CPHI Milan 2026

Strategies for Securing Pharma Manufacturing’s Fast-expanding Data Landscape

Juan Jose Lopez, Associate Director of Cyber Security Architecture and Governance, Life Sciences Manufacturing, Cognizant

In this article, Juan Jose Lopez, Associate Director of Cyber Security Architecture and Governance, Life Sciences Manufacturing at Cognizant, will explore the challenges of AI and how companies can overcome them to effectively harness AI to keep safe their most valuable asset - their data.

Securing Pharma Manufacturing

AI: The key to protecting life sciences data from cyber criminals

Cyber security has become increasingly critical in the life sciences industry, where sensitive data such as patient information, research findings, and intellectual property (IP) are at risk from sophisticated cyber-attacks. This data is extremely valuable, especially when related to the development of blockbuster drugs as it can often be a company’s most valuable asset.

Cyber criminals have become increasingly sophisticated in orchestrating attacks to access this critical data or disrupt a company’s ability to harness it. In addition to IP theft, they may carry out ransomware attacks, which have the potential to cripple a life sciences company’s operations.

Traditional cyber security measures are no longer sufficient to protect against sophisticated cyber-attacks. The same digitalization and integration of data systems that have increased the speed and efficiency of drug development can also leave companies vulnerable if they fail to adopt a more comprehensive approach to security, incorporating the latest technologies.

Artificial intelligence (AI) has a crucial part to play not just when it comes to enhancing the effectiveness and value of life sciences data management, but also in ensuring an organization’s cyber security is fit for the future. AI can be used to detect and respond to cyber-attacks in real-time, and it can also be used to identify and mitigate vulnerabilities in IT systems. By leveraging the power of AI, organizations in the life sciences industry can significantly improve their cyber security posture.

But, as with any new technology, companies face challenges when integrating AI into their cyber security strategy.

The state of cyber security in the life sciences industry

In recent years, the pharmaceutical industry has made significant strides in data protection and cyber security. According to a recent study, the cost of a pharma data breach decreased from $5.01 million in fiscal year 2022 to $4.82 million in 2023. Furthermore, the time taken to detect (189 days) and contain (66 days) data breaches is now shorter than the global average of 204 days and 73 days, respectively.

Malicious attacks (45%), followed by human errors (28%) and IT failures (27%), are the most common root causes of pharma data breaches. Phishing-compromised credentials and cloud misconfigurations are the primary attack vectors employed by threat actors. On-premises storage and private clouds are less frequently breached than public clouds, while multi-cloud environments are the least secure and incur the highest breach costs.

The consequences of these data breaches for the life sciences industry extend beyond mere inconvenience. Cyber threats can disrupt critical operations and manufacturing processes, affecting the supply chain and product distribution. They can result in the theft of IP, as well as patient data. The former can lead to significant loss of profit, while the latter can result in costly regulatory and legal repercussions.

The pharmaceutical industry is subject to strict regulatory requirements regarding data protection and privacy, such as Good Manufacturing Practices (GMP), Good Laboratory Practices (GLP), and data privacy regulations (e.g., the EU’s General Data Protection Regulation [GDPR] or the U.S. Health Insurance Portability and Accountability Act [HIPAA]). Cyber security breaches can lead to non-compliance with these regulations, resulting in legal actions, fines, and damage to the company's reputation. The average HIPAA penalty has reached $1.5 million, with penalties ranging from $137 to $68,928 per violation, depending on the level of culpability. 17 October 2024 is also the deadline for EU Member States to transpose the NIS2 Directive into applicable law. For specific industry sectors, failure to comply with the NIS2 Directive and applicable laws could result in company fines up to €10m or 2% of total global annual revenue for essential entities or up to €7m or 1.4% of total global annual revenue for important entities, whichever figure is higher.

