Cybersecurity

Why cyber resilience in pharma must extend into medicine value chains

Even once systems are restored, cyberattacks can still have cascading consequences for pharmaceutical companies and medical patients.

Even once systems are restored, cyberattacks can still have cascading consequences for pharmaceutical companies and medical patients. Image: Getty Images/iStockphoto

Ashish Gupta
Partner, PwC
Jonathan Sinclair
Head of Cyber Resilience, Roche
This article is part of: Centre for Cybersecurity
  • Cyber resilience in pharma and life sciences is no longer restricted to protecting systems, but also ensuring that medicines remain available to patients.
  • Pharma companies have strengthened their technical defences, yet many cyber resilience programmes struggle to establish business accountability.
  • A medicine value chain-based approach to cyber resilience connects cybersecurity, business continuity and operational decisions regarding patient access.

Cyber resilience in pharma can no longer be measured solely in terms of how quickly systems are restored. Ransomware, compromised supply chains and disruptions to operational technology can also subsequently halt production, delay batch releases and restrict patients’ access to medicines, even when systems are up and running once more. The strategic question is whether resilience programmes are designed to achieve the most important business outcome of all: maintaining a secure and continuous medicine supply.

This is especially pertinent now because pharmaceutical companies’ operating models are changing rapidly. Automated manufacturing, AI-enabled research, cloud platforms, data-rich research laboratories, consumer-led engagement and globally distributed suppliers are creating new value – but also new dependencies and avenues for cyber disruption. The World Economic Forum’s Global Cybersecurity Outlook 2026 identifies AI, geopolitical volatility and supply chain exposure as forces reshaping cyber risk, with third-party and supply-chain vulnerabilities among the top challenges to achieving resilience.

What recent incidents reveal

Recent disruptions in the life sciences ecosystem have demonstrated how cyber incidents outside a pharmaceutical company’s own systems can also affect patient care. In March 2026, a cyberattack at medical device manufacturer Stryker disrupted manufacturing, ordering and distribution channels. As a result, NHS England asked its partners to prioritize clinically important supplies and assess their dependence on Stryker products. In another incident in August 2025, contract research organisation Inotiv disclosed that a threat actor had encrypted systems and disrupted access to applications and data. As a consequence, the company activated its business continuity strategy and moved some operations to offline alternatives.

Have you read?

For the pharma sector, disruptions at manufacturers, contract research organizations, quality control laboratories, logistics partners or digital platforms can affect productivity, deplete inventories, trigger regulatory escalation or limit medicine availability. Leaders must not only ask whether systems can be restored, but also whether medicine supplies can continue during the recovery phase.

The missing link: business-led resilience

Cybersecurity programmes often originate with technology assets: applications, networks, devices, identities and control environments. These remain essential. However, asset-led resilience initiatives can struggle to engage business stakeholders because they do not answer the latter’s core questions: How would disruption affect medicine availability? Do we have an end-to-end view of cascading impacts? Which workarounds are safe and compliant?

This is why cybersecurity leaders can face difficulties to get business engagement and ownership for the resilience outcomes. The discussion is technically valid but not yet framed in the language of business consequences, decision rights and supply to patients. Conversely, a business-led model will assign clearly defined roles and decision-making powers to senior business leaders for effective governance of cyber resilience.

Cyber recovery and business resilience are related – but they are not the same. A restored application may still leave a plant unable to release a medicine if quality evidence is incomplete, while a supplier outage may still be manageable if inventory, alternative sourcing and manual procedures are in place. The business context determines whether a cyber incident becomes an operational, regulatory or patient access problem. Resilience therefore becomes a shared business and cyber responsibility.

How value chain-based cyber resilience changes the conversation

A value-chain resilience approach helps cyber and business leaders to shift the organizing principle for cyber resilience from individual technology assets to the continuity of critical parts of the value chain to minimize the time to patient impact.

Pharmaceutical value chain from research and development to commercialization, showing cyber risks and resilience enablers at each stage
Pharmaceutical value chain from research and development to commercialization, showing cyber risks and resilience enablers at each stage Image: PwC/Roche

In practice, this begins with the most important outcomes: discovering, developing, manufacturing, releasing and delivering medicines safely and reliably. It then maps the end-to-end value chain behind those outcomes, including internal functions, external partners, digital assets, data and process flows, operational technology and third-party dependencies. It also assesses cyber risk and the impact of disruption on the most critical nodes of the value chain.

Four-step value chain cyber resilience approach
Four-step value chain cyber resilience approach Image: PwC/Roche

Without this end-to-end view, organizations may focus on the immediate outage or system compromise and miss the wider consequences: cascading impact on downstream dependencies, delayed quality or batch release, inventory shortages, regulatory action, loss of stakeholder confidence and threats to the licence to operate. The impact on patient care is real and will also result in regulatory actions. The European Medicines Agency, for example, has warned that medicine shortages can lead to rationing, delayed treatments, the deployment of less effective alternatives and medication errors.

How this approach engages business leaders

Consider a cyberattack on a contract development and manufacturing organisation (CDMO) that supports the production of a critical medicine. A traditional cyber assessment might rate the CDMO (i.e. third party) by a severity risk score and recommend mitigation actions. However, proactively discussing value-chain resilience involves bringing manufacturing, quality, supply chain, regulatory, procurement, business continuity and cyber leaders into the same room and asking various questions: What happens if a cyber incident disrupts the CDMO? How much downtime can we tolerate before patient care is affected? Which medicine lines have been interrupted? Are alternative suppliers qualified to produce the medicines?

This type of analysis can change recovery priorities. A system rated as highly critical may not warrant the earliest recovery if the value chain context shows that failure of another platform would halt batch release or deplete available inventory sooner. The mitigation may include stricter third-party requirements, recovery exercises, alternative sourcing, inventory buffers, operational technology segmentation, manual fallbacks or more clearly defined decision rights. This gives executives an actionable business case: reduce disruption, protect the licence to operate, preserve regulatory confidence and maintain patient access.

Why leaders should act now

The wider sector has room to mature. WEF’s 2026 outlook found that only 33% of organizations map their supply chain ecosystems comprehensively and that only 27% simulate cyber incidents or conduct recovery exercises.

For pharma, the call to action is clear: Assign explicit business ownership to essential value chains and use disruption scenarios to guide investment and recovery decisions. For cyber leaders, this is also a leadership shift: The role moves from explaining technical exposure to enabling business decisions on patient care continuity, risk tolerance and operations recovery.

Discover

How the Forum helps leaders understand cyber risk and strengthen digital resilience

Pharma leaders should treat the medicine value chain – rather than the individual system – as the unit of cyber resilience. When boards, business leaders and cyber leaders agree on which business functions are indispensable, how much disruption can be tolerated and who can make critical trade-offs, they are better equipped to maintain patient access while systems and operations recover.

Loading...
Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Related topics:
Cybersecurity
Manufacturing and Value Chains
Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

What are the hidden costs of a fragmented cybersecurity strategy?

Tariq Alharbi

August 25, 2026

How ASEAN is testing the concept of digital multilateralism

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum