We reduce cybersecurity risk for devices in the field - without requiring a redesign, a new FDA submission, or taking the device offline. Whether you're the manufacturer responsible for the device or the hospital managing it, the risk is the same - and the approach differs.
The short answer
Legacy devices often run outdated software that can't be easily patched. Securing them starts with an inventory and SBOM, then a threat model and risk assessment of how they're used today. Compensating controls such as network segmentation, hardening, monitoring and clear customer guidance reduce risk without a redesign. Section 524B applies to premarket submissions sent on or after March 29, 2023.
No Redesign. No New Submission. No Downtime.
A fielded device that hasn't been re-evaluated against current FDA expectations carries three concurrent forms of risk - and they compound the longer the device stays in service.
Section 524B applies to submissions made after March 29, 2023, but older fielded devices are still covered by the FDA's postmarket cybersecurity guidance, complaint handling, and correction and removal rules. A fielded device with unaddressed vulnerabilities can lead to an inspection finding, a safety communication, or in the worst case a recall. And the next submission for a modified version brings Section 524B into play.
A legacy device running unpatched software isn't protected by the cybersecurity controls that cleared it. Attack surfaces expand as the threat landscape evolves; the device doesn't evolve with it. The risk profile that was acceptable at clearance no longer reflects reality.
A coordinated vulnerability disclosure event on a fielded device is public. It damages the brand, triggers regulatory scrutiny, and can force a market withdrawal. Compensating controls put in place before disclosure greatly reduce that exposure.
Legacy devices were rarely built with current cybersecurity expectations and often can't be redesigned. The engagement focuses on compensating controls, network isolation, and a postmarket plan that keeps the installed base defensible without a re-clearance.
Layers shown outermost (top) to innermost (bottom). Dashed rows are part of the surrounding system but out of scope for this view.
Every legacy device protection engagement ships with the artifacts FDA reviewers expect to see - traceable, complete, and aligned with current guidance.
Recalls, CISA ICS-MA advisories, and disclosed research that shape what reviewers ask about - and what this engagement is built to cover.
Stack-level vulnerabilities affecting 200+ legacy device families. The model case for why an installed-base cybersecurity strategy needs compensating controls when patching is not realistic.
Long-tail hospital-network exposed devices with hard-coded credentials and auth bypasses. Drove the FDA expectation that legacy devices ship a compensating-controls bulletin to operating organizations, not just a deprecation notice.
Pressure-test the work yourself before you scope an engagement. No signup, results are yours to keep.
We reduce cybersecurity risk for devices in the field - without requiring a redesign, a new FDA submission, or taking the device offline. Whether you're the manufacturer responsible for the device or the hospital managing it, the risk is the same - and the approach differs.