OTSecurity

Pharmaceutical sector urged to shift cyber resilience focus from systems to medicine value chains


Pharmaceutical companies need to rethink cyber resilience around the continuity of medicine value chains rather than recovery of individual systems, Ashish Gupta, partner at PwC, and Jonathan Sinclair, head of cyber resilience at Roche, wrote in a recent story published by the World Economic Forum (WEF). They observed that ransomware, supply-chain compromises and OT (operational technology) disruptions can halt production, delay batch releases and restrict patient access to medicines even after affected systems have been restored. The shift comes as pharmaceutical operations become increasingly dependent on automated manufacturing, AI-enabled research, cloud platforms, data-rich laboratories and globally distributed suppliers, creating additional dependencies and avenues for cyber disruption. 

The post recognizes that pharma organizations need to connect cybersecurity, business continuity and operational decision-making across the full medicine value chain, including internal functions, third-party partners, digital assets, data flows and OT environments. 

“This is especially pertinent now because pharmaceutical companies’ operating models are changing rapidly,” Gupta and Sinclair identified. “Automated manufacturing, AI-enabled research, cloud platforms, data-rich research laboratories, consumer-led engagement and globally distributed suppliers are creating new value – but also new dependencies and avenues for cyber disruption. The World Economic Forum’s Global Cybersecurity Outlook 2026 identifies AI, geopolitical volatility and supply chain exposure as forces reshaping cyber risk, with third-party and supply-chain vulnerabilities among the top challenges to achieving resilience.”

Recent disruptions in the life sciences ecosystem have demonstrated how cyber incidents outside a pharmaceutical company’s own systems can also affect patient care. In March this year, a cyberattack at medical device manufacturer Stryker disrupted manufacturing, ordering and distribution channels. As a result, NHS England asked its partners to prioritize clinically important supplies and assess their dependence on Stryker products. 

Last August, in another incident, contract research organisation Inotiv disclosed that a threat actor had encrypted systems and disrupted access to applications and data. As a consequence, the company activated its business continuity strategy and moved some operations to offline alternatives.

“For the pharma sector, disruptions at manufacturers, contract research organizations, quality control laboratories, logistics partners or digital platforms can affect productivity, deplete inventories, trigger regulatory escalation or limit medicine availability,” Gupta and Sinclair wrote. “Leaders must not only ask whether systems can be restored, but also whether medicine supplies can continue during the recovery phase.”

They also recognize that cyber recovery and business resilience are related, but are not the same. “A restored application may still leave a plant unable to release a medicine if quality evidence is incomplete, while a supplier outage may still be manageable if inventory, alternative sourcing and manual procedures are in place. The business context determines whether a cyber incident becomes an operational, regulatory or patient access problem. Resilience therefore becomes a shared business and cyber responsibility.”

The story also highlights gaps in current resilience practices, noting that only 33% of organizations comprehensively map their supply chain ecosystems and 27% simulate cyber incidents or conduct recovery exercises, according to the WEF’s 2026 outlook. It recommended assigning explicit business ownership to essential value chains and using disruption scenarios to guide recovery and investment decisions, with the ultimate objective of maintaining safe and continuous medicine supplies to patients.

Gupta and Sinclair identify how a value-chain resilience approach shifts the focus of cyber resilience from individual technology assets to the continuity of critical parts of the pharmaceutical value chain. This approach enables cyber and business leaders to prioritize resilience measures based on how disruptions could affect the delivery of medicines and minimize the time between a cyber incident and its impact on patients.

“In practice, this begins with the most important outcomes: discovering, developing, manufacturing, releasing and delivering medicines safely and reliably,” they noted. “It then maps the end-to-end value chain behind those outcomes, including internal functions, external partners, digital assets, data and process flows, operational technology and third-party dependencies. It also assesses cyber risk and the impact of disruption on the most critical nodes of the value chain.”

They point out that without this end-to-end view, organizations may focus on the immediate outage or system compromise and miss the wider consequences: cascading impact on downstream dependencies, delayed quality or batch release, inventory shortages, regulatory action, loss of stakeholder confidence and threats to the licence to operate. The impact on patient care is real and will also result in regulatory actions.

“For pharma, the call to action is clear: Assign explicit business ownership to essential value chains and use disruption scenarios to guide investment and recovery decisions,” according to Gupta and Sinclair. “For cyber leaders, this is also a leadership shift: The role moves from explaining technical exposure to enabling business decisions on patient care continuity, risk tolerance and operations recovery.”

They also called upon pharma leaders to treat the medicine value chain, rather than the individual system, as the unit of cyber resilience. “When boards, business leaders and cyber leaders agree on which business functions are indispensable, how much disruption can be tolerated and who can make critical trade-offs, they are better equipped to maintain patient access while systems and operations recover.”



Source link