MDC Module 6 Managing What Matters Risk Management for Medical Device Cybersecurity Hero Image

Medical Device Cybersecurity Module 6: Managing What Matters

Asynchronous Icon

Duration

4 Hours

Curriculum Icon

Format

Blended Learning 
(Virtual + Self-paced)

Flexibility Icon

Certificate + CEUs

Earn Certificate of completion 
+ 0.4 CEUs

Strong Network Icon

Instructors

Matt Dimino and Toby Gouker
Experts, Practitioners, and Executive Leaders in Medical Device Security

Healthcare delivery organizations (HDOs) face increasing cyber threats targeting connected medical devices (IoMT). These devices often lack basic security controls, operate on outdated software, or are not integrated into enterprise risk processes. Unlike traditional IT assets, medical devices present unique challenges—such as clinical safety implications, vendor lock-in, and limited patchability.

Despite this, many HDOs still do not apply structured or continuous risk management to their connected clinical devices. Risk decisions are frequently reactive, undocumented, or made in isolation by HTM or IT teams without shared ownership. This exposes hospitals to preventable attacks, patient safety risks, and regulatory non-compliance.

Key topics include:

  • Discuss the business value of passive network monitoring tools.
  • Identify the need and outcomes for integrated systems (CMDB/CMMS with passive network monitoring tools).
  • Identify how data attributes and asset intelligence can be used to create successful business outcomes for risk remediation.
  • How to use MDS2 and SBOM documents for securing medical devices and supporting cyber hygiene in the procurement process.

Participants will be able to:

Results include improved security posture, risk-driven decision making, cross-team alignment, and greater cyber resiliency. 

  • Conduct basic medical device cybersecurity risk assessments using threat, vulnerability, and impact data.
  • Apply compensating controls when patching or remediation is not feasible.
  • Track risk decisions using risk registers, MDS2s, and governance documentation.
  • Communicate risk scenarios and remediation plans to clinical, compliance, and leadership teams.
  • Integrate medical device security risks into broader enterprise risk management (ERM) workflows.

Questions?

Interested in learning more about this module or how it fits into your organization’s needs?

Start the Conversation