M ManySignal

Biotech & Pharmaceutical

Protect clinical trial data and drug formulas from nation-state espionage

APT10, APT41, and Winnti Group have targeted pharmaceutical R&D continuously since 2020. Clinical trial data, synthesis routes, and NDA submissions are the primary targets. ManySignal monitors CDMS platforms, Veeva Vault, and research networks — detecting exfiltration before IP leaves your environment.

$1.9T

Value of global pharmaceutical R&D pipeline (IFPMA, 2023)

40%

Of pharma companies experienced a data breach in 2023 (Deloitte)

COVID-19

APT campaigns targeting vaccine R&D detected in 2020 by NSA/NCSC

21 CFR 11

FDA audit trail requirement for all GxP-validated systems

How ManySignal protects pharmaceutical organisations

Clinical trial data and drug formula protection

Pharmaceutical R&D data — NDA submissions, clinical trial datasets, synthesis routes, and patent applications — are the highest-value intellectual property in any industry. ManySignal monitors access to clinical data management systems (Veeva Vault, Medidata Rave, Oracle Clinical), research document repositories, and laboratory information management systems (LIMS). It detects bulk access by individuals outside their assigned study team and data transfers to personal cloud storage.

  • CDMS access baselining per study role and phase
  • Synthesis route and manufacturing process document access anomalies
  • Veeva Vault and SharePoint bulk export detection

Clinical trial data and drug formula protection

GxP system change control monitoring

FDA 21 CFR Part 11 and EU Annex 11 require that computerised GxP systems maintain complete, unalterable audit trails. ManySignal monitors change events in GxP-validated systems and alerts when changes occur outside the approved change control process — unsigned changes, changes by non-qualified accounts, or changes during data lock periods.

  • GxP system change outside change control window detected
  • 21 CFR Part 11 audit trail completeness monitoring
  • Data lock period protection — alerts on any GxP data modification

GxP system change control monitoring

Nation-state pharmaceutical espionage detection

APT10, APT41, and Winnti Group have conducted sustained campaigns against pharmaceutical companies, targeting COVID-19 vaccine candidates (2020), cancer therapeutics, and manufacturing scale-up data. ManySignal detects the specific TTPs used: VPN credential stuffing, SharePoint enumeration, and exfiltration via legitimate cloud services masquerading as Rclone or cloud sync tools.

  • Rclone and cloud sync tool execution outside approved IT usage
  • SharePoint and OneDrive bulk file access anomalies
  • Spear-phishing link telemetry correlated with subsequent access events

Nation-state pharmaceutical espionage detection

Regulatory requirements supported

FDA 21 CFR Part 11EU GMP Annex 11HIPAA (for clinical data with patient records)GDPR (clinical trial subjects)ICH E6(R3) GCPISO 27001:2022NIST CSF 2.0SOC 2 Type II

Pharma security — common questions

How does ManySignal support FDA 21 CFR Part 11 audit trail requirements?

ManySignal monitors GxP-validated systems to ensure audit trails are not modified, disabled, or bypassed. It detects events that would constitute a 21 CFR Part 11 violation: system clock changes, audit log service termination, log file deletion, and configuration changes that disable logging. Evidence packages for FDA inspection readiness include a complete timeline of system events alongside identity context.

Can ManySignal protect against nation-state attacks targeting our NDA submission data?

Yes. NDA and BLA submission data in Veeva Vault, SharePoint, or ECTDs is monitored for bulk access and unusual export patterns. ManySignal flags access by accounts with no assignment to the relevant compound or therapeutic area, large document set downloads, and access during unusual hours inconsistent with the user's working pattern — all common indicators of industrial espionage exfiltration.

Does ManySignal support monitoring for clinical trial data integrity?

Yes. ManySignal can monitor Medidata Rave, Oracle Clinical, and Veeva EDC for data integrity events — unplanned modifications to locked data, access by accounts outside the study team, and bulk data exports. For multi-site trials, it monitors each site's data entry patterns and flags anomalies that could indicate protocol deviation or data manipulation.

How does ManySignal address supply chain security for contract manufacturing (CMO/CDMO) relationships?

CMOs and CDOs with access to manufacturing formulations, batch records, and quality systems via shared portals represent a significant supply chain risk. ManySignal monitors third-party access to these systems, baselines each CMO's normal access pattern (what systems, what hours, what data volumes), and alerts when a CMO account accesses systems or data outside their contracted scope.

Is ManySignal validated for use in GxP environments?

ManySignal operates as a monitoring and detection platform, not as a GxP system itself — it does not modify GxP data. As such, ManySignal falls into the Annex 11 Category 1 (infrastructure) classification for validation purposes. Customers deploying ManySignal in GxP environments receive a validation support package including IQ/OQ/PQ templates, vendor audit documentation, and supplier assessment responses.

Schedule a pharma-specific demo

See Veeva Vault access monitoring, GxP change control detection, and nation-state exfiltration scenario detection — in one focused session.