A ransomware attack that cuts off a hospital’s ventilation stops being an IT problem. It becomes a building problem.
Key points
- A ransomware attack disrupted access systems and ventilation equipment at a Winnipeg hospital.
- The incident highlights the interdependence of physical and digital infrastructure.
- Any organization whose systems support an essential service is exposed to this risk.
- Identifying your critical system and testing its recovery costs time, not budget.
What do we know about the incident?
According to available information, a ransomware attack disrupted access to computer systems as well as ventilation equipment at the Health Sciences Centre in Winnipeg, a major healthcare facility in Canada. The attackers’ method and demands have not been disclosed.
The exact impact on clinical operations or patient safety has not been made public. We will not speculate: what has been confirmed is enough to draw the lesson.
What stands out is the scope of the breach. It was not limited to records or email; it reached equipment that regulates a building’s air. In practice, the line between information systems and physical systems no longer exists.
Why should an SME see itself in this?
Because the mechanism does not depend on size or sector. An organization whose operations rely on computer systems suffers the same kind of disruption, with one decisive difference: it does not have a public hospital’s reserves to absorb several days of downtime.
The interdependence of physical and digital infrastructure is the most underestimated risk we encounter. A workshop where machines are controlled from an office computer, a warehouse where doors and refrigeration are run by a controller connected to the same network as accounting: these are ordinary setups, and they turn an IT incident into a production stoppage.
Ransomware operators do not only target large institutions, either. The Canadian Centre for Cyber Security puts it plainly: all Canadian organizations are at risk, regardless of size, because targeting is largely automated.
What should be done in the coming weeks?
Three actions, in this order, none of which requires a budget. Identify the system whose failure would stop your operations. Confirm that a backup of that system has actually been restored, for real. Separate what controls physical equipment from what runs office work.
- Identify the critical system. Not the most visible one, nor the one most talked about, but the one whose unavailability would stop you from billing, producing, or serving your customers.
- Prove the backup works. A green status report in the morning means the job ran, not that a file can actually be recovered from it. The restore test is the control, not an optional extra.
- Separate operational technology from office IT. The minimum goal, often sufficient as a first step, is that a compromised office computer can no longer reach production equipment.
- Write down fallback procedures. How to keep running for half a day without the main system: paper order forms, a printed contact list, a backup cash register. It sounds outdated until the day it saves the day.
We remain available to assess your organization’s exposure and how much your operations actually depend on your systems.
FAQ
Can our technical equipment really be reached from the office?
In most assessments we conduct, yes, and the organization did not know it. The cause is rarely a deliberate decision: it is a wiring shortcut, a controller plugged into the nearest outlet, a remote maintenance box that shipped with a machine. None of this appears in official documentation, which makes it more dangerous still: it is not monitored, not patched, and not included in audit scopes.
Can you secure a controller that cannot be updated?
Yes, by not touching it. A controller whose vendor no longer issues patches, or whose configuration was validated by the machine’s manufacturer, should not be updated blindly: doing so can void a warranty or a compliance certificate. The answer is isolation: minimize what can communicate with it, log those exchanges, and place controls at the network level rather than on the device itself.
Does health data change our obligations?
It makes them heavier. Health information counts as sensitive personal information, which raises the expected level of protection and tightens the assessment of serious harm risk in the event of an incident. For a Quebec organization holding even a small volume of such data, this means real encryption, access limited to those who need it, and logging of who consults it.
Sources
- Radio-Canada · ransomware attack at the Winnipeg Health Sciences Centre, 2026
- Canadian Centre for Cyber Security: Ransomware threat overview 2025 to 2027 · exposure of all Canadian organizations
- Commission d’accès à l’information du Québec (Quebec’s access to information commission) · sensitive information and incident-related obligations