ELTON

How ELTON helps manufacturers avoid unnecessary fixes, recalls, and fire drills

The most expensive mistake in medical device cybersecurity is not missing a vulnerability. It is fixing one that never needed to be fixed. A rushed patch on a validated system carries real cost: regression testing, field updates, disrupted clinical workflows, and in the worst cases a recall that protected nobody because the finding was never exploitable to begin with.

And yet the patch everything reflex persists. Teams remediate every reported CVE because fixing feels safer than explaining. I think that instinct gets the risk exactly backwards.

FDA does not ask you to fix everything

A common misconception is that FDA expects every vulnerability remediated. The guidance is consistently risk based. What reviewers require is evidence: that you understand the vulnerability, how it applies to your specific device, and why remediation is or is not necessary. Choosing not to fix is a legitimate regulatory outcome when the reasoning holds up.

Section 524B put premarket and postmarket vulnerability management squarely in scope. It did not mandate that every CVE be patched. What it demands is a process, and proof the process ran.

The problem is that most vulnerability data cannot carry that burden. CVSS base scores are generic by design. Scanner output knows nothing about your architecture. An engineer's hallway opinion that the component is not reachable is worth exactly nothing in an audit unless it is tied to the product and written down.

In an audit, an unsupported claim is indistinguishable from wishful thinking.

From opinion to evidence

We built ELTON to make non-remediation defensible. Every vulnerability is evaluated against a digital twin of the product, constructed from the QMS documentation you already maintain: components, data flows, trust boundaries, assets, and security controls. The twin turns each finding into a set of answerable questions.

  • Can the vulnerable component be reached from any real attack surface?
  • Does the attacker hold the privileges the exploit requires?
  • Are the prerequisite conditions present in the shipped configuration?
  • Do compensating controls break the attack path?
  • Would exploitation meaningfully affect safety or effectiveness?

When the answers show exploitation is not feasible, ELTON documents that conclusion with rationale traced to the architecture. Not adjectives. A chain of reasoning a reviewer can follow from claim to component.

Two ways to answer the same CVE feed Patch everything 100 reported CVEs 100 rushed patches regression risk field updates recall exposure High effort, new risk, nothing proven Evidence first with ELTON 100 reported CVEs Digital twin exploitability checks reachable? privileges? controls? impact? Fix now the 1% that matter Evidence + VEX the 99%, documented Short fix list, audit ready record
Same feed, two postures. Rushed remediation creates work and new risk, while exploitability evidence produces a short fix list and a defensible record.

Scoring with FDA's own rubric

Adjusted ratings only help if the reviewer trusts the method behind them. So ELTON applies the CVSS rubric recognized under FDA's Medical Device Development Tool program (MITRE's rubric, MDDT Q171974) at scale. A downgraded finding is the outcome of a documented methodology reviewers are trained to recognize, not an argument against their expectations.

That shifts the entire conversation. Instead of debating severity labels, you are walking through evidence and method together. Reviews move faster when both sides trust the instrument.

Justification that survives an audit

Defensible non-remediation only works if it lives inside the quality system. ELTON generates documentation that drops into design history files, risk management files, and postmarket cybersecurity records, with every decision traceable to its inputs, analysis, and outputs. Because each commercial release gets its own twin, the justification stays pinned to the exact configuration under review. VEX output carries the same conclusions in machine-readable form for the customers and regulators who ask.

The practical effect is focus. Across products we see a small fraction of findings, call it the 1%, that genuinely require a fix, and the job is to prove why the other 99% do not. Emergency patch cycles become rare. Engineering time goes to the vulnerabilities that actually move risk.

I have watched manufacturers burn entire quarters, and occasionally pull product from the field, over findings that were never reachable on the shipped device. Nobody was safer afterward. Fixing everything is not diligence, it is unexamined fear with a budget, and FDA never asked for it. They asked for evidence. Give them that instead.

← All intelligence
Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo