Explore the most recent editions of MPO Magazine, featuring expert commentary, industry trends, and breakthrough technologies.
Access the full digital version of MPO Magazine anytime, anywhere, with interactive content and enhanced features.
Join our community of medical device professionals. Subscribe to MPO Magazine for the latest news and updates delivered straight to your mailbox.
Explore the transformative impact of additive manufacturing on medical devices, including design flexibility and materials.
Learn about outsourcing options in the medical device sector, focusing on quality, compliance, and operational excellence.
Stay updated on the latest electronic components and technologies driving innovation in medical devices.
Discover precision machining and laser processing solutions that enhance the quality and performance of medical devices.
Explore the latest materials and their applications in medical devices, focusing on performance, biocompatibility, and regulatory compliance.
Learn about advanced molding techniques for producing high-quality, complex medical device components.
Stay informed on best practices for packaging and sterilization methods that ensure product safety and compliance.
Explore the latest trends in research and development, as well as design innovations that drive the medical device industry forward.
Discover the role of software and IT solutions in enhancing the design, functionality, and security of medical devices.
Learn about the essential testing methods and standards that ensure the safety and effectiveness of medical devices.
Stay updated on innovations in tubing and extrusion processes for medical applications, focusing on precision and reliability.
Stay ahead with real-time updates on critical news affecting the medical device industry.
Access unique content and insights not available in the print edition of the MPO Magazine.
Explore feature articles that delve into specific topics within the medical device industry, providing in-depth analysis and insights.
Gain perspective from industry experts through regular columns addressing key challenges and innovations in medical devices.
Read the editor’s thoughts on the current state of the medical device industry.
Discover the leading companies in the medical device sector, showcasing their innovations and contributions to the industry.
Explore detailed profiles of medical device contract manufacturing and service provider companies, highlighting their capabilities and offerings.
Learn about the capabilities of medical device contract manufacturing and service provider companies, showcasing their expertise and resources.
Watch informative videos featuring industry leaders discussing trends, technologies, and insights in medical devices.
Short, engaging videos providing quick insights and updates on key topics within the medical device industry.
Tune in to discussions with industry experts sharing their insights on trends, challenges, and innovations in the medical device sector.
Participate in informative webinars led by industry experts, covering various topics relevant to the medical device sector.
Stay informed on the latest press releases and announcements from leading companies in the medical device manufacturing industry.
Access comprehensive eBooks covering a range of topics on medical device manufacturing, design, and innovation.
Highlighting the innovators and entrepreneurs who are shaping the future of medical technology.
Explore sponsored articles and insights from leading companies in the medical device manufacturing sector.
Read in-depth whitepapers that explore key issues, trends, and research findings for the medical device industry.
Discover major industry events, trade shows, and conferences focused on medical devices and technology.
Get real-time updates and insights live from the CompaMed/Medica conference floor.
Join discussions and networking opportunities at the MPO Medtech Forum, focusing on the latest trends and challenges in the industry.
Attend the MPO Summit for insights and strategies from industry leaders shaping the future of medical devices.
Participate in the ODT Forum, focusing on orthopedic device trends and innovations.
Discover advertising opportunities with MPO to reach a targeted audience of medical device professionals.
Review our editorial guidelines for submissions and contributions to MPO.
Read about our commitment to protecting your privacy and personal information.
Familiarize yourself with the terms and conditions governing the use of MPOmag.com.
What are you searching for?
Who will ultimately pay for the cybersecurity requirements that loom over the industry?
July 24, 2024
By: Christopher Gates
I am going to wade into a subject not usually discussed in polite circles; in fact, it may be considered by some to be a “third rail” topic. Specifically, I want to tackle the cost of cybersecurity. As one of the industry’s leading advocates for medical device cybersecurity, the approach most assume I would take is, “Forget all other requirements or impediments, including costs, and implement all of the best cybersecurity practices.”
However, reality is not quite so black and white. Virtually all individuals and companies are restricted by financial budgets and time schedules. Costs are a critical factor and significant in terms of cybersecurity.
As a provider of medical device cybersecurity assistance to other medical device manufacturers, I need to address this topic frequently. The typical scenario often plays out as follows:
A new client does not know cybersecurity is now mandated by the U.S. Food and Drug Administration (FDA) and is very surprised to learn medical device cybersecurity is not optional. Further, while the client may not have had to address cybersecurity in a previous development project, it is required for them to do so now.
