<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://feeds.captivate.fm/style.xsl" type="text/xsl"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><atom:link href="https://feeds.captivate.fm/meddevicecyberpodcast/" rel="self" type="application/rss+xml"/><title><![CDATA[The Med Device Cyber Podcast]]></title><podcast:guid>c7fff4f2-aaec-56ad-baab-a3a746ee3d80</podcast:guid><lastBuildDate>Thu, 23 Apr 2026 15:15:09 +0000</lastBuildDate><generator>Captivate.fm</generator><language><![CDATA[en]]></language><copyright><![CDATA[Copyright 2026 Blue Goat Cyber]]></copyright><managingEditor>Blue Goat Cyber</managingEditor><itunes:summary><![CDATA[In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. 

Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. 

As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape.

Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. 

Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology.

This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.]]></itunes:summary><image><url>https://artwork.captivate.fm/e6fcffed-bb47-4bed-855d-502298166a83/qH5bLdRcKTvdInIdsZArBoyb.jpg</url><title>The Med Device Cyber Podcast</title><link><![CDATA[https://bluegoatcyber.com]]></link></image><itunes:image href="https://artwork.captivate.fm/e6fcffed-bb47-4bed-855d-502298166a83/qH5bLdRcKTvdInIdsZArBoyb.jpg"/><itunes:owner><itunes:name>Blue Goat Cyber</itunes:name></itunes:owner><itunes:author>Blue Goat Cyber</itunes:author><description>In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it&apos;s essential. 

Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. 

As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape.

Hosted by Christian Espinosa, Founder &amp; CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. 

Whether you&apos;re a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology.

This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.</description><link>https://bluegoatcyber.com</link><atom:link href="https://pubsubhubbub.appspot.com" rel="hub"/><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><itunes:category text="Science"><itunes:category text="Life Sciences"/></itunes:category><itunes:category text="Health &amp; Fitness"><itunes:category text="Medicine"/></itunes:category><itunes:category text="Technology"></itunes:category><podcast:locked>no</podcast:locked><podcast:medium>podcast</podcast:medium><item><title>De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners</title><itunes:title>De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners</itunes:title><description><![CDATA[<p>Product decisions made during early development determine commercialization outcomes years later. Wrong choices about regulatory pathways, feature sets, and market segments create compounding problems limiting commercial success.</p><p>Christian Espinosa and Trevor Slattery explore product management with Brent Lavin, Chief Product Catalyst of Ironwood MedTech Partners, covering why 510(k) pathways average four years while PMA programs require seven to nine years, and how feature set alignment shapes success.</p><p>The engineering mindset applies hypothesis testing to product development through iterative refinement.</p><p>Practical for MedTech founders and product teams.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:02 Introduction</li><li>04:35 Ironwood origin</li><li>06:02 De-risking decisions</li><li>10:15 Hypothesis testing</li><li>14:30 Pathway selection</li><li>18:45 Timelines</li><li>22:20 Claims limits</li><li>26:40 Feature alignment</li><li>30:15 Segmentation</li><li>34:55 Clinical trials</li><li>38:45 Entrepreneurship</li><li>40:45 Insights</li><li>43:29 Close</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Product decisions made during early development determine commercialization outcomes years later. Wrong choices about regulatory pathways, feature sets, and market segments create compounding problems limiting commercial success.</p><p>Christian Espinosa and Trevor Slattery explore product management with Brent Lavin, Chief Product Catalyst of Ironwood MedTech Partners, covering why 510(k) pathways average four years while PMA programs require seven to nine years, and how feature set alignment shapes success.</p><p>The engineering mindset applies hypothesis testing to product development through iterative refinement.</p><p>Practical for MedTech founders and product teams.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:02 Introduction</li><li>04:35 Ironwood origin</li><li>06:02 De-risking decisions</li><li>10:15 Hypothesis testing</li><li>14:30 Pathway selection</li><li>18:45 Timelines</li><li>22:20 Claims limits</li><li>26:40 Feature alignment</li><li>30:15 Segmentation</li><li>34:55 Clinical trials</li><li>38:45 Entrepreneurship</li><li>40:45 Insights</li><li>43:29 Close</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">1aa7b022-9f3f-4ad1-8a66-f065b7ef6d48</guid><itunes:image href="https://artwork.captivate.fm/ed71fdba-a47e-410e-bbfc-e287636defb5/Spotify.jpg"/><pubDate>Thu, 23 Apr 2026 08:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/1aa7b022-9f3f-4ad1-8a66-f065b7ef6d48.mp3" length="64612506" type="audio/mpeg"/><itunes:duration>43:44</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>67</itunes:episode><podcast:episode>67</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners | 67"><podcast:source uri="https://youtu.be/qoGs15STxSg"/></podcast:alternateEnclosure></item><item><title>Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech</title><itunes:title>Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech</itunes:title><description><![CDATA[<p>Vibe coding enables rapid development through AI-generated code but introduces security risks when developers accept outputs without verification. Malicious actors can inject vulnerabilities through manipulated training data or prompt engineering. Supply chain attacks become easier when developers blindly trust AI implementations.</p><p>Jake Rodriguez, Founder and CEO of Triangle Tech, joins Trevor Slattery and Christian Espinosa to explore the security implications of vibe coding, how attackers exploit AI code generation, and what verification processes prevent unverified code reaching production.</p><p>Understanding generated code requires technical knowledge many vibe coding adopters lack.</p><p>Practical for development and security teams.</p><p></p><p><strong>Episode Breakdown:</strong></p><p>00:00 AI Search vs Google + Risks</p><p>01:13 Intro + AI, Marketing, Cybersecurity</p><p>01:39 Jake Rodriguez Background</p><p>04:27 What is SEO Today</p><p>06:30 AI Search vs Traditional SEO</p><p>08:50 How AI Finds Content (Reddit, Quora)</p><p>10:11 AI Bias and Hallucinations</p><p>10:58 Content Strategy + Personal Branding</p><p>12:27 Why Trust is Shifting (Podcasts, Events)</p><p>13:56 Bot Farms and Fake Engagement</p><p>15:02 Apple Branding Psychology</p><p>16:07 App Permissions and Cyber Risks</p><p>16:55 AI Voice Scams and Deepfakes</p><p>19:46 Using AI for Marketing</p><p>21:04 Prompt Engineering Tips</p><p>22:36 Where AI Works vs Fails</p><p>24:28 What is Vibe Coding</p><p>27:23 AI Risks in Medical Devices</p><p>30:46 Cybersecurity Challenges in MedTech</p><p>32:59 AI Jailbreaks and Security Threats</p><p>34:44 MedTech Marketing Strategy</p><p>35:43 SEO Landing Page Strategy</p><p>37:36 Key Takeaways</p><p>39:00 Outro</p><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Vibe coding enables rapid development through AI-generated code but introduces security risks when developers accept outputs without verification. Malicious actors can inject vulnerabilities through manipulated training data or prompt engineering. Supply chain attacks become easier when developers blindly trust AI implementations.</p><p>Jake Rodriguez, Founder and CEO of Triangle Tech, joins Trevor Slattery and Christian Espinosa to explore the security implications of vibe coding, how attackers exploit AI code generation, and what verification processes prevent unverified code reaching production.</p><p>Understanding generated code requires technical knowledge many vibe coding adopters lack.</p><p>Practical for development and security teams.</p><p></p><p><strong>Episode Breakdown:</strong></p><p>00:00 AI Search vs Google + Risks</p><p>01:13 Intro + AI, Marketing, Cybersecurity</p><p>01:39 Jake Rodriguez Background</p><p>04:27 What is SEO Today</p><p>06:30 AI Search vs Traditional SEO</p><p>08:50 How AI Finds Content (Reddit, Quora)</p><p>10:11 AI Bias and Hallucinations</p><p>10:58 Content Strategy + Personal Branding</p><p>12:27 Why Trust is Shifting (Podcasts, Events)</p><p>13:56 Bot Farms and Fake Engagement</p><p>15:02 Apple Branding Psychology</p><p>16:07 App Permissions and Cyber Risks</p><p>16:55 AI Voice Scams and Deepfakes</p><p>19:46 Using AI for Marketing</p><p>21:04 Prompt Engineering Tips</p><p>22:36 Where AI Works vs Fails</p><p>24:28 What is Vibe Coding</p><p>27:23 AI Risks in Medical Devices</p><p>30:46 Cybersecurity Challenges in MedTech</p><p>32:59 AI Jailbreaks and Security Threats</p><p>34:44 MedTech Marketing Strategy</p><p>35:43 SEO Landing Page Strategy</p><p>37:36 Key Takeaways</p><p>39:00 Outro</p><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">8825ef7f-0891-4d76-9734-4ee2e4a60950</guid><itunes:image href="https://artwork.captivate.fm/9d77e7a8-f65b-44a1-a7fb-3fe736bde875/Spotify.jpg"/><pubDate>Thu, 16 Apr 2026 09:20:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/8825ef7f-0891-4d76-9734-4ee2e4a60950.mp3" length="47007018" type="audio/mpeg"/><itunes:duration>39:10</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>66</itunes:episode><podcast:episode>66</podcast:episode><podcast:season>1</podcast:season></item><item><title>Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health</title><itunes:title>Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health</itunes:title><description><![CDATA[<p>Early planning prevents expensive corrections when startups address clinical strategy, regulatory pathways, and cybersecurity requirements from day one rather than improvising solutions before launch. FDA pre-submission meetings provide feedback that de-risks strategies before execution.</p><p>Clinical trial design shapes feasibility for startups with limited budgets. Understanding target markets determines sample requirements since United</p><p>States sales need United States samples while Korean sales need Korean data. Reverse engineering where you want to sell enables appropriate planning.</p><p>Good Clinical Practice guidelines establish responsibility layers. Manufacturers remain accountable for outcomes even when delegating work to CROs or contractors. Understanding responsible versus accountable shapes partner selection.</p><p>Practical for regulatory and clinical strategy.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:01 Welcome</li><li>03:45 CRO terminology</li><li>07:20 Market research findings</li><li>12:15 Startup needs</li><li>16:40 Partnerships</li><li>20:25 Operations</li><li>24:10 Study types</li><li>28:35 FDA strategy</li><li>32:50 GCP guidelines</li><li>36:15 Accountability</li><li>39:40 Markets</li><li>41:36 Thoughts</li></ul><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Early planning prevents expensive corrections when startups address clinical strategy, regulatory pathways, and cybersecurity requirements from day one rather than improvising solutions before launch. FDA pre-submission meetings provide feedback that de-risks strategies before execution.</p><p>Clinical trial design shapes feasibility for startups with limited budgets. Understanding target markets determines sample requirements since United</p><p>States sales need United States samples while Korean sales need Korean data. Reverse engineering where you want to sell enables appropriate planning.</p><p>Good Clinical Practice guidelines establish responsibility layers. Manufacturers remain accountable for outcomes even when delegating work to CROs or contractors. Understanding responsible versus accountable shapes partner selection.</p><p>Practical for regulatory and clinical strategy.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:01 Welcome</li><li>03:45 CRO terminology</li><li>07:20 Market research findings</li><li>12:15 Startup needs</li><li>16:40 Partnerships</li><li>20:25 Operations</li><li>24:10 Study types</li><li>28:35 FDA strategy</li><li>32:50 GCP guidelines</li><li>36:15 Accountability</li><li>39:40 Markets</li><li>41:36 Thoughts</li></ul><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">af718ebf-6745-456b-bd90-ccac403b0104</guid><itunes:image href="https://artwork.captivate.fm/8911d28e-3b54-4e82-b1f5-a195623578c1/Spotify.jpg"/><pubDate>Thu, 09 Apr 2026 00:15:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/af718ebf-6745-456b-bd90-ccac403b0104.mp3" length="62221674" type="audio/mpeg"/><itunes:duration>41:36</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>65</itunes:episode><podcast:episode>65</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="Who Owns Patient Data Security in Trials with Rob Bedford, CEO of Franklyn Health | Ep.65"><podcast:source uri="https://youtu.be/J15kftTETFk"/></podcast:alternateEnclosure></item><item><title>Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA</title><itunes:title>Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA</itunes:title><description><![CDATA[<p>Quality management system implementation delays create cascading failures across medical device development timelines. Startups using SharePoint or Google Drive for documentation discover at audit time that these tools provide no traceability, no version control, and no evidence of systematic processes.</p><p>Dr. Basant Bajpai discusses why design controls begin at the concept stage, regardless of whether companies acknowledge them, how reverse documentation costs 6-12 months when manufacturers reach the submission stage without proper systems, and what happens when scaling exposes foundational quality gaps.</p><p>Simple automated systems that enforce traceability outperform both manual approaches and enterprise platforms that startups cannot fully utilize. Starting early with scalable infrastructure prevents wholesale system transitions during growth.</p><p>Practical for medical device startups and innovators.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:00 Introduction Hook on QMS Mistakes and AI Boundaries</li><li>00:49 Why AI Should Assist, Not Own, the Compliance Process</li><li>01:09 Guest Introduction: Dr. Basant Bajpai and ComplianceMed QRA</li><li>01:32 Why QMS Is a Survival System, Not Just Software</li><li>02:20 The Biggest QMS Mistake Medtech Founders Make</li><li>03:02 Why Early Stage Companies Must Start QMS Sooner Than They Think</li><li>04:03 Why Shared Drives and Manual Systems Fail During Audits</li><li>05:05 Start Simple: Build a Traceable Foundation Before You Scale</li><li>06:08 Cybersecurity and Quality Are More Connected Than Most Founders Realize</li><li>06:59 How AI Is Being Used Inside an Automated QMS</li><li>08:00 Human in the Loop: Where AI Helps and Where Experts Must Step In</li><li>08:48 The Risk of AI Hallucinations in Regulated Documentation</li><li>10:03 When AI Can Invent Content and Why That Requires Extra Caution</li><li>10:45 Why You Should Not Use AI Before Your QMS Basics Are Fully Built</li><li>12:34 Regulator Reactions to AI in Compliance and Documentation</li><li>13:29 Could Regulators Start Using AI Too?</li><li>15:09 The Coming AI Arms Race in Regulatory Reviews</li><li>17:04 Why Traceability Is Still the Hardest Problem for AI</li><li>18:23 Why Manual Traceability Still Matters in an AI Assisted QMS</li><li>20:24 AI in Healthcare: Big Opportunity, Big Responsibility</li><li>22:14 What Happens When Companies Delay Quality System Implementation</li><li>24:00 The Cost of Reverse Documentation and Missed Traceability</li><li>25:20 Why Poor QMS Setup Becomes a Scaling Nightmare</li><li>27:00 Medtech Startups: Limited Budgets, Too Many Critical Priorities</li><li>28:10 The Cybersecurity Retrofit Problem and Why It Delays Submission</li><li>29:07 Why New Regulatory Pressure Makes Early Planning Even More Important</li><li>30:12 FDA Pushback on Weak Cybersecurity Documentation</li><li>30:58 Awareness and Education as the Real Fix</li><li>32:22 Final Takeaways: QMS, AI, and Cybersecurity</li><li>34:05 Why AI Must Stay a Tool and Never Become the Decision Maker</li><li>35:10 Closing Remarks</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Quality management system implementation delays create cascading failures across medical device development timelines. Startups using SharePoint or Google Drive for documentation discover at audit time that these tools provide no traceability, no version control, and no evidence of systematic processes.</p><p>Dr. Basant Bajpai discusses why design controls begin at the concept stage, regardless of whether companies acknowledge them, how reverse documentation costs 6-12 months when manufacturers reach the submission stage without proper systems, and what happens when scaling exposes foundational quality gaps.</p><p>Simple automated systems that enforce traceability outperform both manual approaches and enterprise platforms that startups cannot fully utilize. Starting early with scalable infrastructure prevents wholesale system transitions during growth.</p><p>Practical for medical device startups and innovators.</p><p><strong>Episode Breakdown:</strong></p><ul><li>00:00 Introduction Hook on QMS Mistakes and AI Boundaries</li><li>00:49 Why AI Should Assist, Not Own, the Compliance Process</li><li>01:09 Guest Introduction: Dr. Basant Bajpai and ComplianceMed QRA</li><li>01:32 Why QMS Is a Survival System, Not Just Software</li><li>02:20 The Biggest QMS Mistake Medtech Founders Make</li><li>03:02 Why Early Stage Companies Must Start QMS Sooner Than They Think</li><li>04:03 Why Shared Drives and Manual Systems Fail During Audits</li><li>05:05 Start Simple: Build a Traceable Foundation Before You Scale</li><li>06:08 Cybersecurity and Quality Are More Connected Than Most Founders Realize</li><li>06:59 How AI Is Being Used Inside an Automated QMS</li><li>08:00 Human in the Loop: Where AI Helps and Where Experts Must Step In</li><li>08:48 The Risk of AI Hallucinations in Regulated Documentation</li><li>10:03 When AI Can Invent Content and Why That Requires Extra Caution</li><li>10:45 Why You Should Not Use AI Before Your QMS Basics Are Fully Built</li><li>12:34 Regulator Reactions to AI in Compliance and Documentation</li><li>13:29 Could Regulators Start Using AI Too?</li><li>15:09 The Coming AI Arms Race in Regulatory Reviews</li><li>17:04 Why Traceability Is Still the Hardest Problem for AI</li><li>18:23 Why Manual Traceability Still Matters in an AI Assisted QMS</li><li>20:24 AI in Healthcare: Big Opportunity, Big Responsibility</li><li>22:14 What Happens When Companies Delay Quality System Implementation</li><li>24:00 The Cost of Reverse Documentation and Missed Traceability</li><li>25:20 Why Poor QMS Setup Becomes a Scaling Nightmare</li><li>27:00 Medtech Startups: Limited Budgets, Too Many Critical Priorities</li><li>28:10 The Cybersecurity Retrofit Problem and Why It Delays Submission</li><li>29:07 Why New Regulatory Pressure Makes Early Planning Even More Important</li><li>30:12 FDA Pushback on Weak Cybersecurity Documentation</li><li>30:58 Awareness and Education as the Real Fix</li><li>32:22 Final Takeaways: QMS, AI, and Cybersecurity</li><li>34:05 Why AI Must Stay a Tool and Never Become the Decision Maker</li><li>35:10 Closing Remarks</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">68235cb1-776f-4668-b08f-ddc3d531171a</guid><itunes:image href="https://artwork.captivate.fm/0fd79746-f527-4c01-86c8-e948be5b0057/Spotify.jpg"/><pubDate>Thu, 02 Apr 2026 10:15:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/68235cb1-776f-4668-b08f-ddc3d531171a.mp3" length="53419537" type="audio/mpeg"/><itunes:duration>35:26</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>64</itunes:episode><podcast:episode>64</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="Start QMS Early to Avoid Reverse Documentation with Dr. Basant Bajpai | Ep.64"><podcast:source uri="https://youtu.be/_vfmxG94aHE"/></podcast:alternateEnclosure></item><item><title>Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel</title><itunes:title>Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel</itunes:title><description><![CDATA[<p>Early design decisions define the trajectory of a medical device long before commercialization begins. Choices related to software architecture, third-party components, and system connectivity establish both the opportunity and the risk profile of the product.</p><p>Cybersecurity introduces a layer of complexity that many teams underestimate. It extends beyond protecting data and into safeguarding patient outcomes, ensuring system reliability, and meeting increasingly stringent regulatory expectations.</p><p>Chris Danek, CEO of Bessel, joins Christian and Trevor to examine how a single overlooked dependency or unsupported component can become a critical vulnerability. In many cases, these issues remain hidden until late-stage testing or FDA review, where remediation becomes significantly more expensive and disruptive.</p><p>Effective development requires integrating cybersecurity into requirements, architecture, and validation activities from the outset. Threat modeling, component vetting, and design-level decisions play a defining role in reducing downstream risk.</p><p>The organizations that succeed are those that treat cybersecurity as a core engineering discipline. Building secure, scalable medical devices requires alignment between technical execution, regulatory strategy, and long-term product viability.</p><p></p><p><strong>Episode Breakdown:</strong></p><ul><li>00:01 Welcome</li><li>02:54 Impact definition</li><li>05:16 Security integration</li><li>07:22 Connectivity requirements</li><li>12:30 Architecture</li><li>18:45 Requirements</li><li>24:20 Development</li><li>30:15 Certificates</li><li>36:40 Privacy focus</li><li>42:50 Risk scoring</li><li>48:03 Regulators</li><li>50:55 Thoughts</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Early design decisions define the trajectory of a medical device long before commercialization begins. Choices related to software architecture, third-party components, and system connectivity establish both the opportunity and the risk profile of the product.