Skip to content
The Cyber Security Place

When the target is the production line, the patient waits

Event dated 18 March 2026 · Published 2 September 2026 · 3 sources

Among March 2026's incidents was a large attack on the medical technology manufacturer Stryker, linked by researchers to an Iran-aligned hacktivist group, alongside disruption at other manufacturers. The pattern reported across the month was a shift toward the systems organisations use to operate rather than the records they hold. That changes who carries the harm. A breach of patient records damages the people in the file. A stoppage at the company that makes surgical implants or infusion pumps reaches patients who appear in no file at all, through a hospital that was never attacked, weeks later, as a supply problem nobody labels a cyber incident.

Almost every mechanism built around security incidents assumes the injured party is a data subject. Notification obligations, regulatory fines, breach counters and class actions all start from the premise that somebody's information was exposed and that somebody should be told.

An attack on manufacturing produces no such person. Nobody's record was read. What happened is that a line stopped, and the consequence travels down a supply chain until it arrives somewhere unrelated as a shortage — a procedure rescheduled, a device unavailable, a substitute used instead of the preferred one.

The harm does not get counted

There is no register for this. Breach statistics count records exposed, and a production stoppage exposes none. The cost appears in the manufacturer's accounts as lost output and in the hospital's as a scheduling problem, and the two are never added together because nothing connects them in the reporting.

Which means the sector's own figures systematically understate this class of event. Not through any fault in the counting, but because the thing being counted was defined when the damage was assumed to be informational.

Why manufacturers are structurally exposed

Production systems are the clearest case of the constraint that makes operational technology hard: availability outranks everything, equipment has service lives measured in decades, and a maintenance window is negotiated against output rather than scheduled for a Sunday. A control that requires a restart is not a control that gets deployed.

The result is that the usual advice inverts. Patching promptly is frequently impossible. What remains available is separation — ensuring the path from an ordinary corporate machine to a production controller does not exist, so that a compromise of the first is not automatically a compromise of the second.

The question a hospital should be asking

Not whether its suppliers have been breached, which is unanswerable and mostly unactionable. Whether it knows which of its critical devices and consumables have a single manufacturer, and what the substitute is.

That is a procurement question rather than a security one, and it is the only preparation on this page that a hospital can complete without any cooperation from anybody. The organisations that answered it in March had a difficult month. The ones that had not discovered the dependency and the shortage on the same day.