Cybersecurity
OT Cybersecurity in Healthcare: Connected Medical Devices, Hospitals and NIS2
Hospitals are OT environments in their own right: thousands of connected medical devices, often unmanageable with traditional IT tools. How to secure the IoMT fleet under NIS2.

The hospital is an OT environment
When people talk about industrial security, the mind jumps to factories, PLCs and SCADA. But a large hospital runs a fleet of connected devices comparable in complexity and criticality to a production plant, with an added factor: the controlled process is patient care.
Infusion pumps, multiparameter monitors, ventilators, imaging systems (CT, MRI), laboratory analyzers, medication management systems. This is the Internet of Medical Things, the IoMT. They are devices with long life cycles, certifications that constrain any modification and network connectivity designed for clinical interoperability, not for security.
The problem of unmanaged devices
The figure that defines the sector: more than half of connected medical devices are unmanaged assets. They cannot host a security agent, they do not appear in IT inventories, and the technical department often does not even know how many of them are on the network.
The reasons are structural:
- Closed, certified systems: the manufacturer does not authorize the installation of third-party software. A modification can invalidate the device certification.
- Obsolete operating systems: many devices run on unsupported versions of Windows, because recertifying every update is costly and slow.
- Hybrid ownership: clinical engineering buys the device, IT manages the network, and neither has clear responsibility for its security.
The result is a large fleet of assets invisible to traditional tools, each one a potential entry point.
Where the real risk lies
It helps to distinguish two types of risk, because they point to different interventions.
Direct risk to an individual device (tampering with a pump, altering a parameter) is technically possible but rare in real attacks. It requires specific skills and offers little return to the average attacker.
Indirect risk is what actually hits. Ransomware that encrypts hospital information systems does not touch a single medical device, yet it paralyzes the organization: emergency rooms on diversion, procedures postponed, a return to paper. The documented clinical impacts of ransomware attacks in healthcare almost all run through this mechanism. Patient safety, here, coincides with operational continuity.
Unmanaged devices worsen both risks because they offer the attacker footholds for lateral movement toward the systems that matter.
NIS2 and the regulatory framework
Healthcare is one of the essential sectors under NIS2. For organizations above the threshold this means concrete obligations: cyber risk management, incident notification within the prescribed timeframes, supply chain security. The IoMT fleet is not excluded: it is an integral part of the attack surface to govern.
On top of this comes regulatory pressure on manufacturers. Authorities (CISA in the United States, ENISA in Europe) have issued repeated alerts about medical devices with serious vulnerabilities, in some cases with factory backdoors. Responsibility is progressively shifting toward those who design the devices, but those who operate them remain exposed here and now.
A practical approach
The principles of OT security apply to healthcare with few differences. The sequence that works:
- Passive visibility: rebuild the complete inventory of connected devices by observing network traffic, without actively interrogating clinical equipment (which can react badly to a scan). You cannot protect what you cannot see.
- Classification by clinical criticality: an intensive care monitor and an information display do not deserve the same attention. Prioritize based on impact on the patient and on continuity.
- Segmentation: isolate medical devices in dedicated zones, separated from the administrative network and from the internet. Most clinical devices have no reason to communicate beyond a narrow perimeter.
- Compensating controls: for devices that cannot be updated, work around them (behavior monitoring, flow restriction, alarms on anomalies) instead of trying to secure them from the inside.
- Continuity first: response and recovery plans that assume the worst-case scenario (information systems unavailable) and define how the hospital keeps providing care in the meantime.
OT security in healthcare is not a transplant of industrial practices, but the recognition that the hospital is already a critical OT environment. Treating it as such is the first step.
The MON5 angle
More than half of connected medical devices cannot host an agent or tolerate an active scan: visibility has to come from the network. This is MON5's native approach: passive discovery of traffic to rebuild the complete inventory of the IoMT fleet, from monitors to imaging systems, without interrogating certified clinical equipment and without interfering with department activity.
On top of that inventory the platform correlates known vulnerabilities with the real exposure of each device, helping to prioritize compensating controls on the assets that cannot be updated, and produces evidence useful for the organization's NIS2 obligations. For a healthcare management team or a clinical engineering department, the first concrete step is an OT assessment.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles
Cybersecurity
Port and Maritime Cybersecurity: Terminals, Intermodal Logistics and Onboard Systems
Ports and ships are complex, under-protected OT ecosystems: automated cranes, onboard systems, terminals and intermodal logistics. A map of risks and obligations for a critical sector that is often overlooked.
Cybersecurity
OT incident notification under NIS2: obligations, timelines and what to have ready before it happens
NIS2 sets tight deadlines for notifying significant incidents: 24 hours for the early warning, 72 hours for the detailed notification. In OT, being ready to meet them takes preparation that starts long before the incident.
Cybersecurity
Ransomware landscape, summer 2025: manufacturing in the crosshairs
In spring and summer 2025 ransomware mostly hit manufacturing. Data, active groups and what it means for industrial OT environments.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2