Ambu A/S is a Danish medtech company founded in 1937 that designs and manufactures single-use endoscopes, anesthesia and airway management devices, and patient monitoring and diagnostics equipment. That product portfolio - spanning pulmonology, gastroenterology, ENT, urology, neurology, and cardiology - means the company sits at the intersection of connected medical devices, regulated software, and clinical data pipelines. The threat surface is real: compromised firmware on a video laryngoscope, tampered sensor data from monitoring electrodes, or a supply-chain breach affecting single-use devices deployed at scale could directly impact patient safety.
With over 5,000 employees across Denmark and multiple continents, Ambu operates in a heavily regulated environment where cybersecurity is inseparable from product safety and regulatory compliance under frameworks like the EU Medical Device Regulation (MDR) and FDA premarket guidance. Security teams here aren't protecting abstract corporate assets - they're defending devices that go inside patients and the data streams clinicians depend on in real time. That means secure development lifecycles for embedded systems, vulnerability management across a global fleet of connected devices, and incident response protocols that account for both IT and OT dimensions of the clinical environment.
The company's move into single-use digital endoscopy has accelerated its software footprint, expanding the engineering surface that needs hardened APIs, encrypted data-at-rest and in-transit, and robust access controls. For security professionals, the draw is specificity: the work involves medical device threat modeling, IEC 62443 and IEC 81001-5-1 compliance, penetration testing of embedded platforms, and building security architecture that holds up under regulatory audit. The stakes are legible, the domains are concrete, and the scope is global.





