PODCAST · science
The Med Device Cyber Podcast
by Blue Goat Cyber
In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape.Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you w
-
98
Can We Detect Skin Cancer Without a Biopsy? with Stefan Mazy | Ep 84
What if the biggest problem in skin cancer diagnosis is not finding suspicious lesions, but what happens after we find them?Stefan Mazy joins Christian Espinosa to discuss the personal experience that led him to explore a different approach to skin cancer testing after his mother underwent extensive surgery for an aggressive basal cell carcinoma.Stefan explains how his team is developing a microneedle patch designed to collect cellular tissue without a traditional surgical biopsy, and why he believes the current diagnostic pathway is struggling to scale as skin cancer awareness and testing increase.The conversation also explores the role of AI in identifying suspicious lesions, the trade-off between sensitivity and specificity, and why detecting more abnormalities could increase pressure on an already strained clinical pathway.Christian and Stefan also discuss cybersecurity in medical technology, manufacturing risks, brain-computer interfaces and why connected devices require founders to think beyond the device itself.In This Episode:* 03:33 Stefan’s mother’s skin cancer diagnosis* 08:14 Why he began searching for an alternative to biopsy* 10:08 The scale of unnecessary skin biopsies* 12:37 How the microneedle patch works* 15:13 Why uncertainty creates a diagnostic bottleneck* 23:44 Can AI reliably identify skin cancer?* 28:07 The problem with false positives* 31:50 Cybersecurity, brain-computer interfaces and future risk* 35:20 Stefan’s key takeaway on technology and healthcareCheck out Stefan Mazy and DermaR here: https://www.linkedin.com/in/stefanmazy/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session:https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
97
The Commercialization Gaps MedTech Founders Keep Missing with Ryan Roghaar | Ep 83
Why can a MedTech company have promising technology, a strong team and investor interest, yet still lose momentum when it matters most?Ryan Roghaar joins Christian Espinosa to examine the commercialization gaps that can quietly weaken a medical device company long before the technology itself becomes the problem.Ryan explains why companies often move through fundraising, regulatory strategy, sales and market entry in the wrong sequence, and why inconsistencies between a pitch deck, website, evidence and buyer messaging can immediately create doubt.The conversation explores what happens when claims outpace evidence, why MedTech companies struggle to define exactly who they are selling to, and how cybersecurity and AI are adding entirely new layers of risk to commercialization.In This Episode:07:43 Why Ryan moved into MedTech10:32 Moving from marketing agency to MedTech consultancy11:32 Why devices fail outside the technology itself12:41 Does MedTech commercialization follow a sequence?16:08 The evidence gap inside MedTech companies17:10 How investors pressure-test startups19:55 When a company tells four different stories23:36 Can cybersecurity become a commercial differentiator?24:11 Why medical device hacking feels different27:24 Cybersecurity risks from MRIs to brain implants32:21 The three biggest commercialization gaps Ryan is seeing35:57 Why unclear buyers dilute your message39:08 The pressure to take the wrong customer42:47 Ryan’s three key takeaways for MedTech companiesCheck out Ryan Roghaar’s LinkedIn here: https://www.linkedin.com/in/ryanroghaar/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1*
-
96
Why the Best MedTech Candidates Aren’t Applying to Your Jobs with Darwin Shurig | Ep 82
What happens when AI starts screening job candidates who are also using AI to get through the screening process?In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Darwin Shurig, founder of Top Talent Accelerant, about why recruiting in MedTech is becoming increasingly difficult and what companies can do to avoid costly hiring mistakes.Darwin explores why traditional “post and pray” recruitment is breaking down, how strong candidates can be screened out while weaker candidates use AI to get through the process, and why some highly specialized roles in AI, machine learning and cybersecurity are remaining open for months.The conversation also looks at the enormous cost of getting talent decisions wrong, why the best candidates often are not actively applying for jobs, and how showing candidates the real culture and expectations of a company can help create better alignment before an interview ever takes place.Darwin also shares the personal journey behind his book, The Modern-Day Job, and how major changes in his business and personal life led him to reconsider success, purpose and the importance of the people we choose to work with.In This Episode:01:13 Darwin’s journey from critical care to MedTech recruiting04:38 Why recruiting has become such a crowded industry06:55 The cost of getting the hiring process wrong09:00 How AI is changing candidate screening10:11 Why specialized MedTech roles can stay open for months11:26 Why traditional hiring processes need to change12:31 Creating a better candidate experience13:48 The $9 billion impact associated with warning letters14:49 Why the best candidates are not applying to your job posts15:53 When AI starts interviewing AI16:45 Remote hiring, geography and compensation18:58 The story behind The Modern-Day Job36:51 Why values and alignment matter when choosing people40:33 Building teams around shared values and cultureCheck out Darwin Shurig’s LinkedIn here: https://www.linkedin.com/in/darwin-shurigThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
95
The Hidden Barriers to Clinical Adoption with Amel Havkic | Ep 81
Why do so many promising MedTech companies fail even when the technology is strong, the funding is there and the product is compliant?In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Amel Havkic, founder of EvoMed Consulting, about the hidden barriers that prevent medical technologies from achieving real clinical adoption.Amel explains why clinical adoption is often treated too late, how workflow friction can derail an otherwise strong product and why the founder’s greatest strength can sometimes become the company’s biggest strategic blind spot.The conversation also explores the KOL trap, the cost of forcing behavior change inside already overstretched clinical environments and why cybersecurity, reimbursement, usability and implementation cannot be treated as separate problems.In This Episode01:08 Amel Havkic and VivoMed Consulting02:41 Why 75% of MedTech companies fail04:43 Clinical adoption, fundability and founder blind spots07:23 Why one solution must satisfy many stakeholders09:42 Economic viability and implementation friction12:37 The hidden cost of changing clinical behaviour15:43 The KOL trap and why pilots can mislead18:46 Alarm fatigue and real-world clinical environments20:46 Christian’s introduction to medical-device cybersecurity23:04 Why cybersecurity deficiencies derail submissions27:49 Building the right team around a MedTech founder32:38 Authenticity, intuition and choosing the right partners37:17 Why being human may become a superpower in the age of AICheck out Amel Havkic’s LinkedIn here.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
94
Why Consumer AI Is Not a Medical Device with Tyler Harmon | Ep 80
AI is moving quickly, but medical devices cannot afford to treat every new model like an ordinary software update.In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Tyler Harmon, CEO and co-founder of IASO Automated Medical Systems, about the risks and responsibilities surrounding AI as a medical device.Tyler explains why consumer tools such as ChatGPT and Claude should not be treated as clinical diagnostic systems, even when a doctor remains involved in the final decision. He also explores why a human in the loop does not automatically make an AI system safe when the underlying model was never designed or cleared for that medical use.The conversation examines how predetermined change control plans can support safer AI updates, why developers must understand the difference between frontier models and AI harnesses, and what can go wrong when a medical-device company builds on top of a third-party model.In This Episode00:48 Tyler Harmon and IASO Automated Medical Systems03:34 What qualifies as AI as a medical device?04:44 Predetermined change control plans06:08 When should an AI medical device be updated?09:00 Why medical AI is not new11:32 Why medical AI still needs human oversight17:40 Doctors using ChatGPT to interpret X-rays20:09 Frontier models and AI harnesses24:16 The challenge of developing proprietary AI29:21 Why medical AI can take years to reach the market34:28 Using consumer LLMs outside their intended licence39:25 Licensing third-party AI for medical-device use40:41 Final lessons for medical-AI developersCheck out Tyler Harmon’s LinkedIn here: https://www.linkedin.com/in/tyler-h-938bbb43/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
93
Why Technical Intelligence Is Not Enough with Samantha Silk | Ep 79
