Armis Identifies the Riskiest Medical and IoT Devices in Clinical Environments
HIMSS – Armis, the leading asset visibility and security company, today released new research identifying the top connected medical and IoT devices that are exposed to malicious activity in clinical environments. Data analyzed from the Armis Asset Intelligence and Security Platform, which tracks over three billion assets, found nurse call systems to be the riskiest* IoMT device, followed by infusion pumps and medication dispensing systems. When looking at IoT devices, IP cameras, printers and Voice Over Internet Protocol (VoIP) devices are topping the list.
By 2026, smart hospitals are expected to deploy over 7 million IoMT devices, doubling the amount from 2021. Medical and non-medical devices are increasingly connected, automatically feeding patient data from monitoring devices into electronic records. These connections and communications within a medical environment help improve patient care but also make it increasingly vulnerable to cyberattacks, which could result in the interruption of patient care.
Upon a comprehensive analysis of the data from all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform, several noteworthy conclusions can be drawn:
- Nurse call systems are the riskiest connected medical device, with 39% of them having critical severity unpatched Common Vulnerabilities and Exposures (CVEs) and almost half (48%) having unpatched CVEs.
- Infusion pumps are second, with 27% having critical severity unpatched CVEs and 30% having unpatched CVEs.
- Medication dispensing systems are in third place, with 4% having critical severity unpatched CVEs, but 86% having unpatched CVEs. Moreover, 32% run on unsupported Windows versions.
- Almost 1 in 5 (19%) connected medical devices are running unsupported OS versions.
- More than half of IP cameras we monitored in clinical environments have critical severity unpatched CVEs (56%) and unpatched CVEs (59%), making it the riskiest IoT device.
- Printers are the second riskiest IoT device in clinical environments, with 37% having unpatched CVEs, and 30% having critical severity unpatched CVEs.
- VoIP devices are in third place. Although 53% of them have unpatched CVEs, only 2% have critical severityunpatched CVEs.
“These numbers are a strong indicator of the challenges faced by healthcare organizations globally. Advances in technology are essential to improve the speed and quality of care delivery as the industry is challenged with a shortage of care providers, but with increasingly connected care comes a bigger attack surface,” said Mohammad Waqas, Principal Solutions Architect for Healthcare at Armis. “Protecting every type of connected device, medical, IoT, even the building management systems, with full visibility and continuous contextualized monitoring is a key element to ensuring patient safety.”
Armis secures all medical assets and patient care environments in some of the largest healthcare delivery organizations around the world:
“Armis appeared to be a good alternative for us because it immediately provided us with visibility into what devices were plugging into the network. It shows us how they are interacting with each other, creates alerts based on observed behavior and enforces firewall rules based on those alerts,” said Brian Schultz, Director of Network Operations and Security, Burke Rehabilitation Hospital.
“Metrics and accountability are key to understanding how to protect the hospital’s network, and Armis has a major role in making the relevant data available to us in an easy-to-access manner. It has definitely filled in the gaps in our security arsenal by uncovering risks we never knew about previously. At first, I thought Armis was a nice-to-have, but now it’s become an integral part of our cyber defense,” said Dr. Michael Connolly, Chief Information Officer (CIO), Mater Misericordiae University Hospital.
KLAS Research recently named Armis a top performer at the 2023 Best in KLAS Software & Services Report for Healthcare IoT Security. To learn more about how Armis enables healthcare organizations to identify and secure IoMT, IoT, OT and IT assets please visit: https://www.armis.com/cybersecurity/healthcare/
Armis is attending HIMSS April 17-21, 2023 in Chicago, IL with a speaking session taking place on Wednesday, April 19, 2023 from 3:45pm - 4:05pm CT titled: Hackers Rush in Where Agents Fear to Tread . To meet with Armis at HIMSS, please visit booth 2276 or Kiosk 4309-48 in the Cyber Command Center.
To understand what role you can play in strengthening cybersecurity for your healthcare organization, book a demo.
*Armis defined the riskiest device types by looking at all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform and identifying which types have the highest percentage of devices with unpatched critical severity Common Vulnerabilities and Exposures ( CVEs).
