BPL Logo Banner
CareersContact

In Part 1, we showed how a single text file could compromise an entire healthcare network. But not every breach starts with a forgotten password file. 

Sometimes, the threat is physical. It’s an unlocked workstation in a patient room, an open network jack in a hallway, or a forgotten web portal that everyone—including the IT team—forgot was facing the internet.

The Patient Room Hack

Hospitals are unique environments. They host a constant stream of visitors who are granted a level of privacy not found in a typical corporate office. Unfortunately, this physical access can quickly become a digital nightmare.

The Flaw: For a busy hospital IT team, securing every connected workstation is a monumental challenge, yet these workstations remain a frequent entry point for attackers.

The Attack: An attacker can plug a device into a physical port on an unsecured workstation. Even if the organization has disabled USB drives, many common prevention methods are ineffective against Human Interface Device (HID) attacks.

In this scenario, a malicious device masquerades as a keyboard. This allows it to bypass standard USB storage restrictions and rapidly type commands to download and execute malware.

The Result: In just a few minutes, an attacker can turn an unsecured workstation in a patient room into a persistent foothold deep inside the network. The attacker achieves this without needing to defeat a single security appliance.

Mitigation Strategies: Physical and digital security are deeply intertwined.

The Forgotten Front Door

Sometimes, the greatest risks are the systems you don’t even know are exposed. Poor asset management, a human process, can leave a critical internal system open to the entire internet.

The Flaw: During a pentest for a healthcare customer, our team identified a pager application web portal for medical personnel that was accessible from the internet. The organization didn’t realize this system was publicly exposed. This kind of oversight in asset management is a common challenge we see when conducting security penetration testing for our clients.

The Attack: We discovered we could send a pager message to our Point of Contact without being authenticated to the system. An attacker could exploit this vulnerability to cause significant disruption to staff communications. 

In addition, the application publicly listed personnel names and phone numbers, providing a perfect resource for a future phishing or social engineering campaign.

The Result: A critical communication line was left open to potential disruption, and a sensitive employee directory was exposed to the public, all from a system they didn’t know was exposed.

Mitigation Strategies: You can’t protect what you don’t know you have.

Securing Your Full Attack Surface

Your true attack surface is always larger than the systems you have on paper. A single workstation or forgotten web portal can open doors that attackers are eager to exploit.

Key Takeaways:

Our hospital cybersecurity assessments go beyond basic scans. We evaluate everything from workstations to waiting room jacks to exposed web portals, helping organizations secure both the physical and digital sides of their attack surface.


Once we’re in, we look for the “keys to the kingdom” — and too often, they’re left lying around. In Part 3, we reveal how default credentials, old accounts, and mismanaged data expose entire networks. If you think your old password doesn’t matter, think again.

In the first part of this series, we introduced the ‘turtles all the way down’ concept of the OT attack surface. Then, we dove into the layers of trust within that stack, exploring supply chain and insider threats in Part 2. Now, we move from the digital and trusted to the tangible and physical. In this third installment, based on Ray Blasko’s presentation at OT.SEC.CON, we’ll explore the world of physical security assessments. You can watch the full recordings on the BreakPoint Labs video hub.

You’ve spent millions on firewalls, endpoint detection, and sophisticated monitoring tools. Your digital fortress is state-of-the-art. But what if an attacker could bypass all of it in less than 60 seconds with a cheap lockpick and a bit of nerve?

For an offensive security professional, a physical compromise is often the most fun and eye-opening part of an assessment. While you’ve secured the digital front door, attackers are often able to just walk in through the back.

Case Study: Compromising a Water Utility

If an attacker needs to gain access to your OT environment as quickly as possible, the easiest path is often direct physical access. In the words of our Technical Director, Ray Blasko, “the first thing I’m going to do is I’m going to go find a remote site that’s unmanned and get in that way.”

These sites are a goldmine of vulnerabilities. Let’s walk through a real-world example from one of our assessments.

A water utility took us to a remote water tower. From their perspective, it was well-defended:

The defender saw strengths. An attacker saw a playground of opportunities:

Inside that unlocked building was a connected router inside an (unlocked) PLC cabinet. We plugged in a laptop and instantly had access not only to that site but to their entire main OT environment. Total time from arrival to full network compromise: under a minute.

The Wireless HID Attack and Other Physical Threats

Physical threats aren’t just about doors and fences. A wireless HID attack is particularly dangerous. Attackers have gotten creative with weaponized USB devices. This goes far beyond leaving a thumb drive in the parking lot. We’ve seen malicious hardware hidden in charging cables and even vape pens.

One of the most effective attacks uses wireless mice and keyboards. An attacker can use a tiny, cheap RF dongle to send keystrokes to a wireless mouse receiver from up to 50 feet away, telling the computer to execute commands. Even if you block USB drives, you can’t block Human Interface Devices (HID) like a mouse or keyboard, making this a perfect way to bypass controls and attack secure or even air-gapped networks. An attacker can plug one of these tiny receivers into the back of a machine, and it will likely go unnoticed for a long time.

How to Improve Your Physical Security Posture

Your digital security is only as strong as the physical security that protects it. Don’t let an unlocked door be the downfall of your entire security program.


Up Next: In our final post, we’ll tie it all together and discuss how to build a proactive defense that can even stand up to advanced, nation-state level threats in “Proactive OT Security: Defending Against Zero-Days & Nation-States”

How resilient is your physical security? BreakPoint Labs conducts comprehensive physical security assessments to uncover the gaps you can’t see. Contact us to learn more.

Author Image

About the Author

Ray Blasko is the Technical Director for offensive operations at BreakPoint Labs and a Red Team Operator for a DoD-certified Red Team, responsible for assessing and securing critical ICS/SCADA assets. He is recognized as a subject matter expert in both attacking and defending IT and OT environments, and he excels at resolving the technical and strategic issues that arise in protecting critical infrastructure. Ray holds numerous professional certifications and regularly presents at DoD Red Team conferences, trade conventions, and information security events.

chevron-down