</p><p>Cybersecurity introduces a layer of complexity that many teams underestimate. It extends beyond protecting data and into safeguarding patient outcomes, ensuring system reliability, and meeting increasingly stringent regulatory expectations.</p><p>Chris Danek, CEO of Bessel, joins Christian and Trevor to examine how a single overlooked dependency or unsupported component can become a critical vulnerability. In many cases, these issues remain hidden until late-stage testing or FDA review, where remediation becomes significantly more expensive and disruptive.</p><p>Effective development requires integrating cybersecurity into requirements, architecture, and validation activities from the outset. Threat modeling, component vetting, and design-level decisions play a defining role in reducing downstream risk.</p><p>The organizations that succeed are those that treat cybersecurity as a core engineering discipline. Building secure, scalable medical devices requires alignment between technical execution, regulatory strategy, and long-term product viability.</p><p></p><p><strong>Episode Breakdown:</strong></p><ul><li>00:01 Welcome</li><li>02:54 Impact definition</li><li>05:16 Security integration</li><li>07:22 Connectivity requirements</li><li>12:30 Architecture</li><li>18:45 Requirements</li><li>24:20 Development</li><li>30:15 Certificates</li><li>36:40 Privacy focus</li><li>42:50 Risk scoring</li><li>48:03 Regulators</li><li>50:55 Thoughts</li></ul><br/><p></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">688a90d9-4923-427b-9a1e-aaba6375ab68</guid><itunes:image href="https://artwork.captivate.fm/dbcb8f73-119e-47dd-b7c9-4e3a32047f13/Spotify.jpg"/><pubDate>Thu, 26 Mar 2026 09:45:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/688a90d9-4923-427b-9a1e-aaba6375ab68.mp3" length="122239352" type="audio/mpeg"/><itunes:duration>50:56</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>63</itunes:episode><podcast:episode>63</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel | Ep. 63"><podcast:source uri="https://youtu.be/6efQgb7sUS0"/></podcast:alternateEnclosure></item><item><title>Edge Cases, Alarm Fatigue, and Why AI Cannot Replace Clinical Judgment with Brandon Fertig, Senior Manager at Philips Healthcare</title><itunes:title>Patient Monitoring Systems and the Gingerbread Man: How Brandon Fertig, Senior Manager at Philips Healthcare Uses AI to Help Nurses PrioritizePatient Monitoring Systems and the Gingerbread Man: How Brandon Fertig, Senior Manager at Philips Healthcare Uses AI to Help Nurses Prioritize</itunes:title><description><![CDATA[<p>Alarm fatigue happens when monitoring systems raise so many false flags that clinical staff begin ignoring them, even when real critical events occur. A surgeon during an operation gets alarms indicating patient bleeding, but observes stable blood pressure and no visible bleeding. The surgeon trusts direct patient observation over machine output because edge cases require human judgment that AI cannot reliably provide.</p><p>Brandon Fertig discusses why patient monitoring systems with visual indicators like the gingerbread man figure help nurses prioritize care without replacing their judgment, how edge cases become more important as automation increases, and why AI in healthcare should focus on efficiency rather than autonomous decision-making.</p><p>Alarm noise versus signal, why ground truth patient observation matters more than machine alerts, and how human checkpoints handle situations AI cannot predict.</p><p>Practical for understanding AI limitations in clinical settings.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:01 Welcome</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:20 IT background</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>05:03 Leadership</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:33 Skills transfer</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>12:15 Philips work</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>16:40 Training</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:30 AI tools</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>28:45 Checkpoints</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:20 Monitoring</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:50 Quality</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>40:54 Efficiency</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>41:24 Judgment</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>42:38 Advice</li></ol><br/><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Alarm fatigue happens when monitoring systems raise so many false flags that clinical staff begin ignoring them, even when real critical events occur. A surgeon during an operation gets alarms indicating patient bleeding, but observes stable blood pressure and no visible bleeding. The surgeon trusts direct patient observation over machine output because edge cases require human judgment that AI cannot reliably provide.</p><p>Brandon Fertig discusses why patient monitoring systems with visual indicators like the gingerbread man figure help nurses prioritize care without replacing their judgment, how edge cases become more important as automation increases, and why AI in healthcare should focus on efficiency rather than autonomous decision-making.</p><p>Alarm noise versus signal, why ground truth patient observation matters more than machine alerts, and how human checkpoints handle situations AI cannot predict.</p><p>Practical for understanding AI limitations in clinical settings.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:01 Welcome</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:20 IT background</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>05:03 Leadership</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:33 Skills transfer</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>12:15 Philips work</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>16:40 Training</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:30 AI tools</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>28:45 Checkpoints</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:20 Monitoring</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:50 Quality</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>40:54 Efficiency</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>41:24 Judgment</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>42:38 Advice</li></ol><br/><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <a href="https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session</a></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">fff937de-844d-49bb-acdd-55f5977ce274</guid><itunes:image href="https://artwork.captivate.fm/3ad640b3-bb13-496e-bb78-18f09df33daf/Spotify.jpg"/><pubDate>Thu, 19 Mar 2026 08:15:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/fff937de-844d-49bb-acdd-55f5977ce274.mp3" length="84736860" type="audio/mpeg"/><itunes:duration>42:39</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>62</itunes:episode><podcast:episode>62</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="AI in Healthcare: Why Humans Still Matter with Brandon Fertig, Senior Manager at Philips | Ep. 62"><podcast:source uri="https://youtu.be/D_kxhi332IA"/></podcast:alternateEnclosure></item><item><title>Alarm Fatigue, Workflow Integration, and the Intelligent Operating Room (Professor Aamer Ahmed)</title><itunes:title>Spend Two Weeks in a Hospital Before Designing Your Medical Device (Professor Aamer Ahmed)</itunes:title><description><![CDATA[<p>Devices that do not integrate into the clinical workflow sit unused regardless of technical sophistication. Physicians work in high-pressure environments where equipment must be 100 percent reliable, secure, and enhance workflow rather than disrupt it.</p><p>Professor Aamer Ahmed, a Consultant in Cardiothoracic Anaesthesia, Professor of Anaesthesia and Critical Care at the University of Leicester, and co-founder of Hemeo, a medical technology company designing AI-based personalized Clinical Decision Support Systems for coagulation disorders, discusses with Christian Espinosa and Trevor Slattery why involving Key Opinion Leaders at the design stage prevents expensive redesigns, what alarm fatigue does to clinical decision-making, and how legal precedent will determine AI liability as therapeutic recommendations become more common.</p><p>He also explains why the best medtech development approach involves spending time in hospitals observing physicians before engineering products, how digital twin models enable personalized clinical predictions, and why common sense is not always common practice in device design.</p><p>The discussion offers practical advice for building devices clinicians actually use.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:01 Introduction</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:33 Role explanation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:49 KOL involvement</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>03:32 Workflow integration</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>05:36 Seamless design</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:13 Problem-first approach</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:35 Clinical observation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:45 Digital twin</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>12:20 IT security</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:30 AI support</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:15 Accountability</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:40 Alarm fatigue</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>32:10 Liability</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:07 Advice</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:13 Simplicity</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Devices that do not integrate into the clinical workflow sit unused regardless of technical sophistication. Physicians work in high-pressure environments where equipment must be 100 percent reliable, secure, and enhance workflow rather than disrupt it.</p><p>Professor Aamer Ahmed, a Consultant in Cardiothoracic Anaesthesia, Professor of Anaesthesia and Critical Care at the University of Leicester, and co-founder of Hemeo, a medical technology company designing AI-based personalized Clinical Decision Support Systems for coagulation disorders, discusses with Christian Espinosa and Trevor Slattery why involving Key Opinion Leaders at the design stage prevents expensive redesigns, what alarm fatigue does to clinical decision-making, and how legal precedent will determine AI liability as therapeutic recommendations become more common.</p><p>He also explains why the best medtech development approach involves spending time in hospitals observing physicians before engineering products, how digital twin models enable personalized clinical predictions, and why common sense is not always common practice in device design.</p><p>The discussion offers practical advice for building devices clinicians actually use.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:01 Introduction</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:33 Role explanation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:49 KOL involvement</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>03:32 Workflow integration</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>05:36 Seamless design</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:13 Problem-first approach</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:35 Clinical observation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:45 Digital twin</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>12:20 IT security</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:30 AI support</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:15 Accountability</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:40 Alarm fatigue</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>32:10 Liability</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:07 Advice</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:13 Simplicity</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">6af5e813-63da-4e4b-a082-e9d1cfbc1a64</guid><itunes:image href="https://artwork.captivate.fm/c5544de2-1db0-4f06-a0ff-8e698bd4dfbe/Spotify.jpg"/><pubDate>Thu, 12 Mar 2026 09:30:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/6af5e813-63da-4e4b-a082-e9d1cfbc1a64.mp3" length="56858251" type="audio/mpeg"/><itunes:duration>38:13</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>61</itunes:episode><podcast:episode>61</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="How to Design Devices That Integrate Into Clinical Workflow Without Disruption  | Ep. 61"><podcast:source uri="https://youtu.be/xamMQObdrJk"/></podcast:alternateEnclosure></item><item><title>How to Move Stakeholders from Awareness to Sustained Adoption Without Friction</title><itunes:title>How to Move Stakeholders from Awareness to Sustained Adoption Without Friction</itunes:title><description><![CDATA[<p>Marketing medical devices requires understanding that stakeholders are different, buying processes are longer, and friction points are more complex than consumer products or software. Most companies build websites and attend trade shows hoping prospects will decode their message, but prospects do not have time for that.</p><p>Sustained adoption is not the same as initial purchase. It means the device is used continuously with no friction, no concerns, and no barriers, causing users to stop or switch. Getting there requires understanding every stakeholder involved, what questions they have at each stage, and what fears might stop them.</p><p>This episode covers how to structure marketing that moves stakeholders through a clear path, why ideal client profile refinement produces better results than broad targeting, and how one advisor identified exact pain points to cut through noise and convert a prospect.</p><p>Practical advice for anyone responsible for medtech marketing or go-to-market strategy.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:02 Welcome</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:21 Intro</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:15 Origin</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>04:36 Challenges</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>06:51 Foundation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:00 Knowledge gap</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>09:30 Adoption</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>11:45 Mapping</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>15:20 Friction</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:40 Content</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:30 Targeting</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:15 Failures</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>30:45 Pain points</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:20 Clarity</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:50 Tradeoffs</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>40:44 Advice</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Marketing medical devices requires understanding that stakeholders are different, buying processes are longer, and friction points are more complex than consumer products or software. Most companies build websites and attend trade shows hoping prospects will decode their message, but prospects do not have time for that.</p><p>Sustained adoption is not the same as initial purchase. It means the device is used continuously with no friction, no concerns, and no barriers, causing users to stop or switch. Getting there requires understanding every stakeholder involved, what questions they have at each stage, and what fears might stop them.</p><p>This episode covers how to structure marketing that moves stakeholders through a clear path, why ideal client profile refinement produces better results than broad targeting, and how one advisor identified exact pain points to cut through noise and convert a prospect.</p><p>Practical advice for anyone responsible for medtech marketing or go-to-market strategy.</p><p><strong>Episode Breakdown:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:02 Welcome</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:21 Intro</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>02:15 Origin</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>04:36 Challenges</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>06:51 Foundation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>07:00 Knowledge gap</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>09:30 Adoption</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>11:45 Mapping</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>15:20 Friction</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:40 Content</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:30 Targeting</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:15 Failures</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>30:45 Pain points</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>34:20 Clarity</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>38:50 Tradeoffs</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>40:44 Advice</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">6a9fc756-e58f-49fb-84e9-655a519d324a</guid><itunes:image href="https://artwork.captivate.fm/4f06bbf6-2f0c-40ea-9faa-288d9c5db07f/Spotify.jpg"/><pubDate>Thu, 05 Mar 2026 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/6a9fc756-e58f-49fb-84e9-655a519d324a.mp3" length="62412616" type="audio/mpeg"/><itunes:duration>40:51</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>60</itunes:episode><podcast:episode>60</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="How to Move Stakeholders from Awareness to Sustained Adoption Without Friction | Ep. 60"><podcast:source uri="https://youtu.be/zip-gGljTgE"/></podcast:alternateEnclosure></item><item><title>Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity</title><itunes:title>Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity</itunes:title><description><![CDATA[<p>Medical device risk assessments are failing patients, not because the process is too hard, but because nobody doing the assessment has ever been in the room where the device actually gets used.</p><p>Medtech quality and regulatory leader Stephen Smith describes sitting in a risk session for a device going into an intensive care unit. Twelve people in the room, and not one had ever set foot in an ICU. If you have never been in the environment your device will operate in, risk identification becomes guesswork, mitigations get written for problems that are not the actual problems, and the device goes to market with gaps that stay hidden until something goes wrong.</p><p>This episode covers why the user environment is the most consistently ignored variable in medical device development, and how that same gap shows up in cybersecurity risk assessments.</p><p>Also discussed: the $5,000 problem that gets rationalized today has a way of becoming the $500,000 crisis that cannot be ignored tomorrow, and what this argument actually looks like in practice.</p><p>Stephen also explains why CE marking proves you passed an audit and why FDA clearance does not mean the FDA approved your device.</p><p>Worth listening to if you are focused on medtech quality, regulatory, or cybersecurity.</p><p>Episode Breakdown:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:00 Opening quote</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:47 Intro and guest background</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>04:14 QA vs RA vs QC</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>06:00 Cybersecurity in quality systems</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:30 Risk as the foundation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>11:20 Ignoring clinicians and user environments</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>13:00 ICU risk assessment example</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>14:19 Startups and product market fit</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>15:30 Key Opinion Leaders</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>16:47 Companies hiring comfortable consultants</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:30 $5,000 vs $500,000</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>20:00 Why quality and cybersecurity are invisible</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:00 What regulators actually review</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:54 Self-signed certificates</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>24:30 Cybersecurity speed vs regulation speed</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:30 CE marking is not a quality guarantee</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>27:00 Lost instructions for use</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>28:40 Cleared vs approved</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>29:45 Prevention is better than cure</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>31:00 Final advice</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>32:00 Racing analogy</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.</p><p>Learn more by visiting https://bluegoatcyber.com</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber.</p><p>Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>Medical device risk assessments are failing patients, not because the process is too hard, but because nobody doing the assessment has ever been in the room where the device actually gets used.</p><p>Medtech quality and regulatory leader Stephen Smith describes sitting in a risk session for a device going into an intensive care unit. Twelve people in the room, and not one had ever set foot in an ICU. If you have never been in the environment your device will operate in, risk identification becomes guesswork, mitigations get written for problems that are not the actual problems, and the device goes to market with gaps that stay hidden until something goes wrong.</p><p>This episode covers why the user environment is the most consistently ignored variable in medical device development, and how that same gap shows up in cybersecurity risk assessments.</p><p>Also discussed: the $5,000 problem that gets rationalized today has a way of becoming the $500,000 crisis that cannot be ignored tomorrow, and what this argument actually looks like in practice.</p><p>Stephen also explains why CE marking proves you passed an audit and why FDA clearance does not mean the FDA approved your device.</p><p>Worth listening to if you are focused on medtech quality, regulatory, or cybersecurity.</p><p>Episode Breakdown:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:00 Opening quote</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>00:47 Intro and guest background</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>04:14 QA vs RA vs QC</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>06:00 Cybersecurity in quality systems</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>08:30 Risk as the foundation</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>11:20 Ignoring clinicians and user environments</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>13:00 ICU risk assessment example</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>14:19 Startups and product market fit</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>15:30 Key Opinion Leaders</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>16:47 Companies hiring comfortable consultants</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>18:30 $5,000 vs $500,000</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>20:00 Why quality and cybersecurity are invisible</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:00 What regulators actually review</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>22:54 Self-signed certificates</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>24:30 Cybersecurity speed vs regulation speed</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>26:30 CE marking is not a quality guarantee</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>27:00 Lost instructions for use</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>28:40 Cleared vs approved</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>29:45 Prevention is better than cure</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>31:00 Final advice</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>32:00 Racing analogy</li></ol><br/><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.</p><p>Learn more by visiting https://bluegoatcyber.com</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber.</p><p>Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">c3601d57-e54b-46fc-bb38-8e38598ef4e2</guid><itunes:image href="https://artwork.captivate.fm/d87399af-157d-47a5-9326-1827e7feaa77/Spotify.jpg"/><pubDate>Thu, 26 Feb 2026 09:15:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/c3601d57-e54b-46fc-bb38-8e38598ef4e2.mp3" length="49903253" type="audio/mpeg"/><itunes:duration>32:26</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>59</itunes:episode><podcast:episode>59</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity | Ep. 59"><podcast:source uri="https://youtu.be/fKd61b0ttso"/></podcast:alternateEnclosure></item><item><title>How AI Code Security Became a Medical Device Problem with Jun Xiang Tan</title><itunes:title>Adversarial Attacks on Medical AI: What You Need to Know with Jun Xiang Tan</itunes:title><description><![CDATA[<p>Ten years ago, Singapore's healthcare system got hacked. Patient records were stolen at a national scale. The government responded by building one of the most comprehensive medical device security frameworks in the world.</p><p>The Cybersecurity Labeling Scheme has four tiers. Level one means basic security controls exist. Level four means the device underwent independent code review, has advanced threat detection, and maintains continuous vulnerability management. Hospitals can see exactly what level of security they're getting before they buy.</p><p>Jun Xiang from CareHero explains why this matters, especially now that AI is showing up in medical devices without proper testing. He covers adversarial attacks on medical images, why doctors are uploading patient data to ChatGPT, and what automation bias does to clinical decision making.</p><p>Practical conversation about medical device security in Southeast Asia and what manufacturers need to know about Singapore's approach.</p><p><strong>Episode Breakdown:</strong></p><p>00:01 Welcome</p><p>00:31 Background</p><p>01:09 Military service</p><p>03:09 AI threats</p><p>03:45 23% problem</p><p>04:40 X-rays ChatGPT</p><p>05:43 Attacks</p><p>08:15 Poisoning</p><p>11:30 Hallucinations</p><p>14:20 AI code</p><p>17:45 Vulnerabilities</p><p>20:30 Pair programming</p><p>23:15 Guardrails</p><p>26:40 Automation bias</p><p>28:50 AI scribes</p><p>31:20 Dialects</p><p>34:05 Pre-triage</p><p>36:32 Pricing</p><p>37:25 Pair programmer</p><p>37:40 Human interpretation</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.</p><p>Learn more by visiting https://bluegoatcyber.com</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber.</p><p>Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>Ten years ago, Singapore's healthcare system got hacked. Patient records were stolen at a national scale. The government responded by building one of the most comprehensive medical device security frameworks in the world.</p><p>The Cybersecurity Labeling Scheme has four tiers. Level one means basic security controls exist. Level four means the device underwent independent code review, has advanced threat detection, and maintains continuous vulnerability management. Hospitals can see exactly what level of security they're getting before they buy.</p><p>Jun Xiang from CareHero explains why this matters, especially now that AI is showing up in medical devices without proper testing. He covers adversarial attacks on medical images, why doctors are uploading patient data to ChatGPT, and what automation bias does to clinical decision making.</p><p>Practical conversation about medical device security in Southeast Asia and what manufacturers need to know about Singapore's approach.</p><p><strong>Episode Breakdown:</strong></p><p>00:01 Welcome</p><p>00:31 Background</p><p>01:09 Military service</p><p>03:09 AI threats</p><p>03:45 23% problem</p><p>04:40 X-rays ChatGPT</p><p>05:43 Attacks</p><p>08:15 Poisoning</p><p>11:30 Hallucinations</p><p>14:20 AI code</p><p>17:45 Vulnerabilities</p><p>20:30 Pair programming</p><p>23:15 Guardrails</p><p>26:40 Automation bias</p><p>28:50 AI scribes</p><p>31:20 Dialects</p><p>34:05 Pre-triage</p><p>36:32 Pricing</p><p>37:25 Pair programmer</p><p>37:40 Human interpretation</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry.</p><p>Learn more by visiting https://bluegoatcyber.com</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber.</p><p>Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">fdf360c5-93c7-441b-b29d-489e963c1d3e</guid><itunes:image href="https://artwork.captivate.fm/414b9935-5977-48dc-ae4c-9d1a49acefd8/Spotify.jpg"/><pubDate>Thu, 19 Feb 2026 08:30:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/fdf360c5-93c7-441b-b29d-489e963c1d3e.mp3" length="54244278" type="audio/mpeg"/><itunes:duration>37:40</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>58</itunes:episode><podcast:episode>58</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="The Hidden Cybersecurity Risks When Doctors Use AI Diagnostics | Ep. 58"><podcast:source uri="https://youtu.be/89T-JrmDuo8"/></podcast:alternateEnclosure></item><item><title>How to Build an SBOM That Passes FDA Review</title><itunes:title>SBOMs 101: What the FDA Expects and How to Get It Right</itunes:title><description><![CDATA[<p>SBOMs are one of the most common sources of FDA deficiencies in medical device submissions. Most companies think they're doing it right, but then they get feedback asking for missing components or clarification on what's included.</p><p>In this webinar, Christian Espinosa and Trevor Slattery explain what the FDA actually expects in an SBOM and why it's not just about listing third-party libraries. You need to include first-party code too. You need to follow the NTIA minimum elements. And you need to provide it in a machine-readable format like SPDX or CycloneDX.</p><p>Trevor walks through the history of SBOMs, from their origins in licensing compliance to their current role in medical device cybersecurity. He explains the shift-left approach the FDA wants to see and why transparency matters for healthcare delivery organizations making purchasing decisions.</p><p>The webinar also addresses a big concern people have. Does publishing an SBOM give attackers a roadmap to your system? Trevor breaks down why that's not actually a problem if you're managing your security properly.</p><p>If you're building a connected medical device or preparing for an FDA submission, this is a clear breakdown of how to get your SBOM right the first time.</p><p><strong>Webinar Breakdown:</strong></p><p>00:00 Welcome and introduction to SBOMs</p><p>00:44 What is an SBOM and why does it matter</p><p>03:10 The history of SBOMs: From licensing to cybersecurity</p><p>07:20 Why the FDA cares about SBOMs</p><p>11:30 The biggest mistake: Leaving out first-party code</p><p>15:45 NTIA minimum elements explained</p><p>19:20 Machine-readable formats: SPDX and CycloneDX</p><p>23:00 Real-world examples: Log4j and Shellshock</p><p>26:15 Do SBOMs give attackers a roadmap? The truth</p><p>29:40 Common myths about SBOMs</p><p>33:50 Key takeaways for FDA submissions</p><p>36:20 Q&amp;A session begins</p><p>Blue Goat Cyber provides essential cybersecurity solutions for the medical device industry.Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>SBOMs are one of the most common sources of FDA deficiencies in medical device submissions. Most companies think they're doing it right, but then they get feedback asking for missing components or clarification on what's included.</p><p>In this webinar, Christian Espinosa and Trevor Slattery explain what the FDA actually expects in an SBOM and why it's not just about listing third-party libraries. You need to include first-party code too. You need to follow the NTIA minimum elements. And you need to provide it in a machine-readable format like SPDX or CycloneDX.</p><p>Trevor walks through the history of SBOMs, from their origins in licensing compliance to their current role in medical device cybersecurity. He explains the shift-left approach the FDA wants to see and why transparency matters for healthcare delivery organizations making purchasing decisions.</p><p>The webinar also addresses a big concern people have. Does publishing an SBOM give attackers a roadmap to your system? Trevor breaks down why that's not actually a problem if you're managing your security properly.</p><p>If you're building a connected medical device or preparing for an FDA submission, this is a clear breakdown of how to get your SBOM right the first time.</p><p><strong>Webinar Breakdown:</strong></p><p>00:00 Welcome and introduction to SBOMs</p><p>00:44 What is an SBOM and why does it matter</p><p>03:10 The history of SBOMs: From licensing to cybersecurity</p><p>07:20 Why the FDA cares about SBOMs</p><p>11:30 The biggest mistake: Leaving out first-party code</p><p>15:45 NTIA minimum elements explained</p><p>19:20 Machine-readable formats: SPDX and CycloneDX</p><p>23:00 Real-world examples: Log4j and Shellshock</p><p>26:15 Do SBOMs give attackers a roadmap? The truth</p><p>29:40 Common myths about SBOMs</p><p>33:50 Key takeaways for FDA submissions</p><p>36:20 Q&amp;A session begins</p><p>Blue Goat Cyber provides essential cybersecurity solutions for the medical device industry.Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">79d74718-8815-4991-98af-c9bd8a812139</guid><itunes:image href="https://artwork.captivate.fm/49d7dff0-b3df-4bd4-9046-c8d83f9a6919/SBOM-mistakes-that-keep.jpg"/><pubDate>Wed, 18 Feb 2026 08:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/79d74718-8815-4991-98af-c9bd8a812139.mp3" length="20082476" type="audio/mpeg"/><itunes:duration>41:50</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><podcast:chapters url="https://transcripts.captivate.fm/chapter-7f41b9a5-2ae2-4b13-9767-30a142b51b46.json" type="application/json+chapters"/><podcast:alternateEnclosure type="video/youtube" title="Webinar: FDA Expectations for SBOMs — A Deep Dive with Blue Goat Cyber"><podcast:source uri="https://youtu.be/VijLHN8Gg4A"/></podcast:alternateEnclosure></item><item><title>From Idea to FDA Clearance: What Nobody Tells Medtech Founders with Darcy Bachert</title><itunes:title>Secure Software Development for Medical Devices: The Real Story with Darcy Bachert</itunes:title><description><![CDATA[<p>Building medical device software is hard. Building it the right way is harder. And getting it through FDA approval while managing cybersecurity requirements? That's what Darcy Bachert has been doing for 17 years.</p><p>Darcy runs Prolucid Technologies, an ISO 13485-certified software development firm in Toronto. They work with medtech companies across North America, Europe, and Australia.</p><p>And in that time, he's seen the same mistakes repeatedly.</p><p>The biggest one? Founders build products that solve problems nobody has. Or they build something physicians won't adopt because it adds complexity instead of making their lives easier.</p><p>In this conversation, Darcy talks about IEC 62304 and why it matters when choosing a software partner. The Canadian medtech ecosystem and why Toronto is a major hub. And why quality systems and cybersecurity need to be built in from day one, not added at the end.</p><p>This episode is practical if you're building a medical device or working with medtech startups.</p><p>Episode Breakdown:</p><p>00:01 Welcome and intro</p><p>00:30 Darcy's background and Prolucid Technologies overview</p><p>01:15 The origin of the name Prolucid Technologies</p><p>01:58 Why clarity matters more than code</p><p>04:18 Common challenges beyond software development</p><p>06:11 Toronto's medtech ecosystem</p><p>06:57 IEC 62304 and choosing the right development partner</p><p>09:17 ISO 13485 certification and investor confidence</p><p>12:04 Realistic timelines for medical device software</p><p>15:32 Cost expectations and budget planning</p><p>18:45 Building quality systems from the start</p><p>21:20 Integrating cybersecurity throughout development</p><p>24:15 When and how to do penetration testing</p><p>27:30 Cybersecurity mistakes startups make</p><p>30:42 The MTI program and Canadian medtech resources</p><p>33:18 Canadian vs US medtech markets</p><p>36:22 Physician adoption challenges</p><p>40:18 Trevor: Don't invent your problem</p><p>41:36 Darcy: Find partners who've done it before</p><p>43:05 Christian: Balance user adoption with reimbursement</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Building medical device software is hard. Building it the right way is harder. And getting it through FDA approval while managing cybersecurity requirements? That's what Darcy Bachert has been doing for 17 years.</p><p>Darcy runs Prolucid Technologies, an ISO 13485-certified software development firm in Toronto. They work with medtech companies across North America, Europe, and Australia.</p><p>And in that time, he's seen the same mistakes repeatedly.</p><p>The biggest one? Founders build products that solve problems nobody has. Or they build something physicians won't adopt because it adds complexity instead of making their lives easier.</p><p>In this conversation, Darcy talks about IEC 62304 and why it matters when choosing a software partner. The Canadian medtech ecosystem and why Toronto is a major hub. And why quality systems and cybersecurity need to be built in from day one, not added at the end.</p><p>This episode is practical if you're building a medical device or working with medtech startups.</p><p>Episode Breakdown:</p><p>00:01 Welcome and intro</p><p>00:30 Darcy's background and Prolucid Technologies overview</p><p>01:15 The origin of the name Prolucid Technologies</p><p>01:58 Why clarity matters more than code</p><p>04:18 Common challenges beyond software development</p><p>06:11 Toronto's medtech ecosystem</p><p>06:57 IEC 62304 and choosing the right development partner</p><p>09:17 ISO 13485 certification and investor confidence</p><p>12:04 Realistic timelines for medical device software</p><p>15:32 Cost expectations and budget planning</p><p>18:45 Building quality systems from the start</p><p>21:20 Integrating cybersecurity throughout development</p><p>24:15 When and how to do penetration testing</p><p>27:30 Cybersecurity mistakes startups make</p><p>30:42 The MTI program and Canadian medtech resources</p><p>33:18 Canadian vs US medtech markets</p><p>36:22 Physician adoption challenges</p><p>40:18 Trevor: Don't invent your problem</p><p>41:36 Darcy: Find partners who've done it before</p><p>43:05 Christian: Balance user adoption with reimbursement</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">2733c436-3df8-4533-b5aa-b488b85de18a</guid><itunes:image href="https://artwork.captivate.fm/74473035-6984-4777-ae0f-df56ebbd10e6/57-announment.jpg"/><pubDate>Thu, 12 Feb 2026 08:15:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/2733c436-3df8-4533-b5aa-b488b85de18a.mp3" length="66915463" type="audio/mpeg"/><itunes:duration>44:22</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>57</itunes:episode><podcast:episode>57</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="From Idea to FDA Clearance: What Nobody Tells Medtech Founders with Darcy Bachert | Ep. 57"><podcast:source uri="https://youtu.be/IYv05m74Ros"/></podcast:alternateEnclosure></item><item><title>What MedTech Startups Get Wrong About Cybersecurity Documentation with Marc Zemel</title><itunes:title>The Hidden Cybersecurity Challenges in Software as a Medical Device</itunes:title><description><![CDATA[<p>Marc Zemel has been building Retia Medical for 15 years. The company started as two guys with slides and licensed technology. Now their data-driven hemodynamic monitoring technology for consistently accurate cardiac output measurements in high-risk surgical and critically ill patients is in 75 hospitals across 18 countries, sold by Medtronic in the U.S, and the company is preparing to launch their new product Argos Infinity, pending FDA clearance.</p><p>But getting here meant dealing with cybersecurity challenges that Marc didn't see coming. In this conversation, he talks about what actually slowed them down, what he wishes he'd done differently, and why building a proper quality system from day one would have saved him years of pain.</p><p>Retia Medical develops algorithms that monitor cardiovascular function. Their technology detects problems before blood pressure drops, which makes it valuable in operating rooms and ICUs. Nurses have gotten so attached to their monitors that they literally hug them because the devices help them do their jobs better.</p><p>Marc walks through the specific cybersecurity issues that surprised him. Like how software as a medical device comes with ongoing compliance costs that hardware doesn't have. Or how documentation requirements kept changing as the FDA updated its expectations. Or how retrofitting cybersecurity into an existing product is way more expensive than building it in from the start.</p><p>He also shares his philosophy on building companies. He doesn't focus on exits or acquisition targets. He focuses on building something people can't live without. When the product is that good, the rest takes care of itself.</p><p>If you're building a medical device startup or dealing with FDA submissions, this is a conversation worth hearing.</p><p><strong>Episode Breakdown:</strong></p><p>00:00 Introduction</p><p>00:32 Where everyone's calling from</p><p>02:54 Marc's background and journey into medtech</p><p>04:33 What Retia Medical does</p><p>07:00 Blood flow vs blood pressure</p><p>09:45 Software vs hardware as a medical device</p><p>12:30 Cybersecurity challenges</p><p>15:20 Documentation nightmares</p><p>18:45 Quality systems and why they matter early</p><p>22:10 FDA submissions over 15 years</p><p>25:30 The cost of retrofitting cybersecurity</p><p>28:50 Software updates and compliance</p><p>32:15 Build to be bought, not to be sold</p><p>37:32 What acquirers look for</p><p>39:02 Product market fit: Nurses hugging monitors</p><p>41:14 Wearables and future regulations</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Marc Zemel has been building Retia Medical for 15 years. The company started as two guys with slides and licensed technology. Now their data-driven hemodynamic monitoring technology for consistently accurate cardiac output measurements in high-risk surgical and critically ill patients is in 75 hospitals across 18 countries, sold by Medtronic in the U.S, and the company is preparing to launch their new product Argos Infinity, pending FDA clearance.</p><p>But getting here meant dealing with cybersecurity challenges that Marc didn't see coming. In this conversation, he talks about what actually slowed them down, what he wishes he'd done differently, and why building a proper quality system from day one would have saved him years of pain.</p><p>Retia Medical develops algorithms that monitor cardiovascular function. Their technology detects problems before blood pressure drops, which makes it valuable in operating rooms and ICUs. Nurses have gotten so attached to their monitors that they literally hug them because the devices help them do their jobs better.</p><p>Marc walks through the specific cybersecurity issues that surprised him. Like how software as a medical device comes with ongoing compliance costs that hardware doesn't have. Or how documentation requirements kept changing as the FDA updated its expectations. Or how retrofitting cybersecurity into an existing product is way more expensive than building it in from the start.</p><p>He also shares his philosophy on building companies. He doesn't focus on exits or acquisition targets. He focuses on building something people can't live without. When the product is that good, the rest takes care of itself.</p><p>If you're building a medical device startup or dealing with FDA submissions, this is a conversation worth hearing.