iOS App Cybersecurity Changes

iOS had a reputation of being more secure and less attacked than other mobile systems. Some iOS app cybersecurity protections could be assumed in security assessments.

That is changing.

First, iOS is attacked at about the same frequency as Android devices. The methods may vary, but the pace has picked up.

Second, the existence and availability of advanced hacking tools, including AI, are increasing.

Third, medical device app attacks have caught up with other verticals. Medical app attack rates will likely continue to increase. Criminals pay premium rates for stolen medical data.

Threat modeling, threat actor profiles, and risk assessments for iOS app cybersecurity should reflect these changes.

You can get more details on these trends from various sources. (One example is https://digital.ai/resource-center/webinars/how-ai-reset-the-economics-of-attacking-apps.

Another indicator is that Apple is now making automatic cybersecurity updates to iOS. Starting with iOS 26.1 (and parallel iPadOS and macOS versions), Apple can deliver security releases without user notice or permission. (more detail at https://support.apple.com/guide/security/background-security-improvements-sec87fc038c2/web).

Background cybersecurity updates remove some of manufacturer burden in performing iOS cybersecurity updates. This also has implications for Cybersecurity Management Plans. Manufacturers should include these updates as part of postmarket strategy.

Apple intends for the background updates to be compatible with current apps. However, a manufacturer should not depend on this. This means:

  • Adding monitoring for when background updates occur.

  • More manufacturer testing of apps to ensure maintaining functionality, safety, and security.

The background security updates can reduce time to fix vulnerabilities. The downside is more testing to ensure the updates don’t break anything.

About the author

Mike Russell helps organizations succeed without compromising speed, quality, or regulatory compliance. His 40+ years of leadership and advisory experience ranges from startups to Fortune 20 companies and national governments. He expertise includes product and software development, cybersecurity, AI, and leadership. Mike served on the AAMI group that created TIR45, Guidance on the use of Agile practices in the development of medical device software. He is also an AAMI expert faculty member for software validation (product and non-product) and agile. For SoftwareCPR, he co-created and delivers training on compliant agile and medical device cybersecurity. As an executive, Mike led organizations of up to 1,100 people with over $100 million budgets.

Upcoming Public Courses

No public courses are planned at this time.

If you would like to discuss a private, onsite course, please fill out the form below.

Or just email training@softwarecpr.com for more info.

Corporate Office

15148 Springview St.
Tampa, FL 33624
USA
+1-781-721-2921
Partners located in the US (CA, FL, MA, MN, TX) and Canada.