CIO Magazine: Connected Medical Device Security Levels Up — SV Surveillance Allies with Applus+ to Deliver One-Stop Local Compliance Support
As the US FDA, EU MDR, the CRA and Taiwan's TFDA keep raising cybersecurity requirements, SV Surveillance and Applus+ Laboratories build a Taiwan security lab to help medical device makers clear security verification.

CIO Magazine, July 2026 | Interview: Shih Hsin-tse; Text: Lin Yu-yang
As smart healthcare spreads and connected medical devices become mainstream, the attack surface of medical cybersecurity has widened and incidents have multiplied. USB interfaces — widely used for medical data transfer protocols, software updates and external connections — have become a prime target for malicious attacks and fuzzing. User-plane data and control commands exchanged between devices and computers over Bluetooth (BLE), Wi-Fi or LTE are easy prey for man-in-the-middle attacks, data theft and tampering unless protected with end-to-end encryption.
Medical device software also relies heavily on open-source third-party components (such as Apache Log4j); a single zero-day can expose a manufacturer's cloud assets and hospital network systems to serious threats. Health regulators worldwide have therefore moved from passive guidance to mandatory legislation — the US FDA, the EU and Taiwan's TFDA among them.
Vincent Huang, CEO of Secure Vectors Surveillance (SV Surveillance), points out that financial security incidents cost money or leak data, but medical security incidents touch human life: if an insulin pump or RF therapy system running in an ICU suffers a man-in-the-middle attack, dosages or device parameters can be maliciously altered — clinically enough to cause shock or death. SV Surveillance's cybersecurity laboratory has now joined forces with Spain's Applus+ Laboratories to build a “Taiwan security lab” combining local service with top international credibility, helping Taiwan's medical device makers clear security verification and compete for global business.
Global medical security regulation tightens; the era of one-time certification ends
The US leads medical security legislation: since Congress passed Section 524B, premarket submissions lacking a complete cybersecurity management plan, an SBOM and evidence of ongoing vulnerability monitoring and remediation face outright Refuse-to-Accept (RTA) rejection before substantive review. The EU's MDR mandates the information-security and software-lifecycle provisions of the General Safety and Performance Requirements (GSPR), with the Cyber Resilience Act moving to full implementation in September 2026. Taiwan's TFDA has followed with cybersecurity review guidance for connected and software medical devices.
The familiar “certify once, comply forever” model is over, replaced by dynamic compliance: premarket review, continuous post-market surveillance (PMS), vulnerability remediation and time-bound reporting. Many manufacturers try to handle security testing in-house through IT or R&D teams — and usually fall short of the regulatory bar.
The gap between in-house work and a professional third-party lab is vast, Huang explains. In penetration testing, product teams have blind spots, while lab engineers simulate intrusions from a hacker's perspective across hardware, chips, network and application layers, firmware, APIs, apps and back-end cloud. Fuzz testing demands frameworks and automation environments too costly for a typical development team to build. Firmware reverse analysis requires physically de-capping chips and MCUs and bypassing read-out protection (such as STM32's RDP) — deep hardware reverse-engineering expertise. This is why the FDA and EU Notified Bodies strongly prefer security assessments issued by independent third-party laboratories.
SV Surveillance and Applus+ Laboratories build Taiwan's medical device security verification platform
Applus+ Laboratories of Spain is a testing, inspection and certification company spanning automotive, aerospace, energy and infrastructure, ensuring corporate assets and products meet environmental, quality and safety regulation. With security risk growing exponentially and everything from surgical instruments to diagnostics and implantables now connected, the US FDA, the EU, China's NMPA and Taiwan's TFDA have all introduced mandatory security review standards.
The AI boom brings a new twist: both manufacturers preparing submissions and regulators reviewing them now lean on AI tools. Without strict environment isolation and data control, AI “hallucinations” can plant another product's data into a clinical study report — errors the FDA then finds in quantity. The EU's AI Act has led the response, and standards such as ISO 42001 now require provenance and risk assessment for AI models.