</p><p><strong>Episode Breakdown:</strong></p><p>00:00 Introduction</p><p>00:32 Where everyone's calling from</p><p>02:54 Marc's background and journey into medtech</p><p>04:33 What Retia Medical does</p><p>07:00 Blood flow vs blood pressure</p><p>09:45 Software vs hardware as a medical device</p><p>12:30 Cybersecurity challenges</p><p>15:20 Documentation nightmares</p><p>18:45 Quality systems and why they matter early</p><p>22:10 FDA submissions over 15 years</p><p>25:30 The cost of retrofitting cybersecurity</p><p>28:50 Software updates and compliance</p><p>32:15 Build to be bought, not to be sold</p><p>37:32 What acquirers look for</p><p>39:02 Product market fit: Nurses hugging monitors</p><p>41:14 Wearables and future regulations</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">c93a1f51-2407-4a2d-b07a-5801b4cfb223</guid><itunes:image href="https://artwork.captivate.fm/dfc316ff-9ba7-4ec9-943a-3d8e83fbb831/56-announment.jpg"/><pubDate>Thu, 05 Feb 2026 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/c93a1f51-2407-4a2d-b07a-5801b4cfb223.mp3" length="62721750" type="audio/mpeg"/><itunes:duration>41:56</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>56</itunes:episode><podcast:episode>56</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="What 15 Years In MedTech Taught This CEO About Cybersecurity with Marc Zemel | Ep. 56"><podcast:source uri="https://youtu.be/4c0SsqWjCJo"/></podcast:alternateEnclosure></item><item><title>Why Most Medtech Companies Fail at Global Expansion (And How to Fix It) with William Jin</title><itunes:title>Why Your Cloud Platform Decision Could Destroy Your Global Market Strategy</itunes:title><description><![CDATA[<p>Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the American market?</p><p>William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.</p><p>William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get their products approved and sold in each other's markets. The problems he sees are surprisingly similar whether you're going East or West.</p><p>In this conversation, William walks through the real barriers to global expansion. We're talking about practical stuff like why using Google Cloud can completely block you from the Chinese market, how data sovereignty laws affect AI-powered devices, and why that Baxter ventilator recall should matter to everyone building connected medical devices.</p><p>If you're in medtech and thinking about international markets, this is the reality check you need. William's advice is simple but critical: plan for your target markets before you start building. Otherwise, you'll spend millions redesigning later, or worse, you'll realize you can't enter those markets at all.</p><p><strong>Episode Breakdown:</strong></p><p>00:00 The costly mistake of not planning for global markets early</p><p>00:44 Meet William Jin: Medical doctor turned medtech market strategist</p><p>03:15 What's really stopping Chinese companies from entering Western markets</p><p>07:20 Why Chinese medtech exports to the U.S. dropped while Europe increased</p><p>11:40 The Google Cloud problem nobody warns you about</p><p>15:50 How China's data regulations affect your algorithms and cloud architecture</p><p>19:30 Reverse engineering your markets: Start with the end in mind</p><p>23:00 Where Chinese companies dominate and where they struggle internationally</p><p>26:45 The Baxter recall that was really about cybersecurity</p><p>28:50 Why cybersecurity product recalls are fundamentally different</p><p>29:20 William's final advice for medtech innovators</p><p>29:40 Wrapping up: Design to disposal, not as an afterthought</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></description><content:encoded><![CDATA[<p>Thinking about taking your medical device to China? Or maybe you're a Chinese company looking at the American market?</p><p>William Jin has spent over 30 years helping companies do exactly that, and he'll tell you straight up that most of them aren't ready. Not because they lack good products, but because they didn't think about cybersecurity early enough.</p><p>William was trained as a medical doctor in Shanghai, then moved into the medtech industry working for companies like McCulloch and Stryker. Now he helps businesses on both sides of the Pacific figure out how to actually get their products approved and sold in each other's markets. The problems he sees are surprisingly similar whether you're going East or West.</p><p>In this conversation, William walks through the real barriers to global expansion. We're talking about practical stuff like why using Google Cloud can completely block you from the Chinese market, how data sovereignty laws affect AI-powered devices, and why that Baxter ventilator recall should matter to everyone building connected medical devices.</p><p>If you're in medtech and thinking about international markets, this is the reality check you need. William's advice is simple but critical: plan for your target markets before you start building. Otherwise, you'll spend millions redesigning later, or worse, you'll realize you can't enter those markets at all.</p><p><strong>Episode Breakdown:</strong></p><p>00:00 The costly mistake of not planning for global markets early</p><p>00:44 Meet William Jin: Medical doctor turned medtech market strategist</p><p>03:15 What's really stopping Chinese companies from entering Western markets</p><p>07:20 Why Chinese medtech exports to the U.S. dropped while Europe increased</p><p>11:40 The Google Cloud problem nobody warns you about</p><p>15:50 How China's data regulations affect your algorithms and cloud architecture</p><p>19:30 Reverse engineering your markets: Start with the end in mind</p><p>23:00 Where Chinese companies dominate and where they struggle internationally</p><p>26:45 The Baxter recall that was really about cybersecurity</p><p>28:50 Why cybersecurity product recalls are fundamentally different</p><p>29:20 William's final advice for medtech innovators</p><p>29:40 Wrapping up: Design to disposal, not as an afterthought</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting <u><a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a></u>.</p><p>If you're interested in our services or partnering with us, schedule a Discovery Session: <u><a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a></u></p><p>Christian Espinosa is the CEO and Founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: <u><a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a></u></p><p>Trevor Slattery on LinkedIn: <u><a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></u></p><p>Blue Goat Cyber on LinkedIn: <u><a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a></u></p><p>Blue Goat Cyber on Instagram: <u><a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on Facebook: <u><a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a></u></p><p>Blue Goat Cyber on YouTube: <u><a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a></u></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">1d22559b-916e-4895-af2a-76c231b27f99</guid><itunes:image href="https://artwork.captivate.fm/dbaf0405-645f-4347-8052-bd9fdba6a69d/Announcement-55-1.jpg"/><pubDate>Fri, 30 Jan 2026 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/1d22559b-916e-4895-af2a-76c231b27f99.mp3" length="46044033" type="audio/mpeg"/><itunes:duration>30:09</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>55</itunes:episode><podcast:episode>55</podcast:episode><podcast:season>1</podcast:season><podcast:alternateEnclosure type="video/youtube" title="The Hidden Reason Medtech Products Get Recalled (It&apos;s Not Quality Issues) with William Jin  | Ep. 55"><podcast:source uri="https://youtu.be/ZRxPdcQ09nU"/></podcast:alternateEnclosure></item><item><title>What It Takes to Succeed in the Medtech Industry with Omar Khateeb</title><itunes:title>How to Avoid the 3 Biggest Mistakes in Medtech Startups</itunes:title><description><![CDATA[<p>Ever thought about what it really takes to launch a successful medtech startup?</p><p>Omar M. Khateeb knows the challenges firsthand. As a founder with a track record of building healthtech companies, he’s lived through the hurdles that come with innovating in the medtech space.</p><p>In this episode, Omar dives into the highs and lows of his entrepreneurial journey, sharing key lessons, pivotal moments, and the strategies that helped him succeed. From tackling complex healthcare issues to navigating the regulatory maze, Omar breaks down what it takes to make a lasting impact in medtech.</p><p>Join us for an inside look at the future of health tech and why it’s the perfect time for the next generation of entrepreneurs to get involved.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>Ever thought about what it really takes to launch a successful medtech startup?</p><p>Omar M. Khateeb knows the challenges firsthand. As a founder with a track record of building healthtech companies, he’s lived through the hurdles that come with innovating in the medtech space.</p><p>In this episode, Omar dives into the highs and lows of his entrepreneurial journey, sharing key lessons, pivotal moments, and the strategies that helped him succeed. From tackling complex healthcare issues to navigating the regulatory maze, Omar breaks down what it takes to make a lasting impact in medtech.</p><p>Join us for an inside look at the future of health tech and why it’s the perfect time for the next generation of entrepreneurs to get involved.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">40327804-9fb9-4d6e-a430-264e3e9deb79</guid><itunes:image href="https://artwork.captivate.fm/fe8da6c5-f50d-4fc6-89c8-bc388a12fc94/Announcement.jpg"/><pubDate>Wed, 14 Jan 2026 11:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/40327804-9fb9-4d6e-a430-264e3e9deb79.mp3" length="78263504" type="audio/mpeg"/><itunes:duration>53:00</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>54</itunes:episode><podcast:episode>54</podcast:episode><podcast:season>1</podcast:season></item><item><title>Untangling Software Composition Analysis for MedTech Teams</title><itunes:title>Untangling Software Composition Analysis for MedTech Teams</itunes:title><description><![CDATA[<p>Why does software composition analysis matter beyond regulatory compliance?</p><p>This episode explores SCA (Software Composition Analysis) and explains how SBOMs (Software Bill of Materials), SOUP (Software of Unknown Provenance), and related tooling fit into the broader medical device cybersecurity landscape. Christian and Trevor clarify common misconceptions, including licensing fears, machine-readable requirements, and the role of static testing tools.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>Why does software composition analysis matter beyond regulatory compliance?</p><p>This episode explores SCA (Software Composition Analysis) and explains how SBOMs (Software Bill of Materials), SOUP (Software of Unknown Provenance), and related tooling fit into the broader medical device cybersecurity landscape. Christian and Trevor clarify common misconceptions, including licensing fears, machine-readable requirements, and the role of static testing tools.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">bae992aa-b4c5-4642-9e5c-ff1bfc002439</guid><itunes:image href="https://artwork.captivate.fm/087633d3-3519-4ed3-9723-82d4540ebbd9/MDC-53-Cover-min.jpg"/><pubDate>Tue, 06 Jan 2026 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/bae992aa-b4c5-4642-9e5c-ff1bfc002439.mp3" length="55853899" type="audio/mpeg"/><itunes:duration>29:02</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>53</itunes:episode><podcast:episode>53</podcast:episode><podcast:season>1</podcast:season></item><item><title>When Medical Device Cyber Failures Become Fatal</title><itunes:title>When Medical Device Cyber Failures Become Fatal</itunes:title><description><![CDATA[<p>What past ransomware and medical device incidents might reveal gaps that manufacturers are still overlooking today?</p><p>In this episode, Christian and Trevor examine real incidents where cybersecurity failures, software flaws, and insecure medical devices led to patient harm and death. They break down how ransomware attacks, implantable device vulnerabilities, and AI-driven therapies expose life-critical risks in healthcare. The conversation highlights why regulators are increasing scrutiny and why cybersecurity must be treated as a patient-safety imperative, not an afterthought.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>What past ransomware and medical device incidents might reveal gaps that manufacturers are still overlooking today?</p><p>In this episode, Christian and Trevor examine real incidents where cybersecurity failures, software flaws, and insecure medical devices led to patient harm and death. They break down how ransomware attacks, implantable device vulnerabilities, and AI-driven therapies expose life-critical risks in healthcare. The conversation highlights why regulators are increasing scrutiny and why cybersecurity must be treated as a patient-safety imperative, not an afterthought.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">ca174f93-ba64-4d7f-a713-f993b2e42924</guid><itunes:image href="https://artwork.captivate.fm/71559296-ba12-4ca2-8828-4ef882c296d8/MDC-52-Cover-min.jpg"/><pubDate>Tue, 30 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/ca174f93-ba64-4d7f-a713-f993b2e42924.mp3" length="48004166" type="audio/mpeg"/><itunes:duration>24:58</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>52</itunes:episode><podcast:episode>52</podcast:episode><podcast:season>1</podcast:season></item><item><title>Trevor Slattery Answers Tough Medical Device Cyber Questions</title><itunes:title>Trevor Slattery Answers Tough Medical Device Cyber Questions</itunes:title><description><![CDATA[<p>This episode puts Trevor in the hot seat. If you were put in the hot seat, could you clearly explain cybersecurity, safety, and lifecycle terms like Trevor?</p><p>In this rapid-fire episode, Christian fires questions at Trevor about essential medical device cybersecurity concepts and standards. Together, they clarify how risk management, secure development, and lifecycle thinking intersect across safety, quality, and security.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>This episode puts Trevor in the hot seat. If you were put in the hot seat, could you clearly explain cybersecurity, safety, and lifecycle terms like Trevor?</p><p>In this rapid-fire episode, Christian fires questions at Trevor about essential medical device cybersecurity concepts and standards. Together, they clarify how risk management, secure development, and lifecycle thinking intersect across safety, quality, and security.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">152f0e79-b729-4b9b-81ff-cc65ffd0e5c1</guid><itunes:image href="https://artwork.captivate.fm/6963ab40-11f3-4a4c-a964-8e6d0ea6c89b/MDC-51-Cover-min.jpg"/><pubDate>Tue, 23 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/152f0e79-b729-4b9b-81ff-cc65ffd0e5c1.mp3" length="44580707" type="audio/mpeg"/><itunes:duration>23:10</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>51</itunes:episode><podcast:episode>51</podcast:episode><podcast:season>1</podcast:season></item><item><title>The Differences Between Black, Grey, and White Penetration Testing</title><itunes:title>The Differences Between Black, Grey, and White Penetration Testing</itunes:title><description><![CDATA[<p>MedTech developers, do you know which penetration testing methodology the FDA actually prefers for medical device submissions?</p><p>In this episode, Christian and Trevor explain the differences between black, grey, and white box penetration testing and how each impacts the completeness and realism of cybersecurity assessments. They highlight why regulators increasingly expect deeper testing supported by source-code-level insights. They also outline the risks, costs, and delays manufacturers face when choosing insufficient testing approaches during FDA submission.</p><p>Key points:</p><p>(01:25) Learn how black box testing mimics an attacker with no prior knowledge.</p><p>(06:27) How grey box testing blends limited credentials, architecture insight, and direct communication with engineers to expand visibility.</p><p>(08:29) Why white box testing includes access to full documentation, processes, and source code.</p><p>(10:20) How attacker timeframes differ from tester timeframes.</p><p>(11:29) How the FDA’s static analysis, SBOM, and risk evaluation requirements tie naturally into white box testing workflows.</p><p>(15:06) Learn why choosing black box testing to save money often results in higher total costs after FDA rejection.</p><p>(17:47) Hear why “buy once, cry once” applies to penetration testing.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>MedTech developers, do you know which penetration testing methodology the FDA actually prefers for medical device submissions?</p><p>In this episode, Christian and Trevor explain the differences between black, grey, and white box penetration testing and how each impacts the completeness and realism of cybersecurity assessments. They highlight why regulators increasingly expect deeper testing supported by source-code-level insights. They also outline the risks, costs, and delays manufacturers face when choosing insufficient testing approaches during FDA submission.</p><p>Key points:</p><p>(01:25) Learn how black box testing mimics an attacker with no prior knowledge.</p><p>(06:27) How grey box testing blends limited credentials, architecture insight, and direct communication with engineers to expand visibility.</p><p>(08:29) Why white box testing includes access to full documentation, processes, and source code.</p><p>(10:20) How attacker timeframes differ from tester timeframes.</p><p>(11:29) How the FDA’s static analysis, SBOM, and risk evaluation requirements tie naturally into white box testing workflows.</p><p>(15:06) Learn why choosing black box testing to save money often results in higher total costs after FDA rejection.</p><p>(17:47) Hear why “buy once, cry once” applies to penetration testing.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">a369d03c-929d-4923-9287-19ca97e21207</guid><itunes:image href="https://artwork.captivate.fm/588ead77-2fa6-449c-8392-52c16df2be26/MDC-50-Cover-min.jpg"/><pubDate>Tue, 16 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/a369d03c-929d-4923-9287-19ca97e21207.mp3" length="38737524" type="audio/mpeg"/><itunes:duration>20:09</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>50</itunes:episode><podcast:episode>50</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-e3d3fb91-d858-4d95-98f9-ae0671360ff4.json" type="application/json+chapters"/></item><item><title>How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller</title><itunes:title>How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller</itunes:title><description><![CDATA[<p>What risks do you take when cybersecurity is left off your development roadmap?</p><p>In this episode, Christian, Trevor and guest Jim Goodmiller explore how cybersecurity intersects with regulatory expectations and quality systems, creating new challenges and opportunities for medtech innovators. Jim helps to explain why founders must integrate cybersecurity from concept through commercialization, especially as FDA scrutiny increases.</p><p>Key points: </p><p>00:48 Why cybersecurity now influences every part of the regulatory landscape.</p><p>04:48 How technologies can create serious safety and compliance risks when not fully vetted.</p><p>10:45 Cybersecurity as a mandatory component of regulatory planning.</p><p>14:52 The need for iterative penetration testing </p><p>22:16 Challenges of upgrading legacy devices</p><p>25:37 Avoiding serious legal consequences.</p><p>29:29 Preparing a complete roadmap for investor confidence </p><p>40:08 The role of communication</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Jim Goodmiller for being on the show. </p><p><br></p><p>Connect with Jim on LinkedIn: <a href="https://www.linkedin.com/in/jimgoodmiller/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/jimgoodmiller/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>What risks do you take when cybersecurity is left off your development roadmap?</p><p>In this episode, Christian, Trevor and guest Jim Goodmiller explore how cybersecurity intersects with regulatory expectations and quality systems, creating new challenges and opportunities for medtech innovators. Jim helps to explain why founders must integrate cybersecurity from concept through commercialization, especially as FDA scrutiny increases.</p><p>Key points: </p><p>00:48 Why cybersecurity now influences every part of the regulatory landscape.</p><p>04:48 How technologies can create serious safety and compliance risks when not fully vetted.</p><p>10:45 Cybersecurity as a mandatory component of regulatory planning.</p><p>14:52 The need for iterative penetration testing </p><p>22:16 Challenges of upgrading legacy devices</p><p>25:37 Avoiding serious legal consequences.</p><p>29:29 Preparing a complete roadmap for investor confidence </p><p>40:08 The role of communication</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Jim Goodmiller for being on the show. </p><p><br></p><p>Connect with Jim on LinkedIn: <a href="https://www.linkedin.com/in/jimgoodmiller/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/jimgoodmiller/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">861d9c90-318a-428e-badf-32714e5ac354</guid><itunes:image href="https://artwork.captivate.fm/1505234c-0736-4d44-90df-1d17883fbb0b/Christian-Espinosa.jpg"/><pubDate>Tue, 09 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/861d9c90-318a-428e-badf-32714e5ac354.mp3" length="84767523" type="audio/mpeg"/><itunes:duration>45:00</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>49</itunes:episode><podcast:episode>49</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-cde97e81-b9ae-487a-9d2a-67c2453975c1.json" type="application/json+chapters"/></item><item><title>Webinar: Why FDA Cybersecurity Submissions Fail and How to Get Yours Approved</title><itunes:title>Webinar: Why FDA Cybersecurity Submissions Fail and How to Get Yours Approved</itunes:title><description><![CDATA[<p>Medtech innovators and medical device manufacturers, how can you prevent cybersecurity deficiencies from delaying your FDA submission?