Dossier · Acquired asset · 6 independent sources

CyberMDX

Cybersecurity Acquired asset Dual-Use Technology Founded 2017

Last updated: Jul 31, 2026

CyberMDX developed agentless cybersecurity and asset-intelligence software for connected medical devices, clinical networks, and Internet of Medical Things environments. Forescout acquired the company in 2022, and its capabilities now appear in Forescout's medical-device security portfolio rather than as an independent startup.

Company Overview

CyberMDX built a healthcare-specific security platform for environments containing medical devices that are difficult to scan, patch, or instrument with conventional endpoint agents. Its approach combined passive and active network inspection, device fingerprinting, medical-protocol expertise, endpoint classification, vulnerability and exposure assessment, and contextual risk prioritization. The product was intended to help a hospital identify what is connected, understand how devices communicate, and decide which remediation or containment action could reduce risk without interrupting care. That focus matters because imaging systems, patient monitors, infusion equipment, laboratory systems, and other clinical assets often run legacy software, have long replacement cycles, and cannot tolerate security controls that interfere with availability.

The customer problem was broader than inventory. CyberMDX connected device identity and network behavior to clinical and biomedical workflows, giving security operations teams a more useful picture of the attack surface than a generic IP or MAC-address list. Its agentless model was particularly relevant where manufacturers restrict software installation or where clinical engineering teams need changes to be reversible and carefully governed. The likely buying center therefore spans the CISO, infrastructure and network teams, biomedical engineering, compliance, and clinical operations. The product also fits integration-led deployments involving SIEM, NAC, segmentation, incident response, and asset-management systems; success depends on accurate classification and actionable workflow integration rather than on dashboards alone.

The market remains strategically important, but commercialization is difficult. Hospitals have expanding connected-device estates and high consequences from ransomware, unauthorized access, and clinical-network disruption. At the same time, healthcare security budgets compete with patient-care priorities, procurement and validation cycles are long, and a vendor must prove that risk scoring translates into safer operations. CyberMDX had meaningful category validation through reported institutional deployments, vulnerability research, partnerships, and investor backing, but the public record does not provide a current standalone view of recurring revenue, retention, product share, or post-acquisition financial performance. Forescout's acquisition is the clearest commercialization signal: it gave Forescout additional IoMT expertise and allowed the technology to be distributed through a larger device-visibility and control platform.

Competitive pressure comes from both healthcare specialists and broader cyber-asset-management vendors. Medigate, later acquired by Claroty, established a strong adjacent benchmark in medical-device security; Armis, Cynerio, Asimily, and Ordr address overlapping device visibility, risk, and response needs, while Forescout itself competes as the larger platform owner. CyberMDX's historical differentiation was healthcare-native device context and medical-network workflow knowledge, not an exclusive underlying security primitive. After acquisition, that specialization may be more valuable as part of a broader IT, IoT, OT, and IoMT control plane, but it is harder for external observers to isolate CyberMDX's independent product performance or determine how much of the original brand and team remain.

The defense and national-security case is credible but bounded. Military treatment facilities, defense-affiliated hospitals, public-health infrastructure, and deployed or temporary care environments face the same constraints around unmanaged devices, heterogeneous protocols, patient safety, and operational continuity. Agentless discovery and risk-based segmentation can support resilience in those settings. However, the available evidence establishes healthcare cybersecurity capability, not deployment in military networks or protection of weapons systems. CyberMDX should therefore be treated as a dual-use healthcare-infrastructure security asset and a useful reference for mission-critical medical environments, rather than as a general defense-cyber platform.

Dual-Use Assessment

Military & Commercial Applications

CyberMDX has substantive but domain-bounded dual-use potential. Its agentless medical-device discovery, clinical-network visibility, risk assessment, and segmentation-oriented response capabilities can protect civilian hospitals as well as military treatment facilities, defense-affiliated healthcare networks, and other mission-critical medical operations. The evidence supports healthcare-infrastructure applicability; it does not support claims of weapons-system, battlefield, or confirmed military deployment relevance.

Strategic Fit Assessment

CyberMDX is not an active startup investment-screening signal because Forescout acquired it in 2022 and the independent company no longer offers direct venture access. The acquisition is nevertheless useful evidence that a larger cybersecurity platform valued healthcare-device expertise and product integration. Diligence should focus on capability retention, product integration, customer continuity, and the strategic value of the former technology within Forescout rather than on a standalone financing or growth thesis.

Strategic Value to U.S.-Israel Alliance

CyberMDX is strategically valuable as an acquired healthcare-cyber capability and as a reference case for securing constrained, safety-critical connected devices. Its strongest relevance is to hospital resilience, medical-device visibility, and defense healthcare infrastructure, where security controls must coexist with clinical availability. Current Forescout materials indicate that the former CyberMDX Healthcare Security Suite continues to inform medical-device security offerings, but the public record does not establish the exact degree of product, team, or brand continuity.

Key Technologies

  • Agentless discovery and classification of IoMT and clinical assets
  • Passive and active network inspection
  • Medical-protocol and device fingerprint intelligence
  • Vulnerability, exposure, and operational-criticality risk scoring
  • Network-flow and anomaly analysis for clinical environments
  • Context-aware segmentation and containment integrations
  • Biomedical workflow and security-operations support

Use Cases & Applications

  • Continuous inventory of connected medical devices across hospital networks
  • Prioritized remediation of vulnerable or operationally critical clinical assets
  • Detection and investigation of suspicious traffic involving medical equipment
  • Risk-informed segmentation and network-access policy for IoMT devices
  • Coordination between hospital SOC, IT, and biomedical engineering teams
  • Security posture monitoring for defense hospitals and military treatment facilities
  • Cyber resilience assessment for temporary or field-deployed medical infrastructure

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Forescout acquisition announcement Official announcement of Forescout's February 2022 acquisition and CyberMDX's medical-device visibility, risk management, and threat-prevention capabilities.
  • Forescout Medical Device Security Current Forescout product page identifying CyberMDX as acquired in 2022 and describing medical-device discovery, classification, and risk assessment.
  • Forescout Assist for Healthcare Current Forescout page stating that Medical Device Security was formerly the CyberMDX Healthcare Security Suite.
  • Cisco Security and CyberMDX Partner documentation describing CyberMDX's healthcare device visibility, AI-assisted classification, risk assessment, and segmentation integration.
  • Calcalist acquisition report Reputable 2022 report supporting the Israeli origin, 2017 founding, acquisition context, and approximately 50 employees joining Forescout.
  • Forescout research on CyberMDX vulnerability work Official research page documenting vulnerability research first identified by CyberMDX researchers in medical and IoT devices.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.