Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: Healthcare Device Discovery & Risk Management with Medigate

Claroty
06/28/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


so that we're not causing a lot of noise for users that don't necessarily need to see certain information to do their jobs. So if we dive in here and we want to look at the device overview, we're going to be spending most of the time today talking or bouncing back and forth between this device and this risk tab, but this provides us that visual representation of the variety of devices within our environment. Again, whether we're talking about fleet devices in the healthcare realm, building management controllers, things as innocuous as printers and scanning machines, just showing again that variety of devices that make up the modern healthcare environment. Now, if I dive into medical devices here, we can begin to look at what this profile looks like. So what is this asset data table looking like? What are the IP and MAC addresses that we're picking up? Where are the bulk of manufacturers, model numbers, what are the operating systems in this environment? All of these different things that help us create this profile of devices on the network. Individually, however, we can start to pick up 100 plus assets on these, or 100 plus profile points on these devices to help, again, build that complete foundation for those downstream compensated controls and cybersecurity controls that we can put around these devices to ensure that they can still perform their function. So if I want to dive in here to a specific device, I'm going to pick an MRI machine for a moment. Yeah, we'll just do this first from the Siemens Magnetime. So going back to the slide that I showed, you can see here, this is that device's attribute table. So we've got these custom labels. Who are the assigned departments or users? Does this device have an associated MDS2 file? And then really digging into that information that's either discovered or determined based off that packet information. So what is its IP, its MAC address? Who is the manufacturer, the model number, the firmware version? Is it a mobile device or a static device? What is the guest network? I'm sorry, what is the VLAN that it's on? If it's integrated with a CMMS, what is that CMMS's serial number? All of these different things that help us, again, build that platform, build that foundation of further downstream controls. Things like understanding its risk and vulnerability fully contextualized to this healthcare environment. So of course, because this device is involved with patient care, it's always going to be a severe device. So perhaps we can't lower the risk in that vein, but maybe we can look at the device vulnerabilities for the network risk profile to help understand, again, what compensating controls we can put around this device in order to make it sit within a more acceptable tolerance of risk in the environment. So if I come in here to the risk simulator, I can pull this up and I can say, well, you know what? I can't change the severity of this device, but what I can do is I can put an optimized ACL around it and I can see what impact that is going to have on my risk score. Now, where this risk score comes from, I will show you in a few minutes, but we can start to play with, okay, we've tailored this risks tolerance profile to our unique network. What are the things that I can do to make sure these devices fit within that network risk? Something like the operating system, for example. This is not something you can necessarily control in your environment. The manufacturer probably will not come out and put a new operating system on your device, but you can put something like an optimized ACL around it to ensure that it can only perform its optimized function or only performance clinical function, rather. All in all, Medicaid, of course, has many recommendations for things you can do to lower this risk score to a low category, and we'll dig into those a little bit further down the road. Other things that we will provide are insights on this device, so is it sending information back to the manufacturer? Really important, when does this device store health information? These are devices that, depending on your regulatory environment, you may need to pay extra close attention to. We can look at, again, what switches is this on? What are the policies that are wrapped around it? And then what do these policies look like when you look at the device communication profile? So we're looking at here what this device communicates with throughout the network and which of these communications would be in or out of policy, depending on how that policy is constructed. One other thing that is very, very useful in terms of visibility is providing the utilization profile of this device. So we can see here that, based on the hospital's utilization parameters, this device is only used about half the time, typically operates between 7 a.m. and 8 a.m. However, it's used about 11 hours a day. We can start to look at what these blocks look like in terms of its scheduling. How many examinations does this device do per day? What does the profile look like in terms of examinations over time? Because this is a scanning device, what body parts is it scanning? So really just building that very, very complete device profile of exactly what is this device? How is it communicating in my network? How am I using it so that I can then use this information to start driving better decisions from a security standpoint, from an operational efficiency standpoint, from a financial standpoint? You have all of the information that you need to go and make these decisions.

