Research Library / Case Studies /

Medical Technology (Medtech)

A Leading Medtech Enterprise Assesses its Thick Client Application

Before this medtech company's device software could clear audit and reach the market, Payatu pentested its thick client application across licensing, network, and physical attack vectors, and helped finish the PSR, PSSA, SOM, and Test Case documents the auditor required.
Thick Client Application Security Assessment

At a glance

INDUSTRY

Medical Technology (Medtech)

CLIENT PROFILE

A global medical technology company building medical, surgical, neurotechnology, orthopedic, and spine products

SERVICES

Thick Client Application Security Assessment

ENGAGEMENT

Thick client penetration test plus compliance documentation ahead of market release

Key Takeaways

  • Client – A global medical technology company that builds medical, surgical, neurotechnology, orthopedic, and spine products, where devices and software ultimately operate on patients' bodies.

  • Problem – Before launch, the client needed its thick client application security assessed and a set of formal security and privacy documents completed to satisfy an internal compliance audit and clear the product for market release.

  • What Payatu did – Ran a full thick client assessment covering licensing, peripheral network, physical ports, and internet-based attack vectors, plus code review for known CVEs, and completed PSR, PSSA, SOM, and Test Case compliance documents.

  • Outcome – The client received a hardened thick client build along with audit-ready documentation, clearing the path for its medical device software to pass internal security and quality checks ahead of market release.

the challenge

Why the client called us in

Our client is a global medtech company whose thick client software runs devices used directly on patients, so any flaw carries real clinical risk. Before the product could clear its internal audit and go to market, the client needed the application penetration tested and a stack of formal compliance documents completed to prove the mitigations were in place. The team also needed the results tied back into those documents with clear cross references so an internal senior auditor could sign off.

  • Get an independent security assessment of the thick client application
  • Complete the PSR, PSSA, SOM, and Test Case documents required for internal audit
  • Produce cross-referenced evidence linking findings to compliance documentation

‍

scope of engagement

What was in scope

  1. License assessment of the thick client application
  2. Internet-based attack vectors
  3. Periphery network assessment
  4. Code review for known CVEs in third-party libraries
  5. Physical ports attack vectors
  6. PSR document covering mitigation practices for developers
  7. PSSA document covering mitigation practices
  8. SOM document covering user-side protections against malware and viruses
  9. Test Case document recording test cases, expected results, and observed anomalies

Our Approach

How Payatu ran the engagement

01

Application Setup and Baseline
Installed the application and began working through the obfuscated codebase to understand its structure.

02

Bypassing Controls
Bypassed the code obfuscation and the license check, then manipulated the application's configuration file to extend the license date.

03

Input and Binary Attacks
Supplied payloads manually into UI textboxes, hijacked application DLLs, and checked for vulnerable libraries.

04

Exploitation
Fed malicious input files to the application to achieve remote code execution.

05

Threat Modeling and Reporting
Ran a threat modeling exercise across the application and built a pentest report with an added compliance section.

Documentation and Audit Support

Documentation and Audit Support
Filled in the PSR, PSSA, SOM, and Test Case documents, updating them based on the client's compliance team's feedback.

Key findings

What we found

Binary Hardening
Payatu recommended obfuscating application binaries, blocking runtime input from the console, restricting binary permissions to authorized users, and implementing anti-dynamic instrumentation protections.
Dependency and Code Hygiene
Payatu recommended keeping dependencies on their latest versions and conducting a proper code review before every release.
Access and Directory Restrictions
Payatu recommended blocking installation into shared directories and restricting the treatment plan directory to the system user running the application.
Data Protection
Payatu recommended keeping log files free of sensitive user and license information.

the outcome

Results and Impact

Our assessment gave the client's medtech team a clear, prioritized list of thick client vulnerabilities and the remediation guidance to close them before their internal compliance audit. The completed PSR, PSSA, SOM, and Test Case documents gave the internal senior auditor the evidence needed to sign off on the release, keeping the device software's market launch on track.

‍

  • Thick client application vulnerabilities identified, explained, and prioritized for remediation

  • Four compliance documents (PSR, PSSA, SOM, Test Case) completed and cross-referenced to findings

  • Application positioned to pass internal audit ahead of market release

  • Concrete recommendations delivered on licensing, binary permissions, logging, and code review practices

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment