The exposure is nearly universal
Claroty's healthcare exposure research found that 99% of healthcare organizations have devices carrying known-exploited vulnerabilities, and that 89% run connected medical systems that both carry ransomware-linked flaws and are insecurely connected to the internet, as summarized in industry coverage. Put plainly: the gap isn't an edge case — it's the norm.
The device-level picture is just as stark. Reporting on 2025 IoMT data cited an average of 6.2 vulnerabilities per device, around 60% of devices running end-of-life software with no patches available, and imaging systems — X-ray, CT, MRI — standing out as the riskiest category, with a large share carrying known-exploited vulnerabilities.
Why conventional tools can't close it
The core problem is structural. Endpoint detection and response works by installing an agent on a device. But a huge share of clinical technology cannot host one — the operating systems are closed, unsupported, or certified in a fixed configuration that a hospital cannot modify without voiding the device's regulatory clearance. So the very devices with the most vulnerabilities are the ones EDR structurally cannot reach.
Attackers understand this asymmetry. Roughly 22% of healthcare organizations reported at least one cyberattack targeting medical devices, and ransomware crews increasingly use these unmonitored devices as an entry point and a place to lurk, precisely because conventional tooling is blind to them.
Protecting what you can't put an agent on
If you cannot secure the device from the inside, you secure it from the network. Immune protects connected medical devices at the network boundary — watching their traffic, detecting the behaviors that precede and accompany an attack, and quarantining a compromised device at the network layer rather than shutting it down. That distinction matters in a hospital: you can cut an attacker off from a compromised infusion pump without cutting off the patient depending on it.
It's the piece the rest of the stack leaves open. Endpoint tools guard the managed computers; Immune covers the agentless devices that make up the majority of a hospital's real attack surface.
Sources
- Claroty coverage — 89% run exploitable medical systems
- Infosecurity Magazine — Claroty healthcare IoMT report
- CrowdStrike — What is IoMT security?
- Deepstrike — IoMT vulnerabilities statistics 2025
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
