Back to portfolio

Case study · 02 · Risk & security

Medical Devices Risk Assessment

A structured information security risk assessment of a simulated medical-device company, built on the NIST Cybersecurity Framework — 108 controls reviewed, every risk scored by impact and likelihood, and each gap paired with a costed fix.

What I did

Score every control, fix every gap.

The goal was to give a medical-device organization a complete, defensible picture of its security risk: not just a list of weaknesses, but a scored, prioritized view of where the danger actually is and what each fix would cost.

  • Completed a full information security risk assessment for MedTech Dynamics, a simulated medical-device company, structured entirely around the NIST Cybersecurity Framework.
  • Reviewed 108 controls across all five NIST CSF functions — Identify, Protect, Detect, Respond, and Recover — working through control questions, respondent answers, and documentary evidence for each.
  • Identified the vulnerabilities behind each control and the threat events that could exploit them, along with any compensating controls already in place.
  • Scored every applicable control on an impact × likelihood scale and flagged the 16 controls that exceeded the risk threshold.
  • Paired every flagged control with a specific recommendation, including estimated labor hours and implementation cost.

How the assessment worked

Five steps from framework to fix.

The NIST Cybersecurity Framework gave the assessment its structure; the scoring model gave its results their priority order.

01

Map the framework

Worked through the NIST CSF control catalog function by function — Identify, Protect, Detect, Respond, Recover — turning each control statement into concrete questions for the client.

02

Gather responses and evidence

Recorded each control's respondent answers, documentary evidence, and assessor comments — from how physical assets are prioritized to how remote access is managed.

03

Analyze vulnerabilities and threats

Documented the vulnerability behind every control and the threat event that could exploit it — phishing, unauthorized access, mishandled sensitive information — plus compensating controls already in place.

04

Score the risk

Rated impact and likelihood (low, medium, high) for each control and converted them into a 1–100 risk score. Anything scoring above 1 required a documented recommendation.

05

Recommend and cost the fixes

Wrote practical remediation for all 16 flagged controls with estimated labor hours and dollar cost, so the client could prioritize by risk and budget.

Key risks & recommendations

Highest risk first, every risk costed.

Sixteen controls scored above the risk threshold. These are the highest-scoring risks, each with the recommendation and cost estimate documented in the assessment matrix.

Detection alerts go uninvestigated

Risk 100

Notifications from detection systems were not reliably investigated — a targeted attack or malware event could land without anyone acting on the alert. Recommendation: implement a robust detection and anti-malware system.

Outdated vulnerability scanning

Risk 100

Vulnerability scanning systems were not kept updated, upgraded, or regularly verified, so scans could miss current threats or fail silently. Recommendation: update and upgrade the scanning systems and check on them routinely.

Credential and device management

Risk 50

How identities and credentials were issued, verified, revoked, and audited left room for integrity loss on accessible systems. Recommendation: performance reviews for the responsible owner and a device database that is constantly kept current.

System development life cycle

Risk 50

The SDLC used to manage systems created a path to unauthorized access through unpatched software. Recommendation: keep software updated and monitor the systems continuously.

Incident response capacity

Risk 50

Executing the response plan depended on how capable each individual was — a thin bench slowed response and recovery. Recommendation: add personnel sized to the team's capability to shorten response and recovery time.

Configuration change control

Risk 25

Communication about how system updates were performed was unclear — a change done incorrectly could cause problems. Recommendation: document the update process and communicate it across teams.

What the assessment showed: the fundamentals held

Most controls scored at the lowest risk level — physical access management, data-at-rest and data-in-transit protection, least-privilege access, security awareness training, and remote access were all in reasonable shape. The gaps concentrated where medical-device organizations often struggle: detection, response, and disciplined change management.

Client

MedTech Dynamics · Simulated medical-device company

Assessment

Information security risk assessment · CYRB 490-50 class project

Framework

NIST Cybersecurity Framework · Impact × likelihood risk scoring

Deliverable

108-control scored matrix · 16 costed recommendations · October 2023

Skills applied

NIST CSFRisk assessmentControl analysisVulnerability identificationThreat analysisImpact & likelihood scoringRemediation planningCost estimation

Want the full picture?

This risk assessment sits alongside my hands-on security testing and systems work.