惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
N
Netflix TechBlog - Medium
GbyAI
GbyAI
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
IT之家
IT之家
博客园 - Franky
雷峰网
雷峰网
博客园 - 聂微东
腾讯CDC
M
MIT News - Artificial intelligence
B
Blog RSS Feed
博客园_首页
罗磊的独立博客
S
SegmentFault 最新的问题
I
InfoQ
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
D
Docker
宝玉的分享
宝玉的分享
B
Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
Report: Medical device cyberattacks on the rise
Colin Ryan · 2026-04-29 · via Enterprise – Silicon Republic

A key driver for the rise in medical device cyberattacks, according to RunSafe, is the prominence of legacy tech in healthcare environments.

Cyberattacks on medical devices are becoming more frequent and more disruptive, according to a report released by US cybersecurity company RunSafe Security today (29 April).

The 2026 Medical Device Cybersecurity Index, based on a March 2026 survey of 551 healthcare professionals throughout the US, UK and Germany involved in device purchasing decisions, found that 24pc of surveyed healthcare organisations experienced a cyberattack on a medical device – a rise of 2pc compared to last year.

Of those that experienced an attack, 80pc reported moderate or significant patient care impact as a result, with a quarter of the cohort reporting significant impact.

According to the report, the most commonly affected systems included electronic health record systems (cited by 35pc of affected organisations), patient monitoring devices (23pc), laboratory and diagnostic equipment (18pc), networked surgical equipment (10pc) and imaging systems (8pc).

The most dominant cyberattack methods seen in these incidents were malware infections requiring device quarantine – which were responsible for nearly half of the incidents (48pc) – and network intrusion requiring device isolation (41pc), with both of these incident types maintaining their dominant popularity from 2025.

However, one incident type that RunSafe noted as emerging particularly in 2026 was remote access exploitation, which was seen in 38pc of incidents. RunSafe stated this signalled that attackers are “adapting to the growing remote access footprint of connected devices”.

“Organisations that have not implemented network segmentation, access controls and runtime protections are exposed,” said the company.

For those organisations that experienced a cyberattack on a medical device, recovery was not so simple.

Nearly half (49pc) of reported incidents caused “extended stays or required manual workarounds”, according to the report, with the most common recovery scenario – experienced by 39pc of impacted organisations – involving five to 12 hours of downtime. Meanwhile, 5pc of affected organisations experienced downtime of more than three days.

Legacy issues

A key driver of the growing medical device cyberthreat, according to RunSafe, is the prominence of legacy devices that cannot be patched or easily replaced.

The report found that three in 10 responding organisations operate medical devices that are past the manufacturer’s end-of-support date. A significant proportion of those devices carry known, unpatched vulnerabilities, according to RunSafe.

The reported reasons as to why these healthcare organisations continue to operate at-risk legacy devices spanned clinical, financial and structural constraints.

38pc of respondents said there was no “acceptable” replacement available yet for the legacy device in question, while 36pc said they cannot afford a replacement.

34pc cited regulatory or approval constraints as a barrier, 33pc said replacing the device or system would cause too much disruption and interestingly, 17pc stated that the risk presented by this legacy tech has been formally accepted by leadership.

“The inability to patch, combined with continued clinical reliance on vulnerable devices, creates a structural security gap that cannot be closed solely through procurement alone,” said RunSafe in an analysis of the topic of legacy devices.

“This gap is almost certainly a key driver behind the rise in runtime protection adoption seen in 2026. Runtime protection technologies – which defend devices without requiring a patch – act as a compensating control for a problem that buying new devices cannot solve.”

As recognised by the report, runtime protection technologies are emerging as a critical “compensating control”, with 82pc of respondents stating that they have widely deployed or are piloting runtime exploit protection.

A vulnerable sector

The rise of medical device cyberattacks highlighted by this report comes as the healthcare industry continues to experience breaches and attacks ranging in severity, as noted by RunSafe founder and CEO Joseph M Saunders.

“The findings land against a backdrop of large-scale healthcare cyber incidents that have disrupted care delivery and revenue flows, underscoring how quickly attacks on device-adjacent systems can translate into patient harm,” he said.

“Medical device cybersecurity is increasing in importance to healthcare buyers as they see it as a patient safety and regulatory imperative.”

Last month, medical equipment manufacturing giant Stryker was hit by a cyberattack that caused a global network disruption. Reports at the time suggested that the company’s Cork plant, which employs more than 4,000, was affected by the attack – which pro-Iranian cyber group Handala claimed responsibility for.

Meanwhile, just a few weeks ago, Dublin recruitment platform Healthdaq – which is used by Northern Ireland’s health trusts – reportedly suffered a cyberattack from the relatively new hacker group XP95, which claimed to have accessed hundreds of thousands of files.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.