
New security platform detects cyberattacks from inside connected medical devices
Key Takeaways
- RDAi deploys a lightweight agent within each device to perform Instruction Set Integrity Monitoring, detecting unauthorized changes to instruction sets and static artifacts like configuration files.
- Deterministic evidence and high-confidence alerts are intended to shorten response cycles as AI-driven attack velocity increases and SOC tooling increasingly incorporates autonomous agents.
Crytica Security's RDAi system installs a sub-100 KB software "Probe" inside each device to monitor for unauthorized changes, aiming to catch tampering that network-based tools alone can miss.
Crytica Security has introduced a device-level cybersecurity platform designed to detect unauthorized changes to a device's instruction sets from the inside, rather than relying solely on network monitoring that observes activity from the outside. The company says the patented approach targets a gap in operational technology security — the embedded and connected devices that underpin critical infrastructure, national security and health care.
The platform, called Rapid Detection, Alert and isolation (RDAi™), works by installing a lightweight software agent, which Crytica calls a "Probe" because it is less than 100 KB, inside each protected device. The Probe performs what the company calls Instruction Set Integrity Monitoring, continuously checking whether a device's instruction sets and other static data, such as configuration files, have been altered without authorization. When it detects a change, it generates what Crytica describes as deterministic, high-confidence evidence that can be acted on quickly.
The company frames the launch against a security landscape it says is shifting toward machine speed. IBM's Cost of a Data Breach Report 2026 found that
"Cybersecurity has become extraordinarily good at observing what is happening around and external to a device, but ultimately, for detection to be truly effective, it must take place inside of each device itself," C. Kerry Nemovicher, CEO and co-founder of Crytica Security, said in a statement. "If an attacker changes a device's instruction set and/or any of the other 'static' data, such as configuration files, it is imperative that the appropriate alerts be generated."
Crytica positions RDAi as a complement to, rather than a replacement for, the security tools organizations already have in place. The company says the platform's alerts are designed to feed into existing SOC, security information and event management and XDR workflows, including those increasingly assisted by AI, without requiring a rip-and-replace of current cybersecurity investments.
C. Lloyd Mahaffey, executive chairman and co-founder of Crytica Security, said the company sees a broader industry shift taking shape around this type of detection. "What we're seeing now is an ecosystem forming around deterministic detection and Crytica is at the vanguard of that effort," Mahaffey said in a statement. "Customers and technology partners aren't looking to replace the security investments they already have. They are seeking technologies that can help detect malware and performance anomalies faster." He added that additional partnerships across security platforms, original equipment manufacturers and critical infrastructure sectors are expected to be announced in the coming weeks.
For health care specifically, the company argues the distinction between external and internal detection carries added weight because compromised devices can affect physical operations and patient safety, not just data confidentiality. Crytica says it is applying the technology across commercial, utility and federal environments, supported by a growing network of security technology providers, OEMs, systems integrators and channel partners.
The launch arrives as





