Cybersecurity Skills Shortage In EU ‘Untenable’ Warns Medtech Trade Body

EU medtech companies are subject to many legislative requirements that ensure devices are cybersecure, but more investment in digital literacy is needed to keep Europe safe from cyber breaches, MedTech Europe says in a new policy paper.

Digital training skills
• Source: Shutterstock

The European Union is awash with an alphabet soup of regulations that relate in full or part to cybersecurity and digital safety - from the long-established GDPR to the newly adopted NIS 2 and upcoming CRA.

Decoding The Cyber Alphabet Soup

 

CRA: The Cyber Resilience Act is a proposed EU horizontal regulation aimed at improving the cybersecurity of products with digital elements. The initial draft text of this regulation, published in September 2022, explicitly excludes medical devices and IVDs from its scope - but some experts have called for this exclusion to be reversed.

EHDS: The European Health Data Space is an EU proposed initiative and implementing regulation that will allow the use of health data for secondary purposes if it is anonymized. Although the EHDS does not directly relate to cybersecurity, it is focused on changing the digital infrastructure of the EU and may conflict with provisions in the GDPR.

GDPR: The General Data Protection Regulation sets EU-wide data protection and privacy rules, and is regarded as one of the world’s strictest laws around data sharing.

NIS 1: The original EU Directive on security of network and information systems, which is gradually being replaced by the NIS 2, which member states have until October 2024 to transpose into national laws.

NIS 2: The new version of the NIS Directive. NIS 2 sets out legal cybersecurity requirements for critical infrastructures, including medical device companies.

Read the full article – start your free trial today!

Join thousands of industry professionals who rely on Medtech Insight for daily insights

  • Start your 7-day free trial
  • Explore trusted news, analysis, and insights
  • Access comprehensive global coverage
  • Enjoy instant access – no credit card required

More from Cybersecurity

Congress, Researchers Highlight Security Risks At DNA Testing Services

 
• By 

Congress has launched an inquiry into 23andMe amid privacy concerns following its bankruptcy, particularly regarding the potential sale of sensitive user data. Additionally, a Cybernews report gave 40 DNA testing firms an average cybersecurity grade of D, citing widespread vulnerabilities and data breaches, along with inadequate public information about their security practices.

Birmingham City University Develops New Defense Mechanism Against Cyberattacks On AI Systems

 

AI systems used in healthcare are vulnerable to adversarial cyberattacks, which are a growing concern, said Atif Azad, a professor of AI at Birmingham City University. Azad’s research group has developed a method that trains AI to become more resilient to cyber threats through the use of random image adjustments.

Enovis Appoints Damien McDonald CEO, Reaffirms Q1 Guidance Amid Strategic Growth Push

 
• By 

Enovis has named veteran medtech leader Damien McDonald as its new CEO effective 12 May as the orthopedic company reaffirms first-quarter 2025 revenue guidance of between $555m and $563m. Medtech Insight spoke with Tim Czartoski, Enovis’ president of US surgical and global product and enabling technologies, about the firm’s growth strategy and innovation plans.

Digital Health Roundup: Intuitive Surgical CEO Exec Chat, AI Alert System, FDA, Roche New NGS Prototype

In this week’s Digital Health Roundup, Medtech Insight’s Marion Webb highlights her conference coverage from CES, HIMSS, AAOS and LSI including Exec Chats with Gary Guthart, CEO of Intuitive Surgical, and Arcadia’s chief strategy officer Aneesh Chopra. Brian Bossetta highlights a recently FDA-cleared alert system that sends vital signs to clinicians. Elizabeth Orr discusses FDA warning letters sent to Exer Labs for exceeding marketing claims under what is allowed under the device’s 510(k) clearance. Shubham Singh discusses how Roche's unveiling of its next-generation sequencing (NGS) prototype challenges Illumina. The SBX technology is set to compete directly with Illumina’s NovaSeq and NextSeq platforms.

More from Digital Technologies

DeepLook AI Imaging Provides A Deeper Look At Dense Breast

 

DeepLook Medical recently announced the commercial rollout of DL Precise, an AI-powered imaging platform that enhances breast cancer screening, at major healthcare institutions across the US.

First AI Breast Cancer Prediction Platform Receives FDA Authorization

 

Clairity’s "first-in-class" mammography-based AI screening tool, Clairity Breast, provides "equitable risk assessments," expanding access to lifesaving early detection for breast cancer, said company founder Connie Lehman.

ConcertAI Launches Generative AI-Powered Precision Suite

 

Valued at over $1.9bn, ConcertAI is building on its pre-existing multi-agentic AI SaaS solution CARAai to bring life science customers the new Precision suite of applications: Precision Explorer, Precision Trials, Precision GTM and Precision360.