The Column – Cyber Security Week
For years I have maintained that what happens beyond the screen increasingly produces consequences on this side:
Boston Scientific on August 25th. large US multinational that produces medical devices and biomedical equipment, notified the SEC of a cyber incident that resulted in a global shutdown of operations, limiting access to systems that also support order manufacturing, processing and shipping. We don’t know what the vector of the attack was or even who was behind it. Better this way: at least we can avoid the usual exercise of creative attribution and focus on the most interesting part, that is, on the consequences.
The most sensational one concerned the United Kingdom where the NHS Supply Chain, a public organization that manages the purchasing, logistics and distribution of healthcare and food products for the National Health Service (NHS) in England and Wales, set up a Major Incident Team together with the national healthcare facilities. In the September 4 update, shipping of most of the products already available in European distribution centers had resumed, but production had not yet restarted and there remained a backlog of orders to clear. An emergency channel has been activated for procedures scheduled for the next 48 hours and, in the meantime, the NHS is identifying alternative products.
At that point the problem finally stopped seeming “IT-related”. When you need a dedicated number to understand if a product needed for a medical procedure will arrive on time, bits have entered the physical world.
Then there is a second even more instructive detail. Boston Scientific clarified that the implanted cardiac devices that are already operational nor the remote monitoring already activated are not compromised. However, the accident temporarily prevented the activation of remote monitoring for some new systems: data continues to be recorded, but in certain situations it cannot be transmitted until some systems functionality is restored.
It is therefore useless to imagine someone intent on “hacking a pacemaker”, a perfect image for a television series and much less useful for understanding the problem. Just make whatever makes, orders, ships, activates or supports that device unavailable.
The story is exemplary. In recent years we have built a long digital chain between management systems, production, logistics, portals, hospitals and devices. As long as everything works, this integration is called efficiency: less friction, less waiting, less inventory, more speed, then a link gets blocked and we discover that what we called optimization was also addiction.
Cybersecurity, then, can no longer be described only as the discipline that prevents someone from entering systems or stealing data. Of course, it must continue to do that too, but today it must above all protect the organization’s ability to remain operational when part of its digital infrastructure is unavailable.
It means foreseeing degraded methods, alternatives, redundancies, emergency procedures and accepting that not everything can be optimized down to the last second and the last supply. Every margin eliminated in the name of efficiency can be transformed, in the event of an accident, into a margin that we would have liked to have.
The lesson is precisely here. Cyber enters healthcare through a side door and does not necessarily have to hit the operating room: it just needs to stop the system that gets what is needed into the operating room. We have digitized processes that we considered ancillary until the day we discovered that they had become indispensable.
Security tries to prevent digital from stopping; resilience decides how much the real world will stop with it and, this resilience seems to have an absolute need for a bit of healthy inefficiency.



