Jörn Lubadel, B. Braun Group | DigiCert Trust Summit
Jörn Lubadel, the global product security officer for the B. Braun Group, discusses the challenges of securing medical devices in an era of increasing connectivity and potential threats. The conversation touches on the evolving landscape of medical device security, emphasizing the critical intersection of IT security and patient safety. Jörn addresses the concerns related to emerging technologies such as AI and quantum computing, emphasizing the need for a proactive approach to security in the design phase.
Transcript
This is Textron tv. Hey everyone. We're back here live at, uh, Las Vegas DigiCert Trust Conference.
We are, uh, continuing our full day of coverage with some great conversations, great people we're meeting. I want to introduce you to our next guest. His name is Jorn Vidal.
Jorn is with the B period Braun Company, which is a medical device company. Let me just tell you don't fall into this chapter. These are not the people who make brawn shavers and, and that kind of thing.
Or, or, or, uh, appliances and e-bike kind of stuff. B BRA is one of the oldest, and it's, I think, the largest privately held medical device manufacturer in the world, correct? That's Correct, yes.
I listen and I listen. So, Jorn, why don't you, first of all, thank you for being here. My pleasure.
But, um, what do you do at bbr? So, I'm the global Product security officer, and, um, my job is with my team to put the right guard rails in place to secure all our products. So we have to centralized on purpose so that all our products receive the same, um, security standard.
And it is, um, just part of our philosophy to, you know, provide high quality products in the future. So we want to go ahead a little bit. Absolutely.
So, you know, we're, we're at an interesting place in terms of medical device security and, and it, it really is such a shame because at a time when we, we don't have to prick our fingers with pins to do our blood sugar correct. For so many people who are diabetic or pre-diabetic at a time when pacemakers and, and other implantable devices can help with heart, congestive heart failure and arrhythmia and stuff like that. Um, at a time where we have such promise of medical breakthroughs of technology helping us live better if and longer, we gotta worry about evil people.
And I, and I say the word evil to me, they are evil, right? Yep. Uh, but they're just evil people.
And I, you know, what, what is the, like, what's the motivation to mess someone's pacemaker up or something? I mean, you know, it's, it's crazy, but you have to worry about this. Yeah, that's correct.
I mean, I currently don't think that really an attacker will go to a medical device because this is still kind of very difficult and it's probably not so attractive. However, everything is connected, as you said. Uh, it can be your diabetes measuring, you know, get you the right data in your device, and, you know, okay, I need to eat something because my blood sugar is either to, to low or to high, whatever.
Same in our business, you know, we, we have a connected device which sends and receives data for, for all kinds of purposes. And imagine that somebody manipulates this data could have an, a huge implication on safety. And that's our biggest concern.
People don't understand that our industry, it security is connected to patient safety. And that's why our efforts are extremely high to protect us, because number one, it's always the patient. And last but not least, you have to think about healthcare is provided where the patient is.
This is something I always try to explain to people. It's not only the hospital, it can be at home, right? Absolutely.
It can be somewhere else. Uh, it can be, you know, in ambulatory care, which is good, and it's good for, you know, treating people. We have in Germany situations where we have home dialysis, very nice people with kidney disease can stay home, get the dialysis at home.
What a big advantage. But now we have to ensure the device is always working, the data are correct, everything is, is as it should be, and somebody can help them from abroad. So remote service, remote access, and all this has to be secured.
And after c Ovid 19, it even becomes more and more important because remote telemedicine, all this kind of things, uh, comes to the plate. So we have a huge shop in front of us, a huge shop. Yeah.
And, and I, I, you know, I don't wanna be pessimistic, you know, a downer, but the, the fact is with a lot of the new technologies that are coming out, the potential for them to be misused makes them probably a threat, a greater threat that you've dealt with. Absolutely. To this point.
I mean, think about ai. Um, AI is, for me, always the best example. AI can be used in the right way, can be, it's, is the algorithm and good or whatever.
And it might be possible to prevent diseases because this is our goal, our goal is less, you know, to, you know, of course we wanna treat patients well and you know, they get all the help, they need it, but the data are very helpful to prevent even diseases. So as such, AI can be helpful, you know, to determine what is the best way to, you know, help patients in the future. What is the best therapy, how products interact with these are, on the same token, the bad actors may abuse exactly this to do in, in the wrong things.
So AI can be also abused. And I totally agree with you. And when you look into further down the road, which is not really a topic yet for us, for us, uh, about PQC, you know, quantum computing, um, makes it even more challenging.
Right. You know, we have computers, they can, you know, go into an encryption where you thought a couple of years ago, it takes a hundred years to break it, and now they have this high-end machines, and they can do it in just whatever, minutes, hours or whatever the time is. Yeah.
So I agree with you. I mean, new technology is always good, uh, but, you know, doing the right things around and also consider security always from the beginning. So design is not only, you know, have function that is also that the security is built in from the beginning.
Yeah. You know, I, I had a good friend of mine who unfortunately passed away. Um, he, he, he ran a medical security company and he, he told me something once and it stuck with me.
One of the issues is almost every hospital clinic has like three different networks. There's the regular IT network that every office has. Then there's that medical device network where things like infusion pumps, which is, you know, the bread and butter, it'd be bronc, correct?