“Twenty years ago security compliance was concentrated in finance and payments. In the past five years it has spread across every connected-device industry. That is why we chose this moment to enter the Taiwan market,” explains Josep Prat, General Manager for Asia at Applus+ Laboratories. “Working with SV Surveillance's cybersecurity lab, Taiwanese device makers can run compliance testing locally — sparing the tedious process and heavy time cost of shipping products to Europe.”
From gap assessment to market launch: one-stop international compliance support
Under fast-iterating regulation, manufacturers face pointed security questioning at review. The Taiwan security lab offers a cross-border one-stop solution with three core strengths.
First, it connects to Applus+ Laboratories' global network of more than 200 security experts in automotive, payments, chip hardware, communications cryptography and medical devices, providing the deepest testing support against international cryptographic standards and black-box/white-box security testing. Second, the group directly holds dual EU MDR Notified Body certificates (NB 2764 / NB 3121): once SV Surveillance's lab completes technical documentation review and testing locally, the security assessment feeds straight into the dual NBs' conformity assessment, sharply cutting cross-border communication and regulatory translation time.
Third is full-lifecycle remediation support: security architecture consulting at the SRS/SDD stage, threat modeling and SBOM generation mid-project, premarket technical testing, and — if an additional-information request arrives — compliance gap remediation and supplementary testing. Huang notes that many manufacturers only engage a security lab after receiving an FDA additional-information request or an EU NB finding with a 30-day deadline; by then, changes to underlying architecture or security controls often derail the launch schedule. One-stop service helps absorb remediation demands without losing the timeline.
Security by Design becomes the new standard
As medical devices enter the cyber-device era, the real challenge is not a few extra security tests — the whole development process must change. Newcomers often assume a post-development penetration test or vulnerability scan satisfies regulators; current international law instead demands a complete security management mechanism across design, development, verification, launch and operations, with security built in from the earliest design phase.
From requirements definition onward, companies must weigh connectivity, personal-data exposure, potential attack surfaces, and whether an attack could endanger patients. “Take a smart connected blood-pressure monitor: beyond the hardware there is firmware, a mobile app, a cloud platform, a back-end database, possibly an AI analytics service. Testing the device alone cannot confirm the system is safe,” Huang explains. “You must start from the whole architecture — data flows, privilege management and communications between components — then use threat modeling to find the attackable links. Only then is the protection complete.”
Integrating ISO, SBOM and risk management into a secure development process
Medical device security design integrates multiple international standards rather than following one law: ISO 13485 for quality management, IEC 62304 for the medical software lifecycle, IEC 81001-5-1 for building security into software development, and ISO 14971 for assessing security risk together with clinical risk. Risk management is the core concept: a man-in-the-middle attack on Bluetooth can feed physicians wrong information and lead to misdiagnosis and mistreatment. Companies must therefore link security threats to clinical risk and design proportionate controls — encryption, mutual authentication, digital signatures, replay protection and anomaly detection.
Supply-chain security has become a regulatory focus as well. The SBOM — the software world's bill of materials — records every component, third-party library, open-source package, dependency and version in a product. When a major vulnerability is disclosed globally, a company can immediately confirm exposure and begin remediation.
As regulation keeps evolving, competition in the medical device industry is shifting from features, performance and price to whether a company possesses complete secure-development capability. The contest ahead is not only who can build an innovative device, but who can build a development system that truly unifies quality management, software engineering, risk management and information security — turning security from a regulatory demand into product competitiveness.
The SV Surveillance website offers resources on medical device security compliance — learn more at www.securevectorlab.com. For training sessions and registration, visit the CRA, MDR & ISO 13485 training page; for an in-depth look at the CRA rules, see CRA Countdown: Compliance Guide for Taiwan ICT Manufacturers.