CybeRIS - Cybersecurity in Healthcare
A case study on initiating and coordinating a multi-stakeholder European training program to bridge the gap between healthcare innovators and critical cybersecurity needs.

The Challenge: Innovation vs. Infrastructure in Healthcare
The healthcare and life sciences sectors are in the midst of a profound digital transformation. From AI-driven diagnostics and IoT medical devices to electronic health records (EHRs) and digital therapeutics, innovation is accelerating at an unprecedented pace.
However, this innovation introduces significant risk. Hospitals are critical infrastructure, and the data they manage is among the most sensitive in existence. A cybersecurity breach in a clinical environment is not just a data leak—it can be a direct threat to patient safety, capable of halting critical operations.
Startups and SMEs are the lifeblood of this innovation, but they often operate with limited resources and may lack the specialized knowledge to navigate the unique cybersecurity landscape of healthcare. They need to understand not only how to build a secure product but how to integrate it safely into a complex hospital IT environment without exposing new vulnerabilities.
My Role: Initiating and Coordinating a 360-Degree Solution
Recognizing this critical ecosystem gap, I initiated CybeRIS, a strategic training program designed specifically for startups developing digital health solutions. The project was coordinated under the umbrella of EIT Health, Europe’s leading health innovation network.
My primary role was to act as the architect and coordinator of the program. This involved more than just managing timelines; it required building a unique consortium that could provide a complete, 360-degree view of the problem. I brought together three distinct pillars of the healthcare ecosystem:
- Corporate Pharma (Boehringer Ingelheim RCV): As a global pharmaceutical leader, they provided the industry perspective on regulatory demands, data integrity, and the high stakes of intellectual property and patient data in a commercial environment.
- Academic Medicine (Medical University Graz): As a front-line clinical and academic institution, they brought the crucial “hospital point-of-view.” They provided insight into real-world clinical workflows, the challenges faced by hospital IT staff, and the practical realities of implementing new technologies in a high-pressure setting.
- Cybersecurity Specialists (OXO Cybersecurity): As experts in cybersecurity education and services, they built and delivered the technical curriculum, from basic terminology and compliance standards to advanced threat modeling and mitigation techniques.
The Impact: De-Risking Innovation and Building Trust
By bringing these partners together, CybeRIS was not just another training course. It was an ecosystem intervention.
The program equipped startups with the knowledge to build products that were “secure by design,” not as an afterthought. Participants learned about regulatory compliance (like GDPR and medical device regulations), secure data handling, and the specific case studies and threat vectors unique to healthcare.
The impact was twofold:
- For Startups: It significantly de-risked their solutions, making them more trustworthy and attractive partners for hospitals and pharma. They learned to speak the language of CISOs (Chief Information Security Officers) and hospital IT, turning a potential barrier into a competitive advantage.
- For the Healthcare System: It helped create a safer, more resilient innovation pipeline. By educating suppliers, we inherently protect the providers and, ultimately, the patients. The program fostered a vital dialogue between innovators, clinicians, and security experts—a conversation that is essential for a secure digital health future.
The Broader Context
The CybeRIS model proves that complex, multi-stakeholder challenges can be addressed through curated, collaborative education. This framework is highly replicable for any regulated industry where technical innovation must be balanced with critical infrastructure and public trust.
If you are looking to build a similar bridge in your ecosystem—whether in finance, energy, or law—this consortium-based training model is a powerful tool.
Are you facing a similar challenge of bridging innovation and security? Let’s connect.