</p><p>In this webinar, Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, reveal the most common reasons FDA cybersecurity submissions fail and how you can avoid them. They explain the importance of early risk management, security-by-design practices, and comprehensive testing aligned with NIST and AAMI frameworks. </p><p>Explored in this webinar: </p><p><br></p><p>00:37 Why poor cybersecurity is a top reason for FDA medical device rejection.</p><p>02:56 The FDA’s total product lifecycle approach.</p><p>05:18 Why risk management must start before design. </p><p>07:35 How AAMI TR57 and ISO 14971 interact to assess patient harm. </p><p>10:51 The FDA requirement for traceability among functional, nonfunctional, and security requirements. </p><p>16:16 Why cybersecurity testing must cover the entire product (mobile, cloud, etc.).</p><p>23:33 Why inadequate documentation for critical controls (authentication, logging, encryption) often causes FDA deficiencies.</p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>Medtech innovators and medical device manufacturers, how can you prevent cybersecurity deficiencies from delaying your FDA submission?</p><p>In this webinar, Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, reveal the most common reasons FDA cybersecurity submissions fail and how you can avoid them. They explain the importance of early risk management, security-by-design practices, and comprehensive testing aligned with NIST and AAMI frameworks. </p><p>Explored in this webinar: </p><p><br></p><p>00:37 Why poor cybersecurity is a top reason for FDA medical device rejection.</p><p>02:56 The FDA’s total product lifecycle approach.</p><p>05:18 Why risk management must start before design. </p><p>07:35 How AAMI TR57 and ISO 14971 interact to assess patient harm. </p><p>10:51 The FDA requirement for traceability among functional, nonfunctional, and security requirements. </p><p>16:16 Why cybersecurity testing must cover the entire product (mobile, cloud, etc.).</p><p>23:33 Why inadequate documentation for critical controls (authentication, logging, encryption) often causes FDA deficiencies.</p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">87c46ab3-5cb6-446c-bc73-b890f907ea4e</guid><itunes:image href="https://artwork.captivate.fm/722b8535-2485-4b32-ae8b-cc198643be52/Webinar-11-Graphic.jpg"/><pubDate>Thu, 04 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/87c46ab3-5cb6-446c-bc73-b890f907ea4e.mp3" length="78597661" type="audio/mpeg"/><itunes:duration>40:52</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>Cybersecurity Qs MedTech Innovators Ask: Christian’s Hot Seat</title><itunes:title>Cybersecurity Qs MedTech Innovators Ask: Christian’s Hot Seat</itunes:title><description><![CDATA[<p>MedTech manufacturers, how can you avoid the cybersecurity pitfalls that most often lead to FDA rejection?</p><p>In this episode, Trevor puts Christian “in the hot seat” to tackle the most common—and sometimes misunderstood—cybersecurity questions MedTech innovators ask. Christian breaks down key concepts such as ISO 13485, HIPAA vs. FDA expectations, SAMD vs. SIMD, global regulatory demands, and more. </p><p>Key points: </p><p><br></p><p>(00:30) The purpose of ISO 13485 and why traceability, quality, and documentation are foundational to medical device safety.</p><p>(02:34) How cybersecurity is now the most common reason FDA reviewers reject medical devices.</p><p>(04:32) Why HIPAA focuses on patient data while the FDA focuses on patient safety.</p><p>(07:21) Which global regulators impose the strictest cybersecurity requirements and how FDA and China differ.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>MedTech manufacturers, how can you avoid the cybersecurity pitfalls that most often lead to FDA rejection?</p><p>In this episode, Trevor puts Christian “in the hot seat” to tackle the most common—and sometimes misunderstood—cybersecurity questions MedTech innovators ask. Christian breaks down key concepts such as ISO 13485, HIPAA vs. FDA expectations, SAMD vs. SIMD, global regulatory demands, and more. </p><p>Key points: </p><p><br></p><p>(00:30) The purpose of ISO 13485 and why traceability, quality, and documentation are foundational to medical device safety.</p><p>(02:34) How cybersecurity is now the most common reason FDA reviewers reject medical devices.</p><p>(04:32) Why HIPAA focuses on patient data while the FDA focuses on patient safety.</p><p>(07:21) Which global regulators impose the strictest cybersecurity requirements and how FDA and China differ.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">3d17102d-dc70-45fe-bdf6-f6d33cd085b1</guid><itunes:image href="https://artwork.captivate.fm/0e7ccab8-33c2-4ad6-8ba6-410c29465f56/MDC-48-Cover-min.jpg"/><pubDate>Tue, 02 Dec 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/3d17102d-dc70-45fe-bdf6-f6d33cd085b1.mp3" length="23987130" type="audio/mpeg"/><itunes:duration>12:27</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>48</itunes:episode><podcast:episode>48</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-a82448fa-3bca-4197-8fd5-f7236cc92db2.json" type="application/json+chapters"/></item><item><title>What Is Required for an FDA Pre-Market Cyber Submission?</title><itunes:title>What Is Required for an FDA Pre-Market Cyber Submission?</itunes:title><description><![CDATA[<p>What are the 18 required cybersecurity deliverables for a pre-market submission, and how do they map to eSTAR’s 13 sections? </p><p>This episode breaks down the cybersecurity deliverables required for an FDA pre-market submission and explains why they apply consistently across all device types. Christian and Trevor walk through each deliverable in detail, outline how they map to eSTAR v6.0, and highlight common misconceptions that slow down manufacturers. </p><p>Key points: </p><p><br></p><p>(00:33) Why all devices—high-risk or low-risk—must submit the same 18 cybersecurity deliverables to the FDA.</p><p>(01:41) How device complexity influences documentation depth even though the deliverables never change.</p><p>(04:42) How the 18 deliverables map to the 13 sections of eSTAR version 6.0. </p><p>(09:50) The risk management report, threat model, risk assessment, and SBOM requirements.</p><p>(17:41) How to evaluate and categorize unresolved anomalies.</p><p>(20:04) How manufacturers should track remediation timelines and vulnerability density.</p><p>(23:52) The cybersecurity management plan and the extensive post-market responsibilities expected by the FDA.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>What are the 18 required cybersecurity deliverables for a pre-market submission, and how do they map to eSTAR’s 13 sections? </p><p>This episode breaks down the cybersecurity deliverables required for an FDA pre-market submission and explains why they apply consistently across all device types. Christian and Trevor walk through each deliverable in detail, outline how they map to eSTAR v6.0, and highlight common misconceptions that slow down manufacturers. </p><p>Key points: </p><p><br></p><p>(00:33) Why all devices—high-risk or low-risk—must submit the same 18 cybersecurity deliverables to the FDA.</p><p>(01:41) How device complexity influences documentation depth even though the deliverables never change.</p><p>(04:42) How the 18 deliverables map to the 13 sections of eSTAR version 6.0. </p><p>(09:50) The risk management report, threat model, risk assessment, and SBOM requirements.</p><p>(17:41) How to evaluate and categorize unresolved anomalies.</p><p>(20:04) How manufacturers should track remediation timelines and vulnerability density.</p><p>(23:52) The cybersecurity management plan and the extensive post-market responsibilities expected by the FDA.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">594a35b2-8779-407a-aa17-8558dd04a351</guid><itunes:image href="https://artwork.captivate.fm/27d16a58-0b86-4893-8c28-8ec9d7239899/Webinar-Graphic.jpg"/><pubDate>Tue, 25 Nov 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/594a35b2-8779-407a-aa17-8558dd04a351.mp3" length="67642343" type="audio/mpeg"/><itunes:duration>35:11</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>47</itunes:episode><podcast:episode>47</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-4b2a2dc8-b981-4c56-b805-46ede7ba9c2e.json" type="application/json+chapters"/></item><item><title>Webinar: Postmarket Cybersecurity Management</title><itunes:title>Webinar: Postmarket Cybersecurity Management</itunes:title><description><![CDATA[<p>MedTech manufacturers, how prepared are you to monitor vulnerabilities continuously once your medical device reaches the market? Also, would you like a free checklist for your Cybersecurity Management Plan? (See link below!) </p><p>This webinar dives into how medical device manufacturers should build, maintain, and document postmarket cybersecurity programs that align with FDA expectations. Christian and Trevor outline critical requirements such as continuous SBOM monitoring, testing timelines, update processes, CVD workflows, and secure communication standards. </p><p>Topics explored: </p><p>(03:14) How the FDA's definition of "cyber device"  includes devices with Wi-Fi, Bluetooth, USB, RFID, and NFC connectivity.</p><p>(05:19) Recent FDA guidance changes, including updated cybersecurity expectations.</p><p>(10:30) Cybersecurity management plan personnel: compliance officer, product owner, postmarket owner, and authorizing official.</p><p>(12:30) Static testing, SBOM analysis, penetration testing, and vulnerability assessments. </p><p>(17:50) Security testing expectations and frequencies. </p><p>(20:30) Patching, update processes, and remediation timelines. </p><p><br></p><p>Download your free Cybersecurity Management Plan Checklist: <a href="https://bluegoatcyber.com/wp-content/uploads/2025/09/Blue-Goat-Cyber-Postmarket-Management-Checklist.pdf" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/wp-content/uploads/2025/09/Blue-Goat-Cyber-Postmarket-Management-Checklist.pdf</a> </p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>MedTech manufacturers, how prepared are you to monitor vulnerabilities continuously once your medical device reaches the market? Also, would you like a free checklist for your Cybersecurity Management Plan? (See link below!) </p><p>This webinar dives into how medical device manufacturers should build, maintain, and document postmarket cybersecurity programs that align with FDA expectations. Christian and Trevor outline critical requirements such as continuous SBOM monitoring, testing timelines, update processes, CVD workflows, and secure communication standards. </p><p>Topics explored: </p><p>(03:14) How the FDA's definition of "cyber device"  includes devices with Wi-Fi, Bluetooth, USB, RFID, and NFC connectivity.</p><p>(05:19) Recent FDA guidance changes, including updated cybersecurity expectations.</p><p>(10:30) Cybersecurity management plan personnel: compliance officer, product owner, postmarket owner, and authorizing official.</p><p>(12:30) Static testing, SBOM analysis, penetration testing, and vulnerability assessments. </p><p>(17:50) Security testing expectations and frequencies. </p><p>(20:30) Patching, update processes, and remediation timelines. </p><p><br></p><p>Download your free Cybersecurity Management Plan Checklist: <a href="https://bluegoatcyber.com/wp-content/uploads/2025/09/Blue-Goat-Cyber-Postmarket-Management-Checklist.pdf" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/wp-content/uploads/2025/09/Blue-Goat-Cyber-Postmarket-Management-Checklist.pdf</a> </p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">0f3409f7-83b6-4480-b39f-55b59ffb0a8d</guid><itunes:image href="https://artwork.captivate.fm/d3f9df34-8152-4284-a7fa-e744920df65a/Webinar-10-Graphic.jpg"/><pubDate>Thu, 20 Nov 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/0f3409f7-83b6-4480-b39f-55b59ffb0a8d.mp3" length="63839845" type="audio/mpeg"/><itunes:duration>33:12</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>How Market Intelligence Shapes MedTech Growth with Kevin Saem</title><itunes:title>How Market Intelligence Shapes MedTech Growth with Kevin Saem</itunes:title><description><![CDATA[<p>In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? </p><p>In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. </p><p>Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.</p><p><br></p><p>Key points: </p><p><br></p><p>(04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.</p><p><br></p><p>(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.</p><p><br></p><p>(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.</p><p><br></p><p>(12:00) How AI and connected devices are making cybersecurity a top concern for investors.</p><p><br></p><p>(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.</p><p><br></p><p>(26:30) How medtech founders can self-regulate.</p><p><br></p><p>(32:40) When companies should start building scalable sales systems. </p><p><br></p><p>Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevin-saem/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevin-saem/</a> </p><p><br></p><p>Learn about Zapyrus, a sales system for MedTech service providers: <a href="https://welcome.zapyrus.com/" rel="noopener noreferrer" target="_blank">https://welcome.zapyrus.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>This episode was produced by Story On Media: <a href="https://www.storyon.co/" rel="noopener noreferrer" target="_blank">https://www.storyon.co/</a> </p><p>In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? </p><p><br></p><p>In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. </p><p><br></p><p>Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.</p><p><br></p><p>Key points: </p><p><br></p><p>(04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.</p><p>(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.</p><p>(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.</p><p>(12:00) How AI and connected devices are making cybersecurity a top concern for investors.</p><p>(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.</p><p>(26:30) How medtech founders can self-regulate.</p><p>(32:40) When companies should start building scalable sales systems. </p><p><br></p><p>Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevin-saem/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevin-saem/</a> </p><p><br></p><p>Learn about Zapyrus, a sales system for MedTech service providers: <a href="https://welcome.zapyrus.com/" rel="noopener noreferrer" target="_blank">https://welcome.zapyrus.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer"...]]></description><content:encoded><![CDATA[<p>In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? </p><p>In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. </p><p>Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.</p><p><br></p><p>Key points: </p><p><br></p><p>(04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.</p><p><br></p><p>(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.</p><p><br></p><p>(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.</p><p><br></p><p>(12:00) How AI and connected devices are making cybersecurity a top concern for investors.</p><p><br></p><p>(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.</p><p><br></p><p>(26:30) How medtech founders can self-regulate.</p><p><br></p><p>(32:40) When companies should start building scalable sales systems. </p><p><br></p><p>Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevin-saem/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevin-saem/</a> </p><p><br></p><p>Learn about Zapyrus, a sales system for MedTech service providers: <a href="https://welcome.zapyrus.com/" rel="noopener noreferrer" target="_blank">https://welcome.zapyrus.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>This episode was produced by Story On Media: <a href="https://www.storyon.co/" rel="noopener noreferrer" target="_blank">https://www.storyon.co/</a> </p><p>In the MedTech space, how can you leverage market intelligence and machine learning for business development and sales enablement? </p><p><br></p><p>In this episode, Christian and Trevor talk with Kevin Saem about how market intelligence and cybersecurity intersect in the MedTech space. They unpack how AI and data-driven insights are transforming sales enablement, investor confidence, and device security. They also discuss regulation delays, startup runway challenges, and the growing need for proactive cybersecurity. </p><p><br></p><p>Kevin Saem founded Zapyrus, a SaaS platform that helps MedTech service providers supercharge sales through AI-driven market intelligence.</p><p><br></p><p>Key points: </p><p><br></p><p>(04:20) Why medtech lags five years behind pharma in regulation and sales sophistication.</p><p>(06:30) How Zapyrus uses machine learning to identify market signals and automate sales research.</p><p>(08:45) Why regulatory clarity in Europe is fueling more medtech investment than in the U.S.</p><p>(12:00) How AI and connected devices are making cybersecurity a top concern for investors.</p><p>(19:07) What the Illumina case and AI therapy failures reveal about industry accountability.</p><p>(26:30) How medtech founders can self-regulate.</p><p>(32:40) When companies should start building scalable sales systems. </p><p><br></p><p>Thanks to Kevin Saem for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevin-saem/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevin-saem/</a> </p><p><br></p><p>Learn about Zapyrus, a sales system for MedTech service providers: <a href="https://welcome.zapyrus.com/" rel="noopener noreferrer" target="_blank">https://welcome.zapyrus.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">41a82d9b-e62d-4ef3-8fd2-4d30b6568ee1</guid><itunes:image href="https://artwork.captivate.fm/78534b0c-f4ea-475b-8831-34ff3dc8e727/Webinar-Graphic.jpg"/><pubDate>Tue, 18 Nov 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/41a82d9b-e62d-4ef3-8fd2-4d30b6568ee1.mp3" length="86135982" type="audio/mpeg"/><itunes:duration>44:47</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>46</itunes:episode><podcast:episode>46</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-113eeb48-77df-4314-b8d3-bed8ff69e37d.json" type="application/json+chapters"/></item><item><title>Designing Secure Medical Device Software with Randy Horton</title><itunes:title>Designing Secure Medical Device Software with Randy Horton</itunes:title><description><![CDATA[<p>In medical device software development, why should cybersecurity be viewed as an element of product quality, not an add-on?</p><p>In this episode, Christian and Trevor speak with Randy Horton of Orthogonal about the future of medical device software development. Together, they unpack how DevSecOps, quality systems, and modern engineering practices can elevate safety and speed innovation in MedTech. From the philosophy behind “move faster and break nothing” to lessons learned from real-world cybersecurity cases, this conversation reframes how medical device teams should approach software design.</p><p>Randy Horton is the Chief Solutions Officer at Orthogonal, where he helps MedTech companies build better, safer, and smarter connected devices. A lifelong software innovator, Randy brings profound insight into what it takes to merge cutting-edge tech with the regulated world of healthcare.</p><p><br></p><p>Key points: </p><p><br></p><p>(03:00) Randy shares how discovering the first web browser set him on a lifelong path of innovation.</p><p>(05:11) Why high-quality software inherently includes cybersecurity.</p><p>(08:52) Why traditional engineering mindsets struggle with the flexibility of software development.</p><p>(12:42) How the “move fast” culture in Silicon Valley clashes with MedTech’s demand for control and safety.</p><p>(16:09) Why some manufacturers avoid updating medtech devices, and how that hurts long-term device security.</p><p>(19:49) Randy predicts that born-digital MedTech companies will lead the next wave of innovation, pushing the industry to adapt faster.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Randy Horton for being on the show. </p><p><br></p><p>Learn more about Orthogonal: <a href="https://orthogonal.io/" rel="noopener noreferrer" target="_blank">https://orthogonal.io/</a> </p><p>Connect with Randy on LinkedIn: <a href="https://www.linkedin.com/in/randyhorton" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/randyhorton</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>In medical device software development, why should cybersecurity be viewed as an element of product quality, not an add-on?</p><p>In this episode, Christian and Trevor speak with Randy Horton of Orthogonal about the future of medical device software development. Together, they unpack how DevSecOps, quality systems, and modern engineering practices can elevate safety and speed innovation in MedTech. From the philosophy behind “move faster and break nothing” to lessons learned from real-world cybersecurity cases, this conversation reframes how medical device teams should approach software design.</p><p>Randy Horton is the Chief Solutions Officer at Orthogonal, where he helps MedTech companies build better, safer, and smarter connected devices. A lifelong software innovator, Randy brings profound insight into what it takes to merge cutting-edge tech with the regulated world of healthcare.</p><p><br></p><p>Key points: </p><p><br></p><p>(03:00) Randy shares how discovering the first web browser set him on a lifelong path of innovation.</p><p>(05:11) Why high-quality software inherently includes cybersecurity.</p><p>(08:52) Why traditional engineering mindsets struggle with the flexibility of software development.</p><p>(12:42) How the “move fast” culture in Silicon Valley clashes with MedTech’s demand for control and safety.</p><p>(16:09) Why some manufacturers avoid updating medtech devices, and how that hurts long-term device security.</p><p>(19:49) Randy predicts that born-digital MedTech companies will lead the next wave of innovation, pushing the industry to adapt faster.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Randy Horton for being on the show. </p><p><br></p><p>Learn more about Orthogonal: <a href="https://orthogonal.io/" rel="noopener noreferrer" target="_blank">https://orthogonal.io/</a> </p><p>Connect with Randy on LinkedIn: <a href="https://www.linkedin.com/in/randyhorton" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/randyhorton</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">233b8341-adc7-4f23-80d8-3263f325f36e</guid><itunes:image href="https://artwork.captivate.fm/abdf11e3-10a1-473b-b1c7-17c7be5c58bc/MDC-45-Cover.jpg"/><pubDate>Tue, 11 Nov 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/233b8341-adc7-4f23-80d8-3263f325f36e.mp3" length="76335032" type="audio/mpeg"/><itunes:duration>39:41</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>45</itunes:episode><podcast:episode>45</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-151fc534-0aaf-44ac-83e4-294768664324.json" type="application/json+chapters"/></item><item><title>Cyber Risk Management for MedTech Legacy Devices</title><itunes:title>Cyber Risk Management for MedTech Legacy Devices</itunes:title><description><![CDATA[<p>What options do MedTech manufacturers have to bring older devices up to modern cybersecurity standards? Also, how does the FDA’s latest guidance change the process for updating legacy devices?</p><p>In this episode, Christian and Trevor break down the evolving challenges of managing cybersecurity for MedTech legacy devices. They explain how the FDA’s recent guidance updates create new pathways for handling older devices without requiring full redesigns. Together, they explore practical steps manufacturers can take—like penetration testing and postmarket monitoring—to stay compliant and proactive about security risks.</p><p>Key points: </p><p>(02:13) How the FDA defines legacy devices and why updates to older equipment pose unique challenges.</p><p>(03:47) Why simply replacing old devices isn’t realistic for many healthcare organizations.</p><p>(05:00) How encryption standards evolve and why older devices often can’t meet modern security expectations.</p><p>(06:25) The FDA’s distinction between controlled and uncontrolled risk. </p><p>(09:02) The FDA’s reduced burden pathway for legacy devices.</p><p>(11:07) Best practices for postmarket management plans. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>What options do MedTech manufacturers have to bring older devices up to modern cybersecurity standards? Also, how does the FDA’s latest guidance change the process for updating legacy devices?</p><p>In this episode, Christian and Trevor break down the evolving challenges of managing cybersecurity for MedTech legacy devices. They explain how the FDA’s recent guidance updates create new pathways for handling older devices without requiring full redesigns. Together, they explore practical steps manufacturers can take—like penetration testing and postmarket monitoring—to stay compliant and proactive about security risks.</p><p>Key points: </p><p>(02:13) How the FDA defines legacy devices and why updates to older equipment pose unique challenges.</p><p>(03:47) Why simply replacing old devices isn’t realistic for many healthcare organizations.</p><p>(05:00) How encryption standards evolve and why older devices often can’t meet modern security expectations.</p><p>(06:25) The FDA’s distinction between controlled and uncontrolled risk. </p><p>(09:02) The FDA’s reduced burden pathway for legacy devices.</p><p>(11:07) Best practices for postmarket management plans. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">350840a3-4f13-4cb9-93dd-2864ca12bad7</guid><itunes:image href="https://artwork.captivate.fm/ab518081-bcbf-4cb6-a438-d108a9fcdf83/MDC-44-Cover-min.jpg"/><pubDate>Tue, 04 Nov 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/350840a3-4f13-4cb9-93dd-2864ca12bad7.mp3" length="37186036" type="audio/mpeg"/><itunes:duration>19:19</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>44</itunes:episode><podcast:episode>44</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-8ab3066f-8b93-498a-b764-beb471024bae.json" type="application/json+chapters"/></item><item><title>Webinar: Security Architecture Views: Protecting Medical Devices Through Strategic Design</title><itunes:title>Webinar: Security Architecture Views: Protecting Medical Devices Through Strategic Design</itunes:title><description><![CDATA[<p>How can security architecture views strengthen a medical device manufacturer’s FDA submissions?</p><p>This episode/webinar dives into the four critical security architecture views required by the FDA: global system, multi-patient harm, updatability and patchability, and secure use case views. Christian Espinosa and Trevor Slattery explain how each view strengthens product security while aligning with regulatory expectations. They also share practical strategies and examples, from cloud environments to physical updates, highlighting how proper documentation and foresight can mitigate real-world risks.</p><p>Highlights: </p><p>(01:19) Learn why the FDA requires four specific security architecture views and how they support threat modeling.</p><p>(03:10) Understand how integrating security into architecture views reflects secure coding and DevSecOps practices.</p><p>(04:15) Discover how global regulators beyond the FDA use similar documentation requirements.</p><p>(07:52) Explore why global system views must include both software and hardware components as well as data flows.</p><p>(11:02) The distinction between global system views and multi-patient harm views. </p><p>(14:36) Common vulnerabilities like hard-coded credentials that can lead to multi-patient harm.</p><p>(19:18) The risks of over-the-air updates versus physical updates for medical devices.</p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>How can security architecture views strengthen a medical device manufacturer’s FDA submissions?</p><p>This episode/webinar dives into the four critical security architecture views required by the FDA: global system, multi-patient harm, updatability and patchability, and secure use case views. Christian Espinosa and Trevor Slattery explain how each view strengthens product security while aligning with regulatory expectations. They also share practical strategies and examples, from cloud environments to physical updates, highlighting how proper documentation and foresight can mitigate real-world risks.</p><p>Highlights: </p><p>(01:19) Learn why the FDA requires four specific security architecture views and how they support threat modeling.</p><p>(03:10) Understand how integrating security into architecture views reflects secure coding and DevSecOps practices.</p><p>(04:15) Discover how global regulators beyond the FDA use similar documentation requirements.</p><p>(07:52) Explore why global system views must include both software and hardware components as well as data flows.</p><p>(11:02) The distinction between global system views and multi-patient harm views. </p><p>(14:36) Common vulnerabilities like hard-coded credentials that can lead to multi-patient harm.</p><p>(19:18) The risks of over-the-air updates versus physical updates for medical devices.</p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">08a3517d-e769-46cf-a44d-684bec5eca95</guid><itunes:image href="https://artwork.captivate.fm/b010c22c-178f-4db1-840b-d7d1217a97e1/Webinar-9-Graphic.jpg"/><pubDate>Thu, 30 Oct 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/08a3517d-e769-46cf-a44d-684bec5eca95.mp3" length="81318013" type="audio/mpeg"/><itunes:duration>42:19</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><podcast:chapters url="https://transcripts.captivate.fm/chapter-689ffb80-5771-4956-bd71-6ac5c91e71e9.json" type="application/json+chapters"/></item><item><title>Why AI Literacy Matters for the Future of Healthcare with José Acosta</title><itunes:title>Why AI Literacy Matters for the Future of Healthcare with José Acosta</itunes:title><description><![CDATA[<p>How can AI literacy reduce patient risk in healthcare settings? </p><p>In this episode, Christian Espinosa and Trevor Slattery are joined by Dr. José Acosta. Together, they unpack the promise and pitfalls of artificial intelligence in healthcare—from the accuracy gap in diagnostics to the importance of ethics, alignment, and training. The conversation explores how clinicians can harness AI safely, ensuring innovation never comes at the cost of patient trust or care quality.</p><p>Dr. José Acosta is a retired Navy trauma surgeon turned AI literacy advocate. With decades of experience in medicine and leadership, he’s now helping clinicians understand AI—from how it works to how it should be used responsibly.</p><p>Key points: </p><p><br></p><p>(00:57) José’s background as a Navy trauma surgeon and his passion for AI literacy.</p><p>(02:53) What “AI literacy” really means. </p><p>(05:00) Why precision matters in medicine, and why 85–95% accuracy in AI models isn’t enough when lives are on the line.</p><p>(11:20) A chilling example of an AI therapy app that gave a fatal recommendation. </p><p>(14:16) José predicts a surge in “ambient AI scribes” and explains how they’ll reshape physician workflows. </p><p>(17:53) AI’s productivity paradox—how new tools can both help and overwhelm clinicians.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to José Acosta for being on the show. Connect with José on LinkedIn: <a href="https://www.linkedin.com/in/joseacostasd/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/joseacostasd/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>How can AI literacy reduce patient risk in healthcare settings? </p><p>In this episode, Christian Espinosa and Trevor Slattery are joined by Dr. José Acosta. Together, they unpack the promise and pitfalls of artificial intelligence in healthcare—from the accuracy gap in diagnostics to the importance of ethics, alignment, and training. The conversation explores how clinicians can harness AI safely, ensuring innovation never comes at the cost of patient trust or care quality.</p><p>Dr. José Acosta is a retired Navy trauma surgeon turned AI literacy advocate. With decades of experience in medicine and leadership, he’s now helping clinicians understand AI—from how it works to how it should be used responsibly.</p><p>Key points: </p><p><br></p><p>(00:57) José’s background as a Navy trauma surgeon and his passion for AI literacy.</p><p>(02:53) What “AI literacy” really means. </p><p>(05:00) Why precision matters in medicine, and why 85–95% accuracy in AI models isn’t enough when lives are on the line.</p><p>(11:20) A chilling example of an AI therapy app that gave a fatal recommendation. </p><p>(14:16) José predicts a surge in “ambient AI scribes” and explains how they’ll reshape physician workflows. </p><p>(17:53) AI’s productivity paradox—how new tools can both help and overwhelm clinicians.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to José Acosta for being on the show. Connect with José on LinkedIn: <a href="https://www.linkedin.com/in/joseacostasd/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/joseacostasd/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">c5a42109-8ec7-4f18-839d-95120012ee92</guid><itunes:image href="https://artwork.captivate.fm/e791b7c2-c140-47ce-87d0-c71a08f8e1fb/MDC-43-Cover.jpg"/><pubDate>Tue, 28 Oct 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/c5a42109-8ec7-4f18-839d-95120012ee92.mp3" length="71068962" type="audio/mpeg"/><itunes:duration>36:58</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>43</itunes:episode><podcast:episode>43</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-960ca405-aaf1-466c-aa60-6481f572acd2.json" type="application/json+chapters"/></item><item><title>What Is A Medical Device?</title><itunes:title>What Is A Medical Device?</itunes:title><description><![CDATA[<p>MedTech developers and manufacturers, could your medical device unknowingly qualify as a “cyber device”?</p><p>In this episode, Christian and Trevor break down what the FDA considers a “cyber device” and why so many manufacturers misunderstand this definition. They reveal how even basic interfaces like USB, HDMI, or Bluetooth can make a device cyber-enabled—and why that matters for regulatory compliance.</p><p>Key points:</p><p>(00:33) What makes a medical device a “cyber device,” and why confusion persists among manufacturers.</p><p>(02:14) How proving a device has zero vulnerabilities is nearly impossible, even with minimal code.</p><p>(03:12) Why even a simple USB port can classify a device as “cyber.”</p><p>(05:05) Common interfaces (Wi-Fi, Bluetooth, RFID, NFC, HDMI) that make a device cyber-enabled.</p><p>(09:23) Implantable devices, like pacemakers, and how protocols such as MedRadio introduce hidden connectivity.</p><p>(12:20) A real case where the FDA classified a 3D-printing system as a cyber device due to its software dependencies.</p><p>(16:15) Practical advice on removing unnecessary ports or connectivity to avoid cyber classification.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></description><content:encoded><![CDATA[<p>MedTech developers and manufacturers, could your medical device unknowingly qualify as a “cyber device”?</p><p>In this episode, Christian and Trevor break down what the FDA considers a “cyber device” and why so many manufacturers misunderstand this definition. They reveal how even basic interfaces like USB, HDMI, or Bluetooth can make a device cyber-enabled—and why that matters for regulatory compliance.</p><p>Key points:</p><p>(00:33) What makes a medical device a “cyber device,” and why confusion persists among manufacturers.</p><p>(02:14) How proving a device has zero vulnerabilities is nearly impossible, even with minimal code.</p><p>(03:12) Why even a simple USB port can classify a device as “cyber.”</p><p>(05:05) Common interfaces (Wi-Fi, Bluetooth, RFID, NFC, HDMI) that make a device cyber-enabled.</p><p>(09:23) Implantable devices, like pacemakers, and how protocols such as MedRadio introduce hidden connectivity.</p><p>(12:20) A real case where the FDA classified a 3D-printing system as a cyber device due to its software dependencies.</p><p>(16:15) Practical advice on removing unnecessary ports or connectivity to avoid cyber classification.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">b98a99bd-c136-43f8-bd82-b108b01e7ee4</guid><itunes:image href="https://artwork.captivate.fm/d70ed473-774d-49e3-8877-25ffbd42adc8/Webinar-Graphic.jpg"/><pubDate>Tue, 21 Oct 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/b98a99bd-c136-43f8-bd82-b108b01e7ee4.mp3" length="38745992" type="audio/mpeg"/><itunes:duration>20:09</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>42</itunes:episode><podcast:episode>42</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-31d6ad16-044b-440c-8c39-9f06bea8869f.json" type="application/json+chapters"/></item><item><title>5 Most Common Misconceptions of Medical Device Security</title><itunes:title>5 Most Common Misconceptions of Medical Device Security</itunes:title><description><![CDATA[<p>In this episode, Christian and Trevor unpack the five most common misconceptions that put medical device manufacturers at risk. From confusing data protection with patient safety to misunderstanding what qualifies as a cyber device, the hosts shed light on the blind spots that cause costly delays and compliance failures. They also explore how medical device cybersecurity differs fundamentally from traditional cybersecurity, emphasizing the need for specialized expertise and early integration of secure design principles.</p><p>Key points: </p><p>(01:18) Misconception #1: That cybersecurity is only about protecting data rather than patient safety.</p><p>(06:04) Misconception #2: That your product isn’t a “cyber device.” </p><p>(07:46) Misconception #3: That cybersecurity is a one-time thing to study rather than a full lifecycle process.</p><p>(12:17) Misconception #4: That software developers inherently understand cybersecurity.</p><p>(19:10) Misconception #5: Thinking that traditional cybersecurity and medical device cybersecurity are the same. </p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>In this episode, Christian and Trevor unpack the five most common misconceptions that put medical device manufacturers at risk. From confusing data protection with patient safety to misunderstanding what qualifies as a cyber device, the hosts shed light on the blind spots that cause costly delays and compliance failures. They also explore how medical device cybersecurity differs fundamentally from traditional cybersecurity, emphasizing the need for specialized expertise and early integration of secure design principles.</p><p>Key points: </p><p>(01:18) Misconception #1: That cybersecurity is only about protecting data rather than patient safety.</p><p>(06:04) Misconception #2: That your product isn’t a “cyber device.” </p><p>(07:46) Misconception #3: That cybersecurity is a one-time thing to study rather than a full lifecycle process.</p><p>(12:17) Misconception #4: That software developers inherently understand cybersecurity.</p><p>(19:10) Misconception #5: Thinking that traditional cybersecurity and medical device cybersecurity are the same. </p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">f348fed4-0bab-4eb1-855e-d8a82781a7a6</guid><itunes:image href="https://artwork.captivate.fm/b9cf99ba-3fed-40f9-8b57-14c3461f702c/Webinar-Graphic-1.jpg"/><pubDate>Tue, 14 Oct 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/f348fed4-0bab-4eb1-855e-d8a82781a7a6.mp3" length="49743561" type="audio/mpeg"/><itunes:duration>25:52</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>41</itunes:episode><podcast:episode>41</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-12e5243a-d53d-4471-a908-136af8c8ccf3.json" type="application/json+chapters"/></item><item><title>What Happens When AI in Medical Devices Make Mistakes?</title><itunes:title>What Happens When AI in Medical Devices Make Mistakes?</itunes:title><description><![CDATA[<p>MedTech manufacturers and developers, what happens if your AI-powered medical device makes a terrible, life-threatening mistake?</p><p>This episode explores what happens when artificial intelligence in medical devices goes wrong. Christian Espinosa and Trevor Slattery break down the real-world consequences of AI failure, using a tragic mental health chatbot case to highlight the stakes of inadequate oversight. They also examine the EU AI Act, new MDCG guidance, and the ethical, regulatory, and cybersecurity challenges facing innovators in the high-risk medical AI space.</p><p>Key points: </p><p>(03:02) The EU AI Act and how it intersects with the MDR and IVDR.</p><p>(03:55) A real case study involving a suicidal patient and an AI mental health chatbot.</p><p>(06:07) How general-purpose AI tools differ from regulated medical AI.</p><p>(09:57) Why threat modeling should apply to AI systems.</p><p>(12:16) Ethical decision-making in autonomous systems using self-driving car analogies.</p><p>(14:02) The Medical Device Coordination Group’s guidance on aligning the AI Act with EU medical device regulations.</p><p>(17:10) Shared accountability across regulators, manufacturers, and users for AI oversight.</p><p>(18:35) The U.S. still treats AI as a “Wild West” compared to the EU’s stricter approach.</p><p>(22:42) Regulators aren’t asking if your AI works—they’re asking how it fails.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></description><content:encoded><![CDATA[<p>MedTech manufacturers and developers, what happens if your AI-powered medical device makes a terrible, life-threatening mistake?</p><p>This episode explores what happens when artificial intelligence in medical devices goes wrong. Christian Espinosa and Trevor Slattery break down the real-world consequences of AI failure, using a tragic mental health chatbot case to highlight the stakes of inadequate oversight. They also examine the EU AI Act, new MDCG guidance, and the ethical, regulatory, and cybersecurity challenges facing innovators in the high-risk medical AI space.</p><p>Key points: </p><p>(03:02) The EU AI Act and how it intersects with the MDR and IVDR.</p><p>(03:55) A real case study involving a suicidal patient and an AI mental health chatbot.</p><p>(06:07) How general-purpose AI tools differ from regulated medical AI.</p><p>(09:57) Why threat modeling should apply to AI systems.</p><p>(12:16) Ethical decision-making in autonomous systems using self-driving car analogies.</p><p>(14:02) The Medical Device Coordination Group’s guidance on aligning the AI Act with EU medical device regulations.</p><p>(17:10) Shared accountability across regulators, manufacturers, and users for AI oversight.</p><p>(18:35) The U.S. still treats AI as a “Wild West” compared to the EU’s stricter approach.</p><p>(22:42) Regulators aren’t asking if your AI works—they’re asking how it fails.</p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">34820b88-6e89-485b-858b-56b4d7acfd6a</guid><itunes:image href="https://artwork.captivate.fm/4993ea94-ad14-4b59-a085-97248f039755/With-Daniel-Harty.jpg"/><pubDate>Tue, 07 Oct 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/34820b88-6e89-485b-858b-56b4d7acfd6a.mp3" length="47298448" type="audio/mpeg"/><itunes:duration>24:36</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>40</itunes:episode><podcast:episode>40</podcast:episode><podcast:season>1</podcast:season></item><item><title>Medical Device Startups and Cybersecurity Challenges with Suzy Engwall</title><itunes:title>Medical Device Startups and Cybersecurity Challenges with Suzy Engwall</itunes:title><description><![CDATA[<p>What are some of the greatest challenges medical device startups face when bringing their products to market?</p><p>This episode features Suzy Engwall, a healthcare innovation consultant with experience mentoring startups and guiding hospitals. She joins Christian Espinosa and Trevor Slattery to discuss the hidden roadblocks medical device innovators face—from funding gaps to internal hospital politics to overlooked cybersecurity. Together they unpack the realities of FDA compliance, AI-driven decision support, and why raising cybersecurity awareness early can mean the difference between market success and failure.</p><p>Suzy Engwall is a healthcare innovation leader who’s spent the last 20 years shaking up hospitals and mentoring startups. She runs HealthTech Strategies, where she helps founders, investors, and clinicians bridge the gap between big ideas and practical adoption.</p><p>Key points: </p><p><br></p><p>(04:38) Challenges medtech startups face include funding, go-to-market strategy, and regulatory hurdles, with cybersecurity often overlooked.</p><p>(05:56) Why 93% of med tech startups fail. </p><p>(08:01) How internal politics within hospitals can derail promising innovations.</p><p>(09:32) Hospitals now scrutinize devices for cybersecurity risk beyond FDA approval, raising the bar for manufacturers.</p><p>(12:19) Legacy devices often fail modern cybersecurity requirements, forcing redesigns and frustrating manufacturers.</p><p>(16:43) AI in diagnostics: who’s responsible when mistakes occur?</p><p>(23:24) Why patients rarely question medical devices. </p><p>(31:28) Why cybersecurity is often the last thing innovators ask about—and why that mindset must change.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Suzy Engwall for being on the show. Connect with Suzy on LinkedIn: <a href="https://www.linkedin.com/in/sengwall" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/sengwall</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are some of the greatest challenges medical device startups face when bringing their products to market?</p><p>This episode features Suzy Engwall, a healthcare innovation consultant with experience mentoring startups and guiding hospitals. She joins Christian Espinosa and Trevor Slattery to discuss the hidden roadblocks medical device innovators face—from funding gaps to internal hospital politics to overlooked cybersecurity. Together they unpack the realities of FDA compliance, AI-driven decision support, and why raising cybersecurity awareness early can mean the difference between market success and failure.</p><p>Suzy Engwall is a healthcare innovation leader who’s spent the last 20 years shaking up hospitals and mentoring startups. She runs HealthTech Strategies, where she helps founders, investors, and clinicians bridge the gap between big ideas and practical adoption.</p><p>Key points: </p><p><br></p><p>(04:38) Challenges medtech startups face include funding, go-to-market strategy, and regulatory hurdles, with cybersecurity often overlooked.</p><p>(05:56) Why 93% of med tech startups fail. </p><p>(08:01) How internal politics within hospitals can derail promising innovations.</p><p>(09:32) Hospitals now scrutinize devices for cybersecurity risk beyond FDA approval, raising the bar for manufacturers.</p><p>(12:19) Legacy devices often fail modern cybersecurity requirements, forcing redesigns and frustrating manufacturers.</p><p>(16:43) AI in diagnostics: who’s responsible when mistakes occur?</p><p>(23:24) Why patients rarely question medical devices. </p><p>(31:28) Why cybersecurity is often the last thing innovators ask about—and why that mindset must change.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cybercriminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Suzy Engwall for being on the show. Connect with Suzy on LinkedIn: <a href="https://www.linkedin.com/in/sengwall" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/sengwall</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">66a3502f-2680-40d6-bf6d-98f2efdb365b</guid><itunes:image href="https://artwork.captivate.fm/65732552-14f6-42c9-9765-301d5954cbf3/Suzy-Engwall.jpg"/><pubDate>Tue, 30 Sep 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/66a3502f-2680-40d6-bf6d-98f2efdb365b.mp3" length="88519480" type="audio/mpeg"/><itunes:duration>46:03</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>39</itunes:episode><podcast:episode>39</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-2681b9a2-ca35-45af-af79-5a4019f8fdf1.json" type="application/json+chapters"/></item><item><title>Top 10 Medical Device Vulnerabilities with Myles Kellerman</title><itunes:title>Top 10 Medical Device Vulnerabilities with Myles Kellerman</itunes:title><description><![CDATA[<p>How safe are the medical devices I rely on, and what are the biggest cybersecurity risks I should know about?</p><p>In this episode, the team goes behind the scenes of real-world medical device penetration testing to reveal the 10 most common and dangerous cybersecurity vulnerabilities found in medical devices. The discussion covers practical examples, industry standards, and actionable advice for manufacturers and healthcare organizations.</p><p>Key points: </p><p><br></p><p>(0:00) Introduction &amp; Penetration Testing Context</p><p><br></p><p>(1:29) Why Penetration Testing Matters in MedTech</p><p><br></p><p>(5:50) Top 10 Medical Device Vulnerabilities:</p><p>1. Hardcoded/Default Credentials – Default passwords, BIOS passwords, and supply chain issues.</p><p>2. Unsecured Communication Channels – Lack of encryption, outdated standards, key management, and device constraints.</p><p>3. Outdated/Vulnerable Third-Party Components – Software Bill of Materials (SBOM), continuous monitoring, and post-market risks.</p><p>4. Improper Access Control – Weak authentication, privilege escalation, and user data exposure.</p><p>5. Debug Interfaces Left Enabled – JTAG/UART ports, physical access, and mitigation strategies.</p><p>6. Missing/Weak Firmware Integrity Checks – Secure boot, code signing, and white-box testing.</p><p>7. Poor Session Management – Session timeouts and session hijacking.</p><p>8. Fuzzing Vulnerabilities (Buffer Overflows) – Fuzz testing, buffer overflows, and legacy devices.</p><p>9. Lack of Tamper Detection – Audit trails, tamper-evident stickers, and physical controls.</p><p>10. No Rate Limiting/Automation Controls – Brute-force attacks, automation, and rate limiting.</p><p><br></p><p>(37:26) Secure Product Development Frameworks, and DevSecOps.</p><p><br></p><p>(38:04) Regulatory Perspective.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Myles Kellerman for being on the show. Connect with Myles on LinkedIn: <a href="https://www.linkedin.com/in/myles-kellerman-5763aa22" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/myles-kellerman-5763aa22</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How safe are the medical devices I rely on, and what are the biggest cybersecurity risks I should know about?</p><p>In this episode, the team goes behind the scenes of real-world medical device penetration testing to reveal the 10 most common and dangerous cybersecurity vulnerabilities found in medical devices. The discussion covers practical examples, industry standards, and actionable advice for manufacturers and healthcare organizations.</p><p>Key points: </p><p><br></p><p>(0:00) Introduction &amp; Penetration Testing Context</p><p><br></p><p>(1:29) Why Penetration Testing Matters in MedTech</p><p><br></p><p>(5:50) Top 10 Medical Device Vulnerabilities:</p><p>1. Hardcoded/Default Credentials – Default passwords, BIOS passwords, and supply chain issues.</p><p>2. Unsecured Communication Channels – Lack of encryption, outdated standards, key management, and device constraints.</p><p>3. Outdated/Vulnerable Third-Party Components – Software Bill of Materials (SBOM), continuous monitoring, and post-market risks.</p><p>4. Improper Access Control – Weak authentication, privilege escalation, and user data exposure.</p><p>5. Debug Interfaces Left Enabled – JTAG/UART ports, physical access, and mitigation strategies.</p><p>6. Missing/Weak Firmware Integrity Checks – Secure boot, code signing, and white-box testing.</p><p>7. Poor Session Management – Session timeouts and session hijacking.</p><p>8. Fuzzing Vulnerabilities (Buffer Overflows) – Fuzz testing, buffer overflows, and legacy devices.</p><p>9. Lack of Tamper Detection – Audit trails, tamper-evident stickers, and physical controls.</p><p>10. No Rate Limiting/Automation Controls – Brute-force attacks, automation, and rate limiting.</p><p><br></p><p>(37:26) Secure Product Development Frameworks, and DevSecOps.</p><p><br></p><p>(38:04) Regulatory Perspective.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Myles Kellerman for being on the show. Connect with Myles on LinkedIn: <a href="https://www.linkedin.com/in/myles-kellerman-5763aa22" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/myles-kellerman-5763aa22</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">4c160ec3-4e7c-4bd8-9f52-0d4d7c4814ec</guid><itunes:image href="https://artwork.captivate.fm/f117ab8a-4484-4b5e-9bb4-60d665cd4870/Quote-Graphic.jpg"/><pubDate>Tue, 23 Sep 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/4c160ec3-4e7c-4bd8-9f52-0d4d7c4814ec.mp3" length="75948330" type="audio/mpeg"/><itunes:duration>39:31</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>38</itunes:episode><podcast:episode>38</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-fd59e03d-08a4-40ef-b38e-fd29a45fee8a.json" type="application/json+chapters"/></item><item><title>Overcoming AI and Data Security Challenges in MedTech with May Lee</title><itunes:title>Overcoming AI and Data Security Challenges in MedTech with May Lee</itunes:title><description><![CDATA[<p>How can you prepare your device for future quantum computing risks?</p><p>In this episode of The Med Device Cyber Podcast, Christian and Trevor talk with May Lee of CS Life Sciences about the fast-changing world of medical device cybersecurity. They discuss the growing regulatory demands from the FDA, EU, and China, and why cybersecurity can no longer be an afterthought in device design. The conversation also dives into quantum computing, supply chain risks, and how manufacturers can balance compliance with innovation.</p><p>May Lee is a medical device consultant at CS Life Sciences who specializes in AI, machine learning, and cybersecurity. With experience ranging from startups to global corporations, she brings a practical perspective on navigating regulations and helping innovators bring safer devices to market.</p><p><br></p><p>(03:21) Why cybersecurity is moving from afterthought to design control.</p><p>(05:49) Key takeaways from the FDA’s finalized cybersecurity guidance.</p><p>(08:04) Comparing U.S. FDA and EU MDR cybersecurity requirements.</p><p>(10:44) How quantum computing raises new risks for health data.</p><p>(16:26) The balance between compliance, over compliance, and innovation.</p><p>(18:23) Differences in regulatory approaches across the U.S., EU, and China.</p><p>(28:05) Why third-party supply chain and software components matter for device security.</p><p>(32:48) When medical device companies should engage cybersecurity consultants.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to May Lee for being on the show. Connect with May on LinkedIn: <a href="https://www.linkedin.com/in/may-lee-a1b16186/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/may-lee-a1b16186/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can you prepare your device for future quantum computing risks?</p><p>In this episode of The Med Device Cyber Podcast, Christian and Trevor talk with May Lee of CS Life Sciences about the fast-changing world of medical device cybersecurity. They discuss the growing regulatory demands from the FDA, EU, and China, and why cybersecurity can no longer be an afterthought in device design. The conversation also dives into quantum computing, supply chain risks, and how manufacturers can balance compliance with innovation.</p><p>May Lee is a medical device consultant at CS Life Sciences who specializes in AI, machine learning, and cybersecurity. With experience ranging from startups to global corporations, she brings a practical perspective on navigating regulations and helping innovators bring safer devices to market.</p><p><br></p><p>(03:21) Why cybersecurity is moving from afterthought to design control.</p><p>(05:49) Key takeaways from the FDA’s finalized cybersecurity guidance.</p><p>(08:04) Comparing U.S. FDA and EU MDR cybersecurity requirements.</p><p>(10:44) How quantum computing raises new risks for health data.</p><p>(16:26) The balance between compliance, over compliance, and innovation.</p><p>(18:23) Differences in regulatory approaches across the U.S., EU, and China.</p><p>(28:05) Why third-party supply chain and software components matter for device security.</p><p>(32:48) When medical device companies should engage cybersecurity consultants.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to May Lee for being on the show. Connect with May on LinkedIn: <a href="https://www.linkedin.com/in/may-lee-a1b16186/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/may-lee-a1b16186/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">9c696501-3046-45fd-aac6-ac37ec258bef</guid><itunes:image href="https://artwork.captivate.fm/7133f46b-d22f-4281-8fda-783dfae4fcc3/Pod-Thumbnail-SOLO.jpg"/><pubDate>Tue, 16 Sep 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/9c696501-3046-45fd-aac6-ac37ec258bef.mp3" length="75107137" type="audio/mpeg"/><itunes:duration>39:04</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>37</itunes:episode><podcast:episode>37</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-803aacd5-9282-4ab2-ba26-23d57bd99d95.json" type="application/json+chapters"/></item><item><title>When Cybersecurity Becomes a Crime</title><itunes:title>When Cybersecurity Becomes a Crime</itunes:title><description><![CDATA[<p>What happens when cybersecurity flaws in medical devices cross the line into criminal violations?</p><p>In this episode, Christian and Trevor unpack the groundbreaking case of Illumina, where cybersecurity misrepresentation led to Department of Justice enforcement. They explore how this signals a shift from technical risks to legal and patient safety consequences, highlighting the dangers of cutting corners in device development. The conversation also outlines practical lessons for manufacturers on integrating secure product development, anticipating FDA deficiencies, and aligning business functions with cybersecurity goals.</p><p>Key points: </p><p><br></p><p>(00:02) Misrepresenting cybersecurity controls in medical devices can lead to legal prosecution under the DOJ’s civil cyber fraud initiative.</p><p>(04:28) Regulatory enforcement is evolving beyond HIPAA into direct patient safety risks.</p><p>(06:05) Medical device cybersecurity differs from information privacy laws, especially with potential patient harm.</p><p>(08:30) The Illumina case involved a whistleblower, FDA oversight, and DOJ enforcement.</p><p>(10:54) Ignoring internal warnings about device vulnerabilities led to legal consequences.</p><p>(13:44) Security by design must be integrated early to avoid costly retrofits.</p><p>(16:46) Cybersecurity is recognized as a clinical risk tied to patient mortality.</p><p>(19:12) Manufacturers are adopting secure product development frameworks earlier in the lifecycle.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></description><content:encoded><![CDATA[<p>What happens when cybersecurity flaws in medical devices cross the line into criminal violations?</p><p>In this episode, Christian and Trevor unpack the groundbreaking case of Illumina, where cybersecurity misrepresentation led to Department of Justice enforcement. They explore how this signals a shift from technical risks to legal and patient safety consequences, highlighting the dangers of cutting corners in device development. The conversation also outlines practical lessons for manufacturers on integrating secure product development, anticipating FDA deficiencies, and aligning business functions with cybersecurity goals.</p><p>Key points: </p><p><br></p><p>(00:02) Misrepresenting cybersecurity controls in medical devices can lead to legal prosecution under the DOJ’s civil cyber fraud initiative.</p><p>(04:28) Regulatory enforcement is evolving beyond HIPAA into direct patient safety risks.</p><p>(06:05) Medical device cybersecurity differs from information privacy laws, especially with potential patient harm.</p><p>(08:30) The Illumina case involved a whistleblower, FDA oversight, and DOJ enforcement.</p><p>(10:54) Ignoring internal warnings about device vulnerabilities led to legal consequences.</p><p>(13:44) Security by design must be integrated early to avoid costly retrofits.</p><p>(16:46) Cybersecurity is recognized as a clinical risk tied to patient mortality.</p><p>(19:12) Manufacturers are adopting secure product development frameworks earlier in the lifecycle.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">ccbe630b-3e4a-4359-9318-a6f644078739</guid><itunes:image href="https://artwork.captivate.fm/98781c65-6a67-4e72-afd1-4e035e167cd7/MDC-36-Cover-min.jpg"/><pubDate>Tue, 09 Sep 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/ccbe630b-3e4a-4359-9318-a6f644078739.mp3" length="51209839" type="audio/mpeg"/><itunes:duration>26:38</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>36</itunes:episode><podcast:episode>36</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-47ec2add-0428-4bed-8e57-5aa1e37592ee.json" type="application/json+chapters"/></item><item><title>Balancing Innovation and Regulation in MedTech Development with Karandeep Singh Badwal</title><itunes:title>Balancing Innovation and Regulation in MedTech Development with Karandeep Singh Badwal</itunes:title><description><![CDATA[<p>How can medtech innovators balance speed with compliance in medical devices?</p><p>In this episode, Christian and Trevor sit down with Karandeep Singh Badwal about the challenges of balancing innovation with quality and regulatory compliance in medical devices, especially with the rise of AI and software-driven solutions. From cybersecurity gaps to the staggering startup failure rate, the conversation highlights why building quality and regulatory compliance into devices from the start is crucial for long-term success.</p><p>Karandeep is the founder of QRA Medical, where he helps medtech innovators navigate the maze of quality and regulatory requirements. He’s also the host of The MedTech Podcast and a LinkedIn creator who makes compliance topics easy to understand (and way less boring than the regulations themselves).</p><p><br></p><p>(3:30) AI, Software, and Cybersecurity Challenges</p><p>* Why artificial intelligence data validation remains immature and risky for medtech.</p><p>* How software versioning and outdated penetration testing complicate cybersecurity.</p><p><br></p><p>(9:45) Quality and Development Gaps</p><p>* Why some startups skip quality until it’s too late.</p><p>* The importance of adopting partial QMS early to ease transitions later.</p><p><br></p><p>(28:00) Startup Pitfalls and Failure Rates</p><p>* Why many medtech startups fail. </p><p>* The role of regulatory delays, poor planning, and market misalignment.</p><p><br></p><p>(30:00) Keys to Success </p><p>* What successful startups do differently.</p><p><br></p><p>Thanks to Karandeep Singh Badwal for being on the show: <a href="https://karandeepbadwal.com/" rel="noopener noreferrer" target="_blank">https://karandeepbadwal.com/</a> </p><p>Connect with Karandeep on LinkedIn: <a href="https://www.linkedin.com/in/karandeepbadwal/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/karandeepbadwal/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can medtech innovators balance speed with compliance in medical devices?</p><p>In this episode, Christian and Trevor sit down with Karandeep Singh Badwal about the challenges of balancing innovation with quality and regulatory compliance in medical devices, especially with the rise of AI and software-driven solutions. From cybersecurity gaps to the staggering startup failure rate, the conversation highlights why building quality and regulatory compliance into devices from the start is crucial for long-term success.</p><p>Karandeep is the founder of QRA Medical, where he helps medtech innovators navigate the maze of quality and regulatory requirements. He’s also the host of The MedTech Podcast and a LinkedIn creator who makes compliance topics easy to understand (and way less boring than the regulations themselves).</p><p><br></p><p>(3:30) AI, Software, and Cybersecurity Challenges</p><p>* Why artificial intelligence data validation remains immature and risky for medtech.</p><p>* How software versioning and outdated penetration testing complicate cybersecurity.</p><p><br></p><p>(9:45) Quality and Development Gaps</p><p>* Why some startups skip quality until it’s too late.</p><p>* The importance of adopting partial QMS early to ease transitions later.</p><p><br></p><p>(28:00) Startup Pitfalls and Failure Rates</p><p>* Why many medtech startups fail. </p><p>* The role of regulatory delays, poor planning, and market misalignment.</p><p><br></p><p>(30:00) Keys to Success </p><p>* What successful startups do differently.</p><p><br></p><p>Thanks to Karandeep Singh Badwal for being on the show: <a href="https://karandeepbadwal.com/" rel="noopener noreferrer" target="_blank">https://karandeepbadwal.com/</a> </p><p>Connect with Karandeep on LinkedIn: <a href="https://www.linkedin.com/in/karandeepbadwal/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/karandeepbadwal/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">cfd48872-69b0-4097-b231-e4e8408a1d22</guid><itunes:image href="https://artwork.captivate.fm/325aeda6-3cbb-4fea-9e76-549a5020ee63/MCDP-35-square-thumbnail.jpg"/><pubDate>Tue, 02 Sep 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/cfd48872-69b0-4097-b231-e4e8408a1d22.mp3" length="72575008" type="audio/mpeg"/><itunes:duration>37:45</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>35</itunes:episode><podcast:episode>35</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-be65cc91-79e3-4d87-a9a5-76466cb74abd.json" type="application/json+chapters"/></item><item><title>Webinar: Hacking Med Devices—What Penetration Testing Reveals Before the FDA Does</title><itunes:title>Webinar: Hacking Med Devices—What Penetration Testing Reveals Before the FDA Does</itunes:title><description><![CDATA[<p>Cyber threats targeting medical devices are increasingly sophisticated. A single undiscovered vulnerability could delay your FDA submission and put patient safety at risk.</p><p>Join Blue Goat Cyber’s CTO, Trevor Slattery, and Director of MedTech Cybersecurity, Myles Kellerman, in this webinar as they reveal real-world vulnerabilities uncovered during penetration testing. Gain exclusive insights from actual breaches and vulnerabilities Myles has personally identified, and learn how to ensure your medical device stays secure—and your FDA submission on track.</p><p>In this webinar, you’ll discover:</p><p><br></p><ul><li>Real-world medical device hacks uncovered by penetration testing.</li><li>Common vulnerabilities most manufacturers overlook.</li><li>Practical tips to meet FDA cybersecurity expectations and premarket submission requirements.</li><li>How Blue Goat Cyber helps manufacturers confidently secure FDA approval.</li></ul><br/><p><br></p><p>Featured Speakers:</p><p><br></p><p>Trevor Slattery, CTO: Expert in FDA-compliant cybersecurity strategies for medical devices.