|
Your Tech Stack Is Now Your Operating Model A cyberattack stopped a device maker from shipping, and every headline pointed back to the same question. Life Sciences CIO Weekly • Coverage: August 24 – 30, 2026 This week made the case better than any slide could. A cyberattack identified inside Boston Scientific stopped the company from shipping product and from turning on remote monitoring for newly implanted cardiac devices, a reminder that when the technology stops, the business stops with it. The other headlines rhyme with it. Regeneron and Biogen handed their commercial engine to an AI-driven CRM, a fresh federal patch deadline landed on the exact systems that run regulated plants, and an automated manufacturing platform lost the customer it was built around. None of these are support-desk problems. They are business problems that happen to run on technology, and that is the shift worth sitting with this week. 🔍 The Quick Read
Reading something a colleague should see? Copy the section that fits their world and pass it along, or forward the whole edition. And if this reached you from someone else, you can subscribe free here to get it every week. 🤖 AI & DataRegeneron and Biogen commit globally to Veeva’s AI-native Vault CRM ↗Two of the top biopharmas committed to the same agentic CRM in a single day, and the platform is now shaping commercial decisions. On August 25, 2026, Veeva announced that Regeneron will deploy Vault CRM globally across its commercial organization, sponsored by chief digital and technology officer Ryan Steinberger. A parallel release the same day confirmed Biogen’s global commitment, quoted by global CIO Guy Hadari. Neither disclosed contract value or timing. A day later, on its fiscal second-quarter earnings call, Veeva said it now counts 12 of the top 20 biopharma companies on Vault CRM against 6 for Salesforce, and pointed to the Lilly, Biogen, and Regeneron wins as proof of momentum (Veeva results). The feature driving it, Agentic Call Report, turns unstructured field-rep conversations into structured commercial evidence that can steer decisions, a shift from dropdown data entry to AI-assisted synthesis. 💬 Joe’s Take: A decision like this is one where the CIO needs to be at the table, in partnership with the business. Commercial teams can be won over quickly on the promise that an AI system is trustworthy, and these purchases are often driven by the department most affected, so it is fair to ask how much rigor went into evaluating the solution. To Veeva’s credit, they have a strong, well-earned reputation for building compliant systems in life sciences, so the risk here looks lower than most. Even so, reputation is not a substitute for humans in the loop, for vetting the information, and for testing and validating what the model puts in front of the business before anyone makes critical decisions on it. What to watch: If you are still on a legacy commercial CRM, expect procurement and data-migration pressure to build as peers standardize, so get ahead of that conversation now and make sure IT helps set the evaluation criteria rather than inheriting the decision. ⚖️ Regulatory & PolicyFDA authorizes Abbott’s first continuous glucose-and-ketone wearable ↗A first-of-kind device authorization is also a new connected-device data and security burden for its maker. On August 25, 2026, FDA authorized Abbott’s Libre Duo 10 Day Continuous Dual Glucose Ketone Monitoring System through the De Novo pathway, the first U.S. wearable to track ketones continuously and the first anywhere to combine continuous ketone and glucose sensing in one sensor. FDA reviewed six clinical studies enrolling more than 600 participants, and Michelle Tarver, director of FDA’s Center for Devices and Radiological Health, spoke to the clinical rationale (UPI). The device reads glucose and ketones every minute and streams the data to a smartphone app that alerts as ketones climb toward diabetic ketoacidosis, with integration into Insulet and Tandem insulin-delivery systems planned for 2027. The clinical story is diabetes. The CIO story is the stack underneath, a connected software-driven device generating continuous data that has to be transmitted, stored, secured, and eventually integrated with third-party pumps, each of which adds interoperability, cybersecurity, and postmarket obligations under FDA’s cyber-device framework. What to watch: Treat each new authorization as a checkpoint on your device-data architecture, software change control, and postmarket cyber monitoring, because the data and software obligations outlast the clearance. 🔒 Cybersecurity & RiskBoston Scientific cyberattack causes a global disruption to operations ↗An IT outage stopped a major device maker from shipping product and starting remote monitoring on newly implanted cardiac devices. Boston Scientific disclosed in an SEC filing that it identified a cybersecurity incident on August 25, 2026 that caused a global disruption to its operations, including its ability to manufacture products and to process and ship customer orders (Cybersecurity Dive). Thousands of employees at its Cork, Ireland campus were sent home as network communications were cut. The company’s incident page, updated through August 29, said CrowdStrike is assisting, that impact is limited to certain on-premise systems with no cloud impact identified, and that new remote-monitoring activations for newly implanted cardiac devices and monitors are affected until systems are restored. Existing implanted-device function and previously activated monitoring are unaffected, and orders can still queue through EDI and GHX. Boston Scientific has not named an attacker or an intrusion vector. The detail worth holding is that the separation between on-premise and cloud systems is what kept this from being total. 💬 Joe’s Take: Start by thinking business continuity, not just disaster recovery. Our job now is to run a critical business function, not a support function, and that means owning whether the company can keep operating when systems go down. If you haven’t run a real resilience audit recently, run one now. We still don’t know how the attackers got into Boston Scientific, so assume your internal systems can be reached rather than trusting the perimeter to hold, then walk your technical staff through what happens when each layer of protection fails and add the redundancy before you need it. This is a clear case of making sure the business can continue when critical systems are impacted. What to watch: Pressure-test the separation between your corporate IT and your order-to-ship and manufacturing systems, confirm you have a tested manual fallback for fulfillment, and make sure your incident-response plan covers connected-device data continuity, not just data confidentiality. CISA puts a five-day clock on exploited SQL Server and NetScaler flaws ↗A federal patch deadline landed on the systems sitting under your regulated plants. On August 26, 2026, CISA added six actively exploited flaws to its Known Exploited Vulnerabilities catalog and set a five-day deadline, to August 29, on the two that matter most to life sciences (The Hacker News). One is a remote code execution flaw in Microsoft SQL Server, the database engine that quietly runs LIMS, manufacturing execution, and quality systems. The other is in Citrix NetScaler, the appliance that often serves as the internet-facing front door for remote access into corporate and plant networks. The SQL Server fix has existed since 2019, so its appearance on the list means attackers are still finding unpatched, internet-exposed instances in production. In a validated environment you cannot simply apply the patch, because the change can require revalidation, downtime, and formal change control, which is the squeeze this creates. 💬 Joe’s Take: I would run this as a two-pronged play. First, shore up your compensating controls right away. Put them in place where they are missing. And even where they already exist, they may need to be strengthened, so if they need more attention to hold up, do that now. Whether it is network segmentation or another means to thwart an attack, the goal is to cover the at-risk systems while you work the longer fix. Second, get on the phone with the vendors and press them for a firm patching timeline on both the SQL Server and the remote-access appliance side. At the same time, pull the current validated state of every in-house system that runs on those technologies, gather it from the business and your own IT records, then convene quality and regulatory and build the remediation plan together as a team, rather than IT trying to solve a validated-systems problem on its own. What to watch: Start by inventorying your internet-exposed NetScaler appliances and unpatched SQL Server instances and the validated systems that depend on them, so you know your real exposure before the deadline pressure forces a call. 🎯 Leadership & Operating ModelBMS ends its $380M Cellares deal after an automated platform misses the commercial bar ↗An automated cell-therapy platform lost the customer it was built around, a caution for anyone betting the operation on automation. On August 25, 2026, Bristol Myers Squibb confirmed it ended its manufacturing partnership with Cellares, a South San Francisco cell-therapy CDMO, after deciding its automated Cell Shuttle platform could not meet the requirements to make commercial Breyanzi, BMS’s approved CAR-T therapy. The partnership, signed in 2024, was worth up to $380 million. Cellares disputes the characterization and says Cell Shuttle has already produced a compliant therapy in an FDA-regulated clinical program (BioSpace). A California WARN filing confirms about 100 positions eliminated effective October 20, more than half of them senior, two months after a $327 million funding round aimed at commercial scale. The through-line for a CIO is that Cellares’ technology was the business, and when the anchor customer judged the platform not commercial-ready, the revenue and the headcount went with it. What to watch: Put an explicit, customer-or-production-qualified readiness gate in front of any automation platform before you let it become load-bearing, and treat every workforce reduction as a paired access-review and knowledge-retention sweep. 💬 The Bottom Line — Joe’s TakeThe thread running through every story this week is that technology has become the business, and that changes what the CIO is for. When an attack keeps Boston Scientific from shipping product and turning on new patient monitors, when an AI system starts shaping how a commercial team decides, and when a patch deadline collides with your validated systems, these are not support-desk problems. They are business problems that happen to run on technology, and the CIO’s reach now extends past the data center. Even a call like the automated manufacturing platform behind the Cellares story sits close enough to technology that the CIO should have a voice, whether it runs the plant floor, the equipment, or the service wrapped around it. What often goes unappreciated is that the CIO has spent a career rolling out new technology and seeing exactly where it breaks, and that experience is a hidden asset the business needs most right now, while AI moves faster than most organizations can absorb. Use a week like this to move the CIO from running a support function to leading a critical business function. Ready to move beyond the digest? The LS CIO Community is where these conversations continue. How this is made: each edition is researched two ways in parallel, once with Perplexity and once with Claude, then reconciled into a single verified brief before Joe adds his take. This digest is an interpretive summary of publicly available information and does not constitute legal, regulatory, cybersecurity, or investment advice. Until next week, Founder, Leadership Inklings |