Every medical device manufacturer today is sitting on a mountain of security data—SBOMs, vulnerability scans, quality system records, regulatory filings, field service logs. The tooling has never been more mature, and the volume of information has never been higher.
And yet, according to a new white paper from Health-ISAC, From Metrics to Meaning: Transforming Medical Device Cybersecurity into a Strategic Risk Narrative, most organizations still can't answer the questions that matter most: Are we actually reducing risk? Are our products getting more secure over time? Are we aligned with what regulators and the market expect of us?
That gap—between having data and understanding it—is the entire premise of the paper. Written collaboratively by product security leaders from across the medical device industry (including Medtronic, Abbott, Stryker, Boston Scientific, BD, Baxter, Fresenius, B. Braun, Amgen, and Health-ISAC itself), the report doesn't ask manufacturers to collect more. It asks them to organize what they already have into something a CISO, a general counsel, or a board member can actually use to make a decision.
The core problem: data-rich, insight-poor
The white paper opens with a blunt diagnosis. Medical device manufacturers have become genuinely good at generating cybersecurity data—but that data tend to live in disconnected systems (vulnerability monitoring tools, issue trackers like Jira, quality management systems, regulatory and audit platforms) that were never built to talk to each other. The result is fragmentation, not clarity.
Compounding that fragmentation is what the paper calls "the illusion of coverage." Many organizations track raw activity—total vulnerabilities, number of scans run, number of tests completed—as a stand-in for security posture. But with hundreds of thousands of known vulnerabilities in circulation globally and only a small fraction of those ever actively exploited in the wild, treating every vulnerability as equally urgent doesn't create rigor; it dilutes focus and obscures the risks that actually matter.
There's also a structural mismatch in who needs what. Operational teams need granular detail—remediation timelines, defect density, patch readiness. Executives need strategic signal—potential recalls, regulatory findings, financial exposure. When organizations don't translate between those two levels, the consequences show up downstream: regulatory submission delays, field corrective actions, lingering risk from unsupported end-of-life software, and erosion of market trust.
The fix: a structured measurement framework
Rather than prescribing more dashboards, the paper lays out a four-step framework for turning raw measurement into a defensible narrative.
1. Organize metrics into risk-aligned pillars. The paper groups metrics into four categories: Vulnerability Management & Operations, Compliance/Audit/Risk, Lifecycle & Asset Management, and Strategic Maturity & Investment. Each pillar answers a different strategic question, rather than just accumulating more numbers in one bucket.
2. Prioritize by exploitability, not volume. This is arguably the paper's sharpest recommendation: focus remediation on Known Exploited Vulnerabilities (KEV) and threats already being weaponized in the wild, rather than trying to chase every CVE with equal urgency. It's a shift from volume-based remediation to threat-informed prioritization—a small subset of vulnerabilities that actually carries the overwhelming majority of real-world risk.
3. Map every metric to its source system. Defect density traces back to SBOM and vulnerability monitoring tools; patch timelines live in issue trackers; audit findings sit in the quality management system. This traceability isn't bureaucratic box-checking; it's what makes the resulting metrics defensible in front of a regulator or an auditor.
4. Measure the full lifecycle. From vulnerability intake through risk assessment, remediation, and field deployment, with concrete markers like time to severity determination and deployment coverage milestones (25%, 50%, 75%, 90%).
The breakthrough: a dual-layer model that turns data into a narrative
The report's central insight is this: metrics alone don't create value; they only matter once they're organized into a narrative of risk that can actually influence a decision.
To operationalize that, the paper proposes a dual-layer metric model. Operational metrics answer whether teams are executing effectively—is defect density improving, are KEV-related items closing within tolerance, is field deployment progressing? Executive metrics answer a different question entirely: is all of that operational work actually reducing enterprise risk?
The translation between the two layers is where the paper gets genuinely useful. It maps specific operational signals to their executive-level meaning. For example, a persistent remediation backlog and slowing closure rates roll up into elevated risk of external inspection findings or field corrective actions. A growing footprint of unsupported, end-of-life software signals structural lifecycle risk that may justify new investment or a modernization plan. Recurring audit findings and aging corrective actions point to broader maturity gaps that leadership needs to address through governance, not just technical fixes.
In other words: operational metrics show whether work is getting done. Executive metrics show whether the organization is actually getting safer, more compliant, and more resilient. Confusing the two—or worse, only reporting the operational layer up to the board—is exactly how organizations end up "data rich but insight poor."
What this means for different audiences
For medical device manufacturers, this is a call to treat cybersecurity metrics as a management discipline, not a reporting exercise. The paper's call to action is specific: architect a small, structured set of meaningful KPIs; integrate data across SBOM, vulnerability, quality, and regulatory systems; prioritize real-world exploitable vulnerabilities; align metrics across operational and executive audiences; and communicate all of it as a business narrative rather than a spreadsheet dump. Done well, this reframes product security from a cost center into a function that can demonstrably protect revenue, regulatory standing, and competitive position.
For hospitals and healthcare organizations procuring these devices, the framework offers something practical: a shared vocabulary for evaluating a vendor's security posture. A manufacturer that can speak fluently about inspection readiness, field corrective action risk, and lifecycle exposure from unsupported software—rather than just "we run scans"—is signaling a more mature, more auditable security program. That matters directly to procurement, risk, and clinical engineering teams trying to assess which vendors are actually managing risk versus just generating activity.
For the general public—patients relying on connected medical devices, from infusion pumps to implantables—the stakes are less visible but no less real. The paper is explicit that every metric it discusses ultimately traces back to patient safety, product reliability, and regulatory compliance. A manufacturer that can't tell the difference between "we patched a lot of vulnerabilities" and "we closed the vulnerabilities most likely to be exploited" is a manufacturer that may be missing the risks that could actually affect a device in the field. The framework's push toward threat-informed prioritization and full-lifecycle tracking is, at bottom, a push toward catching the vulnerabilities that could cause real-world harm before they do.
Health-ISAC's framing is worth sitting with: cybersecurity metrics aren't just measurements of activity; they're the mechanism by which an organization explains how it protects patients, manages risk, and earns trust. Manufacturers that treat metrics as a compliance artifact will keep drowning in data without ever answering the question executives, regulators, and hospital customers actually want answered: is this getting better?
The organizations that master this shift—from raw measurement to structured risk narrative—won't just check the compliance box. They'll be positioned to define what secure, resilient, trusted medical technology looks like going forward.

