Danish pharmaceutical giant Novo Nordisk, the manufacturer of blockbuster treatments including Wegovy, disclosed a cybersecurity incident involving unauthorized access to internal IT systems. The company reported that information connected to certain clinical-trial participants had been copied externally without authorization. According to the company, the affected information may include patient identifiers, demographic information, and health-related data used in clinical research.
The incident serves as a reminder that highly regulated organizations remain prime targets for cybercriminals seeking sensitive personal and research information. While Novo Nordisk stated that the exposed information was not directly linked to patient names and that additional identifying information was not compromised, the event demonstrates the challenges organizations face when safeguarding valuable healthcare and research data across complex digital environments.
Following the discovery, the company launched an investigation with external cybersecurity specialists and notified relevant authorities. Several internal systems were temporarily taken offline while remediation and forensic activities were performed. Importantly, the company reported that core business operations continued without interruption, highlighting the role of incident preparedness, response planning, and operational resilience in limiting the business impact of cyber events.
For CISOs, the incident underscores several strategic priorities: protecting sensitive research datasets, enhancing detection capabilities for unauthorized data access, validating segmentation between critical business systems and research environments, and maintaining effective incident response procedures. As organizations continue to manage growing volumes of regulated and high-value data, cyber resilience increasingly depends on the ability to rapidly identify, contain, and investigate security incidents before they evolve into broader operational or regulatory crises.