Pushing whitecoat doctor moving patient with O2 mask on gurney down hospital hall, encryption bar
10 Aug 2026

Why Cybersecurity Testing is Becoming a Critical Part of Medical Device Development

Medical devices are becoming more connected, software-driven, and integrated into larger healthcare ecosystems. From patient monitors and imaging systems to home healthcare equipment and connected wearables, today’s medical technologies rely heavily on software, wireless communication, cloud connectivity, and data exchange to deliver care.

That connectivity creates enormous opportunities for innovation, but it also introduces new cybersecurity risks that manufacturers can no longer afford to overlook.

As cybersecurity expectations continue evolving across the healthcare industry, penetration testing has become a necessary part of medical device development and regulatory compliance. Regulators including the U.S. Food and Drug Administration (FDA) are placing greater emphasis on cybersecurity validation activities, while standards such as IEC 81001-5-1 continue reinforcing the importance of secure development lifecycle processes and ongoing cybersecurity risk management.

For many manufacturers, however, penetration testing is still misunderstood. Some organizations confuse it with vulnerability assessments or general cybersecurity reviews. Others treat it as a final compliance task that happens just before submission.

In reality, penetration testing plays a much broader role in helping manufacturers validate security controls, identify exploitable weaknesses, and support safer medical technologies throughout the product lifecycle.

Vulnerability Assessments vs. Penetration Testing

One of the biggest misconceptions surrounding cybersecurity testing is the assumption that vulnerability assessments and penetration testing are the same activity. While the two work together, they serve different purposes.

A vulnerability assessment focuses primarily on identifying weaknesses within a device or system. Penetration testing takes the process further by actively attempting to exploit those vulnerabilities to determine how an attacker could potentially gain access, compromise functionality, or impact device operation.

That distinction matters because some vulnerabilities may appear relatively minor until they are chained together with other weaknesses. In medical devices, those risks may extend beyond traditional cybersecurity concerns and potentially affect essential performance, patient safety, or protected health information.

The FDA’s cybersecurity guidance specifically references both vulnerability assessments and penetration testing as important elements of medical device cybersecurity evaluations.

Cybersecurity Is a Lifecycle Activity

Historically, some manufacturers treated cybersecurity as a final checkpoint before product release. That mindset is changing rapidly as connected medical devices become more common throughout hospitals, clinics, and home healthcare environments.

Cybersecurity is no longer viewed as a one-time exercise or simple checkbox activity. Threats evolve continuously. Software components change. New vulnerabilities emerge daily.

As a result, organizations are incorporating penetration testing into ongoing lifecycle strategies rather than treating it as a single premarket activity. Manufacturers are expected to evaluate cybersecurity throughout development, during submission preparation, and even after products reach the market.

The earlier security considerations begin, the easier and less expensive it typically becomes to address potential issues. Discovering vulnerabilities during early prototyping is significantly less disruptive than identifying them after regulatory submission or commercial launch.

This “secure by design” philosophy is emerging as a key focus across the industry. Manufacturers are integrating cybersecurity risk assessments, software bill of materials (SBOM) reviews, and early cybersecurity testing into development processes much earlier than in the past.

What Does Penetration Testing Look Like?

Medical device penetration testing often combines several methodologies depending on the product, intended environment, and manufacturer objectives.

One common approach is “grey box” testing, which combines elements of both black box and white box testing. In a black box assessment, testers operate with little or no prior knowledge of the device, simulating an outside attacker. White box testing provides full access to source code, architecture details, and proprietary information. Grey box testing blends both approaches to simulate real-world attacks while still allowing evaluators to focus on specific security controls identified by the manufacturer.

Testing is typically performed in a laboratory environment using production-representative devices configured as they would operate in the field. For medical devices, maintaining operational functionality during testing is especially important. For example, evaluators may operate a ventilator normally during testing to determine whether attempted attacks impact device performance or communication capabilities.

Common Vulnerabilities in Connected Devices

While every medical device presents unique cybersecurity considerations, several recurring issues appear frequently during penetration testing engagements.

Misconfigured communication protocols remain a common finding, particularly involving outdated or improperly configured Transport Layer Security (TLS) implementations used for secure communications between devices or cloud systems. USB interfaces can also create cybersecurity challenges when external or embedded ports allow unauthorized access opportunities.

Another major concern involves the protection of patient information. In some cases, testing reveals that protected health information (PHI) or personally identifiable information (PII) may not be adequately secured during network transmission.

Importantly, the severity of cybersecurity risks often depends heavily on the device environment and intended use. A connected home healthcare device may present very different exposure levels than equipment used in a restricted clinical environment.

Penetration Testing Is About Improvement, Not Failure

Some manufacturers remain hesitant about penetration testing because they worry about what may be discovered during the evaluation. In reality, the purpose of penetration testing is not to create failure points or criticize development teams.

The goal is to identify vulnerabilities before malicious actors can exploit them in real-world environments.

Finding issues during laboratory testing is far preferable to discovering them after a product has entered the market. Penetration testing helps manufacturers strengthen products, validate security controls, support regulatory expectations, and ultimately improve patient safety.

As connected medical technologies continue expanding across healthcare environments, cybersecurity testing will remain a vital part of demonstrating device safety, security, and resilience.

Wyatt Turner headshot
Wyatt Turner

Senior Security Engineer, Intertek EWA-Canada

Wyatt Turner has more than six years of experience conducting high assurance and Internet of Things evaluations at Intertek. He is dedicated to helping clients navigate the challenges of a connected world, and in spreading awareness about cybersecurity.

You may be interested in...

Medical Device Cybersecurity Solutions

Meet regulatory requirements for secured medical product, healthcare equipment and solutions.

End-to-End Security Assessment of a Medical Device Ecosystem Through Penetration Testing

Connected medical devices introduce new cybersecurity risks that can directly impact safety and performance. This paper outlines how penetration testing evaluates real-world attack scenarios, identifies exploitable weaknesses, and supports regulatory expectations.

Medical Podcast - Compliance with Clarissa

Tune in to watch "MEDICAL COMPLIANCE WITH CLARISSA" now available on YouTube

Close up of businessman using a laptop to look at Intertek's Medical Resources hub

Visit our Medical Resources Hub and stay up to date with industry trends, changing standards and market opportunities with white papers, on-demand webinars, FAQs, and fact sheets.

You may be interested in...