Penetration testing and medical device cybersecurity research
Statistics, analysis and standards references built from primary sources. Every figure is dated and linked to the document it came from, so it can be checked and cited.
Latest studies
Statistics · Medical device cybersecurity
Medical Device Vulnerabilities: 536 CVEs, 12 on CISA KEV
536 distinct CVEs in 192 CISA medical advisories; 12 on CISA's exploited list. Free CSVs and source checks. Updated Oct 2026.
Statistics · Medical device cybersecurity
FDA Cybersecurity Guidance (2026): About 3% Changed
About 3% of FDA's February 2026 wording changed. 12 guidance documents, law vs. advice, testing lists and free CSVs. Updated October 2026.
Statistics · Penetration testing
Penetration Testing Statistics 2026: ~$2.8B Market, 100 Stats
About $2.8B is the middle 2026 market estimate from 8 firms. Get 100 sourced penetration testing stats, 21 rules and free CSV data.
What we study
Penetration testing
How penetration testing is bought, priced, delivered and reported, measured from published sources.
Covers
- Testing statistics and trends
- Market size and structure
- Pricing and engagement terms
- Methods and reporting practice
Statistics
Penetration Testing Statistics 2026: ~$2.8B Market, 100 Stats
About $2.8B is the middle 2026 market estimate from 8 firms. Get 100 sourced penetration testing stats, 21 rules and free CSV data.
Medical device cybersecurity
The security of connected medical devices and the regulation and standards that govern it.
Covers
- Disclosed device vulnerabilities
- FDA premarket cybersecurity guidance
- Recognized standards, such as IEC 81001-5-1 and AAMI TIR57
- Testing expectations for device manufacturers
Statistics
Medical Device Vulnerabilities: 536 CVEs, 12 on CISA KEV
536 distinct CVEs in 192 CISA medical advisories; 12 on CISA's exploited list. Free CSVs and source checks. Updated Oct 2026.
Statistics
FDA Cybersecurity Guidance (2026): About 3% Changed
About 3% of FDA's February 2026 wording changed. 12 guidance documents, law vs. advice, testing lists and free CSVs. Updated October 2026.
How the research is produced
Primary sources first
Figures come from the organization that produced them: regulators, standards bodies, vulnerability databases, peer-reviewed studies and company filings. A secondary report is cited only for what it measured itself.
Every figure is dated and linked
Each statistic names its source document, the section or table it came from and the date it was checked, so a reader can confirm it in one step.
Methods are published with the study
Each study states what was measured, how sources or samples were selected, the collection dates, what was excluded and the limits of the result.
Our analysis is labeled as ours
Calculations and interpretations are marked as our own and kept separate from what a source states. Where AI tools assist with drafting or data handling, the study says so.
Corrections stay visible
When a figure changes, the study records what changed and when. The update date on each study reflects its last meaningful change.
Citing this research
You may cite figures and findings from these studies with attribution to The PenTest Index and a link to the study page. Each study states how its charts and data may be reused.
The PenTest Index. (Year, Month Day). Title of the study. PenTest Index Research. https://thepentestindex.com/research/study-name/
Please link to the study itself rather than to this page, and use the date shown on the study. Figures are updated when their sources change.
Corrections and research enquiries
Write to us about a correction, a question about a figure or its source, or a request to reuse data. For a correction, name the study and the figure, and include the source that supports the change.