MiraalTechLTD

Cyber Security

Risk assessments, hardening, and incident response planning for clinics holding identifiable patient data.

Ransomware groups target mid-size clinics assuming IT is a receptionist’s cousin, not a security team. We perform asset inventories, phishing simulations, and MFA rollouts that survive real-world push-notification fatigue. Deliverables map to ISO 27001 controls where useful, but we prioritise fixes that stop breach paths-not binder-weight compliance theatre.

Healthcare engagements cover vendor SaaS review, EMR patch cadence, and backup restore tests that prove you can recover patient schedules within hours, not days. Incident response retainers include regulator notification draft templates for PDPL-style breach timelines.

Deliverables

What we build

  • Threat models for patient portal and API attack surf…

    Threat models for patient portal and API attack surfaces

  • Vulnerability scan remediation roadmaps with severit…

    Vulnerability scan remediation roadmaps with severity-based SLAs

  • MFA and SSO rollout plans including shared kiosk exc…

    MFA and SSO rollout plans including shared kiosk exceptions

  • Security awareness modules tailored to clinical staf…

    Security awareness modules tailored to clinical staff schedules

  • Vendor risk questionnaires and SaaS configuration re…

    Vendor risk questionnaires and SaaS configuration reviews

  • Incident response playbooks with tabletop exercise f…

    Incident response playbooks with tabletop exercise facilitation

How we work

  1. Assess

    Interviews and technical scans establish baseline maturity and crown-jewel data locations.

  2. Prioritise

    Risk register ranks findings by likelihood and patient harm-not only CVSS scores.

  3. Remediate

    We pair with your IT or MSP to patch, segment networks, and tighten cloud IAM.

  4. Verify

    Retest confirms closure; executives receive board-ready summary metrics.

Technology stack

  • Microsoft Defender / CrowdStrike
  • Tenable / Qualys
  • 1Password / Bitwarden Enterprise
  • Cloudflare Zero Trust
  • Splunk or Wazuh SIEM
  • KnowBe4

Frequently asked questions

We implement controls aligned to ISO 27001 and support external certification audits but do not issue certificates ourselves.

Emergency retainers cover containment, forensic imaging, and restore coordination-contact us before paying ransoms.

Often no-unless enterprise hospital clients demand it. We right-size controls to your contract obligations.

We review webhook security, token storage, and subprocessors against your PDPL transfer requirements.

Start your cyber security project

Book a discovery call and we will outline scope, compliance needs, and a fixed timeline.

Contact Us

Alternatively, contact us directly:

contact@miraaltech.com

Schedule a Private Consultation

August 2026
MonTueWedThuFriSatSun