About Armis
Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230417005402/en/
Contact information
Media Contacts:
Rebecca Cradick
Senior Director, Global Communications
Armis
pr@armis.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Wemade’s MMORPG MIR M Reveals New Content ‘Monster Dungeon’30.5.2023 16:00:00 EEST | Press release
Wemade's MMORPG MIR M: Vanguard and Vagabond showcased new content, "Monster Dungeon," on May 30th. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230530005249/en/ MIR M reveals new “Monster Invasion” content on May 30. (Graphic: Wemade) Users can obtain the "Demonic Stones" of field monsters they have defeated. Each "Demonic Stone" can be used to summon that monster in Monster Dungeon. By defeating all summoned monsters, users can obtain "Essence" items as rewards. "Essence" items can be registered to the Monster Codex to increase character stats. MIR M will be holding the event "Grand Operation Defeat Giant Scarecrow" until the update on June 13th. Users can defeat the Giant Scarecrow that appears in the Ginkgo Valley area to obtain gifts such as "Giant Scarecrow Raid Chests" and "Giant Scarecrow Demonic Stones." By using "Giant Scarecrow Demonic Stones," users can obtain Demonic Stones that can be used to summon boss mons
Q4 Inc. Set to Transform IR Effectiveness with Generative AI on the Q4 Platform30.5.2023 14:30:00 EEST | Press release
Q4 Inc. (TSX: QFOR) (“Q4” or “the Company”), the leading capital markets access platform, is excited to announce progress on pioneering generative artificial intelligence (“AI”) that is purpose built for Investor Relations (“IR”) effectiveness to help automate common tasks and accelerate decision making. By combining AI with the industry’s only end-to-end IR platform, IROs will be able to find insights exclusive to them built on a pool of their own proprietary program data and capital markets data aggregated on the Q4 Platform. “We are embarking on one of the most exciting product cycles in our history,” remarked Darrell Heaps, Founder and CEO of Q4. “Our offerings will unlock tremendous new opportunities for our clients to benefit from the unmatched richness and scale of our proprietary data with the integration of generative AI. The result for clients will simply be effective investor relations and better insights for our investment banking and equity capital markets clients.” In the
Kinaxis RapidResponse Available on Google Cloud Marketplace30.5.2023 14:00:00 EEST | Press release
Kinaxis ® Inc. (TSX: KXS), the authority in driving agility for fast, confident decision-making in an unpredictable world, announced today announced that the market’s leading supply chain management solution, Kinaxis RapidResponse® is available on Google Cloud and in the Marketplace. RapidResponse supports key business processes such as demand and supply planning, integrated business planning, sales and operations planning (S&OP) and inventory management, and delivers end-to-end transparency with its control tower capabilities. Concurrent planning breaks down organizational silos, unifies disparate data under a single all-inclusive data model, and codifies business-wide trust through the continuous alignment of everyone and everything across a company’s end-to-end supply chain. “We’re pleased the Kinaxis platform is now available on Google Cloud,” said Dai Vu, Managing Director, Cloud Marketplace & ISV GTM Initiatives at Google Cloud. “Customers can deploy Kinaxis via the Google Cloud
New Clinical Data on Vuse Illustrates Beneficial Public Health Impact of Tobacco Harm Reduction30.5.2023 13:00:00 EEST | Press release
New results from one of the largest ever vapour product studies, which analysed BAT’s flagship vapour brand Vuse, have been published in the journal of Internal and Emergency Medicine (https://link.springer.com/article/10.1007/s11739-023-03294-9). This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230530005321/en/ One of the largest ever vapour product studies compared clinical measurements from exclusive Vuse consumers with smokers (Graphic: Business Wire) The study compared clinical measurements from exclusive Vuse consumers with smokers. The results of the study show that participating Vuse consumers had favourable differences in biomarkers of exposure (BoE) and biomarkers of potential harm (BoPH) relevant to smoking-related diseases when compared to smokers. Vuse users have shown significantly lower biomarkers of exposure for priority cigarette smoke toxicants as defined by the World Health Organization (WHO)iii. The data al
Quectel 5G RG620T modules based on MediaTek T830 gain global certifications to help drive FWA app deployment30.5.2023 13:00:00 EEST | Press release
Quectel Wireless Solutions, a global IoT solutions provider, today announces that its 5G New Radio (NR) modules series, the RG620T has received FCC/ IC/ CE and RCM certifications. The RG620T series is the first 5G module based on the MediaTek T830 System-on-Chip (SoC) to receive all these certifications. The certifications will enable customers to efficiently deploy their 5G fixed wireless access (FWA) devices around the globe. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230530005071/en/ Quectel 5G RG620T modules based on MediaTek T830 gain global certifications to help drive FWA app deployment (Graphic: Business Wire) The RG620T delivers an extensive range of cutting-edge features including ultra-high 5G data speeds, quad-core A55 CPU, the latest Wi-Fi 7 connection as well as a series of innovations in antenna frequency band design, flash memory and QuecOpen, making it an ideal solution for the FWA market which demands h
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom