- Provision and maintenance of physical sites
- Provision and maintenance of virtual infrastructure
- Provision and maintenance of the application hosting platform
- Administration and operation of the information system
- Backup of heath data
That’s the reason why companies and service providers need to continuously to get and maintain international certifications such as ISO 27001 that provides a framework for information security management systems. These regulations and standards form the backbone of cybersecurity efforts in the industry, and we will not be able to work with companies that cannot ensure the security of data that they collect or manage for other companies.
Vendor information risk process
To address the cybersecurity risks associated with third-party vendors, many companies, have implemented vendor Information risk processes. This process evaluates vendors based on three key criteria:
- Relation to critical business functions. (e.g., research & development)
- Type of data stored or managed (e.g., confidential product information or personal data)
- Criticality of the service to the company and level of access to internal systems
CROs, given their critical role and access to sensitive data, typically meet all these criteria and are thus subject to rigorous cybersecurity assessments.
Cybersecurity assessment in CRO qualification
The cybersecurity assessment has become an integral part of the CRO qualification process for clinical studies. The assessment typically involves the following steps:
- Verification of valid and recognized cybersecurity certifications
- If certifications are lacking or invalid, a detailed assessment via a specialized platform
- Evaluation of the assessment results (accepted/accepted with corrective actions/rejected)
The assessment covers various areas, including data privacy, data protection, third party management, and business continuity. It also evaluates the CRO's capacity to identify, protect, detect, and react to cyberattacks.
Risk management
The cybersecurity of service providers is a question of risk management, and it should be adapted to the needs of the sponsor. In cases where a CRO's cybersecurity assessment is insufficient, a business needs to evaluate the risks that they would be exposed to if they select the vendor. While this approach should be used sparingly, it provides a mechanism for balancing business needs with cybersecurity requirements.
CRO selection and qualification process
The CRO selection and qualification process is a multi-step journey that integrates cybersecurity considerations:
- CRO identification
- Service qualification (including data privacy)
- Cybersecurity assessment
- Evaluation of qualification and cybersecurity results
- Contract signature
- Start of services
This process ensures that cybersecurity is considered from the outset and remains a key factor throughout the engagement with the CRO.
Conclusion
As the digital landscape of clinical research continues to evolve, so too must our approach to cybersecurity. The integration of cybersecurity assessments into the CRO selection and qualification process represents a critical step in protecting sensitive data and maintaining the integrity of clinical trials and it should be integrated into the standard qualification process.
To conclude, the key takeaways I would like to provide are:
- Collaboration between digital and business teams is essential to ensure comprehensive cybersecurity.
- Cybersecurity assessments should be a standard part of CRO selection, qualification, and ongoing audits.
- The criticality of data managed in clinical studies necessitates robust cybersecurity measures.
- Continuous work with service providers to develop improvement plans and mitigate risks is crucial.
Our responsibility is to ensure data protection of consumers and patients. In an era where cyber threats are increasingly sophisticated and frequent, this responsibility has never been more important.
The pharmaceutical industry, with its wealth of sensitive data and critical research, must remain at the forefront of cybersecurity efforts. By integrating cybersecurity considerations into every aspect of vendor selection and management, companies can better protect themselves, their research, and most importantly, the patients they serve.
Martin Rodriguez, Medical Strategy & Operational Effectiveness Head, Opella