Security of medical cyber-physical systems

  • Viktoriia Semerenska Kharkiv National University of Radio Electronics Nauky Ave, 14, Kharkiv, Kharkiv Oblast, 61166 https://orcid.org/0009-0008-2955-3676
Keywords: cybersecurity, medical technologies, data protection, security of medical systems, IoMT vulnerabilities, hybrid threats, Cybersecurity Mesh Architecture

Abstract

Relevance. Medical cyber-physical systems (CPS), including IoMT devices for real-time monitoring, diagnostics, and therapy, have become integral to healthcare digitalization. The convergence of operational technology with traditional IT expands attack surfaces, making hospitals and telemedicine infrastructures attractive targets for cyber adversaries. Hybrid warfare further amplifies risks, as cyberattacks on medical networks may cause not only data breaches but also direct harm to patients and disruption of critical care.

Purpose. The research aims to classify and analyze the main types of threats and vulnerabilities affecting medical CPS in hybrid conflict environments, summarize existing protection strategies, and propose a framework for enhancing their cyber resilience through regulatory, organizational, and technological measures.

Research Methods. The study applies the PRISMA methodology to review publications indexed in Scopus, IEEE Xplore, and PubMed. Comparative and analytical methods were used to synthesize findings from recent incidents, including the WannaCry ransomware attack on the NHS, the SingHealth breach in Singapore, and other high-impact cases targeting healthcare data.

Results. The analysis revealed a dominance of ransomware, DDoS, and IoMT exploitation via insecure communication protocols and legacy software. Weak authentication, insufficient network segmentation, and human factor vulnerabilities remain key issues. Among effective countermeasures are multi-factor authentication, blockchain-based data integrity control, end-to-end encryption, and Cybersecurity Mesh Architecture (CSMA). The study highlights the importance of applying quantum-resistant cryptography and AI-driven adaptive defense systems capable of autonomous detection and response in dynamic threat environments.

Conclusions. Despite advances in medical device security, the resilience of CPS in hybrid threat contexts remains insufficient. Ensuring security-by-design, strengthening compliance with international cybersecurity standards (such as ISO/IEC 80001 and IEC 62443), and developing specialized cybersecurity training for medical personnel are critical steps. The integration of AI-based situational awareness, regulatory harmonization, and public-private cooperation will significantly enhance the sustainability and trustworthiness of digital healthcare ecosystems.

Downloads

Download data is not yet available.

Author Biography

Viktoriia Semerenska, Kharkiv National University of Radio Electronics Nauky Ave, 14, Kharkiv, Kharkiv Oblast, 61166

PhD student

References

/

References

Published
2025-06-30
How to Cite
Semerenska, V. (2025). Security of medical cyber-physical systems. Bulletin of V.N. Karazin Kharkiv National University, Series «Mathematical Modeling. Information Technology. Automated Control Systems», 66, 63-72. https://doi.org/10.26565/2304-6201-2025-66-06
Section
Статті