A strong résumé may get someone an interview, but technical ability alone does not determine whether they will succeed within an organization.In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Samantha Silk, CEO of Apex Pro Placement, about recruitment, emotional intelligence, and the challenge of identifying the right people for highly technical roles.Samantha explains why an unfilled critical position can cost an organization thousands of dollars every day, when using a specialist recruiter makes financial sense, and why job descriptions often fail to reflect what the company actually needs. She discusses the importance of listening to hiring managers, setting realistic expectations and evaluating candidates beyond the qualifications listed on paper.The conversation explores why highly intelligent professionals sometimes struggle to explain complex ideas, how poor communication can limit careers and why emotional intelligence plays such an important role in leadership, investment and team performance.Christian and Samantha examine gut instinct in hiring, the risks of overriding warning signs, the growing volume of AI-generated recruitment noise and why human judgment remains essential when someone’s livelihood or a company’s future is at stake.In This Episode00:57 Samantha’s path from cybersecurity recruiting to life sciences04:07 When using an external recruiter makes sense05:39 How an open critical role can cost up to $5,000 per day09:41 Why effective hiring starts with listening to the client11:57 Why most job descriptions fail to describe the real role13:34 Emotional intelligence in recruitment and leadership18:53 Why technical experts must communicate in simple language21:24 Investor pressure and unethical recruitment practices26:25 Using intuition and gut instinct when hiring32:03 How constant screen use affects attention and connection37:22 AI-generated résumés, recruitment noise and human oversight39:58 What rock climbing teaches us about trust in cybersecurity42:36 Final lessons on communication, EQ and technical careers45:04 Christian’s vision for AI agents running a company46:41 Why social engineering succeeds against hospitals47:20 How AI is making phishing more personalized48:21 Why AI is changing every part of business49:25 Final lessons on curiosity, assumptions and frictionCheck out Samantha Silk’s LinkedIn here - https://www.linkedin.com/in/samanthawein/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session:https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
92
Productivity, Psychological Safety and AI with Sarah Ohanesian and Jeff Gibbard | Ep 78
Productivity means making meaningful progress on the work that matters most. Yet many organizations remain trapped in repetitive tasks, unclear priorities, unnecessary meetings and systems that rely too heavily on individual employees saving the day.In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Sarah Ohanesian and Jeff Gibbard, co-founders of Super Productive, to explore how teams can reduce friction, improve communication and build working environments that support different kinds of brains.Sarah and Jeff share practical strategies organizations can implement immediately, including creating a universal system for capturing work, automating processes that have been repeated three times and building personal user guides that explain how individual team members communicate, focus and perform at their best.The conversation examines the hidden problems created by workplace “heroes,” employees who repeatedly step in to solve crises but may prevent the organization from building repeatable systems. Sarah explains why identity, recognition and job security can make delegation difficult, while Jeff discusses how psychological safety and curiosity can create more productive conversations.The episode explores neurodiversity in the workplace, the limitations of labels and why employees should be able to explain what they need without disclosing a diagnosis. During a special mic-swap segment, Sarah and Jeff question Christian about AI, social engineering and the changing future of cybersecurity.In This Episode:00:52 What Super Productive does02:24 The difference between being busy and being productive03:39 Why focusing on one task creates momentum04:33 Defining productivity as meaningful progress05:13 Identifying the work that moves the needle06:44 Jeff’s Hyperfocus task-scoring system08:08 Creating a universal inbox for capturing work08:47 Why anything repeated three times should be automated09:07 Building a user guide for every team member10:44 The productivity problem created by workplace heroes11:41 Why some leaders struggle to delegate13:47 Creating psychological safety through curiosity17:16 Why productivity depends on communication19:30 Using personal instruction manuals to improve teamwork24:35 What neurodivergence means25:21 Why different brains require different working environments26:06 Neurodiversity versus neurodivergence28:06 Why “normal” depends on the environment30:47 Neurodivergence in cybersecurity and MedTech31:26 Can emotional intelligence and social skills be learned?Learn more about Sarah Ohanesian, Jeff Gibbard and Super Productive at: https://getsuperproductive.com/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session:https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
91
From Science Fiction to Visual Prosthesis with Frederik Ceyssens | Ep. 77
What if a blind person could use a pair of glasses where information is transmitted wirelessly to an implant in the visual cortex, allowing them to perceive shapes, movement, and elements of their surroundings?In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Frederik Ceyssens, CEO and co-founder of ReVision Implant, about the development of a visual prosthesis designed to restore useful vision by stimulating the brain directly.Frederik explores why his team chose to bypass the eyes and optic nerve, how flexible electrode arrays can stimulate thousands of points within the visual cortex, and what researchers have learned through long-term animal studies.The conversation also explores the cybersecurity risks surrounding neurotechnology. An attacker could potentially interfere with wireless communication, alter the device’s algorithm, or increase stimulation to unsafe levels. The implant may also remain inside a patient for decades, creating difficult questions about encryption, software updates, and technologies that may become obsolete during the device’s lifetime.In This Episode:00:38 Frederik’s background in neural implant research02:31 Why ReVision Implant targets the visual cortex instead of the eye04:26 Developing flexible brain electrodes through long-term testing06:48 Raising €4 million to advance the technology07:42 Preparing for the first proof of concept with a human volunteer09:24 How the glasses and brain implant work together11:04 What vision through the implant may look like12:33 Why colour and depth perception remain difficult16:16 The cybersecurity implications of a visual prosthesis17:43 How an attacker could manipulate the device20:25 The hardest parts of developing neurotechnology22:42 How the implant was tested using monkeys26:12 Designing an implant that can last 15 to 25 years28:28 Why today’s encryption may not remain secure for decades30:16 Why replacing the implant would require months of rehabilitation34:51 How close the technology is to science fiction36:07 The next steps towards testing with blind volunteersFind Frederik Ceyssens on Linkedin: https://www.linkedin.com/in/frederikceyssens/Find ReVision Implant at: https://revisionimplant.comThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
90
Building Medical Devices Right the First Time with Helen Souris | Ep 76
Bringing an innovative medical device to market takes far more than a great idea. It requires regulatory strategy, cybersecurity, quality systems, and commercial planning from the very beginning.In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), to discuss why so many promising digital health companies struggle when they leave the startup phase and enter the realities of regulation.Helen shares her experience leading a digital therapeutics company, raising investment in Australia, navigating software as a medical device regulations and helping startups avoid costly mistakes that can delay or even derail commercial success.The conversation explores why cybersecurity is becoming a deciding factor in procurement, how founders should think about regulatory strategy before writing a single line of code, why quality management systems cannot be bolted on later, and the real-world consequences of ignoring compliance until it's too late.Whether you're building a medical device, digital therapeutic, AI healthcare platform or connected medical technology, this episode offers practical advice for creating products that are secure, compliant and built to scale.In This Episode:00:57 Helen's journey from pharma to digital therapeutics04:33 The realities of raising MedTech investment in Australia09:06 Why choosing the right investor matters13:22 Why many digital health startups misunderstand regulation15:21 Why cybersecurity comes up in every customer conversation16:15 Why founders still leave cybersecurity until the end16:53 Building regulation, quality and cybersecurity from Day One18:31 The $93 million company forced to pull its product21:09 Explaining medical devices through the user journey22:50 The stadium hacking analogy that changes perspectives25:13 Why wearables need a medical lens26:57 The fake Wi-Fi demonstration everyone should remember28:20 Why rebuilding is always more expensive than building properly29:30 Christian's biggest takeawaysFind Helen Souris here on LinkedIn: https://www.linkedin.com/in/helen-souris/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/
-
89
What MedTech Can Learn from the Casino Industry with Melissa Aarskaug | Ep 75
