THANK YOU FOR SUBSCRIBING



Medical devices are increasingly connected to the internet and hospital networks to improve the ability of healthcare providers to monitor and treat patients. The flip side is that they also introduce new cybersecurity risks. Just like any other computer system, these devices are vulnerable to security threats that could impact the device itself, its user, or the network environment. Given the fact that IoT security has historically not been able to meet the ecosystem standards, hackers are taking full advantage of their vulnerabilities.
To put things in perspective, here are a few data points from the latest FBI’s Private Industry Notification on the topic of medical devices:
● 53% of internet of medical things (IoMT) devices have known critical vulnerabilities
● 33% of healthcare IoT devices have an identified critical risk
● 40% of medical devices are at the end-of-life stage, offering little to no security patches
Acknowledging the above, over the last few years, regulators have been actively updating the cybersecurity standards for medical device manufacturers (MDR, the PATCH Act, and FDA guidelines), calling for a ‘secure by design’ approach, which ensures that devices are shipped with security features built in.

This brings IoMT device manufacturers to where “traditional” IT has been for years and creates an urgency to incorporate on-device security (XDR and RASP). Unfortunately, the solutions to cater to the need are missing, largely because of how technically difficult it is to bring such advanced security models to the diversified IoT ecosystem and because of the limited resources available on the device level. This is where Sternum comes in.
Working with leading medical device manufacturers, including Medtronics, Sternum’s team created a security platform that meets the unique requirements of IoMT devices and regulatory bodies. Using patented technology, it instruments any medical device’s operating system and firmware, as well as third-party binary libraries, to ensure security and deliver fullstack protection for known and unknown (zero-day) threats.
The on-device solution works at runtime, guaranteeing the integrity of memory and code execution, stopping nearly all IoMT exploits in their tracks. It also gathers real-time insights into the performance, health, and operation of connected devices to help detect gaps and other security exposures.
It uniquely works within the constraints of IoMT devices and their environment.
“For medical devices, just like in other industries, when it comes to product security, the buck stops with the device manufacturer,” says Igal Zeifman, VP of Marketing at Sternum. “Our technology helps medical device manufacturers ship high-quality and high-resilient products, offering an easy and cost-effective way to introduce security into the product, stay on top of the latest regulatory requirements and ensure patient safety.”
To deliver on this promise, Sternum offers several key capabilities. The first is embedded integrity verification (EIV). Acting as the core of Sternum’s security offering, this unique technology leverages binary instrumentation to deploy security “checkpoints” within the device code. With these, it detects all exploitation attempts by preventing all code and memory manipulations in runtime. The deterministic (RASP-like) nature of the solution is a natural fit for IoT/IoMT devices that—unlike more complex systems—are similarly deterministic in nature.
The second capability Sternum has to offer is a powerful XDR-like threat detection engine that augments the EIV deterministic protection with awareness of device and user activity, providing proactive alerts about security gaps, unwanted behaviors, and other suspicious activities.
The third is an observability layer offering real-time monitoring and visibility of the device to provide actionable insights beyond security threats. This capability improves preand post-market quality control and allows for much faster identification of the root cause of in-field performance or quality issues.
“The ability to contribute to security and incident response is rapidly becoming a critical component of procurement decision-making,” says Zeifman. “Sternum enables manufacturers to address this need, build tangible security into their products and ensure that their device will never become a point of compromise.”
Sternum’s outstanding work with some of the world’s largest medical device manufacturers proves it’s creating a new benchmark for IoMT security. The company’s extensive knowledge of embedded systems, combined perspectives of the defender and the attacker, and a desire to raise medical security standards constantly motivate it to develop uncompromising and highly-impact technology that drives real change.
Company
Sternum
Management
Natali Tshuva, Co-Founder & CEO, Sternum
Description
Sternum helps IoMT manufacturers ensure product safety, and meet regulations while reducing costs and risk of potential liabilities. Sternum’s outstanding work with the world's largest medical manufacturers, including Medtronic, proves that it is creating a new benchmark for IoMT security
The partnership enables Zephyr’s community of IoT developers and device manufacturers - including innovators like Google, Intel, and NXP - to easily take advantage of secure OS, advanced runtime protection and threat detection, and continuous device monitoring for RTOS-based, low-resource devices.
The increasing risk of cybersecurity threats for the growing global number of connected devices did not go unnoticed by government and regulatory bodies. The US government, the EU government, NIST, FDA, and more have recently underlined the need for more advanced security controls - not only for new products that enter the market but also for legacy devices already in the field.
These new regulations and growing customer needs are a wake-up call for IoT manufacturers - many of which still rely on constant reactive security patching, lacking the on-device resources needed to deploy proactive endpoint defenses (e.g., EPP or XDR) that are considered the norm in other IT sectors.
Sternum enables IoT manufacturers to address rapidly evolving customer demands and market needs with a full-stack platform built for universal support of all Linux and RTOS devices. The platform offers a full suite of security solutions for embedded devices:
• Agentless runtime protection: Embedded Identity Verification (EIV™) is Sternum’s patented low-footprint technology that deterministically prevents exploit attempts, known attacks, unpatched vulnerabilities, zero-day assaults, and software supply chain threats.
• Continuous Monitoring: Sternum provides device and fleet-level insights that raise the bar for IoT observability, offering product, security, and engineering teams ready access to live and historical data, anomaly detection capabilities, advanced log management, and tools for remote debugging and contextual root cause analysis.
• Threat Detection: Sternum introduces XDR-like capabilities that triage data from mitigated attacks with device-level telemetry and AI-based insights to alert about ongoing attacks, emerging threats, malicious behavior, security blindspots, and suspicious activities.
“Sternum’s platform is a valuable addition to Zephyr’s partner ecosystem,” said Kate Stewart, Vice President of Dependable Embedded Systems at the Linux Foundation. “Sternum’s runtime security model enhances Zephyr's built-in security features by providing embedded developers and device manufacturers with additional security and monitoring capabilities, which they can implement with minimal complexity and zero performance compromises.”
“Zephyr is already the platform of choice for some of our largest customers, allowing us a clear view of how it’s being used to power medical devices, payment devices, gateways, and industrial infrastructure,” says Natali Tshuva, CEO and Co-Founder of Sternum. “We see growing demand from device manufacturers for advanced security controls, post-market surveillance capabilities, and threat mitigation that go beyond perpetual security patching. Our built-in support for the Zephyr operating system and toolchains allows us to address these needs and offer an easy way to bring our patented technology to all Zephyr-based devices.”