Case study · 02 · Risk & security
Medical Devices Risk Assessment
A structured information security risk assessment of a simulated medical-device company, built on the NIST Cybersecurity Framework — 108 controls reviewed, every risk scored by impact and likelihood, and each gap paired with a costed fix.
What I did
Score every control, fix every gap.
The goal was to give a medical-device organization a complete, defensible picture of its security risk: not just a list of weaknesses, but a scored, prioritized view of where the danger actually is and what each fix would cost.
- Completed a full information security risk assessment for MedTech Dynamics, a simulated medical-device company, structured entirely around the NIST Cybersecurity Framework.
- Reviewed 108 controls across all five NIST CSF functions — Identify, Protect, Detect, Respond, and Recover — working through control questions, respondent answers, and documentary evidence for each.
- Identified the vulnerabilities behind each control and the threat events that could exploit them, along with any compensating controls already in place.
- Scored every applicable control on an impact × likelihood scale and flagged the 16 controls that exceeded the risk threshold.
- Paired every flagged control with a specific recommendation, including estimated labor hours and implementation cost.
How the assessment worked
Five steps from framework to fix.
The NIST Cybersecurity Framework gave the assessment its structure; the scoring model gave its results their priority order.
Map the framework
Worked through the NIST CSF control catalog function by function — Identify, Protect, Detect, Respond, Recover — turning each control statement into concrete questions for the client.
Gather responses and evidence
Recorded each control's respondent answers, documentary evidence, and assessor comments — from how physical assets are prioritized to how remote access is managed.
Analyze vulnerabilities and threats
Documented the vulnerability behind every control and the threat event that could exploit it — phishing, unauthorized access, mishandled sensitive information — plus compensating controls already in place.
Score the risk
Rated impact and likelihood (low, medium, high) for each control and converted them into a 1–100 risk score. Anything scoring above 1 required a documented recommendation.
Recommend and cost the fixes
Wrote practical remediation for all 16 flagged controls with estimated labor hours and dollar cost, so the client could prioritize by risk and budget.
Key risks & recommendations
Highest risk first, every risk costed.
Sixteen controls scored above the risk threshold. These are the highest-scoring risks, each with the recommendation and cost estimate documented in the assessment matrix.
Detection alerts go uninvestigated
Risk 100Notifications from detection systems were not reliably investigated — a targeted attack or malware event could land without anyone acting on the alert. Recommendation: implement a robust detection and anti-malware system.
Outdated vulnerability scanning
Risk 100Vulnerability scanning systems were not kept updated, upgraded, or regularly verified, so scans could miss current threats or fail silently. Recommendation: update and upgrade the scanning systems and check on them routinely.
Credential and device management
Risk 50How identities and credentials were issued, verified, revoked, and audited left room for integrity loss on accessible systems. Recommendation: performance reviews for the responsible owner and a device database that is constantly kept current.
System development life cycle
Risk 50The SDLC used to manage systems created a path to unauthorized access through unpatched software. Recommendation: keep software updated and monitor the systems continuously.
Incident response capacity
Risk 50Executing the response plan depended on how capable each individual was — a thin bench slowed response and recovery. Recommendation: add personnel sized to the team's capability to shorten response and recovery time.
Configuration change control
Risk 25Communication about how system updates were performed was unclear — a change done incorrectly could cause problems. Recommendation: document the update process and communicate it across teams.
What the assessment showed: the fundamentals held
Most controls scored at the lowest risk level — physical access management, data-at-rest and data-in-transit protection, least-privilege access, security awareness training, and remote access were all in reasonable shape. The gaps concentrated where medical-device organizations often struggle: detection, response, and disciplined change management.
Client
MedTech Dynamics · Simulated medical-device company
Assessment
Information security risk assessment · CYRB 490-50 class project
Framework
NIST Cybersecurity Framework · Impact × likelihood risk scoring
Deliverable
108-control scored matrix · 16 costed recommendations · October 2023
Skills applied
Want the full picture?