Cybersecurity Incident Emergency Response Procedure

 

1.Purpose

This document aims to regulate the implementation of the cybersecurity incident emergency response procedure for Surgerii Robotics (Netherlands) B.V. (EU AR of the manufacturer: Beijing Surgerii Robotics Company Limited), so as to ensure the timeliness and reliability of cybersecurity incident handling. This doc also sets out the allocation of responsibilities between Surgerii (the contractor) and the healthcare institution across the phases of the cybersecurity incident response process.

 

2.Scope of Application

This procedure applies to any cybersecurity incident, as defined in §3.1 of this procedure, that affects or may affect a Surgerii medical device deployed at a healthcare institution under contract.

 

3.Terms and Definitions

3.1Cybersecurity Incident

An event that causes harm to networks and information systems or their data, and has negative impacts on society, due to human factors, software and hardware defects or failures, natural disasters, and other causes.

3.2Cybersecurity Incident Emergency Response Team

Cybersecurity incident response team roles and responsibilities are defined in BSR-SOP-1370 Cybersecurity Incident Emergency Response Management Procedure.

 

4.Contents

4.1Procedure definition and responsibility allocation

 

Phase 1: Preparation (pre-incident)

Contractor (Surgerii) responsibilities:

• Maintain a cybersecurity incident response team with defined roles, including Security Lead and Deputy.

• Monitor cybersecurity intelligence sources for vulnerabilities affecting the device, its software bill of materials (SBOM) components, and update channels.

• Maintain the security.txt file and the underlying incident response procedure.

• Train support and engineering personnel on the procedure; conduct exercises at planned intervals.

Institution responsibilities:

• Designate a Security Lead and a Deputy with 24/7 availability as required by the contract.

• Maintain general IT security posture and physical security around the device per institutional policy.

• Train clinical and IT staff on the device-specific incident reporting path defined in the User Manual and security.txt.

 

Phase 2: Detection

Contractor (Surgerii) responsibilities:

• Monitor for disclosed vulnerabilities affecting the device or its SBOM components (including third-party software such as those listed in the maintenance commitment).

• Monitor for credential leaks and integrity issues affecting Surgerii infrastructure used for firmware distribution and software updates.

• Receive and review incident reports from institutions.

Institution responsibilities:

• Detect anomalies in the operating environment around the device, including physical access events, anomalies on adjacent equipment, user account anomalies, and abnormal operator behaviour.

• Preserve evidence (logs, screenshots, contextual information) at the point of detection.

• Notify Surgerii via the security.txt contact channel without undue delay.

• Surgerii subscribes to vulnerability intelligence feeds and leak monitoring services covering its SBOM components and update infrastructure.

 

Phase 3: Notification

Contractor (Surgerii) responsibilities:

• Notify the institution's designated security contacts without undue delay when an incident is detected by Surgerii or by a third party acting on Surgerii's behalf, and provide documented incident details and initial countermeasures.

• Notify other affected institutions in parallel if the incident is multi-site.

Institution responsibilities:

• Notify Surgerii via the published security.txt contact channel when an incident is detected on the institution side.

• Provide initial scope information: devices affected, environment, observed effects, and any indication of patient impact.

 

Phase 4: Triage and severity classification

Contractor (Surgerii) responsibilities:

• Classify incident severity within 24 hours of detection or notification.

• Determine reportability under MDR Article 87 (2-day clock for serious public health threat; 10-day clock for death or unanticipated serious deterioration in health; 15-day clock for other serious incidents) and activate the applicable reporting clock.

• Assign an incident owner and inform the institution of the assigned point of contact.

Institution responsibilities:

• Provide additional scope and impact information on request to support severity classification.

• Confirm to Surgerii whether patients have been or may have been affected, to the extent known.

 

Phase 5: Containment

Contractor (Surgerii) responsibilities:

• Provide containment guidance to the institution within 72 hours of severity classification, in the form of temporary countermeasures, workaround instructions, or firmware/software updates as applicable.

• Confirm whether and how the device may continue to be used during containment.

Institution responsibilities:

• Apply containment guidance as instructed by Surgerii.

• Restrict or suspend device use if directed by Surgerii.

• Maintain forensic isolation of the device where feasible until investigation is complete.

 

Phase 6: Investigation and root cause analysis

Contractor (Surgerii) responsibilities:

• Lead the investigation and coordinate with software, system, and quality engineering.

• Prepare a root cause analysis report and share relevant findings with the institution.

Institution responsibilities:

• Provide access logs, operating records, environmental data, and authorised personnel for interviews as needed to support root cause analysis.

• Preserve evidence for the duration of the investigation.

 

Phase 7: Remediation

Contractor (Surgerii) responsibilities:

• Develop and validate corrective design changes in accordance with the Design and Development Change Control Procedure.

• Deploy software or firmware updates and provide deployment instructions to the institution.

• Issue a Field Safety Notice (FSN) if a Field Safety Corrective Action is triggered.

Institution responsibilities:

• Implement deployed updates per Surgerii instructions.

• Confirm to Surgerii that remediation has been applied and verify the device returns to normal operation.

 

Phase 8: Regulatory reporting

Contractor (Surgerii) responsibilities:

• Report serious incidents to the competent authority of the Member State concerned per MDR Article 87, within the applicable 2-, 10-, or 15-day timelines.

• Coordinate vigilance reporting via EUDAMED once available, using the MIR form in the interim.

• Inform the institution of the regulatory reporting status.

Institution responsibilities:

• Comply with institution-side regulatory obligations as applicable, including notification to ANSSI under the NIS2 Directive for operators of essential or important services, notification to CNIL under GDPR Article 33 in the case of a personal data breach, and notification to ANSM where required by national rules.

• These obligations are independent of and additional to those of the contractor.

 

Phase 9: Communication during the incident

Contractor (Surgerii) responsibilities:

• Communicate progress to the institution's security contact(s) at the cadence defined for the incident severity (see periodic meetings note below).

• Provide a single point of contact for the duration of the incident.

Institution responsibilities:

• Communicate internally to clinical staff, IT, Data Protection Officer, and information security leadership as applicable.

• Communicate to patients and other external parties in accordance with institutional protocols and legal obligations.

 

Phase 10: Post-incident review and improvement

Contractor (Surgerii) responsibilities:

• Conduct an internal post-incident review.

• Update the procedure, training, and Corrective and Preventive Action (CAPA) records as needed.

• Share lessons learned with the institution and, where appropriate, with other affected institutions.

Institution responsibilities:

• Participate in a joint post-incident review meeting at Surgerii's request.

• Update institution-side procedures and training as applicable.

 

4.2Periodic meetings during an active incident

During an active incident, Surgerii and the institution shall hold periodic progress meetings at the following minimum cadence, scaled to incident severity:

• Serious incidents reportable under MDR Article 87(3) or 87(4): daily.

• Other incidents: at least weekly until the incident is closed.

Each meeting is held as a joint call between the Surgerii incident owner and the institution's Security Lead or Deputy, and is documented in the incident log. The cadence may be adjusted by mutual agreement based on the progression of the incident.