Smith & Nephew is a 168-year-old medical technology company operating across more than 100 countries, with over 18,000 employees building hardware and software that sits at the intersection of robotics, bioengineering, and clinical workflow. The Brazilian subsidiary - BRA - Smith & Nephew Comercio de Produtos Medicos LTDA - is part of a publicly traded parent listed on both the London Stock Exchange (FTSE 100) and the New York Stock Exchange. The attack surface is significant: connected surgical systems like the CORI robotics platform, IoT-enabled wound therapy devices such as PICO, and bioinductive implants like REGENETEN all generate, transmit, or depend on data in regulated healthcare environments.
For security teams, the threat model spans IT/OT convergence in operating theaters, patient data protection under multiple jurisdictions, firmware integrity for implanted or bedside devices, and supply-chain integrity across a global manufacturing footprint. This is not a SaaS play - the domain expertise required includes embedded systems security, medical device regulatory frameworks (FDA, ANVISA, and equivalents), and the ability to reason about safety-critical systems where a vulnerability isn't just a data breach but a patient-safety event.
The company's core business - orthopaedics, sports medicine, ENT, and advanced wound management - means security work directly underpins clinical outcomes for millions of patients annually. Teams here operate in an environment where uptime, integrity, and compliance aren't abstract goals but operational constraints baked into every deployment. The technical stack crosses robotics-assisted surgery, negative pressure wound therapy, and regenerative medicine - each with distinct hardware, firmware, and network considerations.





