Ensuring the highest level of cybersecurity from development to market deployment.
Guardian provides a comprehensive device security platform, combining a flexible software library and robust cloud infrastructure. Provision devices with unique cryptographic identities, enabling secure cloud authentication and controlled access.
North-South Protection (Device-to-Cloud Security)
Ensure secure communication between devices and cloud platforms over a private network or internet.
Both unidirectional and bidirectional traffic between endpoints can be supported over various transport technologies.
East-West Protection (Local Network Security)
Ensure encrypted and authenticated communication between components of devices. Guardian also can integrate to help secure communication protocols such as DDS.
In 2023, the PATCH Act granted the FDA legal authority to enforce medical device cybersecurity. As of October 2023, the FDA began issuing notices to manufacturers failing to meet new security standards in 510(k) submissions.
MDMs should also prepare to meet requirements in the Select Updates for the Premarket Cybersecurity Guidance: Section 524B of the FD&C Act (Draft, March 2024). Key enforcement areas include:
Cybersecurity integrated from the start of development.
Only authorized users and devices can access the system.
Enforcing appropriate access levels.
Protecting sensitive data.
Ensuring data and system functions remain unaltered.
Medcrypt’s Guardian works side-by-side with RTI Connext’s Security Extensions to provide a comprehensive solution. This integrated solution ensures that medical device manufacturers can effectively secure their devices and meet FDA requirements, potentially avoiding the numerous deficiencies that many are currently facing.
Medical device manufacturers face a multitude of challenges when it comes to ensuring their devices meet stringent cybersecurity requirements. Some of the key challenges include:
Many medical devices rely on third-party manufacturers for certain components or even the entire device, introducing significant complexity in maintaining consistent security standards. This fragmented supply chain increases the likelihood of the existence of vulnerabilities, or establishes an environment where vulnerabilities may be more easily introduced or undetected in an ecosystem or product environment, especially when cybersecurity requirements are not uniformly applied. By applying Guardian, you ensure consistent, robust encryption and authentication across your ecosystem.
Over time, devices may evolve across several versions, each with unique configurations deployed in the field. Managing security for all of these variations while ensuring compliance with FDA standards can be extremely challenging. Updating legacy devices to meet current security requirements without disrupting their operations is a critical ongoing concern throughout the device’s lifecycle.
Even medical devices that do not have internet connectivity are still deemed cyber devices by the FDA. These devices often communicate with other equipment, requiring secure communication channels to ensure data integrity, authenticity, and confidentiality. This makes it essential to secure every potential interaction, even when connectivity appears minimal or non-existent.
Devices today must secure communication flows in various directions. North-South traffic such as device-to-cloud connections requires robust perimeter defenses, mutual authentication, and secure transport layers to safeguard data moving between internal and external networks. East-West traffic, such as lateral communication within local networks or between systems, requires stringent internal controls to prevent unauthorized movement within the network.
The use of unauthorized or counterfeit attachments with medical devices is a growing problem. These unofficial add-ons pose significant risks, as they can introduce vulnerabilities or circumvent the built-in security measures, jeopardizing the safety and integrity of the overall system. Guardian can identify and alert you to these unauthorized attachments, preventing access, ensuring the safety of patients and the security and integrity of your network and data.
Medcrypt’s Guardian Platform — featuring Guardian Library, Agent, Cloud, and Vault — addresses the most complex security challenges, ensuring compliance with regulatory standards and securing your devices. Guardian is designed to seamlessly integrate with your device's cryptographic libraries, offering flexibility and cost-effectiveness, which shortens development time while maintaining robust security.