For years, cybersecurity has been viewed as an IT responsibility. Today's threat landscape demands something very different.In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Melissa Aarskaug, a cybersecurity executive with extensive experience protecting highly regulated industries, including banking and casino gaming. Melissa shares lessons from an industry where operations run 24 hours a day, every day of the year, and where even a few minutes of downtime can have enormous financial consequences.The conversation explores why attackers increasingly target regulated industries, how cyber resilience differs from compliance, and why cybersecurity has evolved into a leadership issue rather than simply an IT function. Melissa explains why organisations should focus less on preventing every possible attack and more on ensuring the business can continue operating when incidents occur.Christian and Melissa also discuss how medical device manufacturers can learn from the gaming industry's approach to resilience, the growing role of AI in both cyber defence and cybercrime, why cybersecurity should be integrated into quality management systems, and how leadership teams can better prioritise cyber risk across their organisations.Whether you're a MedTech founder, cybersecurity professional, healthcare leader, or product developer, this episode offers practical insights into building more resilient organisations in an increasingly connected world.Episode Breakdown00:00 Introduction01:09 Lessons from protecting the gaming industry01:58 Why attackers target regulated industries05:22 Cybersecurity is about pressure, not industries06:07 Compliance versus cyber resilience08:08 Medical devices and connected ecosystems12:29 The famous fish tank cyberattack15:03 FDA expectations versus hospital expectations16:04 AI, cyber maturity and the future of security17:25 Four priorities every leader should focus on21:24 Why penetration tests often fail to create change24:38 FDA compliance and designing security from the beginning26:48 Cyber insurance isn't a silver bullet32:21 Cybersecurity is becoming part of quality33:26 Why cybersecurity is moving beyond IT37:42 Final thoughts and key takeawaysFind Melissa Aarskaug here on LinkedIn: https://www.linkedin.com/in/melissa-aarskaug/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
88
The Future of Cardio-Oncology Wearables with Ryan Neely | Ep 74
Cancer treatment is already difficult enough without adding more hospital visits, more testing, and more delays. Yet many cancer therapies carry a significant risk of damaging the heart, forcing patients to undergo regular cardiac screening throughout their treatment journey. What if clinicians could monitor cardiac function with a simple wearable patch instead?In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Ryan Neely, co-founder and CEO of Skribe Medical. Ryan shares his journey from neuroscience research and implantable neuroprosthetics to building a company focused on improving cardiac monitoring for cancer patients.The discussion explores the growing field of cardio-oncology and the challenges patients face when cancer treatment depends on frequent cardiac assessments. Ryan explains how Skribe Medical's wearable monitoring platform aims to reduce treatment delays while improving patient convenience through a battery-free, AI-powered patch designed to measure cardiac function.The conversation also takes a deep dive into cybersecurity considerations for connected medical devices. Ryan and Christian discuss common misconceptions about cybersecurity risk, why hospital networks often present greater challenges than home environments, and how device manufacturers should think about security as products evolve from standalone systems to connected healthcare technologies.Finally, the episode explores commercialization, reimbursement models, FDA engagement, and the reality that regulatory clearance is often just one milestone in a much longer journey toward successful adoption.Whether you're a MedTech founder, healthcare innovator, cybersecurity professional, or clinician, this episode offers valuable insights into the intersection of patient care, connected devices, and healthcare innovation.Episode Breakdown00:00 – Introduction01:53 – The hidden cardiac risks of cancer treatments02:58 – Skribe Medical's wearable cardiac monitoring platform03:53 – Future applications beyond oncology04:45 – Battery-free device design and patient comfort06:00 – Remote patient monitoring and reimbursement models09:40 – Cybersecurity risks for connected medical devices14:06 – Why hospital networks present unique security challenges16:02 – FDA cybersecurity expectations and evolving regulations19:03 – Regulatory changes and long MedTech development cycles21:02 – Commercialization versus FDA approval24:13 – AI models and the Predetermined Change Control Plan25:55 – The realities of clinical testing and device validation28:14 – Final takeaways and lessons learnedFind Ryan Neely here on LinkedIn: https://www.linkedin.com/in/ryan-neely-ph-d-14464340/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
87
Navigating U.S. Market Entry for MedTech Developers with JJ Amell | Ep 73
When you develop a groundbreaking medical device, you assume the engineering and clinical data will carry you across the finish line. The legal landscape of U.S. market entry involves layers of corporate traps that most innovators completely overlook. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with JJ Amell, the founder of Amell Law, to unpack the complex realities of international corporate structuring, business immigration, and intellectual property protection.JJ shares his unique transition from building computers and working within his father's cardiology practice to guiding international medical technology firms through federal bureaucracy. The trio explores why setting up a basic LLC through automated online legal platforms leaves multi-million dollar startups exposed to catastrophic liability. They break down the tactical timing of securing O-1 founder visas and investor visas before state borders close behind you, and analyze the shifting corporate battleground between Delaware and Texas for control over majority shareholder decisions. The specifics may differ, but the challenge is the same: protecting what you've built. This conversation covers everything from Customs and Border Protection issues to defending service marks against public database scrapers.Episode Breakdown:00:00 - Intro00:54 - Welcoming MedTech attorney JJ Amell03:38 - Solving legal pain points for global innovators06:11 - The three pillars of U.S. market entry08:33 - The inverse market challenge: Moving from Europe to the U.S.10:43 - Factoring in fiscal repercussions and international tax consultations12:57 - State jurisdictions: Delaware standards vs Texas corporate law16:21 - California red tape and the rise of alternative technology hubs22:41 - Reverse engineering corporate strategy to avoid late-stage corrections25:44 - The danger of automated penetration tests and interactive FDA reviews29:39 - Deportation risks and B-1/B-2 tourist visa limitations31:24 - Government bureaucracy timelines and USPTO trademark processing realities33:04 - Public database scraping and the explosion of corporate filing scams37:37 - AI voice cloning and deepfake vulnerabilities targeting tech executives40:52 - Code Blue Chart: Documented cybersecurity fatalities in healthcare44:25 - Closing thoughts and reconnecting with natureFind JJ Amell here on LinkedIn: https://www.linkedin.com/in/jjamellesq/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
86
The Psychology of Medical Device Security Awareness with Shahbaz Ahmed | Ep 72
When you try to communicate cybersecurity risks to medical device manufacturers, do you feel like you are speaking ancient Hieroglyphics? You are not alone. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with Shahbaz Ahmed, the Founder and CEO of Leadership Studi. Together, they explore the intersection of human psychology, cross-cultural leadership styles, and the massive awareness deficit currently facing global medical device cybersecurity.Shahbaz shares his unique framework on human engineering, detailing how the emotional depth of Eastern leadership can bridge with the logic-driven framework of the West to build stronger, international tech organizations. The trio explores why cybersecurity professionals struggle to make hospital buyers and developers care about vulnerabilities, why simple, human-centric messaging trumps complex technical jargon every single time, and whether you are a technical specialist looking to scale into broad leadership or an executive trying to keep patient devices secure across global borders.Episode Breakdown:00:00 - Intro02:14 - Leadership styles: Eastern emotion vs Western logic05:07 - Human engineering and the science of emotional psychology08:31 - Capacity vs capability: breaking down our emotional fuses12:28 - Technical leadership vs broad vision leadership14:29 - The Ex Machina color theory analogy for cultural exposure19:10 - Hungry judges and decision fatigue: how state affects choice24:43 - How increasing capability expands human cognitive capacity26:35 - The shocking lack of medical device cybersecurity awareness globally31:12 - Why regulatory updates are outpacing downstream hospital practice35:27 - Breaking down big words to make security simple38:00 - Key takeaways: consistency as the ultimate weapon for successFind Shabaz Ahmed here on LinkedIn: https://www.linkedin.com/in/shahbaz-ahmed-4004ab86/The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
85
The Age of Digital Health Humanity with Philippe Gerwill | Ep 71
Philippe Gerwill manages to be a board advisor for nearly 30 companies without losing his humanity. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with the world-renowned futurist to discuss why “unlearning” is the most vital skill for today’s healthcare leaders. They explore the shift from traditional medicine to consumer-led health and why patients are flocking to ChatGPT regardless of what their doctors think!Philippe explains how he maintains a presence on close to 30 company boards while using a massive AI ecosystem to scale his impact. This conversation is a reminder that the human piece is actually the only thing that matters in the end.Episode Breakdown:00:00 The concept of unlearning as a vital skill for healthcare leaders.01:52 Philippe’s background at Novartis and transition into healthcare technology.03:35 Managing advisory roles for nearly 30 companies using an AI ecosystem.04:50 The Favikon ranking and maintaining a 96.5 percent authenticity score.07:49 Defining the role of a futurist in the modern era.09:21 The intersection of technology and gut feeling.18:15 Patient behavior: why consumers are driving the shift to AI in clinics.32:10 The mandate to use our brain and the risks of over-relying on tools.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn:https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
