- New APAC Health Sector Security Manager: Simon Cowley appointed to strengthen cybersecurity in the Asia-Pacific region.
- High Cost of Breaches: Average healthcare data breach in APAC costs millions, highest of any sector.
- Device Vulnerabilities: Over 50% of connected hospital devices potentially harbor critical flaws.
Experts would likely conclude that Health-ISAC's strategic hiring of Simon Cowley is a critical step in fortifying APAC's digital health infrastructure against escalating cyber threats, particularly in medical device security.
Health-ISAC's Strategic Gambit: Fortifying APAC's Digital Health Frontline
MELBOURNE, Australia – September 01, 2026 – In a move that speaks volumes about the shifting geopolitics of cybersecurity, the Health Information Sharing and Analysis Center (Health-ISAC) has announced a significant reinforcement of its Asia-Pacific operations. The hiring of Simon Cowley, a seasoned medical device security expert, as the new APAC Health Sector Security & Partnerships Manager is far more than a routine staff addition; it is a calculated deployment to the frontline of a region under digital siege.
Based in Melbourne, Cowley's appointment signals a strategic deepening of Health-ISAC’s commitment to a region grappling with an escalating series of cyberattacks targeting its most vulnerable asset: its healthcare infrastructure. Reporting to APAC Operations Director Paul Chua, Cowley is tasked not just with member support, but with weaving a more resilient fabric of collective defense across Australia, New Zealand, and the wider Western Pacific.
"Health-ISAC recognizes the importance of Australia and APAC to global health and has made a commitment to the region by bringing Simon onboard," said Denise Anderson, President and CEO of Health-ISAC, in a statement. The move underscores a critical understanding: in the interconnected world of 2026, a vulnerability in a Melbourne hospital is a threat to the entire global health ecosystem.
A Region Under Digital Siege
The urgency behind Health-ISAC's investment becomes clear when examining the threat landscape. The healthcare sector in the Asia-Pacific region has become a prime target for malicious actors. Motivated by the high value of sensitive patient data and the potential for massive disruption, cybercriminals have relentlessly targeted hospitals and health services. Industry reports paint a grim picture, with the average cost of a healthcare data breach in APAC soaring into the millions of dollars, the highest of any sector.
Australian authorities have consistently flagged the health sector as one of the most targeted for cyber incidents, from crippling ransomware attacks to sophisticated data theft. New Zealand’s health system has also faced significant disruptions from similar attacks, demonstrating that no nation in the region is immune. The challenge is compounded by a diverse landscape of cybersecurity maturity across Western Pacific nations, creating a patchwork of defenses that sophisticated adversaries are adept at exploiting.
This is the complex environment Cowley is stepping into. His role is to build bridges—between organizations, across borders, and between the worlds of clinical care and cybersecurity—to create a unified front against these pervasive threats.
The Specialist for a Specialized Problem: Medical Device Security
Perhaps the most nuanced and critical aspect of Health-ISAC's strategy is the focus on Cowley's specific expertise: medical device security. With over 15 years as a biomedical engineer, he brings a rare and invaluable perspective. The proliferation of the Internet of Medical Things (IoMT)—from smart infusion pumps and patient monitors to complex diagnostic imaging equipment—has revolutionized patient care, but it has also created a vast and often poorly secured attack surface.
Studies reveal a startling level of vulnerability, with over half of connected hospital devices potentially harboring critical flaws. Many of these are legacy systems, designed and deployed long before cybersecurity was a consideration. They are the soft underbelly of modern healthcare, and Cowley's mission is to secure them. His previous success at the Department of Health in Victoria, where he implemented a medical device security assurance program in 2021, provides a proven blueprint.
"Securing the global health ecosystem requires strong local presence and specialized operational expertise," noted Errol Weiss, Chief Security Officer at Health-ISAC. "Simon’s leadership in medical device security assurance makes him an outstanding addition. His regional insight will be pivotal in driving resilience."
This focus on operational technology (OT) security is what sets this initiative apart. It moves the conversation beyond traditional IT security—protecting servers and data—and into the critical realm of devices that directly impact patient safety. Cowley will be tasked with fostering strategies to improve security across both Medical Device Manufacturers (MDMs) and Health Delivery Organizations (HDOs), tackling the problem from both supply and implementation sides.
From Regional Insight to Global Resilience
While the immediate focus is local, the implications are global. Health-ISAC operates on the principle that a stronger link anywhere in the chain reinforces the entire network. The intelligence gathered from threats and incidents in APAC will be funneled into the organization's global threat database, providing invaluable insights for members across Europe and North America. Conversely, global intelligence will be contextualized and disseminated to APAC members, giving them advanced warning of emerging attack vectors.
Cowley's role as a partnerships manager is key to this vision. He will be tasked with cultivating relationships not just with Health-ISAC members, but with the broader ecosystem of government agencies like the Australian Cyber Security Centre (ACSC), national CERTs, and law enforcement. This collaborative approach recognizes that no single organization can defend against these threats alone. Health-ISAC's role is to act as the specialized, trusted hub for the health sector, complementing the broader work of these national bodies.
"I am thrilled to join Health-ISAC at such a critical time... to improve the health sector’s resilience in the face of cybersecurity attacks," said Cowley. "Having dedicated my career to medical device security and health technology, I know firsthand how vital collaboration and intelligence sharing are to protect patient safety."
This push for a more collaborative, intelligence-led defense will be on full display at the upcoming Health-ISAC APAC Summit in Gold Coast in March 2027. The event will serve as a crucial forum for Cowley and his team to engage directly with the community they are tasked to protect, forging the alliances that will define the future security of healthcare in the region.
Topics & Related
Leadership Change
Medical Devices
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →