An ethical approach to hacking

This case study is based on

The case study centers around CyberHealth Security, a cybersecurity consultancy hired to assess the digital security of MedTechPro Hospital (MTPH).

As a technologically advanced healthcare institution, MTPH relies heavily on:

  • electronic health records (EHRs)
  • internal communication systems
  • IoT-enabled medical devices

The goal of CyberHealth is to conduct structured penetration testing using .

PTES Phases

  • Pre-engagement interactions: Planning the test scope, goals, and ethical boundaries. Black box, white box, and grey box testing approaches are evaluated.
  • Intelligence gathering: Using OSINT to collect public data on MTPH, including employee info, network topologies, and exposed systems.
  • Threat modelling: Identifying potential attackers and evaluating their capabilities and intentions. Key digital assets like EHRs are prioritized.
  • Vulnerability analysis: Automated and manual scans uncover system weaknesses and assess their risk levels.
  • Exploitation: Testing real-world attacks such as SQL injection, cross-site scripting, and buffer overflow to gauge system resilience.
  • Post-exploitation: Evaluating data access, privilege escalation, persistence, and forensic traces to understand breach implications.
  • Reporting: Delivering a comprehensive report with findings, impacts, and prioritized security recommendations.

Ethical and Operational Challenges

The case study emphasizes ethical responsibility, especially in a healthcare setting. Testers must:

  • Obtain proper authorization
  • Ensure data confidentiality and integrity
  • Avoid disrupting hospital services
  • Deliver actionable and transparent reporting

Operational challenges include selecting suitable testing approaches, conducting safe reconnaissance, and planning incident response strategies.

International Baccalaureate Organization © 2025

Your goal is to familiarise yourself with the case study (see pdf above) in order to answer Paper 3 exam questions.

An initial strategy is to read the Case Study. This year's is not very long.

Start a notebook or online journal and create a glossary of essential terms you encounter with a definition for each one.

Penetrating Testing Intro