84
Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | Ep 70
Medical software is still underestimated by teams that think generic engineering habits will carry over cleanly into a regulated environment. They do not. The work gets harder when requirements, traceability, security, testing discipline, and approval timelines all collide.A stronger strategy starts earlier, uses specialists sooner, and avoids making AI or code velocity the headline when architectural quality and compliance readiness are what determine whether a product can truly ship.Episode Breakdown00:01 Opening08:02 When to bring in partners10:48 Cybersecurity as a timing issue12:24 AI pressure and code quality27:07 Documentation discipline36:26 Why specialist review matters38:33 Final reflectionsThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
83
Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital | Ep 69
Early-stage MedTech gets riskier when investors confuse a compelling story with a credible device. Stronger diligence starts by testing whether the science is real, whether clinicians would actually use the product, and whether the company has thought seriously about regulatory fit, reimbursement logic, and engineering durability.That framework becomes even more important in neurotech, where public fascination can outrun the evidence base and where the difference between a breakthrough and a weak claim is often diligence quality.Episode Breakdown00:00 Opening02:42 Science and engineering filters07:55 Why neurotech still has open space17:15 Cybersecurity as a hardening issue24:20 How specialist funds operate38:13 Final reflections40:58 EndThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
82
Why MedTech Needs More Than Approval with Michael Branagan Harris of HealthTech Strategies Limited
A device can clear regulatory hurdles and still struggle commercially if the evidence is too narrow. MedTech companies need proof that speaks to affordability, care quality, operational impact, and long term value, not just technical performance.Market selection matters just as much. The same solution may fit the United States, the UK, Germany, or the Netherlands very differently because reimbursement models, provider incentives, and care delivery systems are not built the same way.Episode Breakdown00:00 Opening09:02 What evidence actually needs to prove14:16 Building a stronger adoption case22:43 Economic logic across markets28:36 Choosing where to launch42:08 Key reflections48:30 EndThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
81
De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners
Product decisions made during early development determine commercialization outcomes years later. Wrong choices about regulatory pathways, feature sets, and market segments create compounding problems limiting commercial success.Christian Espinosa and Trevor Slattery explore product management with Brent Lavin, Chief Product Catalyst of Ironwood MedTech Partners, covering why 510(k) pathways average four years while PMA programs require seven to nine years, and how feature set alignment shapes success.The engineering mindset applies hypothesis testing to product development through iterative refinement.Practical for MedTech founders and product teams.Episode Breakdown:00:02 Introduction04:35 Ironwood origin06:02 De-risking decisions10:15 Hypothesis testing14:30 Pathway selection18:45 Timelines22:20 Claims limits26:40 Feature alignment30:15 Segmentation34:55 Clinical trials38:45 Entrepreneurship40:45 Insights43:29 CloseThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
80
Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech
Vibe coding enables rapid development through AI-generated code but introduces security risks when developers accept outputs without verification. Malicious actors can inject vulnerabilities through manipulated training data or prompt engineering. Supply chain attacks become easier when developers blindly trust AI implementations.Jake Rodriguez, Founder and CEO of Triangle Tech, joins Trevor Slattery and Christian Espinosa to explore the security implications of vibe coding, how attackers exploit AI code generation, and what verification processes prevent unverified code reaching production.Understanding generated code requires technical knowledge many vibe coding adopters lack.Practical for development and security teams.Episode Breakdown:00:00 AI Search vs Google + Risks01:13 Intro + AI, Marketing, Cybersecurity01:39 Jake Rodriguez Background04:27 What is SEO Today06:30 AI Search vs Traditional SEO08:50 How AI Finds Content (Reddit, Quora)10:11 AI Bias and Hallucinations10:58 Content Strategy + Personal Branding12:27 Why Trust is Shifting (Podcasts, Events)13:56 Bot Farms and Fake Engagement15:02 Apple Branding Psychology16:07 App Permissions and Cyber Risks16:55 AI Voice Scams and Deepfakes19:46 Using AI for Marketing21:04 Prompt Engineering Tips22:36 Where AI Works vs Fails24:28 What is Vibe Coding27:23 AI Risks in Medical Devices30:46 Cybersecurity Challenges in MedTech32:59 AI Jailbreaks and Security Threats34:44 MedTech Marketing Strategy35:43 SEO Landing Page Strategy37:36 Key Takeaways39:00 OutroThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
79
Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health
Early planning prevents expensive corrections when startups address clinical strategy, regulatory pathways, and cybersecurity requirements from day one rather than improvising solutions before launch. FDA pre-submission meetings provide feedback that de-risks strategies before execution.Clinical trial design shapes feasibility for startups with limited budgets. Understanding target markets determines sample requirements since UnitedStates sales need United States samples while Korean sales need Korean data. Reverse engineering where you want to sell enables appropriate planning.Good Clinical Practice guidelines establish responsibility layers. Manufacturers remain accountable for outcomes even when delegating work to CROs or contractors. Understanding responsible versus accountable shapes partner selection.Practical for regulatory and clinical strategy.Episode Breakdown:00:01 Welcome03:45 CRO terminology07:20 Market research findings12:15 Startup needs16:40 Partnerships20:25 Operations24:10 Study types28:35 FDA strategy32:50 GCP guidelines36:15 Accountability39:40 Markets41:36 ThoughtsThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
78
Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA
Quality management system implementation delays create cascading failures across medical device development timelines. Startups using SharePoint or Google Drive for documentation discover at audit time that these tools provide no traceability, no version control, and no evidence of systematic processes.Dr. Basant Bajpai discusses why design controls begin at the concept stage, regardless of whether companies acknowledge them, how reverse documentation costs 6-12 months when manufacturers reach the submission stage without proper systems, and what happens when scaling exposes foundational quality gaps.Simple automated systems that enforce traceability outperform both manual approaches and enterprise platforms that startups cannot fully utilize. Starting early with scalable infrastructure prevents wholesale system transitions during growth.Practical for medical device startups and innovators.Episode Breakdown:00:00 Introduction Hook on QMS Mistakes and AI Boundaries00:49 Why AI Should Assist, Not Own, the Compliance Process01:09 Guest Introduction: Dr. Basant Bajpai and ComplianceMed QRA01:32 Why QMS Is a Survival System, Not Just Software02:20 The Biggest QMS Mistake Medtech Founders Make03:02 Why Early Stage Companies Must Start QMS Sooner Than They Think04:03 Why Shared Drives and Manual Systems Fail During Audits05:05 Start Simple: Build a Traceable Foundation Before You Scale06:08 Cybersecurity and Quality Are More Connected Than Most Founders Realize06:59 How AI Is Being Used Inside an Automated QMS08:00 Human in the Loop: Where AI Helps and Where Experts Must Step In08:48 The Risk of AI Hallucinations in Regulated Documentation10:03 When AI Can Invent Content and Why That Requires Extra Caution10:45 Why You Should Not Use AI Before Your QMS Basics Are Fully Built12:34 Regulator Reactions to AI in Compliance and Documentation13:29 Could Regulators Start Using AI Too?15:09 The Coming AI Arms Race in Regulatory Reviews17:04 Why Traceability Is Still the Hardest Problem for AI18:23 Why Manual Traceability Still Matters in an AI Assisted QMS20:24 AI in Healthcare: Big Opportunity, Big Responsibility22:14 What Happens When Companies Delay Quality System Implementation24:00 The Cost of Reverse Documentation and Missed Traceability25:20 Why Poor QMS Setup Becomes a Scaling Nightmare27:00 Medtech Startups: Limited Budgets, Too Many Critical Priorities28:10 The Cybersecurity Retrofit Problem and Why It Delays Submission29:07 Why New Regulatory Pressure Makes Early Planning Even More Important30:12 FDA Pushback on Weak Cybersecurity Documentation30:58 Awareness and Education as the Real Fix32:22 Final Takeaways: QMS, AI, and Cybersecurity34:05 Why AI Must Stay a Tool and Never Become the Decision Maker35:10 Closing RemarksThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
77
Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel
Early design decisions define the trajectory of a medical device long before commercialization begins. Choices related to software architecture, third-party components, and system connectivity establish both the opportunity and the risk profile of the product.Cybersecurity introduces a layer of complexity that many teams underestimate. It extends beyond protecting data and into safeguarding patient outcomes, ensuring system reliability, and meeting increasingly stringent regulatory expectations.Chris Danek, CEO of Bessel, joins Christian and Trevor to examine how a single overlooked dependency or unsupported component can become a critical vulnerability. In many cases, these issues remain hidden until late-stage testing or FDA review, where remediation becomes significantly more expensive and disruptive.Effective development requires integrating cybersecurity into requirements, architecture, and validation activities from the outset. Threat modeling, component vetting, and design-level decisions play a defining role in reducing downstream risk.The organizations that succeed are those that treat cybersecurity as a core engineering discipline. Building secure, scalable medical devices requires alignment between technical execution, regulatory strategy, and long-term product viability.Episode Breakdown:00:01 Welcome02:54 Impact definition05:16 Security integration07:22 Connectivity requirements12:30 Architecture18:45 Requirements24:20 Development30:15 Certificates36:40 Privacy focus42:50 Risk scoring48:03 Regulators50:55 ThoughtsThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
76
Edge Cases, Alarm Fatigue, and Why AI Cannot Replace Clinical Judgment with Brandon Fertig, Senior Manager at Philips Healthcare
Alarm fatigue happens when monitoring systems raise so many false flags that clinical staff begin ignoring them, even when real critical events occur. A surgeon during an operation gets alarms indicating patient bleeding, but observes stable blood pressure and no visible bleeding. The surgeon trusts direct patient observation over machine output because edge cases require human judgment that AI cannot reliably provide.Brandon Fertig discusses why patient monitoring systems with visual indicators like the gingerbread man figure help nurses prioritize care without replacing their judgment, how edge cases become more important as automation increases, and why AI in healthcare should focus on efficiency rather than autonomous decision-making.Alarm noise versus signal, why ground truth patient observation matters more than machine alerts, and how human checkpoints handle situations AI cannot predict.Practical for understanding AI limitations in clinical settings.Episode Breakdown:00:01 Welcome02:20 IT background05:03 Leadership08:33 Skills transfer12:15 Philips work16:40 Training22:30 AI tools28:45 Checkpoints34:20 Monitoring38:50 Quality40:54 Efficiency41:24 Judgment42:38 AdviceThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
75
Alarm Fatigue, Workflow Integration, and the Intelligent Operating Room (Professor Aamer Ahmed)
Devices that do not integrate into the clinical workflow sit unused regardless of technical sophistication. Physicians work in high-pressure environments where equipment must be 100 percent reliable, secure, and enhance workflow rather than disrupt it.Professor Aamer Ahmed, a Consultant in Cardiothoracic Anaesthesia, Professor of Anaesthesia and Critical Care at the University of Leicester, and co-founder of Hemeo, a medical technology company designing AI-based personalized Clinical Decision Support Systems for coagulation disorders, discusses with Christian Espinosa and Trevor Slattery why involving Key Opinion Leaders at the design stage prevents expensive redesigns, what alarm fatigue does to clinical decision-making, and how legal precedent will determine AI liability as therapeutic recommendations become more common.He also explains why the best medtech development approach involves spending time in hospitals observing physicians before engineering products, how digital twin models enable personalized clinical predictions, and why common sense is not always common practice in device design.The discussion offers practical advice for building devices clinicians actually use.Episode Breakdown:00:01 Introduction00:33 Role explanation02:49 KOL involvement03:32 Workflow integration05:36 Seamless design07:13 Problem-first approach07:35 Clinical observation08:45 Digital twin12:20 IT security18:30 AI support22:15 Accountability26:40 Alarm fatigue32:10 Liability34:07 Advice38:13 SimplicityThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
74
How to Move Stakeholders from Awareness to Sustained Adoption Without Friction
Marketing medical devices requires understanding that stakeholders are different, buying processes are longer, and friction points are more complex than consumer products or software. Most companies build websites and attend trade shows hoping prospects will decode their message, but prospects do not have time for that.Sustained adoption is not the same as initial purchase. It means the device is used continuously with no friction, no concerns, and no barriers, causing users to stop or switch. Getting there requires understanding every stakeholder involved, what questions they have at each stage, and what fears might stop them.This episode covers how to structure marketing that moves stakeholders through a clear path, why ideal client profile refinement produces better results than broad targeting, and how one advisor identified exact pain points to cut through noise and convert a prospect.Practical advice for anyone responsible for medtech marketing or go-to-market strategy.Episode Breakdown:00:02 Welcome00:21 Intro02:15 Origin04:36 Challenges06:51 Foundation07:00 Knowledge gap09:30 Adoption11:45 Mapping15:20 Friction18:40 Content22:30 Targeting26:15 Failures30:45 Pain points34:20 Clarity38:50 Tradeoffs40:44 AdviceThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
73
Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity
Medical device risk assessments are failing patients, not because the process is too hard, but because nobody doing the assessment has ever been in the room where the device actually gets used.Medtech quality and regulatory leader Stephen Smith describes sitting in a risk session for a device going into an intensive care unit. Twelve people in the room, and not one had ever set foot in an ICU. If you have never been in the environment your device will operate in, risk identification becomes guesswork, mitigations get written for problems that are not the actual problems, and the device goes to market with gaps that stay hidden until something goes wrong.This episode covers why the user environment is the most consistently ignored variable in medical device development, and how that same gap shows up in cybersecurity risk assessments.Also discussed: the $5,000 problem that gets rationalized today has a way of becoming the $500,000 crisis that cannot be ignored tomorrow, and what this argument actually looks like in practice.Stephen also explains why CE marking proves you passed an audit and why FDA clearance does not mean the FDA approved your device.Worth listening to if you are focused on medtech quality, regulatory, or cybersecurity.Episode Breakdown:00:00 Opening quote00:47 Intro and guest background04:14 QA vs RA vs QC06:00 Cybersecurity in quality systems08:30 Risk as the foundation11:20 Ignoring clinicians and user environments13:00 ICU risk assessment example14:19 Startups and product market fit15:30 Key Opinion Leaders16:47 Companies hiring comfortable consultants18:30 $5,000 vs $500,00020:00 Why quality and cybersecurity are invisible22:00 What regulators actually review22:54 Self-signed certificates24:30 Cybersecurity speed vs regulation speed26:30 CE marking is not a quality guarantee27:00 Lost instructions for use28:40 Cleared vs approved29:45 Prevention is better than cure31:00 Final advice32:00 Racing analogyThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.Learn more by visiting https://bluegoatcyber.comIf you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber.Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
72
How AI Code Security Became a Medical Device Problem with Jun Xiang Tan
Ten years ago, Singapore's healthcare system got hacked. Patient records were stolen at a national scale. The government responded by building one of the most comprehensive medical device security frameworks in the world.The Cybersecurity Labeling Scheme has four tiers. Level one means basic security controls exist. Level four means the device underwent independent code review, has advanced threat detection, and maintains continuous vulnerability management. Hospitals can see exactly what level of security they're getting before they buy.Jun Xiang from CareHero explains why this matters, especially now that AI is showing up in medical devices without proper testing. He covers adversarial attacks on medical images, why doctors are uploading patient data to ChatGPT, and what automation bias does to clinical decision making.Practical conversation about medical device security in Southeast Asia and what manufacturers need to know about Singapore's approach.Episode Breakdown:00:01 Welcome00:31 Background01:09 Military service03:09 AI threats03:45 23% problem04:40 X-rays ChatGPT05:43 Attacks08:15 Poisoning11:30 Hallucinations14:20 AI code17:45 Vulnerabilities20:30 Pair programming23:15 Guardrails26:40 Automation bias28:50 AI scribes31:20 Dialects34:05 Pre-triage36:32 Pricing37:25 Pair programmer37:40 Human interpretationThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.Learn more by visiting https://bluegoatcyber.comIf you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber.Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
71
