The Hospital CISO’s Double Challenge: Achieving Device Visibility Across Siloed Teams

Updated on April 17, 2026
Asimily Shankar Somasundaram Headshot copy

As hospitals across North America accelerate their investments in cybersecurity tools to protect the rapidly expanding Internet of Medical Things (IoMT), a critical challenge continues to persist. Hospital CISOs consistently rank complete device visibility as a top priority, yet fragmented internal structures make it difficult to achieve.

For Asimily CEO Shankar Somasundaram, the issue is clear: hospitals are pouring resources into securing connected medical devices, but most still lack complete visibility into what’s actually on their networks, and the fragmented teams responsible for those devices make closing that gap even harder.

“At a high level, technology and process issues are intertwined in hospital IoT, OT, and IoMT security, and the data reflects just how big the challenge has become,” Somasundaram says.

Recent survey data from Asimily’s State of Hospital Cyber Asset Exposure Management underscores this disconnect. While hospital chief information security officers (CISOs) consistently rank device visibility as a top priority, internal process breakdowns are another leading barrier to effective risk management. At the same time, the stakes are rising: 70% of healthcare organizations report that cyberattacks have directly disrupted clinical care, with recovery costs averaging $3.9 million per incident.

A System Built in Silos

The root of the problem lies in how hospitals are structured.

“Most hospitals weren’t designed with unified IoT, OT, and IoMT device governance in mind, let alone at the scale device deployments have reached,” Somasundaram explains.

In practice, responsibility for connected devices is fragmented across multiple departments. Clinical engineering teams often handle procurement and maintenance. Health technology management oversees deployment. Security teams, meanwhile, are tasked with protecting systems they may not even know exist.

“Security, far too often, finds out about a new device on the network after it’s already running (if at all),” he says. “When responsibility is that fragmented, even a well-funded hospital security team can’t protect what it has no idea exists.”

This lack of coordination creates a fundamental visibility problem. Each department operates from its own dataset, with no unified source of truth for device inventory, risk posture, or remediation efforts. As a result, vulnerabilities can emerge, and persist, without detection.

Compounding the issue is limited investment. According to the survey, hospitals typically allocate just 4% to 7% of their IT budgets to cybersecurity. That constraint forces teams into a reactive posture.

“Those limited resources end up going toward reactive firefighting rather than systemic, long-term risk reduction,” Somasundaram says.

The Hidden Risks of No Ownership”

The absence of clear ownership doesn’t just create inefficiencies; it introduces real-world vulnerabilities that can go unnoticed for weeks or even months.

Somasundaram recounts a scenario shared by a hospital security leader that illustrates the risk.

“A third-party technician came in to service a network-connected imaging device, made some configuration changes, and left. Nobody told security, who found out weeks later, almost by accident,” he says. “When they dug into it, they realized this had been happening regularly, with maintenance visits and device deployments running completely parallel to the security function without handoff and documentation.”

This kind of breakdown is not uncommon. As more devices come online, and as older systems fall out of support, these gaps become increasingly dangerous.

“Device vulnerabilities don’t always (or even usually) announce themselves,” Somasundaram notes. “They accumulate quietly, and by the time security has visibility into a problem, the window for straightforward remediation has usually passed.”

The Prioritization Problem

Even when vulnerabilities are identified, determining what to fix, and when, presents another major challenge.

“The most persistent breakdown is the risk prioritization gap,” Somasundaram says. “Security teams often cannot determine which IoT, OT, and IoMT devices warrant immediate attention.”

Part of the difficulty lies in competing priorities. Clinical engineering and biomed teams focus on uptime and care continuity, ensuring that devices remain available for patient use. Security teams, on the other hand, prioritize risk reduction.

“Those are different goals, but they don’t have to be incompatible,” he says. “Without deliberate process structures that bring both functions into much more integrated processes, however, they will continue to pull in different directions.”

The lack of shared workflows means critical clinical context is often missing from security decisions. A vulnerability that appears urgent from a cybersecurity perspective may not be feasible to address without disrupting patient care. Conversely, a seemingly low-priority issue could pose significant risk depending on how a device is used within the network.

Too Many Devices, Not Enough Context

The scale of the problem is staggering.

“The average hospital has more than 30 connected devices per patient bed, which can translate to thousands of IoT, OT, and IoMT systems on a single network,” Somasundaram says.

With limited resources, CISOs are forced to prioritize. According to Asimily’s survey, 22% rely on a combination of vendor alerts, CVSS scores, and device criticality to guide remediation decisions.

“That’s the right instinct,” Somasundaram acknowledges. “But the problem is that vendor alerts are often reactive.”

By the time a vendor issues a warning, a vulnerability may already have been exploited elsewhere. Similarly, CVSS scores provide a measure of severity but lack environmental context.

“A critical CVSS score on a device that’s fully segmented and airgapped may only have minimal actual risk in a specific environment,” he explains.

Where hospitals often struggle, he says, is in treating all vulnerabilities as equal.

“You need to figure out how to isolate the top 1% of riskiest devices and focus energy there,” Somasundaram says. “That requires understanding not just that a device has a vulnerability, but whether it’s genuinely exploitable in your specific network, what it connects to, and what the downstream clinical impact of a compromise would be.”

An MRI machine, an HVAC system, and an administrative workstation each carry different levels of risk. Effective prioritization depends on understanding those distinctions.

