How a software provider closed unknown paths to cloud compromise

Wait 5 sec.

A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security and compliance efforts.Then an insider threat penetration test (pentest) with NodeZero® showed how quickly a single compromised developer credential could enable lateral movement through the environment and toward cloud infrastructure supporting software delivery.“It owned our network in a matter of minutes,” said the company’s IT operations leader.That result changed the conversation immediately. This was not simply a healthcare organization protecting endpoints and servers. The provider was operating in a position of downstream trust, where a compromise would potentially impact customers, healthcare operations, and the systems relying on their software.The organization realized that annual pentests and scanner output were not enough to answer the question that actually mattered: What can an attacker really do once inside the environment?That realization pushed the company toward continuous validation, repeated testing, and a far more operational approach to exposure management.Outcomes at a glanceEliminated internal exposure stemming from 16 weaknesses that compromised four hosts leading to AWS compromise and sensitive data exposureReduced AWS exposure leading to critical business impacts to two low-severity weaknesses that were not able to be chained together to lead to any business impactEliminated overly permissive, local-administrator access across the environment after NodeZero demonstrated rapid lateral movement and privilege escalationImplemented privileged access approval workflows and expanded MFA enforcementEstablished a repeatable monthly cadence of testing, remediation, and validation src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Image1.png" alt="Internal Testing">Image 1: Initial internal testing identified 16 weaknesses compromising 4 hosts which led to AWS compromise and sensitive data exposure.ImpactThe security team believed their network was secure. That was until they understood what an attacker could do once inside their network. The real question wasn’t whether individual weaknesses existed. It was what an attacker could accomplish when those weaknesses were chained together in a real environment.Like many software providers, the organization operated with a widely distributed workforce, extensive developer access requirements, hybrid infrastructure, and growing cloud dependencies. Before adopting NodeZero, the company relied heavily on traditional vulnerability scanning and annual penetration testing. The team understood the limitations immediately after running NodeZero for the first time because the insider threat pentest exposed how quickly those assumptions did break down.“When you think about what an annual penetration test is, it’s a snapshot at a moment in time,” said the IT operations leader. “Technology does not stand still. It only changes.”The team initially attempted a phishing impact pentest paired with their Microsoft 365 environment, but no employees entered credentials during the exercise. Rather than stopping there and trusting their employees would never fall for a phish, the organization decided to model a more realistic compromise scenario by asking three employees — a developer, someone in HR, and someone in support — to intentionally submit credentials into the phishing pentest so the team could observe what an attacker could actually do with different levels of access.That decision quickly exposed where the real risk existed.The HR and support accounts were effectively contained, but once NodeZero impersonated the developer account, the attack path expanded rapidly. The platform cracked password hashes, escalated privileges, moved laterally across segmented environments, and attempted to traverse toward AWS-connected resources.“We’re completely segmented,” said the operations leader. “We thought we were fine by being siloed. But NodeZero jumped the segments.”The speed of the compromise surprised the team, but the path itself was even more important. A single developer system with elevated access had effectively become the pivot point that would allow attackers to move through the environment.That moment reframed the problem entirely. The organization was no longer looking at isolated vulnerabilities. It was looking at exposure, attack chaining, and the reality that one compromised developer credential could potentially become something much larger. src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Image2.png" alt="Image2">Image 2: NodeZero demonstrated how a compromised developer path could move laterally across segmented environments to obtain host compromise.Click here to explore the details around mitigation and remediation efforts.Conclusion“Ultimately, our goal is to make sure our staff has jobs to come to each day,” said the IT operations leader.That perspective reframed the problem entirely. Not as compliance or vulnerability management, but as the ongoing responsibility to continuously validate that it is not possible for a real adversary to traverse their environment.Learn more about Horizon3.ai and NodeZero.