iOS App Cybersecurity Changes

iOS had a reputation of being more secure and less attacked than other mobile systems. Some iOS app cybersecurity protections could be assumed in security assessments.

That is changing.

First, iOS is attacked at about the same frequency as Android devices. The methods may vary, but the pace has picked up.

Second, the existence and availability of advanced hacking tools, including AI, are increasing.

Third, medical device app attacks have caught up with other verticals. Medical app attack rates will likely continue to increase. Criminals pay premium rates for stolen medical data.

Threat modeling, threat actor profiles, and risk assessments for iOS app cybersecurity should reflect these changes.

You can get more details on these trends from various sources. (One example is https://digital.ai/resource-center/webinars/how-ai-reset-the-economics-of-attacking-apps.

Another indicator is that Apple is now making automatic cybersecurity updates to iOS. Starting with iOS 26.1 (and parallel iPadOS and macOS versions), Apple can deliver security releases without user notice or permission. (more detail at https://support.apple.com/guide/security/background-security-improvements-sec87fc038c2/web).

Background cybersecurity updates remove some of manufacturer burden in performing iOS cybersecurity updates. This also has implications for Cybersecurity Management Plans. Manufacturers should include these updates as part of postmarket strategy.

Apple intends for the background updates to be compatible with current apps. However, a manufacturer should not depend on this. This means:

  • Adding monitoring for when background updates occur.

  • More manufacturer testing of apps to ensure maintaining functionality, safety, and security.

The background security updates can reduce time to fix vulnerabilities. The downside is more testing to ensure the updates don’t break anything.

About the author

Succeeding despite relentless change is the goal of 21st century organizations. Mike helps achieve those successes by working with leaders of start-ups to Fortune 20 companies and national governments. His aim is to help them re-imagine and create adaptive, innovative enterprises that increase profitability and value across the quadruple bottom line: customers, employees, owners/shareholders, and communities.

SoftwareCPR Training Courses

ISO13485:2016 ISO 13485 Internal Audit(or) Training Course (Live, 3-day)

IEC 62304 and other Emerging Standards Impacting Medical Device Software (Live, 3-day)

Being Agile & Yet CompliantISO 14971 SaMD Risk Management

Software Risk Management

Medical Device Cybersecurity

Software Verification

IEC 62366 Usability Process and Documentation

Or just email training@softwarecpr.com for more info.

Corporate Office

15148 Springview St.
Tampa, FL 33624
USA
+1-781-721-2921
Partners located in the US (CA, FL, MA, MN, TX) and Canada.