With all of this in mind, it is no surprise that many life sciences companies are exploring how to upgrade their cyber security processes using new technologies. Working with expert digital transformation partners is essential to ensure companies have access to the latest innovations, and that these are effectively integrated into their existing infrastructure for maximum impact. One of the most important new technologies currently being explored by these partnerships between life sciences companies and their digital partners is AI.

cyber security in life sciences

The potential of AI to transform cyber security

AI offers a dynamic and proactive approach to threat detection and risk mitigation. By leveraging AI's capabilities in their digital transformation journey, pharmaceutical companies can enhance their security posture, reduce the risk of data breaches and maintain compliance with regulatory requirements. The new generation of generative AI tools - a type of AI that uses the learning and automation capabilities of AI to offer human-like problem-solving and decision-making - can further improve cyber security. It can potentially analyze reams of security data across systems in real time to make precise recommendations without the need for manual intervention to help organizations boost their data safety. Key benefits of harnessing AI for life science cyber security include:

1. Enhancing threat detection and anticipating potential attacks

AI - and generative AI - offers significant advantages when it comes to enhancing threat detection and response. Traditional systems primarily rely on predefined rules and known threat signatures. As a result, they can be limited in their scope and adaptability to evolving threats.

AI, empowered by machine learning (ML), offers real-time analysis of vast amounts of data. This capability enables the identification of patterns and anomalies indicative of potential security breaches. Immediate response and prevention of attacks are facilitated before substantial damage occurs. AI-driven systems also continuously monitor network traffic, user behavior and system activities to detect anomalies that could signal potential cyber threats.

AI can also be used as a predictive analytical tool to anticipate future cyber-attacks. By analyzing historical data and identifying trends, generative AI systems in particular can forecast the likelihood of future attacks and their potential targets. This foresight empowers pharmaceutical companies to proactively strengthen their defenses and allocate resources more strategically.

2. Automation of routine security tasks

Managing large and intricate IT infrastructures - with many non-integrated sub-systems that handle data not compatible with that in other databases - is a common challenge for many companies, especially those in the life sciences industry. AI enables the automation of routine security tasks that traditionally have to be carried out manually. These tasks include monitoring network traffic, updating security protocols and handling access controls. Automation not only lightens the load for human cyber security professionals but also minimizes the likelihood of errors, a major contributor to security breaches. By implementing AI-driven automation, security measures are uniformly enforced, upholding a high level of vigilance throughout the organization.

3. Optimizing the protection of IP and patient data

In the pharmaceutical industry, where highly sensitive data such as IP and personal health information is handled, AI plays a crucial role in enhancing data protection. Advanced encryption techniques and secure storage solutions are employed by AI to safeguard sensitive data. Moreover, AI algorithms effectively manage and monitor access to this data, ensuring that only authorized personnel can retrieve or modify it. This is paramount for adhering to stringent data protection regulations such as GDPR and HIPAA, which demand the implementation of robust security measures.

4. Sharing threat intelligence

Through advancements in generative AI, the pharmaceutical industry has gained the ability to efficiently share threat intelligence. By consolidating and analyzing data from diverse sources, AI offers a comprehensive perspective of potential threats. This collaborative intelligence empowers organizations to stay vigilant against emerging risks and adopt effective strategies from industry peers. Additionally, AI's capabilities enable the standardization of threat intelligence formats, facilitating seamless sharing and utilization of this vital information.

5. Supplementing the skills of human professionals

The cyber security skills gap is a significant concern for the pharmaceutical industry. AI can help bridge this gap by augmenting the capabilities of existing security teams. AI-driven tools can provide actionable insights and recommendations, helping less experienced staff make informed decisions. Additionally, generative AI in particular can assist in training programs by simulating cyber-attack scenarios and providing interactive learning experiences.

Overcoming AI implementation challenges to build a robust cyber security system

The pharmaceutical industry, with its sensitive data and increasingly sophisticated cyber threats, can greatly benefit from AI-driven cyber security solutions. However, for life science companies to successfully implement AI in cyber security, several significant challenges must be overcome.

