Proposal to Resolve Ransomware Attack on Hospital IT Systems
Prepared by: TechSolution
Course: ITPP5112A2
Institution: The Independent Institute of Education (IIE)
Year: 2025
1. Introduction: Cybercrime and Fraud in the 21st Century
In the 21st century, cybercrime has evolved into one of the most significant threats to global
security and organizational stability. Cybercriminals exploit digital vulnerabilities to
commit acts of fraud, data theft, and extortion through malicious software such as
ransomware. Ransomware is a form of malware that encrypts a victim’s files, demanding
payment in exchange for decryption keys. One of the most well-known ransomwares is the
cyber group named “NotPetya”, which was a cyber-attack that occurred in Ukraine, holding
a company’s information hostage. Cybercrime is ranked as top 10 risks faced by the world,
according to the World Economic Forum. Cybercrime is increasingly becoming
sophisticated, with criminals getting access to advanced malware, cryptocurrency, and
social engineering to exploit system vulnerabilities. A factor leading to this increase is that
“crime as a service” has led to an increase in cybercrime.
2. Role of IT Professionals in Cybersecurity
The IT professionals at TechSolution are responsible for safeguarding the organization’s
digital infrastructure. Their expertise includes implementing security controls, conducting
risk assessments, monitoring networks for anomalies, and responding to cyber incidents. In
this context, TechSolution’s team is uniquely equipped to address the hospital’s
ransomware crisis through immediate containment, forensic analysis, and restoration of
essential systems. Our ethical approach and compliance with South African and
international cybersecurity standards make us the ideal candidates for this project.
3. Ethical Elements and Codes of Conduct
Ethical considerations form the foundation of effective cybersecurity practice. TechSolution
adheres to the (ISC ² Code of Ethics, emphasizing integrity, competence, and diligence in
protecting information assets. Furthermore, compliance with South Africa’s Protection of
Personal Information Act (POPIA) ensures lawful processing and protection of patient data.
All actions are guided by principles of transparency, confidentiality, and professional
responsibility (ISACA, 2023). One of the many codes of conduct to follow is the IITPSA code
of conduct, which involves avoiding harm, being fair, and not discriminating. The IITPSA
sets clear ethical guidelines, provides professional development opportunities, and
advocates for best practices within the industry. Furthermore, adopting ethical governance
practices helps avoid risks associated with information security breaches (IITPS,2022).
4. Stakeholders Involved
Different types of stakeholders within the IT space would be the internal, external, and
operational stakeholders. These key stakeholders in this scenario include hospital
management, IT staff, medical personnel, patients, and regulatory authorities. Additionally,
third-party service providers, cybersecurity consultants, and law enforcement agencies play
a vital role in the containment and investigation process. Effective communication and
coordination among these stakeholders are critical to mitigating operational and
reputational risks.
5. How the Ransomware Entered the Hospital IT System
Initial investigations indicate that the ransomware may have infiltrated the hospital’s IT
system through phishing emails, unpatched software vulnerabilities, or compromised
remote desktop access. Weak password policies and inadequate staff awareness training
further contributed to the exploitation of these vulnerabilities. Lack of multifactor
authentication can be a loophole because this enforces many security layers, and it allows
the system to be heavily encrypted. Human errors, like employees using pirated websites on
the company’s network, allow the system to be hacked. Such loopholes underscore the
importance of proactive security measures and continuous employee education.
6. Immediate Actions to Contain the Ransomware
Immediate response measures include isolating infected devices from the network,
disabling shared drives, and halting automated data backups to prevent reinfection. The
incident response team should identify the type of ransomware, report the attack to
authorities, and communicate transparently with affected stakeholders. Data recovery
efforts should prioritize restoring critical hospital operations, including patient record
access and diagnostic systems.
7. Strategies for Removing the Ransomware
TechSolution recommends using clean, verified backups for data restoration while avoiding
ransom payments to discourage criminal activity. A forensic investigation should be
conducted to trace the breach’s origin and ensure the complete eradication of malware
remnants. If backups are unavailable, professional decryption tools or collaboration with
cybersecurity agencies may assist in recovery. The hospital should maintain a segregated,
secure backup environment moving forward.
8. Continuity of Hospital Operations
To ensure uninterrupted service delivery, the hospital must activate its Business Continuity
Plan (BCP). Critical systems should operate on secure, isolated networks, and manual
record-keeping procedures may temporarily supplement digital operations. TechSolution
will provide real-time monitoring and support to ensure patient safety and operational
resilience during the crisis resolution.
9. Impact of Turning Off Infected Systems
Turning off infected systems can halt the spread of ransomware but may disrupt life-critical
hospital operations. Therefore, decisions must balance patient safety and cybersecurity
containment. TechSolution recommends a phased shutdown approach, prioritising
containment of non-critical systems first while maintaining essential medical functions.
10. Long-term Prevention and Compliance
To prevent future incidents, TechSolution proposes implementing the following rules:
• Enforce strong password and multi-factor authentication policies.
• Conduct periodic software updates and vulnerability and stress assessments.
• Deliver ongoing staff training on phishing and cyber hygiene.
• Align cybersecurity frameworks with ISO/IEC 27001 standards.
• Maintain encrypted, off-site data backups and regular security audits.
These proactive measures will strengthen the hospital’s digital resilience and ensure
compliance with ethical and legal requirements.
11. Conclusion
The ransomware attack on the hospital underscores the growing threat of cybercrime to
critical sectors. Through immediate containment, ethical decision-making, and robust long-
term cybersecurity strategies, TechSolution can restore operational safety and prevent
future crises. Our approach integrates technical expertise, legal compliance, and
professional ethics to protect both organizational integrity and patient welfare.
References
IBM. (2024) *Cost of a Data Breach Report 2024.* IBM Security. Available at:
[Link] (Accessed: October 2025).
ISACA. (2023) *Code of Professional Ethics.* ISACA. Available at:
[Link] (Accessed: 20 October 2025).
IITPSA (Institute if Information Technology Professionals South Africa). (2022)
Code of Conduct and Ethics. Available at: [Link]
condut/ (Accessed: October 2025)
IITPSA. (2022) Code of Conduct and Ethics. Institute of Information Technology
Professionals South Africa. Available at: [Link]
conduct/ (Accessed: October 2025).