Integrating Cybersecurity Controls across IT/OT Environments in the Medical Sector-A Review of Threats, Standards and an Integrated Control Framework for Healthcare Information Technology and Operational Technology

Modern healthcare depends on a dense network of digital systems, connected medical devices and operational technologies. Electronic health records, imaging systems, infusion pumps, patient monitors, cloud platforms and building-control systems now exchange data continuously. This connectivity improves clinical work, but it also creates routes through which a weakness in one system can affect many others. The problem is not simply a shortage of security tools. In many organisations, information technology, clinical engineering, procurement and operational teams manage risk separately, while suppliers retain significant control over device updates and remote access. This review examines recent evidence on medical-device vulnerabilities, healthcare supply-chain exposure, procurement practice and governance across converged IT/OT environments. It finds that known weaknesses remain common in connected devices; cybersecurity conditions are still absent from many tender and contract documents; and fragmented accountability allows local weaknesses to become organisation-wide risks. In response, the paper proposes a four-layer control framework built around shared asset visibility, consistent risk assessment, unified governance and resilient care delivery supported by continuous monitoring. The framework draws on the NIST Cybersecurity Framework, NIST Zero Trust guidance, ISO/IEC 27001, IEC 62443 and medical-device safety requirements. For Nigerian healthcare organisations, the approach is intended to be practical: begin with accurate inventories, protect high-risk clinical systems, place measurable security obligations in procurement documents, and strengthen coordination between IT, clinical engineering, management and vendors.

Keywords: IT/OT convergence; healthcare cybersecurity; Internet of Medical Things; medical-device security; cybersecurity governance; Nigeria.