Columns

The Cost of Cybersecurity in Medtech

Who will ultimately pay for the cybersecurity requirements that loom over the industry?

I am going to wade into a subject not usually discussed in polite circles; in fact, it may be considered by some to be a “third rail” topic. Specifically, I want to tackle the cost of cybersecurity. As one of the industry’s leading advocates for medical device cybersecurity, the approach most assume I would take is, “Forget all other requirements or impediments, including costs, and implement all of the best cybersecurity practices.”

However, reality is not quite so black and white. Virtually all individuals and companies are restricted by financial budgets and time schedules. Costs are a critical factor and significant in terms of cybersecurity.

As a provider of medical device cybersecurity assistance to other medical device manufacturers, I need to address this topic frequently. The typical scenario often plays out as follows:

A new client does not know cybersecurity is now mandated by the U.S. Food and Drug Administration (FDA) and is very surprised to learn medical device cybersecurity is not optional. Further, while the client may not have had to address cybersecurity in a previous development project, it is required for them to do so now.

The FDA started this cybersecurity journey approximately 10 years ago. Then, just over a year ago (March 29, 2023), the agency publicly stated cybersecurity was now a requirement as part of a regulatory submission.

Throughout 2023, the FDA’s representatives (as well as a few industry pundits such as myself) made numerous public presentations to notify everyone of how punctiliously this was being implemented. In spite of this effort, many still act as if this is a big surprise; their reaction is as though the announcement was just made last Tuesday. (Meanwhile, for those same people, Lucky Lindy made it, Amelia Earhart didn’t, and we have computers in phones that fit in our pockets. Is there anything else you may have missed?)

Looking back 10 years ago to the aforementioned start of the FDA’s cybersecurity journey, the premarket guidance in 2014 was only seven pages in length. At the time, it was relatively easy to accept the impact on a project’s budget (and schedule). Now, the latest “finalized” cybersecurity guidance from September 2023 is 57 pages, filled with many more activities and artifacts to be performed and created.

Acting surprised about the requirements in place when the extra work necessary was not budgeted for is simply unacceptable. All future development projects need to account for the expense involved with this critical aspect of device development. In addition, it needs to be understood this portion is not inexpensive.

Further, while budgeting for cybersecurity, consider the other actors in your new development. Do you have third parties creating firmware or mobile apps? If so, do the contracts with these third parties include provisions for fixing/mitigating vulnerabilities as discovered during the security processes?

Both budget and schedule are going to be significantly impacted as part of the cost of cybersecurity. What was once viewed as “change from the corporate sofa cushions” are now six-figure cybersecurity engagements. Similarly, what was once “We’ll get‘er done in four days” is now measured in terms of weeks.

Every year, our team spends close to half a million dollars just for the privilege of having access to the cybersecurity tools we need to perform the design and testing activities for our clients. In addition, most of those tools also have a “consumption” charge associated with each use of the tool. Further, we have to pay our associates—who are highly sought-after and difficult-to-obtain professionals—to use these expensive tools to ensure and implement cybersecurity practices.

These costs do not shrink, even if they are brought in-house (especially including the cost required to find and acquire experienced cybersecurity staff). In fact, trying to establish the necessary expertise to have this become an internal capability may ultimately become more expensive than relying on external third parties for cybersecurity expertise. Unfortunately, cybersecurity is expensive for everyone involved.

Once this has all sunk in, consider the fact this was only regarding premarket development activities. In addition to the aspects already discussed, companies are also currently required to perform a regular cadence of cybersecurity testing, the periodicity of which seems to vary between every three to 12 months for the supported life of the device. This requirement will have a major impact on staffing and budgets. While the practice of sustaining engineering has been waning in recent decades, we may now be faced with sustaining cybersecurity taking its place.

Once the necessity for sustaining cybersecurity is understood, we’re left with two questions: how will these devices be updated and patched in the field and who will perform these tasks? In addition, there is the matter of the ongoing costs associated with this process. Royalties may even be involved on a per-device basis, depending upon how the business model of a commercial update system is structured.

The cybersecurity requirements for the medical device industry are having significant impacts on the financials of medical devices. Someone needs to pay for secure development and the years of testing in the post-market lifecycle [or, as referred to by the FDA, the Total Product Life Cycle (TPLC)].

Will these extra costs be rolled into the upfront cost of medical devices? Have manufacturers even calculated what the TPLC costs are going to be for their devices? Do we need a new business relationship between the manufacturers and the hospitals—a model that more closely resembles a subscription or extended service agreement for cybersecurity?

I look forward to seeing this discussion reach the mainstream. While we know the industry is now required to make medical devices secure from a cybersecurity standpoint, we need to have a new discussion of reimbursement. Who will ultimately pay for the cybersecurity requirements that loom over the industry? 


Christopher Gates is director of Product Security at Velentium and the current co-chair for H-ISAC’s MDSC. He has more than 50 years of experience developing and securing medical devices and works with numerous industry-leading device manufacturers. He frequently collaborates with regulatory and standard bodies, including the CSIA, Health Sector Coordinating Council, H-ISAC, Bluetooth SIG, and FDA to present, define, and codify tools, techniques, and processes that enable the creation of secure medical devices.

Keep Up With Our Content. Subscribe To Medical Product Outsourcing Newsletters