Medical assessment and design solutions for cybersecurity of connected medical devices
Secure Society Health & WellbeingThe European health care system is moving toward personalised, distributed, and home-based services. This is made possible via new and improved connected medical devices (MDs) and in vitro diagnostic devices connected to the internet (together, CMDs), and will benefit health care providers in terms of reduced cost (fewer hospital beds) and improved service. Patients will see improved quality of life in terms of reduced travel time and reduced stress via treatment at home or where they want it. However, for these benefits to be fully realised, the cybersecurity of CMDs needs to be ensured.
NEMECYS will benefit practitioners such as cybersecurity communities, MD manufacturers, CMD scenario system integrators and CMD scenario operators (e.g. health care providers), with downstream benefits to patients and the wider public, through more cost-effective and efficient care enabled via effective and streamlined cybersecurity.
NEMECYS helps practitioners to (i) comply with MD regulations; (ii) to be able to apply proportionate MD cybersecurity (too little security risks exposure, too much is costly and can obstruct clinical care) and (iii) build in cybersecurity by design for both MDs and the connected scenarios they operate in. This is achieved by (i) providing recommendations for best practice and guidelines for MD cybersecurity by design, along with compliance assurance tooling; (ii) providing a risk-benefit scheme to address cybersecurity risk balanced with clinical benefit; and (iii) providing a set of specific tools to address MD cybersecurity by design and their deployment in connected scenarios.
The NEMECYS team has cybersecurity risk experts, two hospitals who are already implementing IoT and remote care-based scenarios, three medical device manufacturers, major computer science research players and experienced systems integrators. This team is ideally placed to ensure that NEMECYS can enable practitioners to apply the right security at the right place.
NEMECYS will address cybersecurity of connected medical devices (CMDs) via three integrated approaches.
IT Innovation eads “Risk benefit analysis schemes” to determine risk benefit schemes for connected medical devices. We will investigate medical device vulnerabilities, indicators of threats, incidents, sensitive data leakage and analytics risks for CMDs considering novel technological developments. We will investigate device-level and systemic cybersecurity risk assessment accommodating propagated threats in multi-MD connected scenarios with different domains of control, at both design time and runtime.
IT Innovation will integrate the results to determine proportionate risk benefit schemes, ensuring adequate but not excessive security, considering patient safety, ethics, regulation, and clinical benefit, plus creating a risk-benefit assessment software prototype
The NEMECYS project is a 36 month project funded by the EC Horizon Europe programme.
Coordinator: SINTEF AS
Website: https://protego-project.eu/
More information: https://cordis.europa.eu/project/id/101094323
This project has received funding from the European Union's Horizon Europe's research and innovation programme under grant agreement No 101094323.