Business Wire

Armis Identifies the Riskiest Medical and IoT Devices in Clinical Environments

Share

HIMSS Armis, the leading asset visibility and security company, today released new research identifying the top connected medical and IoT devices that are exposed to malicious activity in clinical environments. Data analyzed from the Armis Asset Intelligence and Security Platform, which tracks over three billion assets, found nurse call systems to be the riskiest* IoMT device, followed by infusion pumps and medication dispensing systems. When looking at IoT devices, IP cameras, printers and Voice Over Internet Protocol (VoIP) devices are topping the list.

By 2026, smart hospitals are expected to deploy over 7 million IoMT devices, doubling the amount from 2021. Medical and non-medical devices are increasingly connected, automatically feeding patient data from monitoring devices into electronic records. These connections and communications within a medical environment help improve patient care but also make it increasingly vulnerable to cyberattacks, which could result in the interruption of patient care.

Upon a comprehensive analysis of the data from all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform, several noteworthy conclusions can be drawn:

  • Nurse call systems are the riskiest connected medical device, with 39% of them having critical severity unpatched Common Vulnerabilities and Exposures (CVEs) and almost half (48%) having unpatched CVEs.
  • Infusion pumps are second, with 27% having critical severity unpatched CVEs and 30% having unpatched CVEs.
  • Medication dispensing systems are in third place, with 4% having critical severity unpatched CVEs, but 86% having unpatched CVEs. Moreover, 32% run on unsupported Windows versions.
  • Almost 1 in 5 (19%) connected medical devices are running unsupported OS versions.
  • More than half of IP cameras we monitored in clinical environments have critical severity unpatched CVEs (56%) and unpatched CVEs (59%), making it the riskiest IoT device.
  • Printers are the second riskiest IoT device in clinical environments, with 37% having unpatched CVEs, and 30% having critical severity unpatched CVEs.
  • VoIP devices are in third place. Although 53% of them have unpatched CVEs, only 2% have critical severityunpatched CVEs.

“These numbers are a strong indicator of the challenges faced by healthcare organizations globally. Advances in technology are essential to improve the speed and quality of care delivery as the industry is challenged with a shortage of care providers, but with increasingly connected care comes a bigger attack surface,” said Mohammad Waqas, Principal Solutions Architect for Healthcare at Armis. “Protecting every type of connected device, medical, IoT, even the building management systems, with full visibility and continuous contextualized monitoring is a key element to ensuring patient safety.”

Armis secures all medical assets and patient care environments in some of the largest healthcare delivery organizations around the world:

“Armis appeared to be a good alternative for us because it immediately provided us with visibility into what devices were plugging into the network. It shows us how they are interacting with each other, creates alerts based on observed behavior and enforces firewall rules based on those alerts,” said Brian Schultz, Director of Network Operations and Security, Burke Rehabilitation Hospital.

“Metrics and accountability are key to understanding how to protect the hospital’s network, and Armis has a major role in making the relevant data available to us in an easy-to-access manner. It has definitely filled in the gaps in our security arsenal by uncovering risks we never knew about previously. At first, I thought Armis was a nice-to-have, but now it’s become an integral part of our cyber defense,” said Dr. Michael Connolly, Chief Information Officer (CIO), Mater Misericordiae University Hospital.

KLAS Research recently named Armis a top performer at the 2023 Best in KLAS Software & Services Report for Healthcare IoT Security. To learn more about how Armis enables healthcare organizations to identify and secure IoMT, IoT, OT and IT assets please visit: https://www.armis.com/cybersecurity/healthcare/

Armis is attending HIMSS April 17-21, 2023 in Chicago, IL with a speaking session taking place on Wednesday, April 19, 2023 from 3:45pm - 4:05pm CT titled: Hackers Rush in Where Agents Fear to Tread . To meet with Armis at HIMSS, please visit booth 2276 or Kiosk 4309-48 in the Cyber Command Center.

To understand what role you can play in strengthening cybersecurity for your healthcare organization, book a demo.

*Armis defined the riskiest device types by looking at all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform and identifying which types have the highest percentage of devices with unpatched critical severity Common Vulnerabilities and Exposures ( CVEs).

