All whitepapers

Whitepaper · July 28, 2025

FDA Cybersecurity ReadinessPlan & Benchmark Product SecuritySoftware as a Medical Device (SaMD)Software Bill of Materials (SBOM)Thought LeadershipVulnerability Management

What the Medical Device Industry Can Learn From Past Cybersecurity Vulnerability Disclosures

Insights From 10 Years of ICS-CERT Data (2013–2024) and FDA Postmarket Cybersecurity Trends

Open whitepaper PDF
Thumbnail for What the Medical Device Industry Can Learn From Past Cybersecurity Vulnerability Disclosures

Executive summary

What this whitepaper covers

Since the FDA issued its Postmarket Cybersecurity Guidance in 2016, the rate of ICS-CERT medical device advisories has increased by 386%, reflecting growing transparency and maturity across the medical device ecosystem.

This updated 2025 report extends Medcrypt’s longitudinal analysis through 2024, highlighting emerging patterns in vulnerability disclosure, patching, and regulatory impact.

Key findings reveal that:

  • Vulnerabilities continue to cluster around user authentication and code defects — making up nearly 60% of all disclosures.
  • Patch references in advisories declined by 22% in 2024, despite new FDA enforcement authority under Section 524B.
  • Only 27 of the top 40 medical device manufacturers maintain any public vulnerability disclosure process.
  • Half of all vulnerabilities originate from just four manufacturers, demonstrating a clear divide between proactive and lagging programs.

This whitepaper provides data-driven insights into where progress has been made, where it has stalled, and what medical device manufacturers (MDMs) can do to strengthen cybersecurity maturity in 2025 and beyond.

Why it matters

The regulatory and product context

Despite spending $10–20 billion annually on cybersecurity, the healthcare sector consistently ranks among the most targeted and least secure industries. Regulatory fragmentation, economic misalignment, and clinical priorities often push security down the list of business imperatives. As a result, security debt (vulnerabilities that originate from design, integration, or maintenance) is passed downstream to hospitals and patients.

Understanding these constraints is the first step toward systemic reform. This whitepaper provides insight into how industry and regulators can rebalance incentives, reduce security debt, and build sustainable, resilient healthcare technology systems.

Key insights

What you’ll take away

  • Vulnerabilities have tripled since 2016, but the root causes remain unchanged.
  • Disclosure transparency is improving, but patching performance declined in 2024.
  • 59.8% of vulnerabilities still stem from authentication and code-related issues.
  • Researchers now drive two-thirds of all disclosed advisories.
  • FDA’s new Section 524B patch enforcement may redefine disclosure behavior in coming years.

Who should read this

  • Medical Device Manufacturers (MDMs): product security, regulatory, and R&D teams focused on postmarket vigilance
  • Regulatory and Quality Professionals: responsible for FDA submissions and maintaining compliance with 524B and 81001-5-1
  • Healthcare Delivery Organizations (HDOs): security and IT teams relying on manufacturer disclosures for clinical risk management
  • Policy and Standards Leaders: working on coordinated vulnerability disclosure (CVD), ICS, and cybersecurity harmonization
Open PDF

Know where your submission stands this week.

Run the free check in about five minutes or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness
Exploded insulin pump showing its display enclosure, protective plate, control board, pump mechanism, insulin reservoir, and infusion-set tubing connection