All Articles

Cyber Security · September 2026

Medical device vulnerabilities matter outside healthcare too

A recent CISA advisory on infusion pump security shows why connected devices need network segmentation and monitoring, even when you're not a hospital.

CISA published an advisory in April 2026 about vulnerabilities in infusion pumps used in hospitals. If you're reading this in an office in Burlington or Oakville, you probably don't have medical devices on your network. But the pattern matters: connected devices that weren't built with security in mind can become entry points, and the steps that protect a hospital apply to other businesses too.

What the advisory describes

The CISA advisory from April 2026 covers infusion pumps, which are medical devices that deliver fluids and medication to patients. The vulnerabilities allow someone on the same network to interfere with the devices or extract data. An attacker would need network access first, which means these flaws are most dangerous when a device sits on the same network segment as everything else.

The advisory lists a set of steps hospitals should take: isolate devices on separate network segments, monitor traffic, disable unused services, and apply patches when vendors release them. These are standard hardening steps. The reason they're spelled out is that many connected devices ship with defaults that assume they'll live on a trusted, isolated network.

Where this pattern shows up in other businesses

You might not have infusion pumps, but you probably have other connected devices. Security cameras, door controllers, HVAC systems, printers, and networked storage all behave the same way. They run embedded operating systems, often Linux or a vendor variant. Many ship with default credentials, open management ports, and no automatic update mechanism.

If one of those devices is compromised, an attacker can use it to move laterally. A camera with a weak password becomes a foothold. A printer running outdated firmware can be used to capture documents or scan the internal network. The device itself may not hold sensitive data, but it provides access to systems that do.

What this means for a typical Ontario business

Most small and mid-sized businesses already segment guest Wi-Fi from the main network. That's a good start. The next step is to do the same for connected devices. Cameras, door systems, and printers should live on their own VLAN, with firewall rules that allow only the traffic they need to function. A camera should be able to send video to the recorder but not browse the file server.

Monitoring matters too. If a device suddenly starts scanning other IP addresses or sending large amounts of data out, you want to know. Managed detection tools can flag that behaviour even when the device itself has no logging. The earlier you catch lateral movement, the less damage it does.

What's worth doing this week

Make a list of every device on your network that isn't a workstation or server. Include cameras, printers, door controllers, thermostats, and anything else with an IP address. Check whether they sit on the same network segment as your computers. If they do, talk to your IT provider about moving them to a separate VLAN.

Ask whether your firewall logs unusual traffic from those devices and whether anyone reviews those logs. If the answer is no, you're flying blind. A compromised camera can sit quietly for months if no one is watching.

When this doesn't apply

If your business has fewer than a handful of connected devices and they're all modern, name-brand products with automatic updates, this is less urgent. A two-year-old managed printer on a corporate network with strong passwords and current firmware is not a likely entry point. The risk goes up when devices are older, use default credentials, or were installed by a contractor who never came back to update them.

The point is not to panic about every device. It's to recognise that anything with an IP address can be used as a stepping stone, and to build your network so that one compromised device doesn't hand over the keys to everything else.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.