By Michael Haugh, Vice-President of Product Marketing, Gluware
Every hospital security team knows the number by heart: thousands of connected medical devices, running dozens of different operating systems and firmware versions, many of them impossible to take offline without disrupting patient care. Internet of Medical Things (IoMT) devices, including infusion pumps, imaging systems, patient monitors, and the workstations that run them, have become one of the largest and least visible attack surfaces in healthcare. Unlike a laptop or a server, you can’t just push a patch to a ventilator and hope for the best.
That gap is what led Gluware to expand its automation platform into medical device patching and develop a solution that we’re calling IoMT Exposure Management.
Where It Started
The push didn’t come from a product roadmap meeting; it came from a customer. Ohio State University Medical Center (OSU MC), a large research hospital already using Gluware for network automation, came to us with a specific, painful problem: patching its IoMT fleet was almost entirely manual. Security teams were pulling vulnerability data from one system, cross-referencing Common Vulnerabilities and Exposures (CVEs) by hand, hunting down the right Microsoft Knowledge Base (KB) for each device platform, and then routing every change through a separate ticketing process before anything could be touched. For a fleet of thousands of devices, that process meant known vulnerabilities sat unpatched for weeks or months at a time, not because anyone was negligent, but because the workflow simply couldn’t move fast enough.
That customer was already trusting Gluware to automate their network. It made sense to ask: could the same automation-first approach solve this problem too?
What We Built
The answer became a full IoMT patching solution, built on top of the Gluware automation suite customers already know, extended with a new set of integrations and interfaces purpose-built for medical device environments.
On the data side, Gluware now integrates with Claroty xDome to pull in medical device inventory and the vulnerability relationships tied to each device, the foundation of knowing what’s actually on the network and what’s exposed. From there, Gluware enriches every CVE against MITRE, giving security teams authoritative, up-to-date detail on severity and impact rather than relying on stale or incomplete internal records. Once a vulnerability is confirmed, Gluware integrates with Microsoft Security Updates to retrieve the applicable Knowledge Bases (KBs) for that specific device platform and download the patch directly, closing the loop between “here’s a vulnerability” and “here’s the fix” automatically.
On the platform side, we extended the Gluware application suite with the interfaces this workflow needed: a new IoT Device Manager for unified visibility and lifecycle tracking across the medical device fleet, a new IoT Platform Manager to coordinate policy and orchestration across device groups, and enhancements to OS Manager so it can resolve and apply OS-level patches to medical devices with the same rigor Gluware customers already rely on for network infrastructure. And because clinical systems are under strict change control, Gluware also integrates with ServiceNow to automate the opening of a change ticket for every patch action, so speed doesn’t come at the cost of an audit trail and approval cycle.
Why This Matters for Customers Already Using Gluware
The most important part of this story isn’t any single integration; it’s what it means for the customers who are already running Gluware today. If your team is already using Gluware for network automation, you’re not being asked to evaluate, procure, and onboard an entirely separate platform to solve medical device patching. The same suite, the same automation model, and in many cases the same team can now be extended to cover IoMT, turning a new and difficult problem into an expansion of a capability you already trust.
For healthcare organizations that haven’t yet automated network operations, it’s the reverse story: a single platform investment now covers both network automation and the rising demand to secure and patch medical devices, rather than standing up separate tools and separate processes for each. And that solution can address the pressing matter of protecting both the network and medical devices against AI-driven threats, and IT teams against the avalanche of CVEs flooding in as a result of those threats.
The Bigger Picture
Healthcare security teams are being asked to do more with the same headcount, against a device landscape that keeps growing more complex and a threat environment that is getting more threatening due to AI weaponization. Manual CVE research and manual patch matching were never going to scale to the size of a modern hospital’s IoMT fleet. By connecting Claroty xDome, MITRE, Microsoft, and ServiceNow into a single automated pipeline and building the device and platform management interfaces to support it, Gluware is giving hospitals a way to close the gap between “vulnerability discovered” and “vulnerability patched” without adding manual effort or sacrificing the change control clinical environments require.
It started with one research hospital asking a hard question. It’s now an integrated part of how Gluware healthcare customers can protect the devices closest to patient care.
Interested in what IoMT Exposure Management and its patching workflow could look like for your organization? Request an IoMT demo and learn more and to join our early access program.