3
min reading time
Cybersecurity professionals have been alarming the healthcare industry about the threat of exploitation of smart healthcare devices and the doctors’ over-dependence on them until sadly, their warnings became reality, and a person lost her life in a ransomware attack in a German hospital last year.
How the ransomware paralyzed the Duesseldorf University Hospital?
According to the official reports, the internal system of the hospital crashed gradually. First, the hospital staff couldn’t access the data of the hospitalized, then, they got to a point where they couldn’t even perform life-saving operations due to the lack of necessary data and the availability of smart equipment.
Additionally, readers could follow the unfortunate events of the WannaCry cyberattack in 2017 via media, which shut down major healthcare systems, like the NHS in the United Kingdom. Luckily no deaths occurred due to the attack, though it drew the attention of healthcare professionals and smart device creators to the main underlying issue.
Are we threatened by the cybersecurity issues of healthcare devices in any other way?
From patient records and lab results, radiology equipment, hospital elevators to personal wearable tracking devices and mobile applications, healthcare professionals, and individual tech users are increasingly reliant on smart devices that are connected to the Internet. Even though this interdependence facilitates easy data access, data sharing, or user/patient engagement, it contains the risk of data theft, malicious data alteration, denial of access to crucial data, or blackmailing.
In early 2019, researchers in Israel announced that they’ve created a virus that is capable of adding malicious tumors into CT and MRI scans, which proves to be a powerful weapon in order to trick doctors into misdiagnosing their patients.
Talking about wearable tracking devices and applications: they also pose a growing security risk, as their measurement system and statistics become more subtle and real-time. Sadly, these devices are not an exception to vulnerability exploitations. “When you’re looking at the ‘brain’ of one of these devices, if the software isn’t designed to protect itself and it’s not designed without design flaws and without vulnerabilities and implementation bugs in it — which we’ve seen — then it will be attacked,” said Gary McGraw, CTO of software firm Cigital.
How can we avoid such cybersecurity exploitations?
In the healthcare sector, two new regulations have been passed on 25 May 2017, which introduce new safety regulations for medical devices within the EU. As a result, manufacturers can keep building revolutionary, state-of-the-art smart devices, although they will need to abide by the new principles of risk management.
Common Criteria Evaluation is an international standard for computer security certification. By thoroughly evaluating the manufactured devices, let them be healthcare smart tools, or anything else, we can make sure they comply with international regulations, and most importantly, they are built with cybersecurity in mind.
At CCLab, apart from Common Criteria Evaluation, we provide cybersecurity consultation, penetration testing, cybersecurity relevant risk management services and support the security of your product lifecycle management and information security management processes, in order for your medical devices to fulfill the expectations of professionals, and private individuals alike, who are cautious about their personal data.
Want to understand the MDR, IVDR regulation? Download our e-book on the latest requirements of medical cybersecurity
Read and learn more about the Radio Equipment Directive (RED), download our free material now.
Download our ETSI EN 303 635 infographics today and learn about the product certification process for this consumer IoT device cybersecurity standard.
The rapid advancement of connected medical devices has revolutionized the healthcare sector, particularly in vitro diagnostics (IVD). These devices are pivotal in disease detection and management, from genetic tests and blood glucose meters to infectious disease diagnostics, underpinning modern healthcare practices. The global market for in vitro diagnostics (IVD) is projected to grow significantly, with estimates predicting a compound annual growth rate (CAGR) of 5% to 7%, driven by advancements in connected diagnostic devices. While these innovations enhance diagnostic accuracy and operational efficiency, they also amplify cybersecurity risks, demanding urgent attention to device security. However, the growing connectivity of in vitro diagnostic devices exposes them to cybersecurity threats, posing risks to patient data, diagnostic accuracy, and operational continuity. This article explores the vulnerabilities of connected IVD devices, the significance of IVDR compliance, and strategies to safeguard against emerging cyber threats.
10
min reading time
As cyber threats become more sophisticated, businesses are compelled to implement rigorous protection strategies to stay compliant and secureCertification labs, like CCLab, play a crucial role in supporting businesses with expert testing, assessment and comprehensive compliance services, and specialized training. These labs offer services ranging from security audits to penetration testing, ensuring businesses remain resilient against evolving cyber threats while meeting regulatory standards. This article explores the indispensable role of certification labs, highlighting how they enhance cybersecurity, ensure compliance, and support a safer digital landscape.
9
min reading time
This year, CCLab sponsored the opening reception of the International Common Criteria Conference (ICCC) in Qatar. Like in previous years, CCLab experts were present during the event meeting the most important stakeholders of Common Criteria. The ICCC is a highly prestigious professional event now in its 23rd year. It provides opportunities for networking and various forums to discuss CC policy and development. It is aimed at participants involved in the specification, development, evaluation, certification, and validation of IT security products and systems.
5
min reading time