skip to content

The Unpatchable Population

Printers, controllers and out-of-support hosts cannot be patched or authenticated, so the segment carries the whole control. Interviewers ask because 'their own VLAN' is only half of it.

on this pageshow

questions

4

An infusion pump takes no patch or agent: what still constrains an attacker who lands on it, and what does that cost?

level: juniorimportance: must knowfreq 62%

answer

  1. nothing can be installed on it
  2. policy written about it, not on it
  3. reach in, originate out - that is all
  4. the permit is inherited on arrival
  5. an exception with an owner and an expiry

basics

~20 s

You cannot fix the host, so the only control is what the segment permits it to originate and receive. The price is a standing exception with a named owner and a renewal date, and an intruder who lands there inherits it.

solid answer

~50 s

Nothing can be installed on the device, so every control has to be written *about* it by the first device upstream: the switch port and the segment boundary. Those can assert two things only, what may reach the pump and what the pump may originate, and that is the whole control surface. Say plainly what it does not do: the unpatched flaw is exactly as exploitable as before, so this is blast-radius reduction, not remediation. It is also inherited. An attacker who gets code running on the pump does not need to escalate or evade anything; every permitted flow is now theirs, from an address that looks expected in the register. And the permit is not free: it is a documented exception with an owner, an expiry and a review, and in a clinical estate that owner usually outranks the network team.

go deeper

for a junior

Be ready to say what is left when patching, agents and credentials are all unavailable: only what the network permits the device to send and receive. Say clearly that this does not fix the vulnerability.

for a middle

Explain the mechanics of the compensating control - default deny, an enumerated per-device permit, and the fact that the boundary sees traffic and not host state. Be able to list what the segment cannot claim.

for a senior

Demonstrate that you plan for the device being compromised: narrow the origination set to the point of boredom, keep evidence that the rest is denied, and know exactly what an intruder inherits from the permit you wrote.

for a principal

Own the exception as a managed object rather than a rule: who renews it, when it expires, how it is enumerated per device, and how it is answered to a regulator or an auditor without using the word segmentation as a substitute for evidence.

## What unpatchable actually means A device is unpatchable when nothing you control can change its state. The vendor ships no fix; or a fix exists but the support contract voids if you apply it yourself; or the platform underneath went end-of-life years before the device was installed; or there is no agent build for it; or the only account is a shared service password printed in the installation manual. In a hospital that describes infusion pumps, imaging modalities and an anaesthesia workstation, each bought as a certified system rather than as a computer. The shape recurs wherever equipment is purchased whole and certified against a regulator. ## Every normal control lives on the host, and none of them are available Patch it, install a sensor, rotate the credential, disable the listening service, enforce a local firewall: all of those act on the host. Here none can be used. What remains is policy written **about** the device by the first device upstream of it - the access port it is plugged into and the boundary between its segment and everything else. That policy can assert exactly two things: - what may reach the device, and - what the device may originate. That is the entire control surface, and stating it that starkly is the point of the question. It forces the honest next sentence: none of it reduces the vulnerability. The pump remains precisely as exploitable as it was. What changed is who can reach the flaw and where an intruder can travel afterwards. ## What the segment can and cannot claim | The segment can | The segment cannot | | --- | --- | | Stop unrelated hosts reaching the device's listening service | Stop its authorised clinical peer reaching it, which is the path that matters | | Stop the device originating flows nobody authorised | Distinguish a legitimate flow from an intruder using the same permit | | Record that bytes moved to a permitted destination | See inside an encrypted session, or produce host telemetry | | Deny by default and produce evidence of the denial | Prove the device is not already compromised | The right-hand column is what a strong candidate volunteers. A weak one says the device is safe because it is segmented, which confuses a reduced reachable set with a fixed defect. ## Inheritance: what an intruder gets for free This is the framing the question exists for. On an ordinary server an attacker must escalate, evade a sensor, steal a credential, and move. On a device everybody agreed never to constrain, the attacker skips all of that. Every flow the exception permits is now theirs, sourced from an address that appears in the register as expected, at hours nobody reviews, from a host that generates no local log you can read. The exception you wrote precisely because the device could not be fixed is the same exception the intruder receives on arrival. That is why the permitted origination set has to be narrow to the point of being boring: one destination, one port, one direction, and a default deny for everything else. ## The price, and who actually pays it The control is not free and interviewers want to hear the bill: - **An exception record per device**, not a blanket one, with what it may originate and why. - **A named owner** who renews it. In a clinical estate that is a clinical-engineering or biomedical department, not the network team, and the counter-argument in the room is patient safety. - **An expiry**, because the failure mode is an exception approved once for a go-live that is still in the rule base a decade later, attached to a device nobody can identify and that nobody dares delete. - **Addressing discipline**, because the permit is keyed to something that must not change. - **Evidence**, because when an auditor or a regulator asks how the risk is managed, the answer is not the word segmentation, it is the enumerated permit list plus proof the boundary denies the rest. ## How to answer this in a loop Three beats: the control moved off the host and onto the segment; the segment constrains reach and origination and does not fix the flaw; the constraint is a standing exception with an owner and an expiry that an intruder inherits intact. A candidate who gives all three has shown they understand both halves - the mechanism and the bill - and they have not pretended the problem was solved.

  • Why is saying the pump is behind a firewall not an answer on its own?
    A boundary permits things. The question is what it permits: the device's allowed flows are also the intruder's allowed flows. Without the enumerated origination list and a default deny behind it, being behind a firewall says only that traffic passes through a box, not that anything is denied.
  • If segmentation does not fix the flaw, what do you tell an auditor who asks how the risk is managed?
    That the risk is not remediated but bounded, and then show the bound: the per-device permit list, the default deny, the evidence that denied attempts are recorded, the exception owner and its renewal date. Naming it a compensating control without producing that evidence is the answer that fails.
  • What makes the origination direction the more important half here?
    Inbound rules limit who can trigger the flaw. Outbound rules limit what the attacker does after they already have. Since you must assume the device can be exploited by anything permitted to reach it, the value of the segment is mostly in the second: an exploited pump that may originate exactly one flow to one destination is a poor position to work from.

You cannot cure the patient, so you control the doors of the ward. The illness is unchanged; what changed is how far it travels.

saying these in an interview costs you the question

  • Says segmentation makes the unpatched device safe
  • Claims the device is fine because it is not internet-facing
  • Assumes an agent or credential can be forced onto it anyway
  • Treats the exception as permanent and nobody's property
  • Forgets the intruder inherits every permitted flow

context

open as a page

Segment rules for an unpatchable imaging modality are keyed to its fixed IP. How can an attacker inherit that permit?

level: middleimportance: should knowfreq 45%

basics

~20 s

An address-keyed permit trusts a field in the packet, not an identity the device proves, so whoever answers at that address inherits it. Holding the binding true costs static addressing, a hand-kept register and change coordination on every device swap.

open as a page

A modality vendor demands a standing remote-support path or voids support: how do you grant it, and what does an intruder inherit?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Grant it brokered and time-boxed rather than standing: the vendor terminates on a broker you control, the path opens on request and expires by itself. A permanent permit is a doorway an intruder inherits into the segment holding your widest exceptions.

open as a page

Clinical engineering asks you to renew a blanket exception for 60 unpatchable devices. What do you sign, refuse or change?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Refuse the shape rather than the devices. Convert a blanket, indefinite exception into per-device enumerated permits with an expiry and a named owner, and get the residual risk accepted in writing by someone senior enough to accept it.

open as a page