Regulatory Affairs • Cybersecurity

Medical Device Cybersecurity Risk Assessment

Duration: 10 months • Role: Regulatory Affairs Specialist

A recall in one country can surface a cybersecurity gap that needs to be checked against every other market the device is sold in, cybersecurity review can't be done market-by-market in isolation.

Context

Documenting the cybersecurity strategy for identifying the correct 510(k) submission type, following a recall or notice in one country, meant checking the same cybersecurity gap against every other market the device was sold in, not treating the review as market-by-market.

Cybersecurity 510(k) Strategy Recall Review

Primary Risks Identified

  • An unresolved cybersecurity vulnerability being carried forward past a recall closure without documented residual-risk justification

Testing Approach

Reviewed the existing cybersecurity risk documentation against the current threat/vulnerability list, updated the risk assessment, and reconciled it with the recall and document tracker for the affected countries.

Threat/Vulnerability Review Recall/Document Tracker Reconciliation

Outcome

Delivered an updated cybersecurity risk assessment that resolved the open item(s) tied to the recall/notice and gave leadership a clean audit trail.

Key Lessons

A recall in one country can surface a cybersecurity gap that needs to be checked against every other market the device is sold in, cybersecurity review can't be done market-by-market in isolation.

Have a system like this?

If you have no idea of testing your current system, let's talk through what's actually going on.

Contact me