FDA’s medical device cybersecurity deal deemed outdated, watchdog discloses

December 27, 2023
1 min read

The Government Accountability Office (GAO) has found that the cybersecurity agreement between the Food and Drug Administration (FDA) and the Cybersecurity and Infrastructure Security Agency (CISA) needs to be updated. The agreement, which focuses on cybersecurity protocols for medical devices, is five years old and does not reflect recent organizational and procedural changes. While medical device vulnerabilities have not been frequent sources of cyber exploits, the FDA still considers them a significant concern for hospital cybersecurity. The GAO report also highlighted that the FDA’s authority over medical device cybersecurity has increased, due to legislation mandating that manufacturers submit plans to identify and address vulnerabilities. The report recommends that the FDA and CISA update their agreement to reflect these changes, a recommendation that both agencies agree with.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is