Explore more publications!

New Asimily Survey Reveals Hospital CISOs Struggling to See and Secure Complex, Network-Connected Medical Devices

43% of hospital security leaders name IoMT visibility as their top cybersecurity challenge right now, while internal process issues create the biggest obstacle to effective risk management

SUNNYVALE, Calif., Dec. 18, 2025 (GLOBE NEWSWIRE) -- Asimily, the only complete IoT, OT, and IoMT risk mitigation platform, today released “The State of Cyber Asset Exposure Management in 2025,” a new survey report examining the biggest challenges hospital CISOs face in securing connected medical devices and equipment. The findings show that persistent visibility gaps and internal process breakdowns are leaving hospitals exposed to operational disruption and patient care risk.

The survey of North American hospital CISOs found that 43% identified complete device visibility as the challenge they would most want to solve immediately, followed by ransomware threat detection (24%) and compliance automation (22%). When asked about their biggest barriers to effective IoMT device risk management, one-third pointed to internal process issues, closely followed by lack of visibility (30%) and data overload (20%).

The data also uncovered fragmentation in how hospital security teams approach vulnerability remediation. Only 22% of hospital CISOs base their prioritization on device usage and criticality, which is the most effective method for focusing resources on the highest-risk assets. Meanwhile, 18% rely on manual review and 15% report having no clear process at all for addressing IoMT vulnerabilities.

“Hospital CISOs are challenged with protecting many thousands of network-connected devices while navigating organizational silos, data overload, budget constraints, and ensuring patient care isn’t disrupted,” said Shankar Somasundaram, CEO, Asimily. “This survey reinforces that visibility is the critical first step, but it has to be paired with the ability to prioritize and act on what you find. Hospital cybersecurity leadership needs strategies that can connect the dots between device discovery, risk prioritization, and remediation (including segmentation), while also working across the clinical engineering, IT, and security teams that share responsibility for these patient-critical systems.”

Based on the survey findings, Asimily recommends healthcare delivery organizations take the following steps to strengthen their cyber asset exposure management programs:

  • Unify visibility across all asset types. Adopt platforms that provide a single view of IT, IoT, IoMT, and OT devices to eliminate blind spots and enable holistic risk assessment.
  • Prioritize vulnerabilities by device criticality and usage. Move beyond CVSS scores alone by factoring in which devices are most essential to patient care and whether network segmentation already mitigates certain risks.
  • Establish clear ownership and communication channels. Ensure collaboration between clinical engineering, health technology management, and procurement teams to define responsibilities and ensure security is informed whenever devices are added or modified.
  • Reduce data overload with context-aware filtering. Focus security dashboards on actionable signals rather than raw alerts to help resource-constrained teams concentrate on the highest-impact issues.
  • Leverage GRC capabilities to track configuration drift. Define policies for device configurations and monitor for unauthorized changes made by third-party technicians or other internal groups.

The full report, including additional insights into how hospital CISOs and other security/IT leaders manage exposure across all cyber assets, is available for download at https://asimily.com/state-of-iomt-cybersecurity-2025/ 

About Asimily

Asimily provides the only complete IoT, OT, and IoMT Risk Mitigation platform. It has the depth and breadth of capabilities to keep all devices secure, including visibility, vulnerability prioritization, risk mitigation, threat response, and Governance, Risk, and Compliance. By keeping devices safe and operational, the platform drives customers' revenue and cuts capital expenditures. Headquartered in Sunnyvale, California, Asimily is trusted globally by leading organizations across industries, including healthcare, manufacturing, and banking.
For more information on Asimily, visit https://www.asimily.com

Contact
Kyle Peterson
kyle@clementpeterson.com / Clement | Peterson

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/21c38aad-1cdf-44b7-b839-2598eb668bc0


Primary Logo

Report: The State of Cyber Asset Exposure Management

43% of hospital security leaders name IoMT visibility as their top cybersecurity challenge right now, while internal process issues create the biggest obstacle to effective risk management

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share us

on your social networks:
AGPs

Get the latest news on this topic.

SIGN UP FOR FREE TODAY

No Thanks

By signing to this email alert, you
agree to our Terms & Conditions