October 20, 2016 By Larry Loeb 2 min read

While the Internet of Things (IoT)-enslaving distributed denial-of-service (DDoS) attackers have hogged much of the public’s attention lately, the medical devices segment of the IoT has flown under the radar. The field is growing too quickly for security to keep up. Devices can be compromised individually, but they can also provide an attacker with a way into the overall health care infrastructure.

According to ABI Research, as reported by Help Net Security, medical IoT insecurity could endanger patient safety and impair patient care.

Medical IoT Spending to Skyrocket

Michela Menting, the research director at ABI Research, said that health care providers and original equipment manufacturers (OEM) will spend $5.5 billion on cybersecurity in 2016. Only $390 million of that figure will be dedicated to improving the security of medical devices, however.

OEMs will use the majority of that money to embed security into their hardware, as required by regulatory oversight agencies. OEMs must also spend money on reviews, analysis, penetration testing, patch development and over-the-air (OTA) updates when the device software is revised.

Medical devices have historically suffered from multiple vulnerabilities due to a variety of causes. The use of hardcoded passwords may help a service technician access the device, but it also provides a useful stepping stone for attackers. Many devices also lack an authentication mechanism — an issue that security leaders must address before the industry can achieve a reasonable level of security.

Squashing Silos

The overall environment today can be visualized as a set of stakeholder silos. The industry lacks a common effort to devise a standard of security and ensure all stakeholders are protected. ABI cited only a few companies that are significantly committed to medical cybersecurity. Additionally, the U.S. seems to be the only major nation devoting serious effort to this problem.

According to ABI, spending on medical IoT-connected devices will triple globally by 2021. Such an increase in use can only force the security problems of the devices to the forefront in the years to come.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today