Whitepaper · July 28, 2025
What the Medical Device Industry Can Learn From Past Cybersecurity Vulnerability Disclosures
Insights From 10 Years of ICS-CERT Data (2013–2024) and FDA Postmarket Cybersecurity Trends

Executive summary
What this whitepaper covers
Since the FDA issued its Postmarket Cybersecurity Guidance in 2016, the rate of ICS-CERT medical device advisories has increased by 386%, reflecting growing transparency and maturity across the medical device ecosystem.
This updated 2025 report extends Medcrypt’s longitudinal analysis through 2024, highlighting emerging patterns in vulnerability disclosure, patching, and regulatory impact.
Key findings reveal that:
- Vulnerabilities continue to cluster around user authentication and code defects — making up nearly 60% of all disclosures.
- Patch references in advisories declined by 22% in 2024, despite new FDA enforcement authority under Section 524B.
- Only 27 of the top 40 medical device manufacturers maintain any public vulnerability disclosure process.
- Half of all vulnerabilities originate from just four manufacturers, demonstrating a clear divide between proactive and lagging programs.
This whitepaper provides data-driven insights into where progress has been made, where it has stalled, and what medical device manufacturers (MDMs) can do to strengthen cybersecurity maturity in 2025 and beyond.
Why it matters
The regulatory and product context
Despite spending $10–20 billion annually on cybersecurity, the healthcare sector consistently ranks among the most targeted and least secure industries. Regulatory fragmentation, economic misalignment, and clinical priorities often push security down the list of business imperatives. As a result, security debt (vulnerabilities that originate from design, integration, or maintenance) is passed downstream to hospitals and patients.
Understanding these constraints is the first step toward systemic reform. This whitepaper provides insight into how industry and regulators can rebalance incentives, reduce security debt, and build sustainable, resilient healthcare technology systems.
Key insights
What you’ll take away
- Vulnerabilities have tripled since 2016, but the root causes remain unchanged.
- Disclosure transparency is improving, but patching performance declined in 2024.
- 59.8% of vulnerabilities still stem from authentication and code-related issues.
- Researchers now drive two-thirds of all disclosed advisories.
- FDA’s new Section 524B patch enforcement may redefine disclosure behavior in coming years.
Who should read this
- Medical Device Manufacturers (MDMs): product security, regulatory, and R&D teams focused on postmarket vigilance
- Regulatory and Quality Professionals: responsible for FDA submissions and maintaining compliance with 524B and 81001-5-1
- Healthcare Delivery Organizations (HDOs): security and IT teams relying on manufacturer disclosures for clinical risk management
- Policy and Standards Leaders: working on coordinated vulnerability disclosure (CVD), ICS, and cybersecurity harmonization