How to Build an SBOM That Passes FDA Review
SBOMs are one of the most common sources of FDA deficiencies in medical device submissions. Most companies think they're doing it right, but then they get feedback asking for missing components or clarification on what's included.In this webinar, Christian Espinosa and Trevor Slattery explain what the FDA actually expects in an SBOM and why it's not just about listing third-party libraries. You need to include first-party code too. You need to follow the NTIA minimum elements. And you need to provide it in a machine-readable format like SPDX or CycloneDX.Trevor walks through the history of SBOMs, from their origins in licensing compliance to their current role in medical device cybersecurity. He explains the shift-left approach the FDA wants to see and why transparency matters for healthcare delivery organizations making purchasing decisions.The webinar also addresses a big concern people have. Does publishing an SBOM give attackers a roadmap to your system? Trevor breaks down why that's not actually a problem if you're managing your security properly.If you're building a connected medical device or preparing for an FDA submission, this is a clear breakdown of how to get your SBOM right the first time.Webinar Breakdown:00:00 Welcome and introduction to SBOMs00:44 What is an SBOM and why does it matter03:10 The history of SBOMs: From licensing to cybersecurity07:20 Why the FDA cares about SBOMs11:30 The biggest mistake: Leaving out first-party code15:45 NTIA minimum elements explained19:20 Machine-readable formats: SPDX and CycloneDX23:00 Real-world examples: Log4j and Shellshock26:15 Do SBOMs give attackers a roadmap? The truth29:40 Common myths about SBOMs33:50 Key takeaways for FDA submissions36:20 Q&A session beginsBlue Goat Cyber provides essential cybersecurity solutions for the medical device industry.Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
70
From Idea to FDA Clearance: What Nobody Tells Medtech Founders with Darcy Bachert
Building medical device software is hard. Building it the right way is harder. And getting it through FDA approval while managing cybersecurity requirements? That's what Darcy Bachert has been doing for 17 years.Darcy runs Prolucid Technologies, an ISO 13485-certified software development firm in Toronto. They work with medtech companies across North America, Europe, and Australia.And in that time, he's seen the same mistakes repeatedly.The biggest one? Founders build products that solve problems nobody has. Or they build something physicians won't adopt because it adds complexity instead of making their lives easier.In this conversation, Darcy talks about IEC 62304 and why it matters when choosing a software partner. The Canadian medtech ecosystem and why Toronto is a major hub. And why quality systems and cybersecurity need to be built in from day one, not added at the end.This episode is practical if you're building a medical device or working with medtech startups.Episode Breakdown:00:01 Welcome and intro00:30 Darcy's background and Prolucid Technologies overview01:15 The origin of the name Prolucid Technologies01:58 Why clarity matters more than code04:18 Common challenges beyond software development06:11 Toronto's medtech ecosystem06:57 IEC 62304 and choosing the right development partner09:17 ISO 13485 certification and investor confidence12:04 Realistic timelines for medical device software15:32 Cost expectations and budget planning18:45 Building quality systems from the start21:20 Integrating cybersecurity throughout development24:15 When and how to do penetration testing27:30 Cybersecurity mistakes startups make30:42 The MTI program and Canadian medtech resources33:18 Canadian vs US medtech markets36:22 Physician adoption challenges40:18 Trevor: Don't invent your problem41:36 Darcy: Find partners who've done it before43:05 Christian: Balance user adoption with reimbursementThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
69
What MedTech Startups Get Wrong About Cybersecurity Documentation with Marc Zemel
Marc Zemel has been building Retia Medical for 15 years. The company started as two guys with slides and licensed technology. Now their data-driven hemodynamic monitoring technology for consistently accurate cardiac output measurements in high-risk surgical and critically ill patients is in 75 hospitals across 18 countries, sold by Medtronic in the U.S, and the company is preparing to launch their new product Argos Infinity, pending FDA clearance.But getting here meant dealing with cybersecurity challenges that Marc didn't see coming. In this conversation, he talks about what actually slowed them down, what he wishes he'd done differently, and why building a proper quality system from day one would have saved him years of pain.Retia Medical develops algorithms that monitor cardiovascular function. Their technology detects problems before blood pressure drops, which makes it valuable in operating rooms and ICUs. Nurses have gotten so attached to their monitors that they literally hug them because the devices help them do their jobs better.Marc walks through the specific cybersecurity issues that surprised him. Like how software as a medical device comes with ongoing compliance costs that hardware doesn't have. Or how documentation requirements kept changing as the FDA updated its expectations. Or how retrofitting cybersecurity into an existing product is way more expensive than building it in from the start.He also shares his philosophy on building companies. He doesn't focus on exits or acquisition targets. He focuses on building something people can't live without. When the product is that good, the rest takes care of itself.If you're building a medical device startup or dealing with FDA submissions, this is a conversation worth hearing.Episode Breakdown:00:00 Introduction00:32 Where everyone's calling from02:54 Marc's background and journey into medtech04:33 What Retia Medical does07:00 Blood flow vs blood pressure09:45 Software vs hardware as a medical device12:30 Cybersecurity challenges15:20 Documentation nightmares18:45 Quality systems and why they matter early22:10 FDA submissions over 15 years25:30 The cost of retrofitting cybersecurity28:50 Software updates and compliance32:15 Build to be bought, not to be sold37:32 What acquirers look for39:02 Product market fit: Nurses hugging monitors41:14 Wearables and future regulationsThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
68
Why Most Medtech Companies Fail at Global Expansion (And How to Fix It) with William Jin
Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the American market?William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get their products approved and sold in each other's markets. The problems he sees are surprisingly similar whether you're going East or West.In this conversation, William walks through the real barriers to global expansion. We're talking about practical stuff like why using Google Cloud can completely block you from the Chinese market, how data sovereignty laws affect AI-powered devices, and why that Baxter ventilator recall should matter to everyone building connected medical devices.If you're in medtech and thinking about international markets, this is the reality check you need. William's advice is simple but critical: plan for your target markets before you start building. Otherwise, you'll spend millions redesigning later, or worse, you'll realize you can't enter those markets at all.Episode Breakdown:00:00 The costly mistake of not planning for global markets early00:44 Meet William Jin: Medical doctor turned medtech market strategist03:15 What's really stopping Chinese companies from entering Western markets07:20 Why Chinese medtech exports to the U.S. dropped while Europe increased11:40 The Google Cloud problem nobody warns you about15:50 How China's data regulations affect your algorithms and cloud architecture19:30 Reverse engineering your markets: Start with the end in mind23:00 Where Chinese companies dominate and where they struggle internationally26:45 The Baxter recall that was really about cybersecurity28:50 Why cybersecurity product recalls are fundamentally different29:20 William's final advice for medtech innovators29:40 Wrapping up: Design to disposal, not as an afterthoughtThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
67
What It Takes to Succeed in the Medtech Industry with Omar Khateeb
Ever thought about what it really takes to launch a successful medtech startup?Omar M. Khateeb knows the challenges firsthand. As a founder with a track record of building healthtech companies, he’s lived through the hurdles that come with innovating in the medtech space.In this episode, Omar dives into the highs and lows of his entrepreneurial journey, sharing key lessons, pivotal moments, and the strategies that helped him succeed. From tackling complex healthcare issues to navigating the regulatory maze, Omar breaks down what it takes to make a lasting impact in medtech.Join us for an inside look at the future of health tech and why it’s the perfect time for the next generation of entrepreneurs to get involved.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
66
Untangling Software Composition Analysis for MedTech Teams
Why does software composition analysis matter beyond regulatory compliance?This episode explores SCA (Software Composition Analysis) and explains how SBOMs (Software Bill of Materials), SOUP (Software of Unknown Provenance), and related tooling fit into the broader medical device cybersecurity landscape. Christian and Trevor clarify common misconceptions, including licensing fears, machine-readable requirements, and the role of static testing tools.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
65
When Medical Device Cyber Failures Become Fatal
