Incident Response Plan: vital to operational continuity

Published on 04/09/2026 in Customer talks

When a cybercriminal was preparing to launch a ransomware attack on a hospital, Proximus NXT’s CSIRT took immediate action. In the end, the risk was quickly neutralized. An Incident Response Plan made all the difference in this case.

Clinical staff looking at computer monitor analyzing patient medical expertise while discussing medication treatment to help cure disease.

Cybercrime has been a growing problem for years, including in the healthcare sector. Hospitals are a popular target for ransomware attacks, partly because they manage large volumes of confidential patient data. That is why cybersecurity remains a major challenge in the sector. “Hospitals traditionally rely heavily on legacy systems,” says Stephan Van Dyck, a cybersecurity expert at Proximus NXT. “Think of software that’s built into medical devices with a very long service life.” Therefore, planning upgrades is by no means always easy."

Budget constraints in the healthcare sector get in the way of increasing the level of cybersecurity as well. The budget is under pressure, leading to consolidation. This means that new locations are added to hospital groups that have IT connections, such as to a central patient record system. “A large group like this usually contains quite a few independent doctors,” says Stephan Van Dyck. “They use their own tools, which are not always under the control of the IT department. All these factors combined result in an expanding attack surface."

Incident Response Plan

To address this very issue, a major Belgian hospital group approached Proximus NXT to ask for help in strengthening its cyber resilience. “Together, we established a framework for an Incident Response Plan (IRP),” explains Stephan Van Dyck. “We did this using a so-called table-top exercise, in which we used a fictional incident as a basis to determine together what preparations would make a difference in the event of a real incident.”

Specifically, the IRP brings together a wealth of practical information. If an incident occurs, this information is immediately available, so no time is wasted looking up phone numbers or the names of tools and ICT partners. The IRP contains all relevant information about the healthcare facility itself, its IT infrastructure and software, its security processes and its crisis response procedures.

“This includes general information about the company, the organizational chart, and the contact information for the various departments,” says Stephan Van Dyck. “But also technical information about how servers and networks are connected, which ICT vendors you work with, whether backups are available, who is on the crisis team, and whether or not the organization is willing to pay a ransom.” By carefully reviewing all these points and testing them under normal conditions, you’ll already have a ready-to-use plan in place in the event of an incident.

Immediate action

It soon became clear that the request for additional cybersecurity support and the IRP exercise were justified. A few weeks after the IRP framework was implemented, the hospital reported suspicious internet activity via the emergency hotline of Proximus NXT’s CSIRT (Computer Security Incident Response Team). It turned out to be a time of day that cybercriminals often prefer. “We received the report around noon on a Friday before a long weekend.”

The initial analyses made it possible to rule out various types of attacks. “It wasn’t a security vulnerability or a phishing attempt. We determined that the threat was coming from within and that data exfiltration was taking place: the unauthorized transfer of data to an external location. It turned out that the activity had been going on for at least four weeks." This pointed to a cybercriminal who was preparing a ransomware attack, which called for immediate action. The source of the incident needed to be identified as quickly as possible.


By gathering and centralizing crucial information in advance, you can avoid time-consuming search procedures during a crisis.

Stephan Van Dyck, cybersecurity expert at Proximus NXT


Dealt with quickly and efficiently

During the first few hours after the incident was reported, the added value of the IRP framework became immediately apparent. “By gathering and centralizing crucial information in advance, you can avoid time-consuming search procedures during a crisis.” This prevents bottlenecks from occurring because employees are constantly asked the same questions by all kinds of stakeholders: suppliers, customers, partners, and colleagues. With a sound Incident Response Plan, you’ll have all the answers at your fingertips instantly, allowing you to act more quickly and efficiently.”

At 6 p.m., the analysis was complete and Proximus NXT issued its recommendation: to take the hospital group completely offline. “That would obviously have a major impact,” says Stephan Van Dyck. “The emergency room would have to close, as would the operating suite. The hospital would have to postpone all scheduled procedures indefinitely." The scope of the decision meant that a crisis might ensue. “But the impact of a ransomware attack would be much greater.”

Caught on surveillance footage

At the same time, Proximus NXT’s CSIRT recommended analyzing the surveillance camera footage and correlating the results with the physical location of the network port through which the data exfiltration occurred. “That led very quickly to the identification of the perpetrator. By 7 p.m., it was clear who it was, so the hospital no longer needed to go offline." The perpetrator turned out to be a system administrator. The hospital fired him on the spot.

“The man was biking home when he was involved in an accident,” says Stephan Van Dyck. “An ambulance took him back to the hospital. He stayed there for a few days to receive treatment. If he hadn't been unmasked and the hospital had gone offline, he would have been taken to another hospital." Who knows what impact that would have had on his injuries. It is possible that the perpetrator himself would have become a victim of his own attack. Karma is relentless, even for cybercriminals.


Because we had all the information right at our fingertips, we were able to act at least 50% faster and more efficiently.

Stephan Van Dyck, cybersecurity expert at Proximus NXT


50% time saving

Stephan Van Dyck attributes the rapid success of the entire operation—within a few hours—largely to the IRP framework. “Because we had all the information right at our fingertips, we were able to act at least 50% faster and more efficiently.” At the same time, this remarkable story provides inspiration for organizations that want to improve their cyber resilience. The advice is to “bring all your security tools together”. “This allows you to gain a better understanding of your organization’s security situation more quickly.”

Also important: when hiring employees who will have access to critical systems and sensitive data, it is advisable to conduct a background check. “That’s very easy to do. Just call a few of their previous employers,” concludes Stephan Van Dyck. “In this case, it turned out that the system administrator had done something similar during a previous job.” So, just one phone call could have made a big difference. “Zero trust remains an important principle, not only for ‘regular’ employees but also for the IT team itself.”

Discuss your Incident Response Plan with our experts

Contact us Opens a new window

Stephan Van Dyck is a cybersecurity expert at Proximus NXT and co-founder of BSides Limburg, an association that organizes events for and by information security experts.