Gluware Launches IoMT Exposure Management for Enhanced Medical Device Security
Gluware Launches IoMT Exposure Management for Enhanced Medical Device Security
Gluware, the leader in intelligent automation, has announced its newest innovation, the IoMT Exposure Management, extending its automation capabilities to the realm of connected medical devices. This cutting-edge solution addresses the growing challenges hospitals face in managing vulnerabilities within their medical device fleets, ensuring better protection in clinical environments.
Medical devices such as infusion pumps, imaging systems, patient monitors, and clinical workstations are crucial to healthcare delivery. However, they are also susceptible to various vulnerabilities that, if left unaddressed, can lead to severe risks for both patients and healthcare institutions. The rise in reported vulnerabilities, particularly amid a backdrop of a 263% increase in CVE submissions between 2020 and 2025, highlights the pressing need for effective remediation tools.
Gluware's IoMT Exposure Management operates by automating the process that begins once a vulnerability has been disclosed. The system expertly correlates Common Vulnerabilities and Exposures (CVEs) with impacted medical devices, pinpoints the necessary patches, and executes required modifications in accordance with each hospital's distinct approval and auditing protocols. Such an approach alleviates manual burdens while meeting rigorous compliance requirements.
The challenges of remediating vulnerabilities in a hospital setting cannot be overstated. Unlike conventional IT environments where systems can be taken offline during remediation, medical devices often require careful orchestration around clinical schedules and backup systems. This complexity can lead to delays and often forces medical teams to rely on cumbersome methods like spreadsheets and email threads. These challenges underscore the necessity for an efficient solution.
The IoMT Exposure Management solution’s framework is built on the same automation engine that Gluware employs across enterprise networks. Its design leverages the DIAL™ (Device Interaction and Automation Layer™) semantic translation layer, effectively connecting devices across multiple operating systems and vendors. This continuity allows healthcare institutions to seamlessly incorporate the IoMT solution alongside their existing systems, eliminating the need for additional platforms or specialized teams.
Jeff Gray, CEO and Co-Founder of Gluware, emphasizes the importance of integrated visibility in hospital networks. He mentions, "Most hospitals can tell you what's on their network. Far fewer can tell you which of those devices are actually exposed, when they were fixed, and who approved the changes." Ensuring that hospitals do not need to implement separate systems for device protection is a key value proposition of the new solution.
The Five-Stage Pipeline: Simplifying Processes
Gluware’s IoMT Exposure Management is designed to streamline the remediation process through five interconnected stages:
1. Clinical-Grade Discovery: Utilizing Claroty xDome, Gluware serves as the central source of truth for IoMT inventory, updating device details and vulnerability information in real time.
2. Component-Level Vulnerability Matching: The platform enhances CVE data against components within each device, thus mitigating inaccuracies in alert notifications, which can lead to reduced confidence among staff.
3. From Advisory to Applicable Patch: Integrations with the Microsoft Update Catalog enable the system to retrieve specific Knowledge Base updates, identifying components that are unsupported and suggesting alternative actions.
4. A Shared Operational Record: An innovative IoT Device Manager allows both clinical engineering and IT departments to operate from a continuously updated, synchronized view of the device fleet, bridging previously disparate workflows.
5. Change-Controlled Execution: Each patch action triggers a change ticket that navigates through the hospital's existing approval process, with a complete record of actions taken, easing the regulatory auditing burden.
These integrated stages not only eliminate delays caused by disparate systems but also ensure that records are generated as a natural byproduct of the operational processes, rather than relying on backtracking for compliance.
Born from Real Need
The inception of Gluware IoMT Exposure Management traces back to collaborative efforts with The Ohio State University Wexner Medical Center, which was already utilizing Gluware for their network automation. Challenges regarding manual coordination of vulnerabilities across various teams highlighted the need for a more cohesive approach. Siji Atekoja, Deputy CIO and CTO of Ohio State, recognized that the tools already in place could effectively navigate the remediation process from vulnerability disclosure to the application of fixes.
With the launch of Gluware IoMT Exposure Management, healthcare organizations are now better equipped to tackle the complexities associated with medical device vulnerabilities. Available now through an early access program, Gluware encourages healthcare organizations interested in automating their remediation processes to connect with their representatives for further engagement.
For additional insights, individuals can access Gluware's white paper titled Closing the Patch Gap: Automating Vulnerability Remediation for Connected Medical Devices.
About Gluware
Gluware is an innovative automation platform designed for the Agentic Era™, empowering teams to model infrastructure functionalities and automate necessary changes securely across various vendors and environments. With attributes proven across 56 operating systems and 22 vendors, Gluware stands as a robust solution for industries spanning finance, healthcare, pharmaceuticals, energy, and more. Its headquarters are located at 500 Capitol Mall, Suite 2350, Sacramento, CA 95814.