Managing Legacy Device Cyber Risks

Share

A Mitre Corp. report, “Next Steps Toward Managing Legacy Medical Device Cybersecurity Risks,” prepared under a contract with FDA, makes recommendations for protecting legacy medical devices that “cannot be reasonably protected against current cybersecurity threats.” The report says that because of the long lifetimes of medical devices and the lack of harmonization between medical device manufacturer and healthcare delivery organization practices for supporting and replacing devices, what may have been effective cybersecurity controls present at the point of purchase may no longer adequately defend against current cyber threats.

At the same time, it says, legacy medical devices may still be broadly in use and providing needed healthcare, and simple removal of them may present risks to patient safety and clinical operations, as well as fiscal challenges. “Since legacy risks likely cannot be mitigated sufficiently through patching and updating due to outdated technology and compatibility issues, other approaches to managing these risks may be required,” Mitre says.

Mitre used stakeholder interviews and working group discussions to make these recommendations:

  • secure legacy medical devices by implementing regular software updates, establishing firewalls, and ensuring compatibility with modern security protocols, among other controls;
  • improve manufacturing and develop transparency among developers and users;
  • improve the turnaround time for security updates and patches;
  • increase the adoption and rigor of the secure development lifecycle in the development of medical devices;
  • require strong authentication to improve identity and access to medical devices; and
  • employ strategic and architectural approaches to reduce attack surfaces.

Read more