Key considerations that must be taken into account before embarking on an AI-driven cyber security digital transformation project include:

1) Review and address the availability and quality of your data at the beginning of the project

AI systems rely heavily on vast amounts of high-quality data to function effectively. In the pharmaceutical industry in particular, data may be siloed across different departments or legacy systems, making it difficult to aggregate and analyze comprehensively. Additionally, ensuring that the data is accurate, complete and up to date is essential for training AI models. Poor data quality can lead to ineffective AI solutions, which may miss critical threats or generate false positives, undermining trust in the technology. Working with experts at the beginning of a project to assess data quality and identify the databases and systems where relevant data may be stored can allow companies to map and plan an effective AI-enabled cyber security solution suitable for their unique needs.

2) Explore how to integrate new AI tools with legacy systems

Pharmaceutical companies often operate on complex IT infrastructures that include a mix of modern and legacy systems. Integrating AI-driven cyber security solutions with these existing systems can be challenging. Legacy systems may lack the necessary interfaces or compatibility for seamless integration, requiring extensive customization and potentially costly upgrades. Integration of these systems should be considered as early as possible in the project to ensure the finished solution is effective and fit for purpose, without unnecessary costs being incurred to address unforeseen issues.

3) Explore regulatory compliance issues

Implementing AI- and generative AI-driven cyber security solutions must comply with GDPR, HIPAA, and industry-specific standards. Ensuring that AI systems adhere to these regulations can be complex and time-consuming. Non-compliance can result in severe penalties, legal issues and reputational damage. Expert support in addressing these regulatory considerations can help ensure the finished system is compliant and cost-effective.

4) Build and implement an appropriate training regimen early

Implementing AI in cyber security requires a workforce skilled in AI and generative AI technologies and cyber security practices. Early upskilling of team members can help ensure that companies have the skills and expertise in place to harness the new AI-enabled cyber security system effectively.

5) Early team engagement is essential to gain trust and acceptance

Establishing trust in cyber security solutions powered by AI can be difficult. Pharmaceutical company stakeholders, such as executives, IT professionals and end-users, may harbor skepticism regarding the tool’s capabilities and reliability. Bringing team members into the planning and implementation process early can foster a comprehensive understanding of the new solution’s operations while showcasing its effectiveness.

6) Plan for a rapidly evolving threat landscape

Cyber criminals are constantly developing new tactics and techniques to evade cyber security processes. AI systems must be able to adapt quickly to these changes to remain effective. Ongoing training and updating of AI models are vital to address this issue. As this can be resource-intensive, early consideration can help plan for regular reviews and updates helping to streamline the resources needed.

Implementing a new technology, such as AI, can be daunting, especially for life sciences companies with extensive legacy infrastructure. Working closely with a specialist digital transformation partner with a strong track record in supporting companies to harness the power of AI can help organizations overcome integration challenges. In doing so, they can help ensure that the finished AI-driven cyber security system is effective and plugged into the critical systems to deliver optimum performance with minimal disruption.

Pharma cybersecurity

The future of AI-enabled cyber security in life sciences

The pharmaceutical industry is witnessing a growing synergy between AI, generative AI and cyber security, driven by ongoing technological advancements and heightened awareness of cyber threats.

The future of AI in pharmaceutical cyber security will be shaped by continuous progress in AI technology. Sophisticated ML and deep learning algorithms capable of analyzing vast datasets in real time and identifying patterns and anomalies indicative of cyber threats will provide proactive threat and vulnerability detection. AI will also automate tasks, such as vulnerability scanning, patch management, and compliance monitoring, and enhanced incident response processes, empowering cyber security professionals to focus on strategic activities.

Collaboration among AI and generative AI developers, cyber security experts and pharmaceutical companies will be pivotal in refining AI-powered security solutions for the sector over the coming years. By harnessing the expertise of digital transformation partners, life science companies can be confident that they have the support they need not just to provide a solution that works against today’s threats, but against the cyber security challenges of the future as well.

--Issue 05--

Author Bio

Juan Jose Lopez

Juan Jose Lopez, Associate Director of Cyber Security Architecture and Governance, Life Sciences Manufacturing at Cognizant, is focused on security process design, cybersecurity architecture assessment and governance for OT and IoT solutions. He has more than 15 years of experience as a Cybersecurity and Information Security Manager.