On July 2 somebody at Cook Medical said yes to the wrong person. No password got cracked. An employee was deceived by a social engineering attack and gave an outside party access to company systems, MedTech Dive reported on August 13. Cook spotted it and shut it the same day.
Here is what went out the door. Contact information for customers in the United States and Canada. Records of communications with Cook employees held in Salesforce. Some internal business files. Employee names and company email addresses. Cook says it has no evidence that sensitive or protected data was accessed, and that products, manufacturing, and its ability to serve patients and customers were unaffected.
What a CRM is worth to the person who took it
Nothing on that list is the device. It's the commercial layer: who your customers are, what they said to your sales and service people, and which of your employees to write to next. For a company Cook's size, that CRM is a map of hospital relationships built over decades. A competitor would find it useful. Somebody planning the next round of scam emails would find it more useful, which is why Cook is telling customers and employees to watch for follow-on attempts.
Founders building connected hardware spend real money on the other layer. If you're writing a premarket submission for a device with software in it, you have a cybersecurity section, and you've put months into threat modeling, the software bill of materials, the patching plan. That work is worth doing. It also protects a completely different thing than the one that broke here.
Where I learned to put people at the top of the list
I knew Kevin Mitnick a long time ago. He lived in Maryland, I lived in DC, and Interop drew everyone in or near the hacker community, so it was close to impossible for someone in my line of work not to have met him. He was a good friend before he died. What he was famous for was hacking without ever touching a computer. He had a personality people responded to, and allegedly he could charm his way into information that was supposed to require special access. Nobody handed him a keyboard. They handed him the answer.
So social engineering sits at the top of my own threat model, above anything on the network diagram. On the surgical robots I've worked on, hospital IT never allowed a live IP connection during a procedure. Store and forward only. That's a real control and I'd argue for it every time, but store and forward still carries injection risk, and my larger worry was always someone with live access. A friendly person in a company vest who talks their way to a terminal. Not Kevin, who was a good guy, but somebody with his skills and worse intentions.
Hospital cyber departments already understand this, which is part of why they can gate your deployment independent of whether the device works. Design for human access control, man in the middle, and packet injection from the architecture stage, along with the unglamorous stuff like an open USB port. Security planned in is cheap. Security added after the design freeze is expensive and leaky.
The half of the model with no section number
Designed-in security is about stopping the incident. Cook's disclosure teaches the other half, which is what you do once one starts. Same-day detection and containment on July 2, public disclosure in August, an honest inventory of what was reached and a plain statement of what was not, operations running the whole time. That's a company that had practiced its incident response rather than written it.
The device file covers the device. In every submission I've worked on, the cybersecurity questions were about the product: its interfaces, its software components, its update path. None of them asked who inside the company could pull the entire customer list, or what happens when that person takes a convincing phone call. The regulation is doing its job. It asks about the product because the product is what it governs. The gap is in what founders count as done when they say they've handled security.
The strongest attack on any system runs through people, and people don't show up on the network diagram. Cook caught theirs in a day, which is the outcome you want and the one you only get by practicing. Go find out who at your company could hand over the customer list this afternoon, then go ask them how they'd know not to.
From Dave’s video library
Dave on handing decisions to systems that were never smart enough to hold them, and where a person still has to stay in the loop.
I’m here to help you scale.
Work With DavePrefer a smaller first step? Book a $500 one-hour working session →
Dave Saunders is the founder of Base Reality Group and a Fractional CPO for product companies. He was a founder and operator at Galen Robotics, where the surgical-robotics platform earned FDA De Novo authorization in 2023, and he managed a 35-patent portfolio licensed from Johns Hopkins. He wrote Founders Who Finish and publishes The Build. More about Dave →