Companies Should Address Cybersecurity Now: Consultants

In its Pulse of the Industry 2017, the EY medtech consulting firm says it’s only a matter of time until FDA enforces stringent regulations for the security of medical devices. The report notes that in 8/2017, the agency demonstrated how closely it continues to monitor potential cyber vulnerabilities, notifying providers and the public about a software update that could improve the safety of an implantable cardiac pacemaker.

“Medtech companies shouldn’t wait for either safety notifications or formal legislation, however,” the report says. “They need to take preemptive measures now. Setting up a formal security risk management function, including time to train engineers and establish appropriate security engineering processes and protocols, takes about 12 to 18 months to set up. A scarcity of cybersecurity experts proficient in medtech could further slow the process.”

Read more