惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
D
DataBreaches.Net
F
Fortinet All Blogs
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
H
Help Net Security
M
MIT News - Artificial intelligence
美团技术团队
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Cloudflare Blog
有赞技术团队
有赞技术团队
L
LangChain Blog
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
S
SegmentFault 最新的问题
V
Visual Studio Blog
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
B
Blog
I
InfoQ

Silicon Republic

After Amazon, Google commits up to $40bn in Anthropic Cohere buys Aleph Alpha to forge sovereign AI alternative to US Big Tech 4 easy ways to stay on top of cybersecurity in the workplace 15 companies you’ll see at NIBRT Careers in Biopharma 2026 Bloomberg: Bezos’ Project Prometheus bags $10bn at $38bn value Meta to lay off 10pc of its workforce amid an AI push China's DeepSeek unveils long-awaited V4 AI model Intel’s shares soar as Q1 results signal brighter future MongoDB to create 200 new jobs as it invests €74m into Irish operations Why it's full STEAM ahead for young people upskilling in Ireland's west Swedish legal-tech Legora buys AI legal research start-up Qura Belfast’s Cloudsmith eyes ‘massive growth’ with $72m raise France's Univity raises €27m to allow European telecoms compete with Starlink France's Univity raises €27m to allow European telecoms to compete with Starlink AI race intensifies with Google's new agent management platform Government launches new AI initiative for greater access to essential skills Free and inexpensive cybersecurity courses to undertake in 2026 UL looking for ‘changemakers’ amid Research Week 2026 OpenAI taps Airbnb exec as first EMEA managing director EAM platform Blue Mountain acquires Cork’s CompuCal Calibration Solutions SpaceX agrees right to buy AI coding darling Cursor for $60bn Anthropic probing reported Mythos leak on Discord Professional job openings across Ireland increased in Q1, finds report Contract hiring evidence of a cautious jobs market, finds report Can you rely on AI chatbots for medical advice? €6.9m awarded to final four National Challenge Fund winners Amazon investing up to $25bn in Anthropic AI infrastructure deal Vodafone Ireland to invest €360m over the next four years Tim Cook passes Apple leadership to hardware head John Ternus Stripe alum's Seapoint raises €7.5m as ‘financial home’ to start-ups
Report: Medical device cyberattacks on the rise
Colin Ryan · 2026-04-29 · via Silicon Republic

A key driver for the rise in medical device cyberattacks, according to RunSafe, is the prominence of legacy tech in healthcare environments.

Cyberattacks on medical devices are becoming more frequent and more disruptive, according to a report released by US cybersecurity company RunSafe Security today (29 April).

The 2026 Medical Device Cybersecurity Index, based on a March 2026 survey of 551 healthcare professionals throughout the US, UK and Germany involved in device purchasing decisions, found that 24pc of surveyed healthcare organisations experienced a cyberattack on a medical device – a rise of 2pc compared to last year.

Of those that experienced an attack, 80pc reported moderate or significant patient care impact as a result, with a quarter of the cohort reporting significant impact.

According to the report, the most commonly affected systems included electronic health record systems (cited by 35pc of affected organisations), patient monitoring devices (23pc), laboratory and diagnostic equipment (18pc), networked surgical equipment (10pc) and imaging systems (8pc).

The most dominant cyberattack methods seen in these incidents were malware infections requiring device quarantine – which were responsible for nearly half of the incidents (48pc) – and network intrusion requiring device isolation (41pc), with both of these incident types maintaining their dominant popularity from 2025.

However, one incident type that RunSafe noted as emerging particularly in 2026 was remote access exploitation, which was seen in 38pc of incidents. RunSafe stated this signalled that attackers are “adapting to the growing remote access footprint of connected devices”.

“Organisations that have not implemented network segmentation, access controls and runtime protections are exposed,” said the company.

For those organisations that experienced a cyberattack on a medical device, recovery was not so simple.

Nearly half (49pc) of reported incidents caused “extended stays or required manual workarounds”, according to the report, with the most common recovery scenario – experienced by 39pc of impacted organisations – involving five to 12 hours of downtime. Meanwhile, 5pc of affected organisations experienced downtime of more than three days.

Legacy issues

A key driver of the growing medical device cyberthreat, according to RunSafe, is the prominence of legacy devices that cannot be patched or easily replaced.

The report found that three in 10 responding organisations operate medical devices that are past the manufacturer’s end-of-support date. A significant proportion of those devices carry known, unpatched vulnerabilities, according to RunSafe.

The reported reasons as to why these healthcare organisations continue to operate at-risk legacy devices spanned clinical, financial and structural constraints.

38pc of respondents said there was no “acceptable” replacement available yet for the legacy device in question, while 36pc said they cannot afford a replacement.

34pc cited regulatory or approval constraints as a barrier, 33pc said replacing the device or system would cause too much disruption and interestingly, 17pc stated that the risk presented by this legacy tech has been formally accepted by leadership.

“The inability to patch, combined with continued clinical reliance on vulnerable devices, creates a structural security gap that cannot be closed solely through procurement alone,” said RunSafe in an analysis of the topic of legacy devices.

“This gap is almost certainly a key driver behind the rise in runtime protection adoption seen in 2026. Runtime protection technologies – which defend devices without requiring a patch – act as a compensating control for a problem that buying new devices cannot solve.”

As recognised by the report, runtime protection technologies are emerging as a critical “compensating control”, with 82pc of respondents stating that they have widely deployed or are piloting runtime exploit protection.

A vulnerable sector

The rise of medical device cyberattacks highlighted by this report comes as the healthcare industry continues to experience breaches and attacks ranging in severity, as noted by RunSafe founder and CEO Joseph M Saunders.

“The findings land against a backdrop of large-scale healthcare cyber incidents that have disrupted care delivery and revenue flows, underscoring how quickly attacks on device-adjacent systems can translate into patient harm,” he said.

“Medical device cybersecurity is increasing in importance to healthcare buyers as they see it as a patient safety and regulatory imperative.”

Last month, medical equipment manufacturing giant Stryker was hit by a cyberattack that caused a global network disruption. Reports at the time suggested that the company’s Cork plant, which employs more than 4,000, was affected by the attack – which pro-Iranian cyber group Handala claimed responsibility for.

Meanwhile, just a few weeks ago, Dublin recruitment platform Healthdaq – which is used by Northern Ireland’s health trusts – reportedly suffered a cyberattack from the relatively new hacker group XP95, which claimed to have accessed hundreds of thousands of files.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.