
Blog Post
Cyber Loss When the Product Is a Clinical Trial
September 25, 2026
A cyber loss model for a research organization counts subject records and applies a per-record cost. Personal health information, a notification exercise, a regulatory penalty.
The mechanism that matters in a trial is integrity rather than confidentiality, and it produces a loss that occurs even where nothing was altered. What gets destroyed is the ability to demonstrate that nothing was.
Why Does the Loss Occur Without Alteration?
Because the requirement is demonstrability rather than accuracy, and those fail independently.
Regulation requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying or deleting records. Critically, the people who can create or modify records must not be able to modify the trail. An attacker holding administrative access to a data capture system collapses that separation, and once collapsed the trail can no longer evidence anything, including its own integrity.
Which Inverts the Usual Question
A confidentiality incident asks what was taken. An integrity incident asks what can still be proven, and the answer can be nothing even where forensic analysis finds no modification. Absence of evidence of change is not evidence of absence of change once the mechanism that would have recorded it was under someone else's control.
What Is the Remedy?
Regeneration, which is what makes this expensive rather than merely serious.

A confidentiality failure is remedied through notification, monitoring and regulatory engagement. Data whose integrity cannot be demonstrated cannot be repaired by any of those, because the deficiency is in the record rather than in its distribution. The affected portion has to be produced again, meaning subjects enrolled and the protocol run.
Which Makes the Interval the Cost
Repeating a portion of a trial costs whatever that portion cost, plus the delay to every downstream milestone that depended on it. The delay is frequently larger than the direct expense, since a regulatory submission moves and the commercial position moves with it.
Why Is This Unusually Computable?
Because the protocol states the numbers, which is rare in cyber loss modeling and worth exploiting.
A protocol specifies how many subjects, over what recruitment period, with what visit schedule and what follow-up duration. So the cost of repeating a defined portion is arithmetic rather than estimation, and it can be computed before any incident occurs from a document the organization already holds.
Which Reverses the Usual Uncertainty
Most cyber scenarios have a reasonably estimable frequency and a highly uncertain severity. Here severity is the confident term and frequency is the guess, so the modeling effort belongs on how often rather than on how much, and working without an incident history is the harder half in this scenario.
What Determines the Affected Portion?
Dwell time, which converts directly into subjects requiring repetition.

The question is not whether the trial is compromised but which part cannot be demonstrated. Which sites, which subjects and which visit windows fell inside the period when administrative access was held by somebody unauthorized. Every additional week of undetected access enlarges that set.
Which Makes Detection Time a Direct Multiplier
In most sectors faster detection reduces the volume of data exfiltrated. Here it reduces the number of subject visits whose integrity cannot be established, and each one carries a repeat cost. The value of detection is therefore expressible in subjects rather than in records.
What Cannot Be Repeated?
The blind, which is the second loss and the one repetition does not fix.
Where an attacker held access to randomization or trial supply management data, the allocation may be known. An unblinded trial cannot be re-blinded, and the subjects already enrolled cannot be unlearned. Continuing produces data a regulator may discount and repeating requires a fresh cohort rather than a fresh run.
Which Argues for Separating Those Systems
Randomization and supply systems carry a loss category the data capture systems do not, so holding them under the same administrative boundary lets one compromise reach both. Separating the privilege is a control decision with an unusually direct payoff, and separation of duties as a design property is the same reasoning in another setting.
What Does the Regulator Add?
An inspection exposure that runs alongside the repeat cost rather than instead of it.
Data integrity is already the most common category of finding in this area, with more than half of a sample of twelve hundred inspection observations issued to clinical investigators involving integrity, particularly around original data, attribution and accuracy. An incident affecting the systems that produce those records arrives into an inspection regime already focused on exactly that question.
Which Changes What Response Has to Produce
Not a notification but a reconstruction. Which records, which period, which systems, what can be demonstrated and on what basis. The reconstruction is an evidentiary exercise conducted for an audience that inspects records professionally, and it cannot be assembled from a forensic report alone.
Does the Sponsor or the Site Carry It?
The sponsor, mostly, and the exposure sits in systems the sponsor frequently does not operate.