What past ransomware and medical device incidents might reveal gaps that manufacturers are still overlooking today?In this episode, Christian and Trevor examine real incidents where cybersecurity failures, software flaws, and insecure medical devices led to patient harm and death. They break down how ransomware attacks, implantable device vulnerabilities, and AI-driven therapies expose life-critical risks in healthcare. The conversation highlights why regulators are increasing scrutiny and why cybersecurity must be treated as a patient-safety imperative, not an afterthought.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
64
Trevor Slattery Answers Tough Medical Device Cyber Questions
This episode puts Trevor in the hot seat. If you were put in the hot seat, could you clearly explain cybersecurity, safety, and lifecycle terms like Trevor?In this rapid-fire episode, Christian fires questions at Trevor about essential medical device cybersecurity concepts and standards. Together, they clarify how risk management, secure development, and lifecycle thinking intersect across safety, quality, and security.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
63
The Differences Between Black, Grey, and White Penetration Testing
MedTech developers, do you know which penetration testing methodology the FDA actually prefers for medical device submissions?In this episode, Christian and Trevor explain the differences between black, grey, and white box penetration testing and how each impacts the completeness and realism of cybersecurity assessments. They highlight why regulators increasingly expect deeper testing supported by source-code-level insights. They also outline the risks, costs, and delays manufacturers face when choosing insufficient testing approaches during FDA submission.Key points:(01:25) Learn how black box testing mimics an attacker with no prior knowledge.(06:27) How grey box testing blends limited credentials, architecture insight, and direct communication with engineers to expand visibility.(08:29) Why white box testing includes access to full documentation, processes, and source code.(10:20) How attacker timeframes differ from tester timeframes.(11:29) How the FDA’s static analysis, SBOM, and risk evaluation requirements tie naturally into white box testing workflows.(15:06) Learn why choosing black box testing to save money often results in higher total costs after FDA rejection.(17:47) Hear why “buy once, cry once” applies to penetration testing.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
62
How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller
What risks do you take when cybersecurity is left off your development roadmap?In this episode, Christian, Trevor and guest Jim Goodmiller explore how cybersecurity intersects with regulatory expectations and quality systems, creating new challenges and opportunities for medtech innovators. Jim helps to explain why founders must integrate cybersecurity from concept through commercialization, especially as FDA scrutiny increases.Key points: 00:48 Why cybersecurity now influences every part of the regulatory landscape.04:48 How technologies can create serious safety and compliance risks when not fully vetted.10:45 Cybersecurity as a mandatory component of regulatory planning.14:52 The need for iterative penetration testing 22:16 Challenges of upgrading legacy devices25:37 Avoiding serious legal consequences.29:29 Preparing a complete roadmap for investor confidence 40:08 The role of communicationThe Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Thanks to Jim Goodmiller for being on the show. Connect with Jim on LinkedIn: https://www.linkedin.com/in/jimgoodmiller/ Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
61
Webinar: Why FDA Cybersecurity Submissions Fail and How to Get Yours Approved
Medtech innovators and medical device manufacturers, how can you prevent cybersecurity deficiencies from delaying your FDA submission?In this webinar, Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, reveal the most common reasons FDA cybersecurity submissions fail and how you can avoid them. They explain the importance of early risk management, security-by-design practices, and comprehensive testing aligned with NIST and AAMI frameworks. Explored in this webinar: 00:37 Why poor cybersecurity is a top reason for FDA medical device rejection.02:56 The FDA’s total product lifecycle approach.05:18 Why risk management must start before design. 07:35 How AAMI TR57 and ISO 14971 interact to assess patient harm. 10:51 The FDA requirement for traceability among functional, nonfunctional, and security requirements. 16:16 Why cybersecurity testing must cover the entire product (mobile, cloud, etc.).23:33 Why inadequate documentation for critical controls (authentication, logging, encryption) often causes FDA deficiencies.This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://spoti.fi/3XX95g0Subscribe via Apple Podcasts: https://apple.co/483OJ9I
-
60
Cybersecurity Qs MedTech Innovators Ask: Christian’s Hot Seat
MedTech manufacturers, how can you avoid the cybersecurity pitfalls that most often lead to FDA rejection?In this episode, Trevor puts Christian “in the hot seat” to tackle the most common—and sometimes misunderstood—cybersecurity questions MedTech innovators ask. Christian breaks down key concepts such as ISO 13485, HIPAA vs. FDA expectations, SAMD vs. SIMD, global regulatory demands, and more. Key points: (00:30) The purpose of ISO 13485 and why traceability, quality, and documentation are foundational to medical device safety.(02:34) How cybersecurity is now the most common reason FDA reviewers reject medical devices.(04:32) Why HIPAA focuses on patient data while the FDA focuses on patient safety.(07:21) Which global regulators impose the strictest cybersecurity requirements and how FDA and China differ.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
59
What Is Required for an FDA Pre-Market Cyber Submission?
What are the 18 required cybersecurity deliverables for a pre-market submission, and how do they map to eSTAR’s 13 sections? This episode breaks down the cybersecurity deliverables required for an FDA pre-market submission and explains why they apply consistently across all device types. Christian and Trevor walk through each deliverable in detail, outline how they map to eSTAR v6.0, and highlight common misconceptions that slow down manufacturers. Key points: (00:33) Why all devices—high-risk or low-risk—must submit the same 18 cybersecurity deliverables to the FDA.(01:41) How device complexity influences documentation depth even though the deliverables never change.(04:42) How the 18 deliverables map to the 13 sections of eSTAR version 6.0. (09:50) The risk management report, threat model, risk assessment, and SBOM requirements.(17:41) How to evaluate and categorize unresolved anomalies.(20:04) How manufacturers should track remediation timelines and vulnerability density.(23:52) The cybersecurity management plan and the extensive post-market responsibilities expected by the FDA.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
58
Webinar: Postmarket Cybersecurity Management
MedTech manufacturers, how prepared are you to monitor vulnerabilities continuously once your medical device reaches the market? Also, would you like a free checklist for your Cybersecurity Management Plan? (See link below!) This webinar dives into how medical device manufacturers should build, maintain, and document postmarket cybersecurity programs that align with FDA expectations. Christian and Trevor outline critical requirements such as continuous SBOM monitoring, testing timelines, update processes, CVD workflows, and secure communication standards. Topics explored: (03:14) How the FDA's definition of "cyber device" includes devices with Wi-Fi, Bluetooth, USB, RFID, and NFC connectivity.(05:19) Recent FDA guidance changes, including updated cybersecurity expectations.(10:30) Cybersecurity management plan personnel: compliance officer, product owner, postmarket owner, and authorizing official.(12:30) Static testing, SBOM analysis, penetration testing, and vulnerability assessments. (17:50) Security testing expectations and frequencies. (20:30) Patching, update processes, and remediation timelines. Download your free Cybersecurity Management Plan Checklist: https://bluegoatcyber.com/wp-content/uploads/2025/09/Blue-Goat-Cyber-Postmarket-Management-Checklist.pdf This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://spoti.fi/3XX95g0Subscribe via Apple Podcasts: https://apple.co/483OJ9I
-
57
How Market Intelligence Shapes MedTech Growth with Kevin Saem
In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.Key points: (04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.(12:00) How AI and connected devices are making cybersecurity a top concern for investors.(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.(26:30) How medtech founders can self-regulate.(32:40) When companies should start building scalable sales systems. Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: https://www.linkedin.com/in/kevin-saem/ Learn about Zapyrus, a sales system for MedTech service providers: https://welcome.zapyrus.com/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 This episode was produced by Story On Media: https://www.storyon.co/ In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.Key points: (04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.(12:00) How AI and connected devices are making cybersecurity a top concern for investors.(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.(26:30) How medtech founders can self-regulate.(32:40) When companies should start building scalable sales systems. Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: https://www.linkedin.com/in/kevin-saem/ Learn about Zapyrus, a sales system for MedTech service providers: https://welcome.zapyrus.com/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer"...
