Security1 publisher2 min readPublished
Post-quantum-ready SSH runs on 6% of the hospital IoMT devices Forescout analyzed
Forescout found post-quantum-capable SSH on 6% of IoMT and 16% of medical OT devices in a 2.5 million-device study of over 50 healthcare organizations. With long device lifecycles and few upgrade paths, hospitals are left planning around segmentation.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Traditional IT devices in the same analysis reached 50%, well above both medical device categories.
- Many of the affected devices are directly involved in patient care, including infusion pumps, patient monitors, imaging systems and laboratory equipment.
- Forescout found more than 5,500 internet-exposed systems, among them platforms holding electronic medical records and picture archiving systems.
- Only 31% of those exposed systems support TLS 1.3, the only TLS version capable of carrying standardized PQC.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Medical histories and diagnostic images stay sensitive for decades, so encrypted traffic recorded from exposed systems before migration stays a liability well past a five-year quantum window.
- constraint For medical gear with limited upgrade paths, post-quantum protection has to come from the network around the device, through segmentation and isolation.
- decision Procurement is where hospitals set a long-lived device's cryptography, so PQC readiness and TLS 1.3 belong in purchase requirements before installation.
Harvest now, decrypt later has two stages. Recording encrypted traffic works today. Reading it requires a quantum computer able to break current encryption, and the Infosecurity Magazine report says such machines are predicted within the next five years [20]. The article does not say who made that forecast. Forescout's researchers single out the internet-exposed systems as particularly vulnerable to this pattern, because an attacker can take the data now and decrypt it later [9].
The device percentages measure SSH. Forescout's report, published October 6 [3], counted which SSH implementations could support a move to PQC [2]. By that count, 94% of IoMT devices and 84% of medical OT devices fall short [17]. Traditional IT does about eight times better than IoMT [19]. Forescout describes the medical gear as long-lived, with limited upgrade paths and slow uptake of modern cryptographic standards [6].
Daniel dos Santos, VP of research at Forescout, said: "Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy." [7]
For anything facing the internet, the TLS number matters more. Roughly 3,800 or more of the exposed systems run TLS older than 1.3 [18]. Each of them needs a protocol upgrade before a post-quantum migration can start [11].
Forescout's guidance expects part of the fleet to stay as it is. Its assessment step sorts systems into upgrade, replacement or compensating controls [13]. The list begins with an inventory of every connected IT, OT, IoT and IoMT asset and what each one communicates with [12], and it calls for segmenting and isolating legacy systems that cannot be upgraded [14]. The 6% figure counts SSH stacks as deployed. Whether a vendor can ship a post-quantum stack to an installed pump is a firmware question, and Forescout's answer is to ask vendors for their PQC roadmaps and migration timelines [16].
I'd order the work by reachability. The internet-exposed systems [8] are the ones an outside attacker can record traffic from without first getting into a hospital network [9]. Isolating them cuts that exposure whether or not the five-year forecast holds [20].
What to watch
- Vendor PQC roadmaps from pump, monitor and imaging makers. They set how much of the IoMT fleet can be fixed in firmware and how much must be isolated or replaced.
- A sourced date for quantum decryption capability. The five-year forecast in the coverage sets the window for segmenting legacy gear.
- Evidence of a group bulk-recording healthcare traffic. That would turn harvest now, decrypt later from a modeled risk into an observed campaign.