IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

80% of medtech firms suffered a cyber attack in the past five years

Survey finds that just 18% of organizations believed their medical device security was strong

CAT scan machine with IoT markings in the foreground

Medical internet of things (IoT) devices promise great benefits, but companies working with them must tighten their cyber security, according to new research from Irdeto.

The security company surveyed senior executives at Fortune 1000-sized US-based companies working in the medical device sector to assess their cyber security stance.

Responses to the survey suggested a high level of confidence in medical IoT security among just one in five companies, with 18% believing their medical device security was strong. Slightly fewer (13%) believed they were well-prepared to mitigate future risks, while 18% weren’t prepared at all.

These responses correlated with the rate of reported security incidents. The survey found 80% of companies suffered at least one cyber attack in the past five years, with over two-thirds (67.5%) sustaining multiple attacks.

Poor cyber security is often linked to a lack of visibility, as you can’t manage what you can't see. Most companies (78%) found device inventory management problematic, often because of bureaucracy. Many failed to patch the devices they could see, warned the report. And if they did patch them, they used inefficient and possibly dangerous methods, such as passing patches around on USB keys.

Related Resource

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Security analytics for your multi-cloud deployments - whitepaper from IBMDownload now

Most companies want to mitigate their medical device cyber security problems by turning to the cloud, with 48% advocating for this solution. This clashes with a separate Trend Micro survey that revealed significant cloud adoption challenges, including privacy and security concerns.

When assessing the importance of cyber security, companies concentrated heavily on compliance rather than the risk of business disruption or financial losses. Of the respondents, 80% cited regulatory requirements as a driving factor for cyber security, with just over two-thirds pointing to brand protection as an issue. Only 2.5% worried about ransomware or financial losses.

Understanding those regulations was not universal, with 40% saying they had a good handle on new cyber security rules. Another 45% said their cyber security knowledge was adequate. A worrying 15% claimed to have no knowledge of regulations at all. Some companies were escalating regulatory compliance to board level, while others called in their legal teams. Other companies working with medical devices focused on external help.

Featured Resources

Join the 90% of enterprises accelerating to the cloud

Business transformation through digital modernisation

Free Download

Delivering on demand: Momentum builds toward flexible IT

A modern digital workplace strategy

Free download

Modernise the workforce experience

Actionable insights and an optimised experience for both IT and end users

Free Download

The digital workplace roadmap

A leader's guide to strategy and success

Free Download

Recommended

Protecting healthcare from cybercrime
Whitepaper

Protecting healthcare from cybercrime

25 May 2022
Best paying tech jobs of 2022
Careers & training

Best paying tech jobs of 2022

10 Mar 2022
Why is the healthcare industry so vulnerable to ransomware?
Sponsored

Why is the healthcare industry so vulnerable to ransomware?

28 Feb 2022
Vast majority of US healthcare web apps vulnerable to attack
network security

Vast majority of US healthcare web apps vulnerable to attack

24 Nov 2021

Most Popular

Universities are fighting a cyber security war on multiple fronts
cyber security

Universities are fighting a cyber security war on multiple fronts

4 Jul 2022
Hackers claim to steal personal data of over a billion people in China
data breaches

Hackers claim to steal personal data of over a billion people in China

4 Jul 2022
Raspberry Pi launches next-gen Pico W microcontroller with networking support
Hardware

Raspberry Pi launches next-gen Pico W microcontroller with networking support

1 Jul 2022