ResMed's threat surface is a medical device fleet. The company, founded in 1989 and now operating in over 140 countries, connects CPAP machines, bilevel devices, and ventilators to the cloud. Its software stack manages respiratory care and out-of-hospital healthcare workflows. This isn't hypothetical IoT; it's life-sustaining hardware with a 154+ million annual patient touchpoint. The attack model centers on protecting patient data integrity and device availability at scale across a globally distributed cloud-connected medical device ecosystem.
Security work here spans the full lifecycle of digital health technologies and cloud-connected medical devices. Teams operate at the intersection of embedded firmware security, cloud infrastructure hardening, and the regulatory compliance frameworks (HIPAA, GDPR, MDR) that govern the entire healthcare vertical. The residential care software segment adds a layer of application and data security for out-of-hospital clinical workflows. With a team of over 10,000, the security function supports product lines across sleep apnea, respiratory care, and residential care software.
The technical domains demand fluency in both OT and IT security. You're defending devices that patients depend on nightly, managed through cloud platforms that clinicians rely on for treatment decisions. The attack surface includes the device-to-cloud data path, API layers connecting clinical systems, and the software platforms managing patient populations. The company's global footprint - rooted in Australia with operations worldwide - means navigating fragmented data sovereignty requirements alongside continuous vulnerability management across a massive, active device fleet.






