Medical Device Hacking and the Vulnerability of Connected Medical Devices
November 13, 20181 min read78 words
I work on medical device cybersecurity because the failure mode is a person, not a spreadsheet. That reframes every argument about cost, timeline, and what good enough looks like.

The takeaways
- 01
Every connected medical device is an attack surface, and most were designed before that sentence was true.
What to do nextAdd medical to the next leadership review as a standing item, not a one-time slide.
- 02
FD&C Act 524B moved cybersecurity from nice-to-have to a gate for market clearance.
What to do nextRun a 20-minute tabletop with your team this month using market as the scenario.
- 03
The hard part is almost never the technology. It is the team culture that thought cybersecurity was someone else's job.
What to do nextRun a 20-minute tabletop with your team this month using team as the scenario.
- 04
Threat modeling early costs a fraction of what a post-market vulnerability disclosure costs.
What to do nextOpen your current threat plan today and identify the one gap you would not want an auditor to find.
Hacked medical devices are now a top security threat. Pacemakers, hospital equipment, anything connected wirelessly can be compromised. I spoke with Kim on Komando on Demand about the myths and realities of medical device hacking and security. We discussed what’s being done to make devices and hospitals more secure.
“A vulnerability in a medical device is not a data breach. It is a patient safety event with a network stack.”
Frequently asked
Keep reading
-
Hacking Medical Devices for Profit and Terror - Christian Espinosa
Same thread: cybersecurity.
Read essay → -
Aviation Cybersecurity – Hacking Aircraft - Christian Espinosa
Same thread: cybersecurity.
Read essay → -
Leetspeak: The History of Hacking Subculture's Native Tongue - Christian Espinosa
Same thread: cybersecurity.
Read essay →