MEC Veradigm 8.26
News|Articles|August 12, 2026

New security platform detects cyberattacks from inside connected medical devices

Author(s)Todd Shryock
Fact checked by: Chris Mazzolini
Listen
0:00 / 0:00

Key Takeaways

  • RDAi deploys a lightweight agent within each device to perform Instruction Set Integrity Monitoring, detecting unauthorized changes to instruction sets and static artifacts like configuration files.
  • Deterministic evidence and high-confidence alerts are intended to shorten response cycles as AI-driven attack velocity increases and SOC tooling increasingly incorporates autonomous agents.
SHOW MORE

Crytica Security's RDAi system installs a sub-100 KB software "Probe" inside each device to monitor for unauthorized changes, aiming to catch tampering that network-based tools alone can miss.

Crytica Security has introduced a device-level cybersecurity platform designed to detect unauthorized changes to a device's instruction sets from the inside, rather than relying solely on network monitoring that observes activity from the outside. The company says the patented approach targets a gap in operational technology security — the embedded and connected devices that underpin critical infrastructure, national security and health care.

The platform, called Rapid Detection, Alert and isolation (RDAi™), works by installing a lightweight software agent, which Crytica calls a "Probe" because it is less than 100 KB, inside each protected device. The Probe performs what the company calls Instruction Set Integrity Monitoring, continuously checking whether a device's instruction sets and other static data, such as configuration files, have been altered without authorization. When it detects a change, it generates what Crytica describes as deterministic, high-confidence evidence that can be acted on quickly.

The company frames the launch against a security landscape it says is shifting toward machine speed. IBM's Cost of a Data Breach Report 2026 found that AI-driven cyberattacks increased 56% year over year, while half of organizations with security operations centers have already deployed AI agents in production, according to the release. As both attackers and defenders increasingly rely on automation, Crytica argues that the underlying trustworthiness of a device's security signal becomes more important, not less.

"Cybersecurity has become extraordinarily good at observing what is happening around and external to a device, but ultimately, for detection to be truly effective, it must take place inside of each device itself," C. Kerry Nemovicher, CEO and co-founder of Crytica Security, said in a statement. "If an attacker changes a device's instruction set and/or any of the other 'static' data, such as configuration files, it is imperative that the appropriate alerts be generated."

Crytica positions RDAi as a complement to, rather than a replacement for, the security tools organizations already have in place. The company says the platform's alerts are designed to feed into existing SOC, security information and event management and XDR workflows, including those increasingly assisted by AI, without requiring a rip-and-replace of current cybersecurity investments.

C. Lloyd Mahaffey, executive chairman and co-founder of Crytica Security, said the company sees a broader industry shift taking shape around this type of detection. "What we're seeing now is an ecosystem forming around deterministic detection and Crytica is at the vanguard of that effort," Mahaffey said in a statement. "Customers and technology partners aren't looking to replace the security investments they already have. They are seeking technologies that can help detect malware and performance anomalies faster." He added that additional partnerships across security platforms, original equipment manufacturers and critical infrastructure sectors are expected to be announced in the coming weeks.

For health care specifically, the company argues the distinction between external and internal detection carries added weight because compromised devices can affect physical operations and patient safety, not just data confidentiality. Crytica says it is applying the technology across commercial, utility and federal environments, supported by a growing network of security technology providers, OEMs, systems integrators and channel partners.

The launch arrives as connected medical devices remain a persistent entry point for attackers. Many of the devices used daily in clinical settings, including infusion pumps, monitoring equipment and imaging systems, run on older or unsupported software that was never designed with modern threats in mind, and practices often lack full visibility into which connected devices sit on their networks in the first place. That visibility gap has pushed vendors, providers and researchers toward approaches that assume a device could already be compromised rather than relying only on perimeter defenses to keep threats out — a shift that mirrors the "zero trust" thinking that has gained traction elsewhere in health care IT. Regulatory pressure has reinforced the trend: the FDA has required that connected medical devices meet baseline cybersecurity guidelines since 2023, but manufacturers and health care organizations continue to share responsibility for closing gaps in aging equipment that predates those rules. Whether device-level monitoring tools like RDAi gain traction in clinical settings specifically may depend on how well they integrate with the vendor-management and IT resource constraints many practices already face.