Manual Processes, Clinical Consequences

Despite the complexity of modern healthcare environments, many organizations still rely on manual or fragmented approaches to vulnerability management.

“Manual review of vulnerabilities was cited by 18% of CISOs as their primary prioritization method, and another 15% reported having no clear process at all,” Somasundaram says. “When you add those together, you have roughly a third of hospital security leaders operating without systematic, scalable remediation workflows.”

The consequences are significant. Manually cross-referencing vendor alerts, vulnerability databases, and device inventories is time-consuming, even for fully staffed teams. For organizations already facing workforce shortages, the delays can be substantial.

“That lag creates windows where known vulnerabilities sit unaddressed on devices connected to clinical care systems,” he says.

The impact extends beyond IT operations to patient safety itself.

“Attacks that compromise IoT, OT, and IoMT devices disrupt care delivery,” Somasundaram says. “Research from the Ponemon Institute found that 70% of healthcare organizations reported cyberattacks directly disrupted their clinical care, and half reported that data loss or exfiltration incidents contributed to increased mortality rates. Those are clinical outcomes because device risk management execution had failed.”

Reframing Cybersecurity as Clinical Risk

To address these challenges, Somasundaram argues that hospitals must fundamentally rethink how they view IoMT security.

“The framing shift needs to happen at the board and executive level, not just in the security team,” he says.

Cybersecurity incidents involving medical devices are not merely technical disruptions; they are clinical events with direct implications for patient care. A ransomware attack that disables imaging systems or forces patient diversions can have immediate and serious consequences.

“It belongs in the same conversation as other clinical risk categories, and hospital leadership needs to govern it accordingly,” Somasundaram says.

This shift requires broader organizational involvement. Security can no longer operate in isolation.

“IoT, OT, and IoMT security can’t live solely in the CISO’s lane,” he explains. “Clinical leadership, risk management, and operations all have a stake in the outcomes, and the governance structures, budget conversations, and risk tolerance frameworks need to reflect that.”

Importantly, framing cybersecurity as a clinical issue can also strengthen the case for investment.

“When you can clearly connect security investments directly to patient safety outcomes and care continuity, the ROI justification becomes much clearer than traditional cybersecurity ROI arguments,” he adds.

Fixing the Governance Gap

For hospitals already investing in IoMT security tools but struggling to see results, the solution begins with governance.

“The most important structural change is establishing clear and documented ownership of connected device security across the device lifecycle, from procurement through decommissioning,” Somasundaram says.

Ownership must be paired with visibility. That means creating a shared, organization-wide view of all connected devices, including their risk status and remediation options.

“There must be a unified view of device inventory, current risk posture, and risk remediation options that security, clinical engineering, and health technology management are all comfortable working from,” he says.

Equally important is shifting from reactive to proactive approaches.

“Tools that produce long vulnerability lists without network context or prioritization intelligence will overwhelm resource-constrained teams, not help them,” Somasundaram notes.

Effective segmentation offers one example of how governance and technology can work together. By translating device intelligence into enforceable policies, hospitals can better control how devices interact within the network. But even the most advanced tools require accurate data and clear processes to function effectively.

“Hospitals getting the most value from their IoT, OT, and IoMT security investments are the ones that have solved the process problem first,” he says. “The right tools amplify good governance, but they cannot be a direct substitute for it.”

Expanding the Risk Lens

The challenge extends beyond internal systems.

Recent high-profile cyber incidents involving medical device manufacturers highlight the importance of considering vendor and supply chain risks. When a manufacturer experiences a breach, hospitals must quickly assess potential impacts across their own environments.

“When a major device manufacturer gets hit, hospitals that depend on that vendor suddenly have to ask questions they may not have clear answers to,” Somasundaram says. “What systems are interconnected? What data has been shared? Which devices in our environment have ongoing software dependencies with that vendor?”

Too often, those answers are not readily available.

“Attack surfaces can extend well beyond the hospital’s own walls, and most governance frameworks aren’t built to account for that,” he explains. “Vendor risk, supply chain dependencies, third-party integrations…those all need to be part of the IoT, OT, and IoMT security conversation, and too often right now they still aren’t.”

The Path Forward

As hospitals continue to expand their use of connected medical devices, the complexity of securing those environments will only increase. Technology will remain a critical component of the solution, but it cannot succeed in isolation.

In Somasundaram’s view, the path forward requires strategies that give security, clinical engineering, and operations teams a shared view of device risk, paired with the organizational structures that turn that visibility into action.

Because in healthcare, cybersecurity is no longer just an IT issue. It is, fundamentally, a patient safety issue, and one that demands the same level of coordination, accountability, and leadership as any other clinical risk.

For more information, visit asimily.com

c8e61c7eb1c5d84a4b0b869d7443327301979bf37c44294d3404c5f3e4ac36ea?s=150&d=mp&r=g
Web |  + posts

Daniel Casciato is a seasoned healthcare writer, publisher, and product reviewer with two decades of experience. He founded Healthcare Business Today to deliver timely insights on healthcare trends, technology, and innovation. His bylines have appeared in outlets such as Cleveland Clinic’s Health Essentials, MedEsthetics Magazine, EMS World, Pittsburgh Business Times, Post-Gazette, Providence Journal, Western PA Healthcare News, and he has written for clients like the American Heart Association, Google Earth, and Southwest Airlines. Through Healthcare Business Today, Daniel continues to inform and inspire professionals across the healthcare landscape.