A trial runs across a sponsor, contract research organizations, investigator sites and specialist laboratories, with data capture, patient-reported outcomes, imaging and safety reporting often in different hands. Regulatory accountability for the reliability of the submission stays with the sponsor while the systems producing the records belong to several other parties.
Which Makes This a Third-Party Exposure
An integrity failure at a research organization or a central laboratory produces a repeat cost the sponsor absorbs, and the contract determines whether any of it flows back. Most agreements address confidentiality thoroughly and integrity barely, so what a supplier arrangement has to specify needs a clause about audit trail controls rather than only about data protection.
What Should the Clause Require?
Separation of audit trail modification from record modification, notification of administrative compromise within a period short enough to bound the affected window, and access to the trail for reconstruction purposes. Three requirements, none of them expensive to grant, and all three unavailable after an incident if they were not agreed before.
What Should Be Established?
Four things, and the first is a document somebody already has.
The cost of repeating a defined portion of each active trial, from the protocol. Whether audit trail modification is separated from record modification in every system holding trial data, since that separation is the whole control. Whether randomization and supply systems sit under a different administrative boundary from data capture. Then how long unauthorized administrative access would persist before detection, since that interval sets the number of subjects. Cyber risk quantification built on those inputs produces a figure with an unusually firm severity term.
The Loss Is Demonstrability
Trial data whose integrity cannot be demonstrated is unusable even where forensic analysis finds no alteration, because the requirement is provability rather than accuracy. Regulation separates the ability to modify records from the ability to modify the audit trail, and administrative compromise collapses that separation so the trail can no longer evidence its own integrity. The remedy is regeneration rather than notification, so the affected portion has to be run again, and the protocol states the numbers so that cost is arithmetic. Dwell time converts directly into subjects requiring repetition, making detection time a multiplier expressible in subjects. The blind also cannot be restored at all, which is a separate loss requiring a fresh cohort. Kovrr's cyber risk quantification models this with severity as the confident term rather than the estimated one.
To see integrity exposure modeled from protocol duration rather than from a per-record cost, book a demo with our risk experts.
Trial Data Integrity FAQs
Speak to an ExpertIs clinical trial data integrity a confidentiality problem?
No, and treating it as one misses the loss. A confidentiality incident asks what was taken, while an integrity incident asks what can still be proven, and the answer can be nothing even where forensic analysis finds no modification. Absence of evidence of change is not evidence of absence of change once the mechanism that would have recorded it was under someone else's control, so the loss occurs without any alteration.
What does 21 CFR Part 11 require for audit trails?
Secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying or deleting electronic records. Critically, the people who can create or modify records must not be able to modify the trail, and trails must be retained at least as long as the underlying records and be available for agency review. An attacker with administrative access collapses that separation.
Does a compromise of trial data mean repeating the study?
The affected portion, potentially. A confidentiality failure is remedied through notification, monitoring and regulatory engagement, and data whose integrity cannot be demonstrated cannot be repaired by any of those because the deficiency is in the record rather than its distribution. The affected portion has to be produced again, meaning enrolling subjects and running the protocol, plus the delay to every downstream milestone.
How do you cost a clinical trial data integrity failure?
From the protocol, which is why this is unusually computable. A protocol specifies how many subjects, over what recruitment period, with what visit schedule and what follow-up duration, so the cost of repeating a defined portion is arithmetic rather than estimation. That reverses the usual position, since severity becomes the confident term and frequency the guess, so modeling effort belongs on how often rather than how much.
What determines how much of a trial is affected?
Dwell time. The question is not whether the trial is compromised but which part cannot be demonstrated, meaning which sites, which subjects and which visit windows fell inside the period when administrative access was held by somebody unauthorized. Every additional week of undetected access enlarges that set, so detection time is a direct multiplier expressible in subjects rather than in records.
Can a compromised blind be restored?
No, and this is the loss repetition does not fix. Where an attacker held access to randomization or trial supply management data the allocation may be known, an unblinded trial cannot be re-blinded, and the subjects already enrolled cannot be unlearned. Continuing produces data a regulator may discount while repeating requires a fresh cohort rather than a fresh run, which argues for holding those systems under a separate administrative boundary.




