Health · Cyber
Guide

How should health services prioritise vulnerabilities when they can't patch everything?

Your vulnerability report has more findings in it than your team could clear in a decade, and a meaningful share of your estate can't be patched at all because the vendor won't support it or a restart is a clinical event rather than an IT one. This guide sets out why patch-everything was never achievable, what you're actually obliged to do across hospitals, community care and aged care, and how to build a decision framework your audit and risk committee can defend.

HealthCyberVulnerability managementExposure managementComplianceMedical devices
Inside the guide
  1. 01Why is the vulnerability list growing faster than any team can clear it?
  2. 02How many of these vulnerabilities are actually real?
  3. 03Why can't health services simply patch faster?
  4. 04What are you actually obliged to do in Australia?
  5. 05What should you be deciding instead?
  6. 06What does good look like?
  7. 07Where does automation belong, and where does it not?
  8. 08What this argument does not claim

Full guide delivered to your inbox

What the guide covers

A framework for deciding what to act on when you can't patch everything

Covers why published vulnerabilities have outpaced remediation capacity, how fabricated AI-generated CVEs are entering the same feeds as genuine ones, and why Australian regulation gives health services no binding standard for the part of the clinical estate that can't be patched. Sets out the Stakeholder-Specific Vulnerability Categorization framework CISA now mandates in place of severity scoring, and the four practical capabilities, a reconciled asset picture, a written decision rule, a compensating-control pathway and procurement that prices unpatchability upfront, that let a health service answer 'is this exposure urgent' in hours.

What's inside

The four-question exposure decision tree, a table mapping which Australian obligations (Privacy Act, SOCI Act, Essential Eight, My Health Records Act, Aged Care Quality Standards) actually bind which type of provider, and the funnel diagram showing what a health service should be resourcing against instead of the raw CVE count.

Get the full guide
Delivered to your inbox. Name and email only.

No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.

95%
Of health care and social assistance sector cyber incidents responded to by ASD's Australian Cyber Security Centre in FY2024-25 were successful for the attacker, against nearly 52 per cent across all sectors.
Source: Australian Signals Directorate, Annual Cyber Threat Report 2024-25, p.30
35,364
Vulnerabilities published in the first half of 2026 alone, roughly one every seven and a half minutes, a 49.5 per cent increase on the same period in 2025.
Source: Independent analysis by Jerry Gamblin, H1 2026
99%
Of 351 healthcare organisations analysed had connected medical or operational technology devices carrying known exploited vulnerabilities.
Source: Analysis of 2.25 million connected medical devices and 647,000 OT devices across 351 healthcare organisations

Martin Barnier

Principal Consultant · Lumaris Consulting

Martin is a strategy, architecture, and technology leader with over a decade of experience helping public and private sector clients securely evolve their digital services. Martin consults at the intersection of AI, cyber security, and enterprise transformation; advising clients on risk, designing architectures, and leading delivery across complex regulated environments.

View LinkedIn profile
Before you download

Questions about this guide

Generally no. The Therapeutic Goods Administration's guidance for large-scale service providers instructs health services to avoid installing unvalidated patches or changing device configuration without explicit manufacturer instructions. Obligations under the therapeutic goods framework sit with the manufacturer, not the hospital, and modifying a device without authorisation risks the hospital being treated as a manufacturer itself under the Act.

Only narrowly. The Security of Critical Infrastructure Act's register and incident reporting obligations apply solely to a 'critical hospital', meaning one with a general intensive care unit. The Critical Infrastructure Risk Management Program obligation applies only to the roughly 91 hospitals named in Schedule 1 of the CIRMP Rules. Most community care and aged care providers sit outside the regime entirely.

SSVC is a decision-tree framework, published by CISA in 2022 and developed at Carnegie Mellon's Software Engineering Institute, that replaces severity scoring with decision points including exploitation status, technical impact, automatability, mission prevalence and public well-being impact. CISA formally adopted it over patch-by-severity in June 2026 through Binding Operational Directive 26-04.

Aged care isn't captured by the SOCI Act. Under the strengthened Quality Standards in force since 1 November 2025, the only express information security obligation is Outcome 2.7, Action 2.7.1, which requires an information management system to securely manage records. It's outcome-based, with no maturity level or patching timeframe specified in the Standard itself.

Let us talk

If the guide surfaces something you want to work through, that is a good place to start.

Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.