became part of how the organisation operated.

Employees received role-based training, helping them understand not just what to do, but why it mattered. Phishing simulations provided practical learning, while internal security champions created accessible points of contact within each department.

This shift ensured that security was not only implemented, but sustained.

The outcome: measurable improvement and early certification

The results of the transformation were clear and measurable:

  • Cybersecurity maturity increased from 1.8 to 3.8
  • Incident detection time dropped from approximately 72 hours to under 4 hours
  • Shadow IT was reduced from 47 uncontrolled applications to just 3 managed exceptions
  • Employee training participation rose from 12% to 98%
  • Phishing vulnerability decreased from 34% to 7%
  • All medical devices were fully segmented within the network

Most notably, the hospital achieved ISO 27001:2022 certification 14 months ahead of the required deadline, positioning itself strongly for CyFun Essential compliance.

What made the difference

The success of this transformation was not driven by a single solution, but by a combination of key factors:

  • A unified approach to multiple frameworks, reducing complexity
  • Strong involvement from leadership, ensuring accountability
  • Close alignment between security measures and clinical workflows
  • Practical handling of legacy systems through compensating controls

These elements ensured that security improvements were both effective and sustainable.

How Dadir can support your organisation

Many organisations face similar challenges, complex environments, increasing regulatory pressure, and limited clarity on where to start.

Dadir supports organisations in building structured, practical, and scalable cybersecurity programmes.

We help you:

  • Align frameworks such as ISO 27001, CyFun, GDPR, and NIS2 into one approach
  • Establish governance and risk management that work in practice
  • Identify and prioritise your most critical risks
  • Implement effective technical and organisational controls
  • Achieve certification while building long-term resilience

Our focus is not only on compliance, but on creating security that supports your organisation’s operations and growth.

Because in environments where data and trust are critical, security must be more than a requirement.

It must be part of how you operate.

WHO IS THE DADIR TEAM?

Read our other blogs