I'm Mary Ann Kolbasek McGee, executive editor at Information Security Media Group. Today I'm speaking with Nastasia Tamari, who is division director for medical device cybersecurity at the Food and Drug Administration. Nastasia joined the FDA last year after nearly a decade working on cybersecurity issues at medical device maker, Bectin Dickinson, or BD. So Nastasia, please tell us a little bit about yourself and your new role at the FDA, and I understand that this is a new position within the agency, is that correct?
Yes, it is. Recently the Office of Strategic Partnerships and Technology Innovation was elevated to a super office. That was back in January, which really just allows the center to adapt and address public health needs while just continuing to advance the voice of patients, innovation, safety, all of that good stuff. And so it's part of that organization, the new division of medical device cybersecurity was created, and will continue to support the CDRH's efforts to advance the cybersecurity posture of the medical device ecosystem.
So I am very glad to be here today. So Nastasia, what type of medical device cyber related work are you involved with at the FDA, and how did your prior work at medical device maker at BD help prepare for this new role? The FDA, I lead the Division of Medical Device Cybersecurity, or BMDC. We have a lot of acronyms, and that really looks at providing leadership, strategic direction for medical device cybersecurity policy.
We're really looking at protecting patient safety by strengthening medical device cyber resiliency to cybersecurity threats. And so I think if I maybe take a step back and see how with the type of work that I've previously done, you mentioned I did come to FDA from BD. And my most recent responsibility there was to really drive effective cybersecurity requirements and compliance and strategy across multiple different global regions. So think of North America, Europe, Greater Asia, it was really looking at it from that global sense.
And then previous to that role, I led more of the traditional cybersecurity operations roles, think of incident response, vulnerability management, the rep response monitoring and detection for the enterprise product and manufacturing systems. And so as part of that role, it included leading cyber crisis tabletop response plans and exercises. I had established the coordinated disclosure process for software-enabled products. And that really came from implementing the FDA's recommendations into that private medical device manufacturer processes and procedures.
And I think looking at that work, right, making sure that we are able to take the voice of FDA and implement it into the processes at that manufacturer really did help give perspective from a medical device manufacturer of what some of those challenges are, where some of those successes could be. And so being able to take those learnings and bring it here to FDA is something I'm really excited about. So Nastancia, what are some of the top cybersecurity issues that you're seeing these days involving medical devices? What's cyber threats facing medical devices are most worrisome to you and why?
Yeah, I think as we continue to see those cybersecurity threats and issues are continuing to advance. Devices in the field that may not have been designed with cybersecurity in mind continue to be exposed to cybersecurity threats and at times impacted by cybersecurity incidents. And these impacts can be realized due to connectivity innovation into networks, into those larger systems out of date, unsupported software and operating systems are just really a lack of cybersecurity controls. And so those are concerns that we are seeing.
And I think what we are seeing a lot of as well are manufacturing environments and manufacturing operations where they're being impacted by those cybersecurity incidents. So by chain for healthcare pays particularly large challenges. Their systems have aged and so has really the cybersecurity infrastructure to support them. So we're seeing device manufacturers begin to look at right sizing this focusing on some of that segmentation and then looking at updates to the systems.
But those are costly solutions. They take time to implement it. So really wanting to drive home the point that making sure that our devices are secure by design from the onset and really following through on some of those risk management approaches are key to making sure that as those cybersecurity threats face medical devices, we have processes in place to make sure that we're addressing those risks and that we know what those risks are. So the FDA's refused to accept policy for medical device cybersecurity went to effect last year.
What sort of progress is being made in terms of medical device makers and their focus on cybersecurity issues during the pre-market submission process? How is that program going and are manufacturers still kind of unsure what they need to do? That's a great point and we refuse to accept policy did end on October 1st, 2023. So it is now an expectation for manufacturers to have the documentation for the five to four be requirements and the pre-market guidance prepared for the time of submission.
So the manufacturer is making a pre-market submission. Using those Easter templates, they won't be able to make the submission meaning they'll be rejected from the system unless all of those cybersecurity attachments are provided and that the associated questions are answered before they can even submit that. So during the technical screening process, a submission can be on hold if the attachments are not relevant for a particular submission deliverable or the responses to the questions of the template are inaccurate. What we do see is that medical device manufacturers generally appear to be really accepting of the change and really trying to address the more detailed recommendation in the guidance.
