The threat surface here is clinical. Roswell Park Comprehensive Cancer Center, founded in 1898 and based in Buffalo, New York, is one of roughly 50 National Cancer Institute-designated Comprehensive Cancer Centers in the U.S. That designation means it handles cancer research, clinical trials, and direct patient care at scale - domains where data integrity, privacy, and system uptime aren't abstract concerns. Protected health information, genomic data, trial protocols, and operational systems across a major research hospital all fall within scope.
For a cybersecurity team, the attack model spans the usual suspects - ransomware targeting healthcare infrastructure, phishing campaigns aimed at clinical staff, and the particular sensitivity of oncology data under HIPAA - but also the unique challenges of securing research environments running alongside live clinical operations. The organization operates within healthcare, oncology, and medical research verticals, which means compliance frameworks aren't optional paperwork; they're the baseline.
The center's stated mission centers on cancer research and treatment, which in practice translates to a complex IT environment: electronic health records, laboratory information systems, clinical trial management platforms, and the research computing that supports it all. Security here isn't perimeter defense for a SaaS product - it's protecting systems that directly affect patient outcomes and the integrity of multi-year research data.




