Summary
For healthcare institutions like Mercy Health, strong cybersecurity isn’t just about protecting patient data – it directly impacts the quality of care Australians receive. Understanding growing cyber threats – highlighted in the 2024 Ponemon Healthcare Cybersecurity Report, which found that 92% of healthcare organisations experienced a cyberattack in 2024 – Mercy Health made it a priority to enhance its security posture.
To stay ahead of potential risks like a large vulnerability backlog and an unsupported device fleet, they proactively partnered with Endpoint Focus. Together, they implemented a robust Vulnerability Management Service, successfully upgraded thousands of devices to the latest Windows 10 Feature Update, and established a forward-thinking security framework.
This collaboration has drastically improved security posture, ensured regulatory compliance, and fortified Mercy Health’s ability to protect sensitive patient data without disrupting life-saving services.
Introduction
Mercy Health is a major Australian provider of health and community services, operating around the clock to deliver exceptional patient care. With a vast network of hospitals and aged care facilities, their operations depend on thousands of devices, including mobile ‘Workstation on Wheels’ units used at bedsides. In a highly regulated industry where patient data privacy is paramount, maintaining a secure and efficient IT environment is not just a priority – it’s essential for their mission.
The problem
Healthcare organisations worldwide are prime targets for cyber exploitation, facing sophisticated threats that jeopardise patient data and operational integrity. The pressure to deliver critical care, often with legacy systems and numerous interconnected devices, creates vulnerabilities.
Proactive cybersecurity is paramount to fortifying defences and safeguarding patient trust. A staggering 99% of healthcare organisations manage IoMT (Internet of Medical Things) devices with known vulnerabilities, highlighting the urgent need for robust security strategies.
Facing these universal challenges, Mercy Health’s IT team was stretched thin by several critical projects. Their primary challenges included:
- Need for a proactive vulnerability management regime: The team needed to establish a continuous program for managing patches and upgrades across their entire fleet of computers to keep security threats at bay..
- Maintain up-to-date devices: A significant number of devices needed a timely in-place upgrade from unsupported Windows 10, but given the 24/7 nature of hospital operations and zero tolerance for downtime, these upgrades are notoriously complex to execute.
- Compliance pressures related to third-party application patching: Strict Department of Health standards required monthly reporting and timely patch management. The organisation needed an efficient way to deploy these patches for hundreds of non-Microsoft, third-party applications to close security gaps.
These issues created a challenging environment. With a constant threat of security breaches and the need to comply with strict Department of Health cybersecurity standards, Mercy Health needed a partner who could provide deep technical expertise and hands-on support.
The Solution
Endpoint Focus, a specialised endpoint security and management integrator, stepped in to provide a tailored, multi-faceted solution. The partnership began with a clear strategy to tackle Mercy Health’s most pressing issues head-on.
- Establishing a robust patching regime
The foundational work was dedicated to creating a solid System Centre Configuration Manager (SCCM) patching process. Endpoint Focus worked with Mercy Health to set up and fine-tune deployment rings, ensuring that updates were tested in pilot groups before being rolled out across the organisation. This methodical approach minimised disruption and was guided by Mercy Health’s KPIs for reducing critical and high-level vulnerabilities.
- Strategic and seamless upgrades
The team knew that system updates could be disruptive in a busy hospital environment. To manage this, they developed a strategic communication and scheduling plan. Updates were scheduled during quieter periods based on a greater understanding of business operations. This people-first approach ensured that patient care was never compromised.Endpoint Focus successfully executed the large-scale, timely in-place upgrade for Windows 10 version. The project was heavily automated, but far from ‘set-and-forget’. Latter stages required the team to manually track down devices that were offline, out of space, or not syncing correctly.
- Implementing a comprehensive vulnerability management service (VMS)
Endpoint Focus’s VMS became the cornerstone of Mercy Health’s new security posture. This involved:
- Initial assessment: A thorough review identified immediate security fixes and established a baseline for improvement.
- Process automation: Key security processes were automated and integrated into existing workflows, ensuring IT and cyber defence teams were always informed.
- Advanced security infrastructure: Beyond vulnerability management, the solution included migrating to the CrowdStrike platform for enhanced endpoint protection, deploying a hardened Windows 11 environment, and implementing application whitelisting.
“Healthcare is a high-stakes environment where technology must be an enabler, not a hindrance. We worked closely with Mercy Health to build a security framework that was not only robust and compliant but also flexible enough to support their 24/7 operations without getting in the way.”
Dave Stagg
Director, Endpoint Focus
Results
The partnership between Endpoint Focus and Mercy Health has transformed the hospital’s cybersecurity landscape, delivering measurable outcomes and fostering a culture of proactive security.
- Significant vulnerability reduction: The targeted VMS has dramatically reduced Mercy Health’s security exposure, creating a safe environment for patient data and critical operations.
- Full regulatory compliance: Mercy Health now confidently meets the Victorian Department of Health’s cybersecurity standards, including alignment with the Essential 8 framework.
- Improved security maturity: The organisation has transitioned to a mature and resilient cybersecurity posture.
- Limited disruption to operations: All major upgrades and security implementations were completed with minimal interruption to patient care, a critical success factor for the project.
- Standardised and reliable environment: With most devices now on a standard operating environment (SOE), the user experience is more consistent, and the IT support team can resolve issues more efficiently.
- Internal team growth: Endpoint Focus continues to provide ongoing support and mentorship, helping Mercy Health build its internal cybersecurity expertise for the long term.
“Endpoint Focus’s Vulnerability Management Service has transformed the way we manage risk. Since engaging them, we’ve reduced our critical vulnerabilities significantly. Their proactive, hands-on approach has lifted a huge weight off our internal teams and given us confidence that patching and remediation are being managed end to end.”
Vijay Narayan
Chief Information Security Officer (CISO), Mercy Health
Conclusion
The collaboration between Mercy Health and Endpoint Focus is a testament to the power of a true partnership. By combining deep technical skill with a genuine understanding of the client’s operational needs, Endpoint Focus delivered a security transformation that went far beyond a simple checklist. They have not only resolved critical challenges but have also empowered Mercy Health to face the future with confidence.
As the relationship continues, Endpoint Focus is helping Mercy Health with its ongoing Windows 11 migration and other strategic projects. The foundation of trust, honesty, and shared accountability has made this partnership a resounding success.

