Yes. WordPress is not the deciding factor in whether a pharmaceutical site is secure or compliant — unmaintained dependencies and stale accounts compromise sites on every platform — and a maintained, properly structured WordPress build is considerably safer than an unmaintained enterprise CMS.
WordPress has an enterprise reputation problem, usually earned by badly built implementations: generic page builders, unmaintained plugins, no real content model. That is an implementation quality issue, not a limitation of the platform itself.
A pharmaceutical WordPress build means a real content model matched to your actual content types, a component-based editing system instead of a page builder, and a maintenance discipline that keeps the platform current. See pharmaceutical WordPress for how that is actually structured.
Very large multi-market groups sometimes need enterprise-scale infrastructure and governance on top of WordPress, which is achievable — see enterprise WordPress — rather than a reason to move to a different platform by default.
Yes, provided it is properly hardened and maintained, since WordPress itself is not inherently less secure than other platforms but is a frequent target because of its popularity and the plugins sites add to it. See website security for the specific hardening measures a pharmaceutical portal should have in place.
Yes, WordPress Multisite lets several affiliate sites share one governed installation with shared plugins, security patching, and a central update schedule, while still allowing each market its own content and languages. See WordPress Multisite for how that shared governance model is typically structured across a multi-country group.
Migrating is often the right move once licence and maintenance cost stop matching what the site needs, particularly if the enterprise platform is oversized for a marketing or informational site. See CMS replatform for how that migration is typically scoped and sequenced to avoid disrupting live content.
Yes, with the right plugin configuration WordPress can enforce a draft-review-approve workflow before content publishes, and log who approved what and when. This is not built in by default, so it needs to be configured deliberately as part of the build rather than assumed to exist out of the box.
Tell us what you are running today and we will tell you honestly whether WordPress fits.