Since the FDA issued its Postmarket Cybersecurity Guidance in 2016, the rate of ICS-CERT medical device advisories has increased by 386%, reflecting growing transparency and maturity across the medical device ecosystem.
This updated 2025 report extends Medcrypt’s longitudinal analysis through 2024, highlighting emerging patterns in vulnerability disclosure, patching, and regulatory impact.
Key findings reveal that:
- Vulnerabilities continue to cluster around user authentication and code defects — making up nearly 60% of all disclosures.
- Patch references in advisories declined by 22% in 2024, despite new FDA enforcement authority under Section 524B.
- Only 27 of the top 40 medical device manufacturers maintain any public vulnerability disclosure process.
- Half of all vulnerabilities originate from just four manufacturers, demonstrating a clear divide between proactive and lagging programs.
This whitepaper provides data-driven insights into where progress has been made, where it has stalled, and what medical device manufacturers (MDMs) can do to strengthen cybersecurity maturity in 2025 and beyond.