IN THE NEWS
2026 · Cisco + Cylera win Scottish Cyber Innovation AwardInside the digital twin that leaves the live device alone

Company / Healthcare cybersecurity

Cylera and the hospital machines you dare not switch off

A hospital can have a vulnerable device and a patient who needs it running. Cylera builds its security business around that inconvenient fact, using digital twins to assess risk without probing the equipment delivering care.

Consider an infusion pump. To a nurse, it is a piece of equipment with a job to do. To a security analyst, it is also a network endpoint, communicating with other systems and potentially carrying vulnerabilities. Both descriptions are correct. The trouble begins when the analyst’s remedy interferes with the nurse’s work. A hospital cannot treat every suspicious machine like an office laptop.

The useful bits
  • Find connected medical devices without installing agents on them.
  • Assess digital twins while the physical equipment keeps working.
  • Use clinical context to prioritize risks and coordinate action.

Cylera has built a company around that collision of duties. Its software discovers connected devices, constructs an inventory, assesses vulnerabilities and watches for threatening behavior. The promised result is practical: security teams and clinical engineers can understand the same equipment without making its continued operation the price of understanding it.

Give the machine a double

The interesting part is where the investigation happens. Cylera observes network traffic rather than installing security software on each medical device. Its Adaptive Data Type Analysis identifies devices and their characteristics from those communications. Its IoT Device Emulation Engine creates digital twins, simulations that reflect device configurations and behavior. Assessment can then focus on the twin rather than probing the live equipment.

This is a rather civilized arrangement for a machine that might be attached to someone. A digital twin provides another place to examine weaknesses. Cylera’s network monitoring also tracks communications for anomalies. Inventory, risk assessment and threat detection feed a common platform, giving staff a route from discovering a device to deciding what deserves attention.

How the investigation moves
01ObserveMirrored network traffic
02EmulateA digital device twin
03PrioritizeRisk in clinical context
04ActTeams + integrated controls
The double takes the examination. The original keeps its appointment with the patient. Simplified workflow.

That distinction also sets a sensible boundary around the pitch. Seeing a weakness does not repair it. Hospitals still need staff, manufacturer guidance and appropriate network controls. An inventory cannot discover equipment on traffic it never receives. The operational question is whether useful intelligence reaches someone authorized and equipped to act.

The spreadsheet was too small

At St. Luke’s University Health Network, Cylera’s published case study describes a requirement spanning 300 facilities and multiple interrelated networks. Connected devices needed to be available for critical care. Equipment utilization data was insufficient for efficient purchasing decisions. The problem was larger than maintaining a list: the organization needed to understand changes, anomalies and security issues across a dispersed estate.

Cylera says the deployment consolidated inventory and supplied ongoing risk analysis, usage information and remediation priorities. Those are customer-case-study claims, rather than an independent controlled evaluation. Nevertheless, the underlying logic is persuasive. The same device record can help a security analyst investigate an exposure and help an equipment manager decide whether another purchase is necessary.

“Cylera has provided us a means to fully know what we have, in-depth”

David Finkelstein · CISO, St. Luke’s University Health Network

A British example adds a different pressure. University Hospitals of Morecambe Bay NHS Foundation Trust needed a reliable device registry and a way to track responses to NHS cyber alerts. Cylera’s account describes automated inventory and more efficient threat management. The appeal is partly administrative: evidence that once required chasing different teams can be assembled from continuously updated device information.

Three years before the first revenue

Founded in 2017 by Timur Ozekcin, Sean Abraham and Paul Bakoyiannis, Cylera spent three years developing its platform before becoming revenue-producing in 2020, according to Crunchbase News. Ozekcin brought experience from medical-device venture Heuristics Health and work with a Department of Homeland Security-funded consortium concerned with device safety and security. The founders were entering an industry with unusually inconvenient constraints.

One early obstacle was explaining the problem to investors. In an AlleyWatch interview, Ozekcin said many were surprised by the risks that connected devices posed to patients and clinical operations, and by the limits of generalized IT tools. The sale began with education. Before an investor could value the solution, the investor had to understand why familiar remedies were insufficient.

A $10 million Series A in March 2021, led by Concord Health Partners and Maverick Ventures, brought reported cumulative funding to $17 million. In the same period, Ozekcin pointed to Armis’s financing as evidence of market validation: “The Armis deal helped validate the market.” That was his stated reason for accelerating, rather than a documented change in Cylera’s product direction.

A price tag with a scope attached

Cylera sells business software to healthcare organizations, including through partners. A useful public cost comes from NHS National Services Scotland: a Cylera medical-device management software contract worth £2.3 million excluding VAT. It runs for 42 months, from September 17, 2024 to March 17, 2028. That is one procurement’s value, with its own scope, rather than a price every hospital would pay.

One disclosed NHS software contract£2.3m
excluding VAT / 42 months
17 September 2024 - 17 March 2028

The market is competitive. Armis offers medical-device security; Claroty’s xDome supplies healthcare device visibility and clinical risk context. Agentless discovery alone does not settle the comparison. Cylera’s particular argument centers on its patented analysis and device emulation, plus the usefulness of its workflows. A buyer should examine device coverage, integration and remediation effort against the hospital’s actual estate.

The partners finish the sentence

Cylera’s relationships explain how intelligence becomes action. Illumio brings segmentation capabilities. Extreme Networks receives device profiles to inform network controls. Integra e-Quip connects the story to maintenance management. The strategy acknowledges that medical-device security lives among tools already purchased and departments already busy. A new dashboard has to earn its place in that company.

Cylera CEO Timur Ozekcin, left, and Omantel chief commercial officer Aladdin Baitfadhil at the partnership announcement
Two executives, one expanding hospital network. Timur Ozekcin, left, and Omantel’s Aladdin Baitfadhil mark the 2023 Oman partnership. Photo: PRNewsfoto/Cylera.

Omantel’s 2023 partnership provided a route into Oman. More recently, Cisco and Cylera won the Cyber Innovation Award at the 2026 Scottish Cyber Awards. Abertay University also documents Cylera’s medical-IoT testbed for cybersecurity research and doctoral training. These are useful signs of activity, though an award cannot substitute for evidence from a particular deployment.

The transferable lesson is modest and demanding: establish what is connected, understand what its work means, and give the resulting risk a responsible owner. Cylera makes that sequence easier to organize. Its value depends on what happens after discovery, when clinical engineering and security agree on a remedy that lets the patient’s machine keep doing its job.