TL;DR

  • Medigate by Claroty provides comprehensive visibility into healthcare networks, profiling medical devices with 100+ data points including manufacturer, firmware, network configuration, and CMMS integration details.
  • The platform's risk simulator enables security teams to model the impact of compensating controls like optimized ACLs on device risk scores, helping organizations manage devices that cannot be patched or upgraded.
  • Beyond security, the platform delivers operational intelligence including device utilization patterns, examination scheduling, and communication profiles to support efficiency and financial decision-making.

Summary

This product demonstration showcases Medigate by Claroty's healthcare-focused cybersecurity platform, specifically its capabilities for medical device discovery, inventory management, and risk assessment. The walkthrough illustrates how the platform provides comprehensive visibility into diverse healthcare environments, capturing detailed profiles on medical devices like MRI machines, building management controllers, and IoT devices. The demonstration emphasizes the platform's ability to collect over 100 profile points per device, including manufacturer details, firmware versions, network configurations, and CMMS integration data. A key focus is the risk simulation feature, which allows security teams to model the impact of compensating controls like optimized access control lists on device risk scores. The platform also provides operational insights such as device utilization patterns, examination scheduling, and communication profiles, enabling healthcare organizations to make informed decisions across security, operational efficiency, and financial planning domains.

Chapters

0:00 - User Experience & Device Overview
0:44 - Medical Device Profiling
1:28 - MRI Machine Deep Dive
2:53 - Risk Simulation & Compensating Controls
4:33 - Device Utilization & Operational Insights

Key Quotes

1:06 "Individually, however, we can start to pick up 100 plus assets on these, or 100 plus profile points on these devices to help, again, build that complete foundation for those downstream compensated controls and cybersecurity controls that we can put around these devices to ensure that they can still perform their function."
2:32 "Of course, because this device is involved with patient care, it's always going to be a severe device. So perhaps we can't lower the risk in that vein, but maybe we can look at the device vulnerabilities for the network risk profile to help understand, again, what compensating controls we can put around this device in order to make it sit within a more acceptable tolerance of risk in the environment."
3:33 "The manufacturer probably will not come out and put a new operating system on your device, but you can put something like an optimized ACL around it to ensure that it can only perform its optimized function or only performance clinical function, rather."

FAQ

How does Medigate handle medical devices that cannot be patched or upgraded?

Medigate provides a risk simulator that allows security teams to model compensating controls like optimized access control lists (ACLs) around devices. While you may not be able to change factors like the operating system or severity classification, you can implement network controls that restrict the device to only its clinical function, thereby lowering the overall network risk score to an acceptable tolerance level.

What types of operational insights does the platform provide beyond security?

The platform delivers detailed utilization profiles including device usage hours, examination volumes per day, scheduling patterns, and for imaging devices, even the types of body parts being scanned. This operational intelligence supports decision-making across security, operational efficiency, and financial planning, giving organizations a complete view of how medical devices are actually being used in their environment.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Compliance & GRC
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Data Protection
  • Compliance & Governance
  • Demo
  • Technical Deep Dive
  • Healthcare Cybersecurity
  • Medical Device Security
  • Asset Discovery & Inventory
  • Risk Management
  • Vulnerability Management
  • Network Segmentation
  • Access Control Lists
  • IoMT Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: Healthcare Device Discovery & Risk Management with Medigate

              Upcoming Webinar Calendar

              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Worthy Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-worthy-security-team-for-unmatched-defense/
              • 07/14/2026
                02:00 PM
                07/14/2026
                Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies for Effective Data Privacy and Protection
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
              • 07/22/2026
                01:00 PM
                07/22/2026
                Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 07/29/2026
                12:00 PM
                07/29/2026
                Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
              • 07/29/2026
                01:00 PM
                07/29/2026
                Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Becoming Agent Ready: Insights from Cyera's Expertise
                https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jul
                14

                Crafting a Championship-Worthy Security Team for Unmatched Defense

                07/14/202601:00 PM ET
                • Jul
                  14

                  Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                  07/14/202602:00 PM ET
                  • Jul
                    21

                    Strategies for Managing AI Governance and Securing App-to-LLM API Traffic

                    07/21/202604:00 AM ET
                    • Jul
                      22

                      Insights and Strategies for Effective Data Privacy and Protection

                      07/22/202606:30 AM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version