Cyber resilience: Protecting tomorrow's therapies before they reach tomorrow's patients

Digital
Digital lock - cyber security concept - black background

The life sciences sector has never been more innovative. Every year, hundreds of new companies are founded around promising therapies, diagnostics, medical technologies, and AI-enabled healthcare platforms. Many begin life with a handful of employees, modest operating budgets, and an overwhelming focus on advancing their science.

Yet, those same companies often possess assets worth many millions. Their value is rarely found in buildings or manufacturing plants – it lies in intellectual property, experimental data, proprietary algorithms, regulatory submissions, manufacturing know-how, and clinical evidence. Increasingly, those assets exist almost entirely in digital form.

That creates a paradox: an early-stage biotechnology company may resemble a small business in terms of size, but its information assets can rival those of a global pharmaceutical company in strategic importance.

As investors place increasing emphasis on operational maturity alongside scientific excellence, cyber resilience deserves to become part of the conversation from the earliest stages of growth.

A different kind of cyber risk

Cyber security guidance is often written either for large multinational organisations or for generic small businesses. Emerging life sciences companies occupy a very different position.

They are typically highly collaborative organisations, relying on extensive networks of external partners. Contract research organisations (CROs), contract development and manufacturing organisations (CDMOs), specialist laboratories, bioinformatics providers, cloud platforms, regulatory advisers, and consultants all play critical roles in developing new therapies.

For many companies, these partners collectively hold large volumes of valuable research data, patient information, and commercially sensitive intellectual property. The result is a digital ecosystem that is both highly interconnected and increasingly difficult to oversee.

Every additional supplier, cloud platform, or data exchange introduces another potential point of vulnerability. Cyber resilience is therefore no longer simply an internal IT issue – it extends across the entire supplier network.

Why early-stage companies are attractive targets

Life sciences organisations have become increasingly attractive to cyber criminals, not because they are easy targets, but because they hold information that is uniquely valuable.

Research data can take years and millions of pounds to generate, and clinical trial datasets cannot simply be recreated overnight. Manufacturing methods, proprietary biological processes, and AI models may underpin an entire company's future valuation. In many cases, the greatest risk is not immediate financial loss, but the theft of intellectual property that may only become apparent years later.

The threat is far from theoretical. In 2025, contract research organisation Inotiv disclosed a ransomware attack attributed to the Qilin group, which claimed to have stolen around 170GB of proprietary research data, disrupting ongoing research programmes. More recently, the cyber extortion group FulcrumSec claimed responsibility for stealing approximately 1.3TB of data from Novo Nordisk, including source code and molecular research. Whether motivated by financial gain or strategic intelligence gathering, these incidents demonstrate the value that cyber criminals place on life sciences organisations.

Nation-state actors have shown similar intent. The US Department of Justice has brought charges relating to attempts by Chinese state-sponsored hackers to steal COVID-19 vaccine research from American universities, while Google's Threat Intelligence Group has reported on a China-linked espionage campaign that spent more than a year inside academic and clinical research networks, quietly harvesting credentials and exfiltrating research data.

These examples illustrate why life sciences now sits alongside sectors such as financial services, energy, and critical infrastructure as a priority target for sophisticated attackers. For organisations conducting clinical research, the value lies not only in the personal data they hold, but also in years of scientific investment, intellectual property, and competitive advantage that cannot easily be recreated.

For founders focused on reaching the next funding milestone or clinical endpoint – and the patients who will ultimately depend on their innovations – cyber resilience can understandably feel like tomorrow's problem. Increasingly, it is today's.

Growth creates complexity

As companies move from Seed funding through Series A and toward Series B, operational complexity often accelerates much faster than internal capability. Headcount increases and supplier numbers multiply; clinical programmes expand and new systems are introduced; international collaboration becomes routine. Each of these developments creates additional opportunities for cyber exposure.

Importantly, many organisations remain lean by design. Rather than building large internal functions, they outsource specialist expertise wherever practical. That approach makes commercial sense, but it also means cyber resilience depends as much on external partners as on internal systems.

Understanding where critical information resides, who can access it, and how it is protected becomes a fundamental management responsibility.

Investors are asking different questions

Operational due diligence has evolved considerably over the past decade. Alongside questions about intellectual property, regulatory strategy, and financial controls, investors increasingly want confidence that companies understand and actively manage cyber risk.

