Cybersecurity After an Acquisition: Lessons for Medical Device
- Ross Dehmoobed

- Jul 19
- 2 min read
Cybersecurity due diligence should not end when an acquisition closes.
In July 2026, Abbott disclosed unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, which was formed following its acquisition of Exact Sciences. Abbott stated that the incident did not affect products, manufacturing, laboratory operations, business operations, or its ability to serve patients. It also noted that legacy Exact Sciences systems remained separate from Abbott’s other systems.

There is no public evidence that the acquisition caused the incident or that any medical device or diagnostic product was compromised. Still, the disclosure highlights an important reality for medical device companies: acquisitions can introduce significant cybersecurity complexity.
Acquisitions expand the attack surface
An acquisition brings more than products, employees, and intellectual property. It can also introduce:
Legacy applications and infrastructure
Different identity and access controls
Unknown cloud environments
Third-party and contractor access
Unsupported software
Development and build systems
Laboratory and manufacturing networks
Incomplete hardware and software inventories
Until these systems are fully understood, the acquiring company may not know where its most significant risks exist.
Segmentation matters
Abbott’s statement that legacy systems remained separate illustrates the value of maintaining segmentation during integration.
Connecting networks too early can allow a compromised account, endpoint, or application to create a path into the parent company’s environment. Before systems are connected, companies should understand what data needs to move, who needs access, what controls will apply, and how connections will be monitored or disabled during an incident.
Segmentation is not a substitute for remediation, but it can help limit the impact while inherited systems are assessed and strengthened.
Product and enterprise cybersecurity are connected
Medical device companies often focus cybersecurity efforts on the regulated product. That work is essential, but the systems surrounding the product are also critical.
Source-code repositories, build pipelines, signing keys, cloud services, manufacturing systems, customer portals, and vulnerability-management tools can all affect product security. A compromise in one of these systems may create regulatory, operational, or patient-safety consequences even if the device itself was not the initial target.
Cybersecurity integration should therefore involve engineering, quality, regulatory, IT, manufacturing, privacy, and business continuity teams.
Plan for incidents during integration
The period following an acquisition is often disruptive. Systems are being migrated, responsibilities are changing, and teams are learning unfamiliar technology.
Companies should establish clear incident-response ownership before major integration begins. They should know who monitors each environment, how logs will be preserved, who assesses potential product or patient impact, and how operations will continue if systems must be disconnected.
The takeaway
Acquisitions do not inevitably lead to cybersecurity incidents. They do, however, create a period of increased complexity and incomplete information.
For medical device companies, cybersecurity integration should begin during due diligence and continue well after the transaction closes. The goal is not simply to connect two organizations. It is to create a technology environment that is understood, controlled, monitored, and resilient.
MedTechWare helps medical device companies assess cybersecurity architecture, perform threat modeling, develop software bills of materials, plan vulnerability-management activities, and integrate cybersecurity into product development and quality-system processes.



Comments