Full Report
Intelligent automation company Gluware announced Gluware IoMT Exposure Management, bringing its proven automation platform to the Internet of... The post Gluware extends automation platform to automate CVE matching and remediation across IoMT devices appeared first on Industrial Cyber.
Analysis Summary
# Industry News: Gluware Extends Automation Platform to Secure IoMT Ecosystems
## Summary
Intelligent automation leader Gluware has launched **Gluware IoMT Exposure Management**, a new solution designed to automate the identification and remediation of vulnerabilities in medical devices. By bridging the gap between vulnerability discovery and clinical patch execution, the platform aims to reduce the manual overhead and operational risks associated with securing critical healthcare infrastructure.
## Key Details
- **Date:** October 01, 2026
- **Companies Involved:** Gluware (Lead), Claroty (Integration Partner), Microsoft (Data Source)
- **Category:** Product Launch / Market Expansion
## The Story
The Internet of Medical Things (IoMT)—including infusion pumps, imaging systems, and patient monitors—has become a significant security bottleneck. According to NIST, CVE submissions surged 263% between 2020 and 2025, leaving hospital IT teams struggling to manage a backlog where the average device carries 6.2 known vulnerabilities. Unlike standard IT assets, medical devices cannot be easily taken offline for patching due to patient care requirements and strict regulatory audit trails.
Gluware’s new solution addresses this "remediation gap" by connecting five operational stages into a single pipeline. It integrates with **Claroty xDome** for asset inventory, enriches data via the **MITRE CVE Program**, and pulls specific updates from the **Microsoft Update Catalog**. Most critically, it provides a shared operational record through a new **IoT Device Manager**, allowing clinical engineering and IT departments to synchronize remediation efforts without disrupting hospital workflows.
## Business Impact
### For the Companies Involved
- **Gluware:** Successfully pivots its core network automation expertise into the high-value healthcare vertical, diversifying revenue streams.
- **Claroty:** Strengthens its ecosystem position as the preferred "source of truth" for clinical inventory.
### For Competitors
- Traditional Vulnerability Management (VM) players (e.g., Tenable, Qualys) face pressure to offer deeper automated remediation rather than just discovery/scanning.
- Niche IoMT security startups may find it harder to compete against a platform that integrates IoMT security into the broader enterprise network management stack.
### For Customers
- **Hospitals/Healthcare Providers:** Reduced operational costs associated with manual patching and a lower risk of expensive data breaches (currently averaging $7.42 million per incident).
- **Clinical Staff:** Improved device uptime and reliability through coordinated, scheduled maintenance.
### For the Market
- Signals a shift from "Visibility" to "Remediation" in the OT/IoMT security market.
- Highlights the growing necessity for cross-functional tools that serve both IT and specialized engineering teams (Clinical Engineering).
## Technical Implications
The platform utilizes Gluware’s **DIAL (Device Interaction and Automation Layer)**, which provides semantic translation across 56 operating systems. This allows the tool to execute changes across a heterogeneous environment of legacy and modern medical hardware. The integration of **component-level matching** is a significant technical advancement, reducing false positives by checking if specific vulnerable sub-components are actually active in the device configuration.
## Strategic Analysis
- **Market Positioning:** Gluware is positioning itself as the "operational bridge" between cybersecurity discovery tools and clinical reality.
- **Competitive Advantage:** Leveraging a proven enterprise-grade automation engine gives Gluware a "battle-tested" reputation that pure-play startups lack.
- **Challenges:** Navigating the complex regulatory requirements of medical device manufacturers (MDMs) who may have restrictive terms regarding third-party software updates.
## Industry Reactions
- **Analyst Opinion:** Market watchers note that the 263% increase in CVEs has rendered manual spreadsheets obsolete, making automation a "must-have" rather than a "nice-to-have."
- **Market Response:** The partnership-led approach (Claroty/Microsoft) suggests a collaborative industry move toward integrated security fabrics rather than isolated tools.
## Future Outlook
- **Predictions:** Expect to see Gluware expand this model into other highly regulated OT sectors like energy or water utilities, where "downtime is not an option."
- **Watch For:** Potential friction or formal partnerships with Medical Device Manufacturers (MDMs) to ensure automated patching does not void warranties.
## For Security Professionals
Practitioners in healthcare should evaluate how this reduces the "Mean Time to Remediation" (MTTR). This tool shifts the burden from manual ticket entry to overseen automation, allowing security teams to focus on high-level risk strategy rather than the logistics of patch deployment for thousands of disparate devices.