Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
Cybersecurity

What Do Nation-State Hackers Actually Want From a Biotech?

By Open Door Salon · August 8, 2026
What Do Nation-State Hackers Actually Want From a Biotech?

A nation state attacking a biotech is not trying to get paid. It is trying to get the roadmap. Raja Mikkili, Vice President of Core Technologies and Security at Arcutis Biotherapeutics, draws the line between a state actor and an ordinary criminal precisely: the criminal wants leverage over your files, and the state actor wants the shape of your science. That means the target set is different from what most security programs are built to defend. It is not just the database. It is the formulation, the manufacturing process, the clinical data set, the partner list, and the map of where the company is weak. On Open Door Salon, Mikkili and Anne Herold Li, Shareholder and New York Managing Partner at Brownstein Hyatt Farber Schreck, explain what that changes for a company that has been budgeting against ransomware.

What does a nation state actually target in a biotech?

The whole company's direction, not a single asset. Mikkili separates the two threat models by their economics.

"I think nation state, interestingly, is different than the regular threat actors that you see. One of the things that they are looking at, not tactical monetary extortion, but they're seeing something big."

What "something big" means in practice is a composite picture rather than a file.

"They're not just after a company's database, but they're looking at a full roadmap for an organization. They want to see where the science is going. They want to see where the company is vulnerable, what partners are they engaging with, and if they kind of give them an advantage to go after their third parties and other partners."

Read that list again as an attacker would. Three of the four items are not data you would classify as crown jewels. Where the science is going is strategy. Where the company is vulnerable is architecture. The partner list is a directory. A program tuned to protect regulated personal data can leave all three exposed while passing every audit it was designed for.

Why is this different from a ransomware attack?

Because there is no transaction, and therefore no moment when you find out. Ransomware announces itself. That is the business model: the attacker needs you to know, so you pay. A state actor gathering a roadmap has the opposite incentive and wants the access to persist quietly.

Mikkili's framing is that the value being extracted is the accumulated cost of the research itself. The prize is the R&D and the intellectual property tied to it, the formulation, the manufacturing process, the clinical data set, anything that lets an adversary skip the parts a biotech has already paid for. The attacker is not monetizing your data. They are avoiding your development timeline.

Why do most biotechs assume they are not a target?

Because the signal never reaches the people who set priorities. Mikkili has watched this fail at the communication layer more than the technical one.

"There's definitely a lot of noise, right? In terms of hackers and anything that you hear on the news media, it is overwhelming."

The consequence is a default posture that is simply wrong.

"Are they even a target from a nation state? Most people, most biotechs don't think they are actually a target."

Herold Li puts the strategic logic underneath that mistake. The attacker is not running a competitive play against one company. It is running an industrial catch-up play against a region.

"Nations are trying to jumpstart an industry in which the United States has such a lead, particularly United States and Europe, that there's almost no way to get there without this jumpstart, right? The scientists, the methodology, the manufacturing, the know-how that have been built up over decades."

That reframes the question a board should be asking. It is not whether your company is big enough to be worth attacking. It is whether your company holds any part of a capability another country cannot build on its own schedule. Most companies doing novel work do, which is the argument developed in the companion piece on why small biotechs are a bigger cyber target than big pharma.

What convinces a CEO that the risk is real?

Peer evidence, delivered as a signal rather than a warning. Mikkili's method is deliberately unalarming, because alarm is what the noise already sounds like.

"I think building that trust in showing the data. What is a data point, a signal that somebody has seen within the organization or a peer organization?"

From there the conversation becomes concrete: here is a signal seen at an organization of our size in our industry, here are the consequences that followed, and here is what it would have meant for us. He is explicit about why the softer route works better than escalation.

"Otherwise, it's something that you're asking your CEO to focus and pay attention to, which is maybe not their priority at this point in time. They don't see the imminent need because that's not the core business."

That is a fair description of a functioning executive team rather than a negligent one. The CEO is running the business. The security leader's job is to make the risk legible in business terms before an incident does it for them.

Is the government treating biotech data as a security issue?

It already has. The BIOSECURE Act was enacted as Section 851 of the FY2026 National Defense Authorization Act, and Herold Li is careful about where it came from, because the origin story shapes how durable it is.

"This was a Biden era effort and it was a bipartisan effort. And it came out of a security intelligence briefing because there was concern from what has been publicly disclosed. There was a concern that China, the country, the military components of China are looking at U.S. bio data."

Her reading of the intent is that the statute is doing indirectly what no cybersecurity regulation has done directly.

"They're forcing companies to take their cybersecurity seriously and their supply chain seriously in a way that they just haven't before."

For a company that has treated security as an IT line item, that is the practical signal. The obligation is arriving through procurement and supply-chain rules rather than through a security mandate, which means it lands on legal and compliance teams who may not be talking to the people who own the network. Where that obligation gets specific is in the contracts themselves, covered in what a biotech vendor contract should require. The same drafting gap shows up inside collaboration agreements, where who owns the data a collaboration generates is often decided in four sentences nobody read. The mechanics of how the theft itself happens are laid out in our earlier piece on how intellectual property is stolen in China.

What should a security leader do with this?

Start by re-scoping what counts as sensitive. If the roadmap is the target, then the partner list, the architecture diagram, the pipeline timeline, and the manufacturing know-how belong in the protected set alongside the clinical data. Then build the peer-signal habit Mikkili describes, so the board hears about risk on a normal Tuesday instead of during an incident.

This post draws on the recorded, on-the-record conversation with Raja Mikkili and Anne Herold Li on Open Door Salon. Watch or listen to the full episode, Nation States Aren't Targeting Big Pharma, or read more about Raja Mikkili and Anne Herold Li.

Open Door Salon brings the people who build, fund, and fight for global healthcare into one room. If your organization wants to reach that audience, see our sponsorship options.

← Back to the Blog