RCCE Course
Course #225

Medical devices Incident Response: Basics

📊 Level: Intermediate
⏱️ Duration: 2 Days
🏷️ Track: OT Security
📋 Prerequisites: Foundations
🖥️ Mode: Online Instructor-Led
📝 Course Description

RCCE students will learn medical device cybersecurity including FDA premarket and postmarket guidance, medical device network security, legacy device protection, clinical network segmentation, and healthcare IoT security. RCCE students will learn to assess medical device cybersecurity risks in clinical environments, implement network segmentation to isolate medical devices from general IT networks, manage legacy medical device vulnerabilities without disrupting patient care, comply with FDA cybersecurity guidance and HIPAA security requirements, monitor medical device communications for anomalies, coordinate vulnerability disclosure with device manufacturers, and respond to cybersecurity incidents affecting medical devices while maintaining patient safety. This incident response course prepares students to act decisively during security incidents with structured workflows and clear decision frameworks. Building on core knowledge, RCCE students will learn containment, evidence collection, eradication, and recovery procedures specific to this domain. Students practice incident scenarios that build the composure, coordination, and documentation skills essential for effective incident handling.

🎯 Target Audience
  • Security Engineers building defensive controls
  • Security Analysts and Blue Team members
  • Systems Administrators with security responsibilities
  • GRC and Risk Professionals supporting controls
  • Professionals implementing Medical devices Incident Response: Basics
🧠 What You Will Learn
  • Build detections and response workflows for privilege escalation
  • Explain Course Overview fundamentals
  • Execute hands-on tasks for what you will learn
  • Execute hands-on tasks for domain & level — covering Domain: OT Security | Foundations.
  • Execute hands-on tasks for learning objectives
  • Execute hands-on tasks for unique challenges
  • Execute hands-on tasks for regulatory drivers — covering Implantable devices, Life-critical operations.
  • Execute hands-on tasks for medical device categories & cyber risk
  • Execute hands-on tasks for device class
  • Execute hands-on tasks for network exposure
  • Execute hands-on tasks for risk level
  • Execute hands-on tasks for diagnostic imaging
📚 Course Outline
Module 01Medical Devices Incident Response:
Module 02Course Overview
Module 03What You Will Learn
Module 04Domain & Level
Module 05Learning Objectives
Module 06Unique Challenges
Module 07Regulatory Drivers
Module 08Medical Device Categories & Cyber Risk
Module 09Device Class
Module 10Network Exposure
Module 11Risk Level
Module 12Diagnostic Imaging
Module 13Why Medical Devices Are High-Risk Targets
Module 14Patient Data Value
🧪 Lab Details

All hands-on labs run on Rocheston Rose X OS. Students practice medical devices incident response: basics by implementing the controls discussed in class, with a focus on real-world deployment, monitoring, and validation.

  • Lab 1: Build detections and response workflows for privilege escalation
  • Lab 2: Explain Course Overview fundamentals
  • Lab 3: Execute hands-on tasks for what you will learn
  • Lab 4: Execute hands-on tasks for domain & level
  • Lab 5: Execute hands-on tasks for learning objectives
📊 Skill Level
Intermediate
Beginner Intermediate Advanced Expert
Duration
2 Days
🎓
Certificate
Completion
🖥️
Lab Platform
Rose X OS
👨‍🏫
Mode of Training
Online Instructor-Led
🔥
Platform
Zelfire
🐦‍⬛
Cyber Range
Raven
📓
Study Material
CyberNotes
🏆 Certificate

Upon successful completion of this course, students will receive an official RCCE Course Completion Certificate for Medical devices Incident Response: Basics, verifiable through the Rocheston certification portal.

🔑 Student Access & Materials
  • Full access to all course materials and slide decks
  • Hands-on lab access on Rocheston Rose X OS environment
  • Access to Rocheston CyberNotes
  • Access to Rocheston Zelfire — EDR/XDR SIEM platform
  • Access to Rocheston Raven — online cyber range exercise platform
  • Access to Rocheston Vulnerability Vines AI