Yeah. Infusion pumps, CAT scans, MRIs, dialysis, everything that's connected, they kind of run on their own network, right? It's kind of, it's almost like an IOT network Mm-Hmm.
If you will, um, separate from that regular IT network, and then there's like a third network for the doctors who think, you know, that they're God, they make their own rules and and they don't, you don't want them on the network that the fusion pump is on. Yes. And that is such a, a challenge to, to providing good security at, at a hospital or something.
Then you get a company that wants to ransomware, right? And, and, and it doesn't have to necessarily be ransomware and start in terms of stealing the data. They're gonna DDoS Mm-Hmm.
The, the hospital or whatever. Okay. If they don't get paid money or whatever.
Um, it, it was always a hard job, and it just seems to be getting harder. I guess my, my question to you, yarn is you're here, right? You've come all the way here to Las Vegas.
What have you learned that give us a little upside, a little sunshine, right? What have you learned that makes you fake? You know what, we could do this Well, um, I mean, when we talk here is digital trust, right?
And, and everything you talk is completely right. So the hospital is, you know, a very diverse environment, uh, with all kinds of things. And that means also you have all kinds of different attack vectors in this hospital.
Futurewise thinking about IOT cloud computing that will remove all these things to a certain extent, but it requires that we build the right trust and trust can be done through certificates, through whatever technology. That makes me very confident. Uh, as well as that the industry started also working together to develop the right standards.
You know, as I said, design from the, uh, security as a design position, not as a, oh, we have to do this. It is just mandatory to do it. Um, and I would encourage people really to think about, you know, thinking about cloud computing more than on-premise.
Let the hospitals, let the caregivers being focused on their core competence and let people with the knowledge do the right things. And, and, you know, and I believe, is it always solvable? I'm pretty sure, yes, we can solve it to a certain extent will be, will be a hundred percent security.
Never. You have still the human social engineer will remain. Uh, but you have to prepare this.
That's the other message I always have. Don't sit down and think, you know, your technology will solve everything. You still have to work, you still, still have to prepare yourself for the worst.
And this fire drill plan should be in place all the time. Absolutely. And that's, look, that's security 1 0 1.
It's about managing risk, right? And then number two, you've gotta have a response plan, not just a prevention plan. Right?
And then that's what kind of the heart of what you're talking about. Um, I'm gonna imagine that most of the devices and stuff that you manufacture have some sort of digital certificates involved in them that allow you to fingerprint them, if you will. Yes.
I mean, that's a mandatory, um, um, table Mistakes. That is what we call foundation. Mm-Hmm.
Uh, foundation is really, you know, building identity, having integrity software assigned so you can ensure that, or the device knows that this software comes from a, from a known trusted source. And as such, this is very important to implement this. We have, uh, also introduced PGI, uh, for medical devices, uh, in our, for our, um, portfolio.
And I know others in the industry do the same thing. I mean, people are really trying to do the right things at as such, um, you know, to protect with at least the minimum standard, which is required. However, I must admit, in the medical device, something is always in front, and that's the purpose of the device.
So you really have to balance all the time, um, what you do in, in terms of does it influence the purpose of the device? Is the performance still the same? And you, you mentioned wrist.
So we do everything risk based. So we assess the wrist, we have techniques like threat modeling and, and look into the, the real situation. And not only on the product, we look entirely to the entire, what we call the ecosystem.
So everything which is around this device must be, must be reviewed. And to your point, going back to your hospital, um, description in, in this environment is even their network is part of our, uh, threat model review and our risk assessment. Sure.
Right. Well, you have to and you have to and, and, and you know, as I said, my friend was in, in the healthcare security space, and that that's the reality of that space. That's the Reality.
Absolutely. Yeah. Absolutely.
What else can we share from today with our audience? Uh, first and foremost, what I really liked was, um, I see a lot of technology coming to solve the problem that is very encouraging. And I also see that people get away from the idea, it's always a threat.
They see the op opportunities. And this is also good because quite honestly, in in a business, a business is a business. People want to sell their products and need to sell the products.
And if you always come in and have threats, it's difficult to convince people. But if you see also value for everybody, I think that was one of the key message I really loved. And, and the other thing is really working with other industry leaders, understanding how they solve problems.
That is very refreshing for me because it always give me a signal, look, there is a possibility to solve it. Um, yeah, just talk to others. So networking is more and more important.
This is the right place here, to be honest. It is a very, well, uh, I say the setup is really well designed and, um, has the right people also at the right competition. It's Also nice to be in person again.
Oh, that is really great. I mean, yeah, even in this country, I mean, as I said, I I, I used to live here in the United States as a German. I always like to go back.
This is my second home, basically. Um, and I love this country very much. Um, even I live in Texas and some people look, oh, how can you live in Texas?
And like it Well, it is a great state. I can tell you this. And you all, you all will love it.
You are Exactly. Yeah. No, perfect, uh, setup.
I really, um, I think it was worse to spend the two days here and, and, and, Yeah. No, I, it was a great, great thing, your Honor, I want to thank you for coming on today. Thank you.
Keep up the great work of, be broad and keep us posted. Absolutely. Thank you.
Thanks for having me. It's a pleasure. Pleasure.
Thank you. All right, We're gonna take a break. I think we have maybe one, maybe one more person.
I'm not sure. Two. And we will go from there.
We'll be back in a minute here. We're live in Vegas for DigiCert Trust. I.





