Why Are Small Biotechs a Bigger Cyber Target Than Big Pharma?

Small and mid-size biotechs are the more interesting target because they hold the newest science, not because they are easier to breach. That is the correction Anne Herold Li, Shareholder and New York Managing Partner at Brownstein Hyatt Farber Schreck, makes to the assumption she hears most often from company leadership. Executives at smaller companies tend to reason that nation-state attention scales with company size, so a firm of two hundred people is beneath notice. The logic runs backwards. Big pharma acquires innovation from smaller companies, which makes those companies the research labs of the industry, which makes them precisely where an adversary would go to leapfrog a decade of work. On Open Door Salon, Herold Li and Raja Mikkili, Vice President of Core Technologies and Security at Arcutis Biotherapeutics, work through what that means for a company that has never considered itself a national-security asset.
Why is company size the wrong measure of cyber risk?
Because the adversary is shopping for technology, and technology does not track headcount. Herold Li states the correction in one line.
"it's not a size thing. It's a technology thing."
She then explains why the smaller company is the better destination, and the reasoning is drawn from how the industry's own deal flow works.
"the smaller companies are doing sort of the innovative pivot, the new R&D, the latest technology, and big companies are shopping them for that."
"They're looking to get acquired by these big companies, but because they're the R&D labs for the big companies, they're actually the more interesting target, I would say, for a nation state trying to leapfrog into the industry."
The uncomfortable implication is that the thing making a small biotech attractive to an acquirer is the same thing making it attractive to a state actor. A company cannot pursue the first without carrying the second.
Does outsourcing to the cloud transfer the risk?
No, and Mikkili identifies this as the specific reasoning error he encounters at early-stage companies. The security stack genuinely does belong to somebody else. The intellectual property does not.
"when you're starting out a smaller biotech, you're actually relying on cloud technologies, SaaS, outsourced partners."
"It's like, I don't have anything to lose. It's them, the third parties are actually taking care of all of those security things because we have hired them to do so."
His answer separates the two.
"But I think the IP that you are generating and that you hold, that actually makes it very valuable to the nation. So I think that's the catch right here. That's the asymmetry here."
A vendor can operate your controls. A vendor cannot hold your risk, because the loss lands on your pipeline and your valuation. That distinction is what a right-to-audit clause exists to enforce, covered in what a biotech vendor contract should require.
What did the West Pharmaceutical breach reveal?
That the exposed tier is the supplier layer sitting underneath the companies that think of themselves as innovators. Mikkili describes what makes the company structurally significant.
"It's a company that makes packaging equipment for injectables, delivery systems. Right. It's a supplier to most pharmaceutical organizations. So it's the it's a central point for a lot of the organization. So it's almost like a third party to many organizations, the whole industry."
West Pharmaceutical Services disclosed in an SEC filing that it determined it had experienced a material cybersecurity attack in which data was exfiltrated and systems were encrypted, following detection of an intrusion on May 4, 2026. Mikkili's reading is that the exfiltration itself is the strategic event, separate from the operational disruption.
"Now, if you go after this exfiltrate data, which is what has been done at this company. Right. There's valuable information that somebody could actually map another strategy, another attack."
He is explicit that the obligation ran in both directions, which is the part most readers will recognize from their own vendor lists.
"It's it's actually both ways. West pharmaceutical should have actually thought about the way to risk management. Also, the companies who've hired or have been engaged in with West pharmaceuticals for their products and supply packaging services."
If a single supplier sits inside the operations of much of an industry, then every customer inherits a share of that supplier's security posture. Mapping that exposure is the subject of our earlier piece on how to map sub-tier supply chain risk.
What does it take for a CEO to accept this?
A specific and slightly uncomfortable belief about their own company. Herold Li names it directly, and the delivery is deliberately light because the underlying ask is not.
"So it takes a little bit of, I know this is going to come as a shock to some people, arrogance of the CEO to understand that their company is so interesting and impressive that they would give a nation state a head start."
This is a genuine obstacle rather than a joke about executive ego. A founder who has spent three years being told the science is unproven has been trained into modesty about its value. Nation-state threat modeling asks them to invert that instinct and assume the work is significant enough to steal. The board conversation and the threat model both depend on which belief the CEO actually holds, which connects to what nation-state hackers want from a biotech in the first place.
What is the defense for information that cannot be secured?
Take it off the network. Herold Li has started giving advice she acknowledges sounds like a step backward, and she is specific about which category of information it applies to.
"for your protocols, the secret things that are your quote, unquote, crown jewels, the things that you're not patenting, the things that give you a competitive edge, particularly like manufacturing or benchtop sciences, paper is safe and not hackable."
The logic is a comparison of attack costs. Placing a human being inside a small research company where everyone knows each other is slow, expensive, and carries real exposure. Reaching the same information through the company's software is none of those things.
"if this is really your value, your IP value, your company's value, don't even put it out there."
The practical version is narrow rather than absolute. Unpatented protocols, benchtop methods, and manufacturing know-how are a small enough set that keeping them off networked systems is a real option, and they are exactly the assets that a patent filing would otherwise never protect.
This post draws on the recorded, on-the-record conversation with Raja Mikkili and Anne Herold Li on Open Door Salon. Watch or listen to the full episode, Nation States Aren't Targeting Big Pharma, or read more about Raja Mikkili and Anne Herold Li.
Open Door Salon brings the people who build, fund, and fight for global healthcare into one room. If your organization wants to reach that audience, see our sponsorship options.