-
56
Designing Secure Medical Device Software with Randy Horton
In medical device software development, why should cybersecurity be viewed as an element of product quality, not an add-on?In this episode, Christian and Trevor speak with Randy Horton of Orthogonal about the future of medical device software development. Together, they unpack how DevSecOps, quality systems, and modern engineering practices can elevate safety and speed innovation in MedTech. From the philosophy behind “move faster and break nothing” to lessons learned from real-world cybersecurity cases, this conversation reframes how medical device teams should approach software design.Randy Horton is the Chief Solutions Officer at Orthogonal, where he helps MedTech companies build better, safer, and smarter connected devices. A lifelong software innovator, Randy brings profound insight into what it takes to merge cutting-edge tech with the regulated world of healthcare.Key points: (03:00) Randy shares how discovering the first web browser set him on a lifelong path of innovation.(05:11) Why high-quality software inherently includes cybersecurity.(08:52) Why traditional engineering mindsets struggle with the flexibility of software development.(12:42) How the “move fast” culture in Silicon Valley clashes with MedTech’s demand for control and safety.(16:09) Why some manufacturers avoid updating medtech devices, and how that hurts long-term device security.(19:49) Randy predicts that born-digital MedTech companies will lead the next wave of innovation, pushing the industry to adapt faster.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Thanks to Randy Horton for being on the show. Learn more about Orthogonal: https://orthogonal.io/ Connect with Randy on LinkedIn: https://www.linkedin.com/in/randyhorton Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
55
Cyber Risk Management for MedTech Legacy Devices
What options do MedTech manufacturers have to bring older devices up to modern cybersecurity standards? Also, how does the FDA’s latest guidance change the process for updating legacy devices?In this episode, Christian and Trevor break down the evolving challenges of managing cybersecurity for MedTech legacy devices. They explain how the FDA’s recent guidance updates create new pathways for handling older devices without requiring full redesigns. Together, they explore practical steps manufacturers can take—like penetration testing and postmarket monitoring—to stay compliant and proactive about security risks.Key points: (02:13) How the FDA defines legacy devices and why updates to older equipment pose unique challenges.(03:47) Why simply replacing old devices isn’t realistic for many healthcare organizations.(05:00) How encryption standards evolve and why older devices often can’t meet modern security expectations.(06:25) The FDA’s distinction between controlled and uncontrolled risk. (09:02) The FDA’s reduced burden pathway for legacy devices.(11:07) Best practices for postmarket management plans. The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
54
Webinar: Security Architecture Views: Protecting Medical Devices Through Strategic Design
How can security architecture views strengthen a medical device manufacturer’s FDA submissions?This episode/webinar dives into the four critical security architecture views required by the FDA: global system, multi-patient harm, updatability and patchability, and secure use case views. Christian Espinosa and Trevor Slattery explain how each view strengthens product security while aligning with regulatory expectations. They also share practical strategies and examples, from cloud environments to physical updates, highlighting how proper documentation and foresight can mitigate real-world risks.Highlights: (01:19) Learn why the FDA requires four specific security architecture views and how they support threat modeling.(03:10) Understand how integrating security into architecture views reflects secure coding and DevSecOps practices.(04:15) Discover how global regulators beyond the FDA use similar documentation requirements.(07:52) Explore why global system views must include both software and hardware components as well as data flows.(11:02) The distinction between global system views and multi-patient harm views. (14:36) Common vulnerabilities like hard-coded credentials that can lead to multi-patient harm.(19:18) The risks of over-the-air updates versus physical updates for medical devices.This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://spoti.fi/3XX95g0Subscribe via Apple Podcasts: https://apple.co/483OJ9I
-
53
Why AI Literacy Matters for the Future of Healthcare with José Acosta
How can AI literacy reduce patient risk in healthcare settings? In this episode, Christian Espinosa and Trevor Slattery are joined by Dr. José Acosta. Together, they unpack the promise and pitfalls of artificial intelligence in healthcare—from the accuracy gap in diagnostics to the importance of ethics, alignment, and training. The conversation explores how clinicians can harness AI safely, ensuring innovation never comes at the cost of patient trust or care quality.Dr. José Acosta is a retired Navy trauma surgeon turned AI literacy advocate. With decades of experience in medicine and leadership, he’s now helping clinicians understand AI—from how it works to how it should be used responsibly.Key points: (00:57) José’s background as a Navy trauma surgeon and his passion for AI literacy.(02:53) What “AI literacy” really means. (05:00) Why precision matters in medicine, and why 85–95% accuracy in AI models isn’t enough when lives are on the line.(11:20) A chilling example of an AI therapy app that gave a fatal recommendation. (14:16) José predicts a surge in “ambient AI scribes” and explains how they’ll reshape physician workflows. (17:53) AI’s productivity paradox—how new tools can both help and overwhelm clinicians.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Thanks to José Acosta for being on the show. Connect with José on LinkedIn: https://www.linkedin.com/in/joseacostasd/ Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
52
What Is A Medical Device?
MedTech developers and manufacturers, could your medical device unknowingly qualify as a “cyber device”?In this episode, Christian and Trevor break down what the FDA considers a “cyber device” and why so many manufacturers misunderstand this definition. They reveal how even basic interfaces like USB, HDMI, or Bluetooth can make a device cyber-enabled—and why that matters for regulatory compliance.Key points:(00:33) What makes a medical device a “cyber device,” and why confusion persists among manufacturers.(02:14) How proving a device has zero vulnerabilities is nearly impossible, even with minimal code.(03:12) Why even a simple USB port can classify a device as “cyber.”(05:05) Common interfaces (Wi-Fi, Bluetooth, RFID, NFC, HDMI) that make a device cyber-enabled.(09:23) Implantable devices, like pacemakers, and how protocols such as MedRadio introduce hidden connectivity.(12:20) A real case where the FDA classified a 3D-printing system as a cyber device due to its software dependencies.(16:15) Practical advice on removing unnecessary ports or connectivity to avoid cyber classification.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.comIf you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-sessionChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1Feedback? Questions? Contact: https://bluegoatcyber.com/contact/Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficialThe Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmhSubscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
51
5 Most Common Misconceptions of Medical Device Security
In this episode, Christian and Trevor unpack the five most common misconceptions that put medical device manufacturers at risk. From confusing data protection with patient safety to misunderstanding what qualifies as a cyber device, the hosts shed light on the blind spots that cause costly delays and compliance failures. They also explore how medical device cybersecurity differs fundamentally from traditional cybersecurity, emphasizing the need for specialized expertise and early integration of secure design principles.Key points: (01:18) Misconception #1: That cybersecurity is only about protecting data rather than patient safety.(06:04) Misconception #2: That your product isn’t a “cyber device.” (07:46) Misconception #3: That cybersecurity is a one-time thing to study rather than a full lifecycle process.(12:17) Misconception #4: That software developers inherently understand cybersecurity.(19:10) Misconception #5: Thinking that traditional cybersecurity and medical device cybersecurity are the same. The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1 Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
50
What Happens When AI in Medical Devices Make Mistakes?
MedTech manufacturers and developers, what happens if your AI-powered medical device makes a terrible, life-threatening mistake?This episode explores what happens when artificial intelligence in medical devices goes wrong. Christian Espinosa and Trevor Slattery break down the real-world consequences of AI failure, using a tragic mental health chatbot case to highlight the stakes of inadequate oversight. They also examine the EU AI Act, new MDCG guidance, and the ethical, regulatory, and cybersecurity challenges facing innovators in the high-risk medical AI space.Key points: (03:02) The EU AI Act and how it intersects with the MDR and IVDR.(03:55) A real case study involving a suicidal patient and an AI mental health chatbot.(06:07) How general-purpose AI tools differ from regulated medical AI.(09:57) Why threat modeling should apply to AI systems.(12:16) Ethical decision-making in autonomous systems using self-driving car analogies.(14:02) The Medical Device Coordination Group’s guidance on aligning the AI Act with EU medical device regulations.(17:10) Shared accountability across regulators, manufacturers, and users for AI oversight.(18:35) The U.S. still treats AI as a “Wild West” compared to the EU’s stricter approach.(22:42) Regulators aren’t asking if your AI works—they’re asking how it fails.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
-
49
Medical Device Startups and Cybersecurity Challenges with Suzy Engwall
What are some of the greatest challenges medical device startups face when bringing their products to market?This episode features Suzy Engwall, a healthcare innovation consultant with experience mentoring startups and guiding hospitals. She joins Christian Espinosa and Trevor Slattery to discuss the hidden roadblocks medical device innovators face—from funding gaps to internal hospital politics to overlooked cybersecurity. Together they unpack the realities of FDA compliance, AI-driven decision support, and why raising cybersecurity awareness early can mean the difference between market success and failure.Suzy Engwall is a healthcare innovation leader who’s spent the last 20 years shaking up hospitals and mentoring startups. She runs HealthTech Strategies, where she helps founders, investors, and clinicians bridge the gap between big ideas and practical adoption.Key points: (04:38) Challenges medtech startups face include funding, go-to-market strategy, and regulatory hurdles, with cybersecurity often overlooked.(05:56) Why 93% of med tech startups fail. (08:01) How internal politics within hospitals can derail promising innovations.(09:32) Hospitals now scrutinize devices for cybersecurity risk beyond FDA approval, raising the bar for manufacturers.(12:19) Legacy devices often fail modern cybersecurity requirements, forcing redesigns and frustrating manufacturers.(16:43) AI in diagnostics: who’s responsible when mistakes occur?(23:24) Why patients rarely question medical devices. (31:28) Why cybersecurity is often the last thing innovators ask about—and why that mindset must change.The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session Thanks to Suzy Engwall for being on the show. Connect with Suzy on LinkedIn: https://www.linkedin.com/in/sengwallChristian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh Subscribe via Apple Podcasts: https://apple.co/483OJ9ISubscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape.Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you w
HOSTED BY
Blue Goat Cyber
Loading similar podcasts...