About Armis

Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Media Contacts:
Rebecca Cradick
Senior Director, Global Communications
Armis
pr@armis.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

New Study from UK’s Largest Virtual ADHD Service Validates Role of Objective Testing in Delivering Personalized, High-Quality Remote ADHD Care10.5.2025 13:45:00 EEST | Press release

As demand for virtual ADHD care increases, findings from a new study conducted with ADHD 360, the UK’s largest evidence-based digital service specializing in ADHD diagnosis and treatment, reveal how objective ADHD diagnostic and monitoring technology improves patient outcomes and clinical certainty. Presented at the 2025 ADHD World Congress in Prague, Czech Republic, the findings highlight the role of QbCheck, Qbtech’s remote testing solution, in enabling clinicians to make more confident, data-informed decisions, supporting a more personalized and collaborative care model. The tool allows for greater clarity when assessing symptoms and adjusting treatment plans over time, ensuring diagnostic accuracy and helping to improve alignment between clinicians and patients throughout the care journey. The results from ADHD 360’s implementation of this model showcase how a standardized approach to virtual ADHD care improves clinician confidence, reduces wait times, and enhances patient engageme

Ant International Partners with Barclays on Global Treasury Management with Proprietary AI-Powered FX Model9.5.2025 16:57:00 EEST | Press release

Ant International has entered a partnership with leading UK bank Barclays to enhance efficiency and resilience in global treasury management for businesses. Under the partnership, the two sides will combine innovative solutions, including Ant’s proprietary Time-Series Transformer (TST) AI FX Model, to help businesses reduce FX-related costs and risks against global volatilities. At the initial stage of the collaboration, Ant International has successfully completed the first batch of its intra-group FX transactions with Barclays. Ant International’s TST Model is a transformer architecture-based big data model with close to 2 billion parameters. By integrating the latest time series forecasting algorithms, the TST Model predicts patterns over time. Ant also created new pre-training and Supervised Fine-Tuning (SFT) frameworks to train the model and improve its predictions over time. The TST Model now forecasts the company's cashflow and FX exposure on an hourly, daily and weekly basis, w

Monument Re Transfers €1.4bn Greycastle Portfolio to RGA and Strengthens European Life Insurance Consolidation Platform9.5.2025 15:00:00 EEST | Press release

Monument Re Limited (“Monument”) announces today that it has transferred a legacy €1.4bn reinsurance portfolio, comprising annuity and other life insurance liabilities acquired as part of the 2020 Greycastle transaction, to RGA Americas Reinsurance Company, Ltd. (“RGA”). This transaction releases capital resources that Monument will redirect to its core strategy of consolidation in European life insurance markets. The transaction completed on 2May 2025 following approval by the Boards of Directors of both Monument and RGA and non-objection from the Bermuda Monetary Authority. Monument has taken significant steps in recent months to strengthen its business operations by consolidating its European group support functions in Dublin and by aligning with the recently strengthened regulatory regime in Bermuda. With its strong financial position and best in class capabilities in the Group, Monument remains ideally positioned to build on its success to date and grow its European footprint, del

IFF Completes Divestiture of Nitrocellulose Business9.5.2025 15:00:00 EEST | Press release

IFF (NYSE: IFF) today announced that it has completed the divestiture of its nitrocellulose business, including Walsrode Industrial Park in lower Saxony, Germany, to Czechoslovak Group (CSG). The business manufactures nitrocellulose strictly for industrial purposes, serving customers primarily in coatings and printing inks, and had been part of IFF’s Pharma Solutions business unit. “The divestiture of our nitrocellulose business builds upon our deleveraging journey and enables us to focus on our core businesses,” said Erik Fyrwald, IFF CEO. “I’d like to thank our nitrocellulose colleagues for their dedication and wish them continued success as part of CSG.” Welcome to IFF At IFF (NYSE: IFF), we make joy through science, creativity and heart. As the global leader in flavors, fragrances, food ingredients, health and biosciences, we deliver groundbreaking, sustainable innovations that elevate everyday products—advancing wellness, delighting the senses and enhancing the human experience.Le

CPAC Systems AB Announces Strategic Minority Investment in Flying Fish9.5.2025 13:33:00 EEST | Press release

CPAC Systems AB, a leader in advanced control systems and embedded vessel and commercial vehicle technology, today announced a strategic minority investment in Flying Fish Maritime Innovations B.V., a pioneer in advanced shared water mobility solutions and robust, cost-effective hydrofoil technology. The investment underscores both companies’ commitment to redefining water-based transportation through innovation, sustainability, and seamless integration. It marks the beginning of a deeper collaboration aimed at enabling smarter, cleaner, and more connected mobility on the water — for both recreational and commercial applications. “We are thrilled to support Flying Fish and their impressive work in redefining water mobility,"saidMarcus Wingolf, CEO of CPAC Systems. "Our investment in Flying Fish represents a strategic alignment of our technical proficiencies and innovative ambitions. This partnership opens exciting new possibilities for integration and sustainable transformation across

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye