top of page

When did cybersecurity stop being a project?

  • Writer: Ann Lebar
    Ann Lebar
  • Jul 15
  • 1 min read

For years, many medical device manufacturers have approached cybersecurity as a milestone.


✔️ Complete a threat model.

✔️ Perform penetration testing.

✔️ Submit to FDA.


Then move on to the next project. But Section 524B of the FD&C Act changed that mindset.


Today, manufacturers are expected to maintain processes to identify, assess, and address cybersecurity vulnerabilities throughout the Total Product Life Cycle (TPLC). That's a fundamental shift.


Cybersecurity isn't just about finding vulnerabilities before release—it's about maintaining visibility into vulnerabilities long after a device enters the field. This is where vulnerability scanning becomes an important part of a mature cybersecurity program. Not because it replaces penetration testing—it doesn't. But because it provides ongoing awareness of:


  • Newly disclosed CVEs 

  • Outdated software components 

  • Configuration weaknesses 

  • Emerging risks that develop between major security assessments 


For many manufacturers, especially those with lean cybersecurity teams, recurring vulnerability scanning provides an efficient way to support vulnerability management without adding significant internal overhead.


At MedSec, we've launched a Vulnerability Scanning service specifically for medical device manufacturers. It can be performed as a one-time assessment or as an ongoing program, and can be combined with our technical and regulatory advisory services to help triage findings and integrate them into your cybersecurity risk management process.


The conversation has shifted from "Have we tested security?" to "How are we maintaining security over the product lifecycle?" That's the conversation every manufacturer should be having.

 
 
 
bottom of page