Security for connected medical devices, without pretending they are ordinary laptops.
F Creative Studio 360 helps hospitals and manufacturers in any country see how connected devices sit on the network, and what can be done without breaking clinical use.
A device is in service. Treat it that way.
Infusion pumps, monitors and imaging systems often cannot take a normal patch. Many were not built for a hostile network. The useful work is visibility, segmentation and a record of known issues, including published CVEs.
Device software may be regulated. In the United States, cybersecurity expectations for devices sit with the FDA. In Australia, the Therapeutic Goods Administration regulates devices that are supplied there. F Creative Studio 360 does not approve a device, and we do not change regulated software unless the manufacturer and the operator agree that change in writing.
- Patient safety comes first
- An assessment does not scan a live clinical network in a way that could interrupt care. Active testing is allowed only in a written, approved window.
- Segmentation is the usual control
- Isolating a device the vendor cannot patch is often the control that can actually be used.
- Default access is still common
- Shared passwords and vendor remote access are reviewed because they are how many of these networks are entered.
- We are not the regulator
- A review is not a marketing authorisation and not a declaration that the device is safe.
What can be in scope
You name the device types and the sites. We do not roam a hospital network by default.
- Inventory
- What is connected, what it talks to, and who supports it.
- Known weaknesses
- Published vulnerabilities, default credentials and systems that cannot be patched in the usual way.
- Network place
- Whether a compromise of one device is a path into the rest of the hospital.
- Vendor access
- How a manufacturer or a service firm reaches the device, and how that access is closed.
How an engagement runs
The same care applies in any country. The regulatory file, where one is needed, stays with the manufacturer.
- 1
Name the devices and the sites
Clinical areas that must not be disturbed are written down first.
- 2
Prefer passive visibility
Active testing only with written authorisation and a stop condition.
- 3
Write a segmentation path
What can be isolated without stopping the clinical workflow.
- 4
Leave regulated changes with the right party
If software on a regulated device must change, the manufacturer leads that change.
What you receive
- An inventory of the device types in scope.
- A note of known weaknesses and default access.
- A segmentation recommendation that respects clinical use.
- No claim of regulatory approval.
Industrial standards, used carefully
Where the environment is closer to a plant than an office, IEC 62443 can be the language of the review. It is a standard to align with, not a certificate we issue.
Common questions
Will you patch our pumps?+
No. Patching a regulated device is a clinical and regulatory decision. We identify the exposure and the controls that do not require an unapproved change.
Who is this for?+
Hospitals, clinics and device manufacturers in any country. A device regulator’s rules, such as the FDA or the TGA, are used only when that device is actually supplied under them.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
See the devices before you touch them.
F Creative Studio 360 will look at the sites and the clinical constraints, then say what a safe review includes.