The FDA started this cybersecurity journey approximately 10 years ago. Then, just over a year ago (March 29, 2023), the agency publicly stated cybersecurity was now a requirement as part of a regulatory submission.
Throughout 2023, the FDA’s representatives (as well as a few industry pundits such as myself) made numerous public presentations to notify everyone of how punctiliously this was being implemented. In spite of this effort, many still act as if this is a big surprise; their reaction is as though the announcement was just made last Tuesday. (Meanwhile, for those same people, Lucky Lindy made it, Amelia Earhart didn’t, and we have computers in phones that fit in our pockets. Is there anything else you may have missed?)
Looking back 10 years ago to the aforementioned start of the FDA’s cybersecurity journey, the premarket guidance in 2014 was only seven pages in length. At the time, it was relatively easy to accept the impact on a project’s budget (and schedule). Now, the latest “finalized” cybersecurity guidance from September 2023 is 57 pages, filled with many more activities and artifacts to be performed and created.
Acting surprised about the requirements in place when the extra work necessary was not budgeted for is simply unacceptable. All future development projects need to account for the expense involved with this critical aspect of device development. In addition, it needs to be understood this portion is not inexpensive.
Further, while budgeting for cybersecurity, consider the other actors in your new development. Do you have third parties creating firmware or mobile apps? If so, do the contracts with these third parties include provisions for fixing/mitigating vulnerabilities as discovered during the security processes?
Both budget and schedule are going to be significantly impacted as part of the cost of cybersecurity. What was once viewed as “change from the corporate sofa cushions” are now six-figure cybersecurity engagements. Similarly, what was once “We’ll get‘er done in four days” is now measured in terms of weeks.
Every year, our team spends close to half a million dollars just for the privilege of having access to the cybersecurity tools we need to perform the design and testing activities for our clients. In addition, most of those tools also have a “consumption” charge associated with each use of the tool. Further, we have to pay our associates—who are highly sought-after and difficult-to-obtain professionals—to use these expensive tools to ensure and implement cybersecurity practices.
These costs do not shrink, even if they are brought in-house (especially including the cost required to find and acquire experienced cybersecurity staff). In fact, trying to establish the necessary expertise to have this become an internal capability may ultimately become more expensive than relying on external third parties for cybersecurity expertise. Unfortunately, cybersecurity is expensive for everyone involved.
Once this has all sunk in, consider the fact this was only regarding premarket development activities. In addition to the aspects already discussed, companies are also currently required to perform a regular cadence of cybersecurity testing, the periodicity of which seems to vary between every three to 12 months for the supported life of the device. This requirement will have a major impact on staffing and budgets. While the practice of sustaining engineering has been waning in recent decades, we may now be faced with sustaining cybersecurity taking its place.
Once the necessity for sustaining cybersecurity is understood, we’re left with two questions: how will these devices be updated and patched in the field and who will perform these tasks? In addition, there is the matter of the ongoing costs associated with this process. Royalties may even be involved on a per-device basis, depending upon how the business model of a commercial update system is structured.
The cybersecurity requirements for the medical device industry are having significant impacts on the financials of medical devices. Someone needs to pay for secure development and the years of testing in the post-market lifecycle [or, as referred to by the FDA, the Total Product Life Cycle (TPLC)].
Will these extra costs be rolled into the upfront cost of medical devices? Have manufacturers even calculated what the TPLC costs are going to be for their devices? Do we need a new business relationship between the manufacturers and the hospitals—a model that more closely resembles a subscription or extended service agreement for cybersecurity?
I look forward to seeing this discussion reach the mainstream. While we know the industry is now required to make medical devices secure from a cybersecurity standpoint, we need to have a new discussion of reimbursement. Who will ultimately pay for the cybersecurity requirements that loom over the industry?
Christopher Gates is director of Product Security at Velentium and the current co-chair for H-ISAC’s MDSC. He has more than 50 years of experience developing and securing medical devices and works with numerous industry-leading device manufacturers. He frequently collaborates with regulatory and standard bodies, including the CSIA, Health Sector Coordinating Council, H-ISAC, Bluetooth SIG, and FDA to present, define, and codify tools, techniques, and processes that enable the creation of secure medical devices.
Enter your account email.
A verification code was sent to your email, Enter the 6-digit code sent to your mail.
Didn't get the code? Check your spam folder or resend code
Set a new password for signing in and accessing your data.
Your Password has been Updated !