INDUSTRY SOLUTIONS

Runtime Protection for Medical Device Firmware

Symbiote adds on-device runtime integrity to medical devices, checking selected code, memory, control flow, and processes against device-specific policies. No source code or hardware changes required.

// DEVICE CATEGORIES

What Red Balloon Security protects

Our solutions are broadly applicable across medical device categories.

Infusion & drug delivery pumps

Firmware holds the drug library, the dose limits, and the motor control loop.

Patient monitors & telemetry

Firmware decides which waveform, alarm, and vital sign a clinician sees.

Ventilators & anesthesia delivery

Firmware governs pressure, volume, and gas mixture in real time.

Imaging & radiation therapy

Firmware controls beam delivery, gantry motion, and dose calculation.

Surgical robotics & powered instruments

Firmware translates surgeon input into motion.

Implantables & wearables

Constrained hardware, wireless interfaces, and no practical service visit.

If firmware decides what the hardware does, the firmware is the control surface worth defending.

// The Solution

Runtime Integrity

Extend security beyond startup

Secure Boot establishes a starting point.

Runtime integrity adds scoped assurance during operation.

Secure boot and authenticated updates help control which software can load. Symbiote adds policy-based integrity checks while the device operates.

Symbiote can monitor selected:

// HOW IT WORKS

How Red Balloon Security protects medical device firmware

Defense goes into the firmware image itself. The protected image moves through your existing test and signing process, and the device defends itself from that point forward, connected or not.

OFRAK inserts Symbiote into your release binary

OFRAK unpacks the firmware, inserts the payloads, and repacks it. No source code changes. The image you sign is the protected image.

Symbiote runs inside the firmware, not beside it

Embedded in the real-time operating system, the Linux kernel, or a trusted execution environment. It cannot be unloaded while the device is running. Typically 2 to 3 percent average CPU, from around 16K.

Payloads defend what matters on your device

Memory integrity, task-spawn enforcement, control-flow integrity, and custom checks on values such as dose limits and calibration constants. You define the response: block, restore, log, alert, or fail safe.

AESOP turns defense into evidence

Attestation streams to your SIEM on connected devices and stays local on air-gapped ones. Postmarket claims arrive with runtime data behind them.

// FAQ

Questions from device manufacturers

Does Symbiote require our source code?

No. OFRAK operates on the release binary. Your build pipeline, toolchain, and signing process stay as they are.

What is the performance impact?

Typically 2 to 3 percent average CPU utilization, scheduled only when the processor has spare cycles, tuned per device, and verified against your own acceptance tests before release.

Can Symbiote be added to devices already in the field?

Yes. It’s delivered as a firmware update with no hardware change, on the device’s next scheduled update.

How does Symbiote relate to FDA Section 524B?

It contributes runtime evidence from fielded devices to your postmarket picture. It doesn’t replace your risk management process, your software bill of materials, or your patch program.

Does the EU Cyber Resilience Act apply to our medical device?

Generally no. Article 2 excludes products covered by Regulation (EU) 2017/745 and Regulation (EU) 2017/746. Accessories and connected software outside MDR scope can still fall under it, so it is worth confirming product by product.

// NEXT STEP

Contact Us.

Learn how Symbiote integrates with your medical device firmware, what it monitors and protects, and how it impacts performance.