I think at the end of the day, we want to make sure that we do have safe, effective, and cyber secure devices out there and so we really are wanting to make sure that manufacturers know what they need to do and help them to get to the point where they are able to get that documentation and be able to show that those devices are safe, effective, and cyber secure. So, Nastasia, there's the documentation side of it, you know, providing the FDA with those details during that pre-submission sort of process but it's also the actual let's focus on cyber security in these new products. Where do the device makers still seem to need to beef things up? You know, are there certain kinds of issues in cyber security, you know, details that the FDA wants the manufacturers to be focused on that they're just still having trouble with or they're overlooking or they're not spending enough attention on, are there certain key areas that need to be beefed up by many manufacturers at this point?
Yeah, and I'm going to give you a very FDA answer of it depends. But I think, you know, the majority of cyber device manufacturers, they may have deficiencies across a multitude of cyber security review areas. Again, we're working closely with manufacturers during that review process to address some of those concerns that are raised during the submission process about some of those design issues. So needing for more clear documentation, addressing incomplete or inadequate documentation, and potential issues with cyber security testing, I think the three areas that we perhaps see challenges with or should continue to see that is within those design controls, documentation, s-fums, software, build materials, and testing, which really all continues to have challenges during the submission process.
We have had conversations in our hearing that manufacturers are also facing this three to six month wait time for third party penetration organizations to be able to fit them in when they do need to be able to penetration test them. So that's why we say planning ahead for some of those engagements is so critical and making sure that the testing is completed and time to address those findings prior to making this submission is really important. So we want to see those testing plans completed but also knowing that whatever the findings are within those documents also have controls that are implemented and that the manufacturer can really speak to. In terms of the three to six month wait often for the pen testing that these device makers need, why is there a delay?
Is it because now every manufacturer knows they need the pen testing and there's just more demand but meanwhile you have some of the other regular other entities that are not medical device makers perhaps but they still organizations that need pen testing, is there just not enough pen testing organizations or pen testers of the elbow in the industry? What's causing the delight you think? I think and not being within the kind of not having you know that penetration testing organization here to maybe speak for themselves, you know this is a requirement that the FDA is expecting that manufacturers have done completed and so I think that given that we are that is an expectation especially for those cyber devices given that we now have 524B requirements we're really looking at that not to be any sort of exception and so there are more manufacturers who are needing to get penetration tested and so planning ahead is critical and there can be you know a multitude of right it depends reason but we have noticed that the amount of lead time from what we're being told is that there that that does exist and does put a stress on the manufacturer especially when they're looking for that submission. So now when it comes to various sorts of medical devices whether it's robotic medical devices, artificial intelligence and machine learning enabled devices, implantable devices, you know in other sorts of emerging medical device technology what's your advice to device makers and healthcare delivery organizations in terms of the cyber issues that they should be thinking about moving ahead in the use of these sorts of products and in the design.
I think we are expecting that the draft AI ML guidance which is on the A list of priorities for FY24 to be released so I think manufacturers can be expecting to look at that or some of the the guidance but the security objectives that are detailed in the free market guidance really apply to all types of devices whether it's AI or ML as well and so how the objectives are achieved may have unique considerations in the threat model and the design controls implemented for those AI ML devices and I think you know looking ahead right FDA continues to engage with a range of stakeholders on emerging topics and so we're going to continue to look at reviewing and updating policy as appropriate depending on what we're seeing within those trends and really at the end of the day manufacturers are responsible for ensuring the safety effectiveness of devices and cyber security is you know that's not something that's optional and should be included as part of the device so going back to those security objectives in the guidance whether it's an AI ML enabled device or other emerging technologies really should help a manufacturer look at all of their unique considerations when it comes to risk assessments threat models and some of those design controls. And finally Nesassia what should device makers and healthcare delivery organizations be looking for when it comes to FDA's ongoing work and priorities involving cyber security of medical devices in the months ahead. The A is going to continue to engage with stakeholders across the healthcare sector and really evolve that total like cycle approach to address cyber security issues as they emerge. You both FDA and medical device manufacturers are maturing to better understand and address those cyber security issues and you know we really expect this process to continue and for FDA to evolve the processes in response to those emerging issues in the medical device healthcare sector and so as FDA continues to partner with group like HSCC we you know we have a call out for those who want to be part of a new task group to address the complexity of updating and patching medical devices installed in the clinical environment so we'll continue to have those partnerships and where we continue to see some of those challenges really continue to create and foster the public and private partnership as it really helps both of the private and public to really come together and help solve some of those complex problems and lean on each other for making sure we both have best practices and really are doing what's right when it comes to making sure that we're protecting that patient safety aspect and strengthening the medical device resiliency to cyber threats.
Well thank you so much Nastasia. I've been speaking to Nastasia Kamari. I'm Maryette Mobisak-McGhee of Information Security Media Group. Thanks for joining us.