They will want to know where critical research data is stored; which suppliers hold sensitive information; and how third parties are assessed before engagement. They will also consider whether the company has an incident response plan, how quickly operations could recover following a cyber incident; and whether a significant cyber event could delay key development milestones.

These questions are not simply about compliance. They provide insight into how well management understands operational risk and how effectively the organisation is preparing for growth.

Building resilience across the supplier ecosystem

No company can eliminate cyber risk entirely – what distinguishes more resilient organisations is a systematic approach to managing it. That begins with understanding which information assets matter most and identifying where they are held across both the organisation and its external suppliers.

Supplier selection should increasingly include consideration of cyber maturity alongside scientific capability, quality systems, and commercial performance. Appropriate contractual protections, clear responsibilities for data security, incident notification procedures, and ongoing supplier oversight all contribute to reducing exposure throughout the supply chain.

This is one area where procurement and supplier management can make an important contribution. Decisions made during supplier selection and contracting can significantly influence cyber resilience long before an incident occurs.

Equally important is developing internal awareness. Most successful cyber attacks continue to exploit people, rather than technology, making regular staff training, clear reporting procedures, and tested response plans essential even within relatively small organisations.

The evolving role of cyber insurance

Cyber insurance has evolved significantly over recent years. Historically, many organisations viewed it primarily as a financial backstop following a cyber incident. Today, leading insurers work with businesses to improve their cyber resilience before an attack occurs.

Underwriters increasingly assess factors such as governance, supplier dependencies, incident response planning, access controls, and staff awareness as indicators of organisational resilience. Companies demonstrating strong cyber hygiene are not only better protected against attack, but may also benefit from broader cover, improved policy terms, and more competitive premiums.

Many policies now include access to services such as external vulnerability assessments, employee phishing awareness training, incident response planning, and specialist cyber expertise that may otherwise be beyond the reach of many emerging businesses.

For life sciences organisations, insurance is also becoming more tailored to the sector's unique risk profile. Unlike many businesses, the greatest exposure is often not the loss of hardware or the ransom demand itself, but the disruption of clinical trials, the compromise of valuable research data, or an incident affecting a key third party such as a CRO, CDMO or cloud provider. As a result, insurers are increasingly assessing these operational dependencies as part of the underwriting process and structuring cover to better reflect the sector's unique exposures.

Equally important is the support provided when an incident occurs. Access to specialist forensic investigators, breach coaches, legal advisers, crisis communication experts, and technical recovery teams can substantially reduce the operational and financial impact of an attack. For an early-stage company approaching a funding round or critical clinical milestone, restoring operations quickly may be more valuable than the financial compensation itself.

Selecting the right cyber policy therefore requires more than comparing premiums or indemnity limits. Companies should understand what events are covered, how incidents involving third-party suppliers are treated, what specialist support is available, and whether the policy is designed to respond to the specific risks faced by life sciences businesses.

Cyber resilience is becoming a competitive advantage

The life sciences companies that succeed over the next decade will be distinguished by far more than the quality of their science. They will also demonstrate operational maturity, disciplined governance, and the ability to manage increasingly complex networks of partners and suppliers.

Cyber resilience should not be viewed simply as another compliance exercise or an unavoidable business cost. It is an investment in protecting intellectual property, maintaining investor confidence, preserving development timelines, and safeguarding the innovations that future patients may ultimately depend upon.

Building that resilience does not require enterprise-sized IT departments or unlimited budgets. It does require recognising cyber risk as a strategic capability from the earliest stages of growth and combining good governance, careful supplier management, informed leadership, and appropriate specialist support.

For emerging life sciences companies, protecting tomorrow's therapies increasingly begins with protecting today's information.

About the authors

Tom Wells is principal at Agar Advisory, a procurement and supply chain consultancy focused on supporting growing life sciences companies.

 

 

Lucy Barker-Hahlo is deputy head of Cyber, Technology and Media at Rokstone Athena Cyber, a London-based specialist cyber, technology, and media underwriting proposition within Rokstone, the international specialty (re)insurance MGA.

Image
pharmaphorum symbol
profile mask

Tom Wells & Lucy Barker-Hahlo