NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Risk workspace
Inherent and residual ratings under RM-5x5 v2.1; a cell filters, a row opens the assessment.
Inherent risk matrix
- Low 1-4
- Medium 5-9
- High 10-16
- Critical 17-25
| Impact | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 0 | 0 | 2 | 1 | 0 |
| 4 | 0 | 1 | 0 | 2 | 0 |
| 3 | 0 | 0 | 3 | 1 | 0 |
| 2 | 0 | 1 | 0 | 0 | 0 |
| 1 | 0 | 0 | 0 | 0 | 0 |
- Attacker sends unauthorized dosing commandRSK-000118TV-000118SafetyCritical
- Score
- L4 × I5 = 20
- Residual
- High10
- Replay of captured dosing command re-doses patientRSK-000124TV-000124High
- Score
- L4 × I4 = 16
- Residual
- Medium8
- Unauthenticated serial service port grants privileged shellRSK-000101TV-000101High
- Score
- L4 × I4 = 16
- Residual
- Low4
- Unsigned application firmware package accepted by update agentRSK-000112TV-000112High
- Score
- L3 × I5 = 15
- Residual
- Not projected
- Tampered drug library uploaded from compromised pharmacy workstationRSK-000129TV-000129SafetyHigh
- Score
- L3 × I5 = 15
- Residual
- Medium5
- Gateway flood starves dosing command channelRSK-000133TV-000133High
- Score
- L4 × I3 = 12
- Residual
- Medium6
- Rogue device impersonates clinician app over BLE pairingRSK-000126TV-000126High
- Score
- L3 × I3 = 9override
- Residual
- Not projected
- Maintenance actor alters or truncates pump audit logRSK-000127TV-000127Medium
- Score
- L3 × I3 = 9
- Residual
- Medium6
- Cloud telemetry stream exposes PHI to unauthorized readerRSK-000131TV-000131Medium
- Score
- L3 × I3 = 9
- Residual
- Low4
- Maintenance mode left enabled exposes diagnostic shellRSK-000135TV-000135Medium
- Score
- L2 × I4 = 8
- Residual
- Not projected
- Protocol downgrade between gateway and cloud ingestionRSK-000138TV-000138Low
- Score
- L2 × I2 = 4
- Residual
- Not projected
11 assessments
Tampered drug library uploaded from compromised pharmacy workstation
RSK-000129Treatment plannedHigh
Inherent
HighL3 × I5
Residual
MediumL1 × I5
Factors (1 to 5)
Exploitability3
Impact: confidentiality1
Impact: integrity5
Impact: availability3
Impact: authenticity4
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 16% |
| Impact: confidentiality | 1 | 5% |
| Impact: integrity | 5 | 26% |
| Impact: availability | 3 | 16% |
| Impact: authenticity | 4 | 21% |
| Detectability | 3 | 16% |
Safety consequence: Potential hazardous situationScope: Device fleetUncertainty: LowSafety-risk linkage: confirmed
- Exploitability
- 3/5
- Requires workstation compromise; pharmacy endpoints historically targeted; push path then trusted.
- Impact: confidentiality
- 1/5
- Library content is not confidential.
- Impact: integrity
- 5/5
- Dose validation bounds silently altered fleet-wide.
- Impact: availability
- 3/5
- Bad library can force devices into safe-hold.
- Impact: authenticity
- 4/5
- Library provenance unverifiable end-to-end.
- Safety consequence
- Potential hazardous situation
- Wrong-limit delivery scenario; ISO 14971 file HZ-0146 opened by Clinical Safety.
- Affected scope
- Device fleet
- Library distribution reaches every subscribed device.
- Detectability
- 3/5
- Library version diffs reviewable, content diffs not surfaced today.
- Uncertainty
- Low
- Push path confirmed with R&D.
High 15 = L3 x I5; safety-linked; treatment adopted (REM-208).
- Threat
- TV-000129
- Assessor
- Marcus Chen
- Assessed
- 16 Apr 2026, 11:55 UTC
- Method / matrix
- RM-5x5 v2.1 · MTX-2026-01