Blog Post

Cyber Loss When the Product Is a Clinical Trial

September 25, 2026

Table of Contents

A cyber loss model for a research organization counts subject records and applies a per-record cost. Personal health information, a notification exercise, a regulatory penalty.

‍

The mechanism that matters in a trial is integrity rather than confidentiality, and it produces a loss that occurs even where nothing was altered. What gets destroyed is the ability to demonstrate that nothing was.

‍

Why Does the Loss Occur Without Alteration?

‍

Because the requirement is demonstrability rather than accuracy, and those fail independently.

‍

Regulation requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying or deleting records. Critically, the people who can create or modify records must not be able to modify the trail. An attacker holding administrative access to a data capture system collapses that separation, and once collapsed the trail can no longer evidence anything, including its own integrity.

‍

Which Inverts the Usual Question

‍

A confidentiality incident asks what was taken. An integrity incident asks what can still be proven, and the answer can be nothing even where forensic analysis finds no modification. Absence of evidence of change is not evidence of absence of change once the mechanism that would have recorded it was under someone else's control.

‍

What Is the Remedy?

‍

Regeneration, which is what makes this expensive rather than merely serious.

‍

Exposure trended across successive assessments alongside a change log recording what moved between them and when
A change record nobody can alter after the fact is the artifact this entire loss category turns on.

A confidentiality failure is remedied through notification, monitoring and regulatory engagement. Data whose integrity cannot be demonstrated cannot be repaired by any of those, because the deficiency is in the record rather than in its distribution. The affected portion has to be produced again, meaning subjects enrolled and the protocol run.

‍

Which Makes the Interval the Cost

‍

Repeating a portion of a trial costs whatever that portion cost, plus the delay to every downstream milestone that depended on it. The delay is frequently larger than the direct expense, since a regulatory submission moves and the commercial position moves with it.

‍

Why Is This Unusually Computable?

‍

Because the protocol states the numbers, which is rare in cyber loss modeling and worth exploiting.

‍

A protocol specifies how many subjects, over what recruitment period, with what visit schedule and what follow-up duration. So the cost of repeating a defined portion is arithmetic rather than estimation, and it can be computed before any incident occurs from a document the organization already holds.

‍

Which Reverses the Usual Uncertainty

‍

Most cyber scenarios have a reasonably estimable frequency and a highly uncertain severity. Here severity is the confident term and frequency is the guess, so the modeling effort belongs on how often rather than on how much, and working without an incident history is the harder half in this scenario.

‍

What Determines the Affected Portion?

‍

Dwell time, which converts directly into subjects requiring repetition.

‍

Per-event impact summary showing median loss with the first and ninety-ninth percentile range, alongside equivalent ranges for duration and records affected
A duration range beside a records range is the right shape here, since the number of subjects affected is a function of how long access persisted.

The question is not whether the trial is compromised but which part cannot be demonstrated. Which sites, which subjects and which visit windows fell inside the period when administrative access was held by somebody unauthorized. Every additional week of undetected access enlarges that set.

‍

Which Makes Detection Time a Direct Multiplier

‍

In most sectors faster detection reduces the volume of data exfiltrated. Here it reduces the number of subject visits whose integrity cannot be established, and each one carries a repeat cost. The value of detection is therefore expressible in subjects rather than in records.

‍

What Cannot Be Repeated?

‍

The blind, which is the second loss and the one repetition does not fix.

‍

Where an attacker held access to randomization or trial supply management data, the allocation may be known. An unblinded trial cannot be re-blinded, and the subjects already enrolled cannot be unlearned. Continuing produces data a regulator may discount and repeating requires a fresh cohort rather than a fresh run.

‍

Which Argues for Separating Those Systems

‍

Randomization and supply systems carry a loss category the data capture systems do not, so holding them under the same administrative boundary lets one compromise reach both. Separating the privilege is a control decision with an unusually direct payoff, and separation of duties as a design property is the same reasoning in another setting.

‍

What Does the Regulator Add?

‍

An inspection exposure that runs alongside the repeat cost rather than instead of it.

‍

Data integrity is already the most common category of finding in this area, with more than half of a sample of twelve hundred inspection observations issued to clinical investigators involving integrity, particularly around original data, attribution and accuracy. An incident affecting the systems that produce those records arrives into an inspection regime already focused on exactly that question.

‍

Which Changes What Response Has to Produce

‍

Not a notification but a reconstruction. Which records, which period, which systems, what can be demonstrated and on what basis. The reconstruction is an evidentiary exercise conducted for an audience that inspects records professionally, and it cannot be assembled from a forensic report alone.

‍

Does the Sponsor or the Site Carry It?

‍

The sponsor, mostly, and the exposure sits in systems the sponsor frequently does not operate.

‍

A trial runs across a sponsor, contract research organizations, investigator sites and specialist laboratories, with data capture, patient-reported outcomes, imaging and safety reporting often in different hands. Regulatory accountability for the reliability of the submission stays with the sponsor while the systems producing the records belong to several other parties.

‍

Which Makes This a Third-Party Exposure

‍

An integrity failure at a research organization or a central laboratory produces a repeat cost the sponsor absorbs, and the contract determines whether any of it flows back. Most agreements address confidentiality thoroughly and integrity barely, so what a supplier arrangement has to specify needs a clause about audit trail controls rather than only about data protection.

‍

What Should the Clause Require?

‍

Separation of audit trail modification from record modification, notification of administrative compromise within a period short enough to bound the affected window, and access to the trail for reconstruction purposes. Three requirements, none of them expensive to grant, and all three unavailable after an incident if they were not agreed before.

‍

What Should Be Established?

‍

Four things, and the first is a document somebody already has.

‍

The cost of repeating a defined portion of each active trial, from the protocol. Whether audit trail modification is separated from record modification in every system holding trial data, since that separation is the whole control. Whether randomization and supply systems sit under a different administrative boundary from data capture. Then how long unauthorized administrative access would persist before detection, since that interval sets the number of subjects. Cyber risk quantification built on those inputs produces a figure with an unusually firm severity term.

‍

The Loss Is Demonstrability

‍

Trial data whose integrity cannot be demonstrated is unusable even where forensic analysis finds no alteration, because the requirement is provability rather than accuracy. Regulation separates the ability to modify records from the ability to modify the audit trail, and administrative compromise collapses that separation so the trail can no longer evidence its own integrity. The remedy is regeneration rather than notification, so the affected portion has to be run again, and the protocol states the numbers so that cost is arithmetic. Dwell time converts directly into subjects requiring repetition, making detection time a multiplier expressible in subjects. The blind also cannot be restored at all, which is a separate loss requiring a fresh cohort. Kovrr's cyber risk quantification models this with severity as the confident term rather than the estimated one.

‍

To see integrity exposure modeled from protocol duration rather than from a per-record cost, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Trial Data Integrity FAQs

Speak to an Expert

Is clinical trial data integrity a confidentiality problem?

What does 21 CFR Part 11 require for audit trails?

Does a compromise of trial data mean repeating the study?

How do you cost a clinical trial data integrity failure?

What determines how much of a trial is affected?

Can a compromised blind be restored?