top of page
Search

Cybersecurity After an Acquisition: Lessons for Medical Device

  • Writer: Ross Dehmoobed
    Ross Dehmoobed
  • Jul 19
  • 2 min read

Cybersecurity due diligence should not end when an acquisition closes.


In July 2026, Abbott disclosed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, which was formed following its acquisition of Exact Sciences. Abbott stated that the incident did not affect products, manufacturing, laboratory operations, business operations, or its ability to serve patients. It also noted that legacy Exact Sciences systems remained separate from Abbott’s other systems.


There is no public evidence that the acquisition caused the incident or that any medical device or diagnostic product was compromised. Still, the disclosure highlights an important reality for medical device companies: acquisitions can introduce significant cybersecurity complexity.


Acquisitions expand the attack surface


An acquisition brings more than products, employees, and intellectual property. It can also introduce:

  • Legacy applications and infrastructure

  • Different identity and access controls

  • Unknown cloud environments

  • Third-party and contractor access

  • Unsupported software

  • Development and build systems

  • Laboratory and manufacturing networks

  • Incomplete hardware and software inventories


Until these systems are fully understood, the acquiring company may not know where its most significant risks exist.


Segmentation matters


Abbott’s statement that legacy systems remained separate illustrates the value of maintaining segmentation during integration.


Connecting networks too early can allow a compromised account, endpoint, or application to create a path into the parent company’s environment. Before systems are connected, companies should understand what data needs to move, who needs access, what controls will apply, and how connections will be monitored or disabled during an incident.

Segmentation is not a substitute for remediation, but it can help limit the impact while inherited systems are assessed and strengthened.


Product and enterprise cybersecurity are connected


Medical device companies often focus cybersecurity efforts on the regulated product. That work is essential, but the systems surrounding the product are also critical.


Source-code repositories, build pipelines, signing keys, cloud services, manufacturing systems, customer portals, and vulnerability-management tools can all affect product security. A compromise in one of these systems may create regulatory, operational, or patient-safety consequences even if the device itself was not the initial target.


Cybersecurity integration should therefore involve engineering, quality, regulatory, IT, manufacturing, privacy, and business continuity teams.


Plan for incidents during integration


The period following an acquisition is often disruptive. Systems are being migrated, responsibilities are changing, and teams are learning unfamiliar technology.

Companies should establish clear incident-response ownership before major integration begins. They should know who monitors each environment, how logs will be preserved, who assesses potential product or patient impact, and how operations will continue if systems must be disconnected.


The takeaway


Acquisitions do not inevitably lead to cybersecurity incidents. They do, however, create a period of increased complexity and incomplete information.


For medical device companies, cybersecurity integration should begin during due diligence and continue well after the transaction closes. The goal is not simply to connect two organizations. It is to create a technology environment that is understood, controlled, monitored, and resilient.


MedTechWare helps medical device companies assess cybersecurity architecture, perform threat modeling, develop software bills of materials, plan vulnerability-management activities, and integrate cybersecurity into product development and quality-system processes.


 
 
 

Comments


bottom of page