Medela is a global medical device company headquartered in Baar, Switzerland, founded in 1961 and employing approximately 1,500 people. Its core business centers on breastfeeding and lactation - research-based breast pumps, breast care products, feeding bottles, storage bags, and cleaning solutions for consumer and professional healthcare markets. The company also operates in NICU care, wound care, and surgical care verticals, impacting more than 14 million moms, babies, patients, and healthcare professionals annually across Europe, the Americas, and Asia.
From a security standpoint, the threat model is substantial. Medela ships connected medical devices and operates in a heavily regulated healthcare environment - two domains where compromise carries outsized consequences. Patient data, device firmware integrity, supply chain telemetry, and clinical research IP all present high-value targets. The attack surface spans consumer IoT endpoints (breast pumps with digital features), cloud-backed mobile applications, global enterprise IT infrastructure, and the operational technology layers supporting manufacturing and distribution across multiple continents.
A cybersecurity team here would be working across domains that don't typically get spotlighted but matter: securing medical device software pipelines, hardening cloud platforms that handle sensitive health data, managing compliance across jurisdictions (think FDA, EU MDR, HIPAA), and defending a global network that connects factories, research labs, and commercial operations. It's critical infrastructure with real downstream impact on vulnerable populations - NICU patients, postpartum mothers, and surgical wound care recipients - making resilience and incident response less theoretical and more operational.





