Cyber security set to triple by 2021 but it will not be enough in the “new hostile environment”
While the medical Internet of things (IoT) is set to transform healthcare through smart medical devices, their success is in jeopardy if cyber security concerns are not addressed immediately, ABI Research has stated.
ABI believes that the millions of connected medical devices introduce dangerous new threat vectors into the healthcare IT infrastructure, and will seriously undermine patient safety and effective care delivery if left unchecked.
“We estimate spending by healthcare providers and OEMs on healthcare cyber security to reach $5.5 billion by 2016,” said Michela Menting, research director at ABI Research. “However, only $390 million of that will be dedicated to securing medical devices. Healthcare stakeholders have to understand that there is a new hostile environment that will emerge around networked medical devices and that threat actors have multiple levels of skills and diverging motivations for attacking the medical IoT.”
The money spent on securing medical devices will primarily be due to OEMs embedding security in the hardware, reviewing, analysing, pen testing, developing patches, and performing OTA updates, among other functions. The rest of the expenditure will focus on data protection.
Yet medical devices suffer from numerous vulnerabilities, and many often compound several critical vulnerabilities: code errors in software, use of hardcoded passwords, disabling of firewalls, lack of authentication mechanisms, unencrypted communications, among many other issues.
Protecting devices requires addressing technical issues, healthcare delivery, and business challenges, said ABI. To do this, collaboration across the various stakeholder silos is necessary, the company claimed.
ABI stated that the industry, however, is at the beginning stages of the discussion. Globally, the efforts are poor, it noted, and the US is the only country currently putting significant energies into the matter.
However, awareness is growing, which will push spending on devices to triple globally by 2021, resulting primarily from dynamic US public and private efforts in the space. A few companies are already fully embracing medical device cyber security, including Battelle, Coalfire, Dräger, Extreme Networks, Sensato, Synopsys, UL, and WhiteScope.
“Investment in medical device cyber security is critical in order to deliver the full promise of next generation healthcare technology,” concluded Menting. “OEMs and healthcare providers taking part in the discussion today will be the pioneers forming the foundation of future cyber security for medical devices.”