On July 27, 2026, the European Commission published its most substantial guidance yet on applying the EU Cyber Resilience Act (CRA). The guidance helps manufacturers, developers, and businesses of all sizes by working through questions that have caused the most...
Download RunSafe’s 2025 Medical Device Cybersecurity Index
Industry-defining insights from 605 healthcare decision-makers on medical device cybersecurity
Medical device cybersecurity has evolved from an IT concern to a patient safety imperative. Our comprehensive survey of 605 healthcare executives reveals how cyberattacks on medical devices are reshaping procurement decisions, budget priorities, and patient care across the healthcare ecosystem.
Key Findings At-a-Glance:
- 22% of healthcare organizations have experienced cyberattacks on medical devices
- 75% of these incidents affected patient care
- 46% have declined device purchases due to cybersecurity concerns
- 79% are willing to pay premium prices for devices with advanced security
- 35% now identify medical devices as their biggest cybersecurity concern
What’s Inside the Report:
- Real-world examples of how cyber incidents are affecting patient care
- How security is changing procurement and vendor expectations
- Where healthcare budgets are shifting—and why
- What healthcare buyers now demand from medical device manufacturers
- What forward-thinking leaders can do to stay ahead
Who Should Read This Report:
- Healthcare executives and decision-makers
- Medical device manufacturers and vendors
- Healthcare IT and security professionals
- Healthcare procurement professionals
- Healthcare investors and analysts
Check Out Our Latest Blog Posts
Mapping CISA’s 2026 SBOM Minimum Elements to CycloneDX and SPDX: An Implementation Guide
On July 29, 2026, CISA and a coalition of international cybersecurity agencies published the 2026 Minimum Elements for a Software Bill of Materials (SBOM)—the first full update to the baseline the National Telecommunications and Information Administration (NTIA)...
CRA Readiness: 6 Steps Embedded Product Teams Should Take Now
The first major Cyber Resilience Act (CRA) deadline is nearly here. Beginning September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The broader CRA requirements become...



