Evidence: threat model. Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.

Case at a glance

Case number
008
Date / range
Threat-model scenario
Sector
Genomic infrastructure
Genetic asset
Hypothetical sequencing workflow and laboratory datastore
Security principle
Genomic Infrastructure Compromise

Event summary

The security boundary includes sequencer remote access, credentials, host software, cluster filesystems, data stores, transfer paths, and administrative interfaces.

Source: NIST: Genomic Data Threat Modeling.

Acquisition and processing

Remote access and account compromise may provide paths toward data stores

What became inferable or exposed

Hypothetical sequencing workflow and laboratory datastore

The security boundary includes sequencer remote access, credentials, host software, cluster filesystems, data stores, transfer paths, and administrative interfaces.

Security dimensions

Confidentiality

Potential exposure in the model; no observed compromise claimed.

Integrity

No demonstrated data alteration established by the cited material.

Availability

Ransomware models loss of access; no real outage assigned.

Provenance

Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.

Use the scenario to ask better questions

The value of a threat model lies in the questions it makes concrete. Which remote paths reach an instrument? Which identities can move data into shared storage? What would prevent a compromised account from affecting a larger workflow? These questions can be useful without implying that the scenario records an actual attack.

For a hypothetical workshop, draw the instrument, analysis environment, and data store as separate parts. Mark the access between them and identify who is responsible for each connection. Then examine where an unwanted action could continue beyond its initial entry point. The drawing should describe the real workflow under review, not an assumed generic laboratory.

Restore the workflow, not just the files

An exercise can consider what happens after access is restored. Are the inputs, reference versions, and outputs still trustworthy? Can staff distinguish work completed before the disruption from work that needs review? Could a restored report be associated with the wrong stage of analysis?

These are proposed recovery questions, not reported consequences of the NIST scenario. They help keep integrity and provenance in view alongside availability. A team may need separate evidence that data is readable, that it is the expected version, and that it supports the intended result.

Why the scores remain blank

There is no specified population of confirmed victims or observed set of exfiltrated files in this record. Assigning a numeric exposure radius or persistence level would require additional scenario assumptions. Those assumptions could be useful in a workshop, but they should be written down explicitly.

Leaving the scores unassigned makes that boundary visible. It also prevents someone downloading the database from accidentally treating a modeled pathway as a measured breach. The record is evidence that a threat was analyzed, not evidence that the threat occurred.

GeneticSecurity.org analysis

Genetic Exposure Radius

Not assessed

Not assigned: no bounded observed exposure with sufficient evidence. Scenario scope must be specified before scoring.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Persistence Risk

Not assessed

Not assigned: the information exposed or its retention is insufficiently specified. Biological-resource loss is different from credential persistence.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Provenance Integrity

Not assessed

Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

What this case does not prove

This is a documented threat-model scenario, not evidence that this exact attack occurred in a real laboratory.

Mitigations and lessons

Segment instrument networks; protect remote access; test offline restoration; pin workflow versions and verify artifact integrity.

Primary sources

Secondary sources

No additional source listed. See the evidence notes for limitations.

Policy and standards

Genetic Security Policy and Standards

Review and correction history

Last reviewed: September 19, 2026. Initial source synthesis; no substantive corrections recorded.

Correction policy and log

Cite this case

GS-CASE-008. Sequencer to Datastore: NIST's Ransomware Model for a Genomic Laboratory. GeneticSecurity.org. https://geneticsecurity.org/cases/008-genomic-sequencing-ransomware-threat-model/