</p><p>Myles Kellerman, Director of MedTech Cybersecurity: Renowned penetration tester who identifies vulnerabilities before they become costly crises.</p>]]></description><content:encoded><![CDATA[<p>Cyber threats targeting medical devices are increasingly sophisticated. A single undiscovered vulnerability could delay your FDA submission and put patient safety at risk.</p><p>Join Blue Goat Cyber’s CTO, Trevor Slattery, and Director of MedTech Cybersecurity, Myles Kellerman, in this webinar as they reveal real-world vulnerabilities uncovered during penetration testing. Gain exclusive insights from actual breaches and vulnerabilities Myles has personally identified, and learn how to ensure your medical device stays secure—and your FDA submission on track.</p><p>In this webinar, you’ll discover:</p><p><br></p><ul><li>Real-world medical device hacks uncovered by penetration testing.</li><li>Common vulnerabilities most manufacturers overlook.</li><li>Practical tips to meet FDA cybersecurity expectations and premarket submission requirements.</li><li>How Blue Goat Cyber helps manufacturers confidently secure FDA approval.</li></ul><br/><p><br></p><p>Featured Speakers:</p><p><br></p><p>Trevor Slattery, CTO: Expert in FDA-compliant cybersecurity strategies for medical devices.</p><p>Myles Kellerman, Director of MedTech Cybersecurity: Renowned penetration tester who identifies vulnerabilities before they become costly crises.</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">2d553227-9542-43d3-8b87-b432d98880b4</guid><itunes:image href="https://artwork.captivate.fm/66922ee4-ab1c-4be7-aa78-906ffcefea7b/Webinar-5-Graphic.jpg"/><pubDate>Thu, 28 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/2d553227-9542-43d3-8b87-b432d98880b4.mp3" length="57972776" type="audio/mpeg"/><itunes:duration>40:13</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry</title><itunes:title>Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry</itunes:title><description><![CDATA[<p>What project management mistakes can med tech innovators avoid? What methods and tools can help med tech companies manage projects?</p><p>In this episode, Christian Espinosa welcomes Steve Curry to explore how strong project management can make or break a med tech company’s cybersecurity readiness. They discuss why many innovators overlook planning, how this oversight causes costly delays, and the benefits of integrating cybersecurity into every project phase. Steve shares practical strategies for execution, tool selection, and aligning team resources to ensure both speed to market and compliance success.</p><p>Steve Curry founded MustardSeed, a company that brings world-class project management to the sciences. With a background in billion-dollar defense programs, Steve now helps med tech, biotech, and pharma companies execute better, faster, and smarter. </p><p>Key points: </p><p><br></p><p>(4:47) Core Challenges in Med Tech Project Management</p><p>* Many companies skip creating a true project plan, leading to unachievable timelines.</p><p><br></p><p>(11:16) Investor Perspectives and PMO Value</p><p>* A skilled PMO can integrate teams, drive schedules, and improve decision-making.</p><p><br></p><p>(18:16) Cybersecurity’s Place in the Project Plan</p><p>* Cybersecurity is often added too late, causing redesigns and delays.</p><p><br></p><p>(27:37) Tools, Efficiency, and Execution </p><p>* Choosing the right project management software is critical and difficult to reverse.</p><p><br></p><p>Thanks to Steve Curry for being on the show. Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/steve-curry-ab883378/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/steve-curry-ab883378/</a> </p><p>Learn about MustardSeed: <a href="https://www.mustardseedpmo.com/" rel="noopener noreferrer" target="_blank">https://www.mustardseedpmo.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What project management mistakes can med tech innovators avoid? What methods and tools can help med tech companies manage projects?</p><p>In this episode, Christian Espinosa welcomes Steve Curry to explore how strong project management can make or break a med tech company’s cybersecurity readiness. They discuss why many innovators overlook planning, how this oversight causes costly delays, and the benefits of integrating cybersecurity into every project phase. Steve shares practical strategies for execution, tool selection, and aligning team resources to ensure both speed to market and compliance success.</p><p>Steve Curry founded MustardSeed, a company that brings world-class project management to the sciences. With a background in billion-dollar defense programs, Steve now helps med tech, biotech, and pharma companies execute better, faster, and smarter. </p><p>Key points: </p><p><br></p><p>(4:47) Core Challenges in Med Tech Project Management</p><p>* Many companies skip creating a true project plan, leading to unachievable timelines.</p><p><br></p><p>(11:16) Investor Perspectives and PMO Value</p><p>* A skilled PMO can integrate teams, drive schedules, and improve decision-making.</p><p><br></p><p>(18:16) Cybersecurity’s Place in the Project Plan</p><p>* Cybersecurity is often added too late, causing redesigns and delays.</p><p><br></p><p>(27:37) Tools, Efficiency, and Execution </p><p>* Choosing the right project management software is critical and difficult to reverse.</p><p><br></p><p>Thanks to Steve Curry for being on the show. Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/steve-curry-ab883378/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/steve-curry-ab883378/</a> </p><p>Learn about MustardSeed: <a href="https://www.mustardseedpmo.com/" rel="noopener noreferrer" target="_blank">https://www.mustardseedpmo.com/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a> </p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">db87c26b-b4f4-4ffe-8f0d-22028d139b5a</guid><itunes:image href="https://artwork.captivate.fm/b77fce8d-56e7-4903-b652-0c899a2a4a93/MCDP-40-square-thumbnail.jpg"/><pubDate>Tue, 26 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/db87c26b-b4f4-4ffe-8f0d-22028d139b5a.mp3" length="85502037" type="audio/mpeg"/><itunes:duration>44:29</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>34</itunes:episode><podcast:episode>34</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-719cd7c7-fed1-44d4-96fe-3f64277b044b.json" type="application/json+chapters"/></item><item><title>Webinar: Navigating FDA Cybersecurity Compliance: A Guide for RA/QA Professionals</title><itunes:title>Webinar: Navigating FDA Cybersecurity Compliance: A Guide for RA/QA Professionals</itunes:title><description><![CDATA[<p>When you’re working with a manufacturer to ensure that a medical device has strong cybersecurity, what do you need to know from a regulatory perspective? </p><p>In this episode, Christian and Trevor dive into the current state of cybersecurity, discussing emerging threats and defense strategies. They also explore the role of AI in both cyberattacks and security measures, offering insights into how businesses can stay ahead of evolving threats. </p><p>Key topics for regulatory affairs (RA) and quality assurance (QA) professionals covered in this webinar: </p><p>(02:15) The Current Cyber Threat Landscape</p><p>* The most pressing cybersecurity threats facing businesses today.</p><p>* Why ransomware attacks are becoming more sophisticated.</p><p><br></p><p>(10:45) Social Engineering </p><p>* How cybercriminals manipulate human behavior to breach systems.</p><p><br></p><p>(19:30) AI in Cybersecurity</p><p>* The ways AI is being used by both attackers and defenders.</p><p>* Ethical concerns around AI-driven cybersecurity tools.</p><p><br></p><p>(27:50) Building a Culture of Security Awareness</p><p>* Why employee training is crucial in preventing breaches.</p><p>* Why multifactor authentication is a must.</p><p>* Regularly updating and patching software.</p><p><br></p><p>(44:30) The Future of Cybersecurity</p><p>* Predictions for upcoming threats and defensive strategies.</p><p>* Steps businesses can take today to prepare for tomorrow’s challenges.</p><p><br></p><p>This episode is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>When you’re working with a manufacturer to ensure that a medical device has strong cybersecurity, what do you need to know from a regulatory perspective? </p><p>In this episode, Christian and Trevor dive into the current state of cybersecurity, discussing emerging threats and defense strategies. They also explore the role of AI in both cyberattacks and security measures, offering insights into how businesses can stay ahead of evolving threats. </p><p>Key topics for regulatory affairs (RA) and quality assurance (QA) professionals covered in this webinar: </p><p>(02:15) The Current Cyber Threat Landscape</p><p>* The most pressing cybersecurity threats facing businesses today.</p><p>* Why ransomware attacks are becoming more sophisticated.</p><p><br></p><p>(10:45) Social Engineering </p><p>* How cybercriminals manipulate human behavior to breach systems.</p><p><br></p><p>(19:30) AI in Cybersecurity</p><p>* The ways AI is being used by both attackers and defenders.</p><p>* Ethical concerns around AI-driven cybersecurity tools.</p><p><br></p><p>(27:50) Building a Culture of Security Awareness</p><p>* Why employee training is crucial in preventing breaches.</p><p>* Why multifactor authentication is a must.</p><p>* Regularly updating and patching software.</p><p><br></p><p>(44:30) The Future of Cybersecurity</p><p>* Predictions for upcoming threats and defensive strategies.</p><p>* Steps businesses can take today to prepare for tomorrow’s challenges.</p><p><br></p><p>This episode is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">e2ab34a0-e6ca-40a1-801d-895f74aae9ee</guid><itunes:image href="https://artwork.captivate.fm/f818ca47-e2ed-4696-9cd5-ed9e7f4b7e40/Webinar-5-Graphic.jpg"/><pubDate>Thu, 21 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/e2ab34a0-e6ca-40a1-801d-895f74aae9ee.mp3" length="75870999" type="audio/mpeg"/><itunes:duration>39:31</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><podcast:chapters url="https://transcripts.captivate.fm/chapter-b86e0c22-1731-4155-b082-dd0f8600aace.json" type="application/json+chapters"/></item><item><title>Vulnerability, Penetration &amp; Other Cybersecurity Testing Types Explained</title><itunes:title>Vulnerability, Penetration &amp; Other Cybersecurity Testing Types Explained</itunes:title><description><![CDATA[<p>Which cybersecurity tests are the most crucial, and which ones does the FDA require for medical device approval?</p><p>In this episode, Christian and Trevor break down the many types of cybersecurity testing required for medical devices. They explore the distinctions between vulnerability assessments, penetration testing, and other critical methods like fuzz testing, security requirement testing, and dynamic analysis. Along the way, they share real-world examples, FDA compliance insights, and practical tips for ensuring no entry point goes untested.</p><p>Key points:&nbsp;</p><p><br></p><p>(3:21) Vulnerability vs. Penetration Testing</p><p>* Vulnerability testing identifies issues quickly, while penetration testing digs deeper to exploit them.</p><p><br></p><p>(6:01) Software Composition and Static Analysis</p><p>* Using SBoMs to identify risks in third-party and unknown code.</p><p>* Dangers of insecure, copied code such as hardcoded credentials.</p><p><br></p><p>(10:23) Penetration Testing Types and Abuse Cases</p><p>* Differences between black, gray, and white box testing.</p><p>* Abuse case testing for overlooked or “out of scope” device interfaces.</p><p><br></p><p>(20:44) Fuzz Testing and Security Requirements</p><p>* Fuzz testing for unexpected input handling and potential zero-day vulnerabilities.</p><p>* Security requirement testing, dynamic analysis, and advice on choosing skilled third-party testers.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a>&nbsp;</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a>&nbsp;</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.&nbsp;</p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a>&nbsp;</p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a>&nbsp;</p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a>&nbsp;</p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a>&nbsp;</p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a>&nbsp;</p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a>&nbsp;</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a>&nbsp;</p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a>&nbsp;</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.&nbsp;</p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a>&nbsp;</p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p><p><br></p><p>This episode was produced by Story On Media: <a href="https://www.storyon.co/" rel="noopener noreferrer" target="_blank">https://www.storyon.co/</a>&nbsp;</p>]]></description><content:encoded><![CDATA[<p>Which cybersecurity tests are the most crucial, and which ones does the FDA require for medical device approval?</p><p>In this episode, Christian and Trevor break down the many types of cybersecurity testing required for medical devices. They explore the distinctions between vulnerability assessments, penetration testing, and other critical methods like fuzz testing, security requirement testing, and dynamic analysis. Along the way, they share real-world examples, FDA compliance insights, and practical tips for ensuring no entry point goes untested.</p><p>Key points:&nbsp;</p><p><br></p><p>(3:21) Vulnerability vs. Penetration Testing</p><p>* Vulnerability testing identifies issues quickly, while penetration testing digs deeper to exploit them.</p><p><br></p><p>(6:01) Software Composition and Static Analysis</p><p>* Using SBoMs to identify risks in third-party and unknown code.</p><p>* Dangers of insecure, copied code such as hardcoded credentials.</p><p><br></p><p>(10:23) Penetration Testing Types and Abuse Cases</p><p>* Differences between black, gray, and white box testing.</p><p>* Abuse case testing for overlooked or “out of scope” device interfaces.</p><p><br></p><p>(20:44) Fuzz Testing and Security Requirements</p><p>* Fuzz testing for unexpected input handling and potential zero-day vulnerabilities.</p><p>* Security requirement testing, dynamic analysis, and advice on choosing skilled third-party testers.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a>&nbsp;</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a>&nbsp;</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.&nbsp;</p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a>&nbsp;</p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a></p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a>&nbsp;</p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a>&nbsp;</p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a>&nbsp;</p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a>&nbsp;</p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a>&nbsp;</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a>&nbsp;</p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a>&nbsp;</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.&nbsp;</p><p><br></p><p>Subscribe via Spotify: <a href="https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh" rel="noopener noreferrer" target="_blank">https://open.spotify.com/show/5ol62ROdF6mBfwOFqKFHmh</a>&nbsp;</p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p><p><br></p><p>This episode was produced by Story On Media: <a href="https://www.storyon.co/" rel="noopener noreferrer" target="_blank">https://www.storyon.co/</a>&nbsp;</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">6cf9feb7-28e9-40bc-aee5-410b065fd48b</guid><itunes:image href="https://artwork.captivate.fm/a8f3dbfc-8bc3-4c03-ac59-641556c37e27/MCDP-38-square-thumbnail.jpg"/><pubDate>Tue, 19 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/6cf9feb7-28e9-40bc-aee5-410b065fd48b.mp3" length="59200165" type="audio/mpeg"/><itunes:duration>30:47</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>33</itunes:episode><podcast:episode>33</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-c79734a8-b666-4225-a0f4-09dc4c686d86.json" type="application/json+chapters"/></item><item><title>Webinar: Medical Device Penetration Testing: What Every Manufacturer Must Know</title><itunes:title>Webinar: Medical Device Penetration Testing: What Every Manufacturer Must Know</itunes:title><description><![CDATA[<p>What are the unique challenges and regulatory requirements of medical device penetration testing?&nbsp;</p><p>In this webinar episode with Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, you’ll learn:&nbsp;</p><p>* How Medical Device Penetration Testing Differs from Traditional IT Security.</p><p>Unlike conventional IT security testing, medical device penetration testing prioritizes patient safety and device functionality. Discover how attackers exploit firmware, wireless protocols, and hardware vulnerabilities—threats often overlooked in standard IT security assessments.</p><p><br></p><p>*&nbsp; Meeting FDA &amp; Global Regulatory Requirements for Penetration Testing.</p><p><br></p><p>With the FDA’s 2023 cybersecurity guidance, EU MDR expectations, and IEC 62304 compliance now requiring risk-based security testing, manufacturers must integrate penetration testing to avoid regulatory delays, design deficiencies, and costly late-stage changes.</p><p><br></p><p>*&nbsp; Identifying &amp; Preventing the Most Exploited Medical Device Vulnerabilities.</p><p><br></p><p>From weak authentication and unpatched third-party components to unencrypted communication channels, real-world attacks on pacemakers, insulin pumps, and hospital IoT devices illustrate the critical need for proactive security measures. Learn how these vulnerabilities could have been prevented.</p><p><br></p><p>*&nbsp; Medical Device Risk Matrix: Replacing Probability with Exploitability &amp; Prioritizing Patient Harm.</p><p><br></p><p>Traditional risk assessments rely on probability vs. impact, but medical device risk scoring prioritizes exploitability (CVSS-based) over probability for a more objective evaluation. Learn how patient harm replaces a solely HIPAA-focused data exposure approach, aligning risk assessment with real-world consequences.</p><p><br></p><p>*&nbsp; How Penetration Testing Strengthens Security &amp; Accelerates FDA Approval.</p><p><br></p><p>Early integration of security testing in development reduces costly last-minute fixes and regulatory deficiencies, while postmarket penetration testing ensures ongoing protection against evolving cyber threats, preventing unexpected recalls and compliance failures.</p>]]></description><content:encoded><![CDATA[<p>What are the unique challenges and regulatory requirements of medical device penetration testing?&nbsp;</p><p>In this webinar episode with Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, you’ll learn:&nbsp;</p><p>* How Medical Device Penetration Testing Differs from Traditional IT Security.</p><p>Unlike conventional IT security testing, medical device penetration testing prioritizes patient safety and device functionality. Discover how attackers exploit firmware, wireless protocols, and hardware vulnerabilities—threats often overlooked in standard IT security assessments.</p><p><br></p><p>*&nbsp; Meeting FDA &amp; Global Regulatory Requirements for Penetration Testing.</p><p><br></p><p>With the FDA’s 2023 cybersecurity guidance, EU MDR expectations, and IEC 62304 compliance now requiring risk-based security testing, manufacturers must integrate penetration testing to avoid regulatory delays, design deficiencies, and costly late-stage changes.</p><p><br></p><p>*&nbsp; Identifying &amp; Preventing the Most Exploited Medical Device Vulnerabilities.</p><p><br></p><p>From weak authentication and unpatched third-party components to unencrypted communication channels, real-world attacks on pacemakers, insulin pumps, and hospital IoT devices illustrate the critical need for proactive security measures. Learn how these vulnerabilities could have been prevented.</p><p><br></p><p>*&nbsp; Medical Device Risk Matrix: Replacing Probability with Exploitability &amp; Prioritizing Patient Harm.</p><p><br></p><p>Traditional risk assessments rely on probability vs. impact, but medical device risk scoring prioritizes exploitability (CVSS-based) over probability for a more objective evaluation. Learn how patient harm replaces a solely HIPAA-focused data exposure approach, aligning risk assessment with real-world consequences.</p><p><br></p><p>*&nbsp; How Penetration Testing Strengthens Security &amp; Accelerates FDA Approval.</p><p><br></p><p>Early integration of security testing in development reduces costly last-minute fixes and regulatory deficiencies, while postmarket penetration testing ensures ongoing protection against evolving cyber threats, preventing unexpected recalls and compliance failures.</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">d620a97a-1f2d-4bf8-8bd5-16e5f71c45fc</guid><itunes:image href="https://artwork.captivate.fm/49b976f8-43be-4071-8997-af1e4578219b/Webinar-4-square-Graphic.jpg"/><pubDate>Thu, 14 Aug 2025 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/d620a97a-1f2d-4bf8-8bd5-16e5f71c45fc.mp3" length="43177623" type="audio/mpeg"/><itunes:duration>44:59</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>From Surgery to MedTech Startups: Dr. Dylan Attard’s Journey</title><itunes:title>From Surgery to MedTech Startups: Dr. Dylan Attard’s Journey</itunes:title><description><![CDATA[<p>What cybersecurity challenges face hospitals and medical devices today that medtech innovators should know about?</p><p>Today’s guest is Dr. Dylan Attard, who swapped his scalpel for startups when he founded MedTech World, a global conference series elevating healthcare innovation. He’s passionate about connecting startups with investors and sparking conversations that turn bold ideas into life-saving solutions.</p><p>In this episode, Dr. Attard shares his transition from surgeon to founder of MedTech World and offers a global perspective on med tech growth, innovation, and cybersecurity. Along with Christian and Trevor, he explores how startups can safeguard patient lives—and their bottom line—by thinking about cybersecurity from day one.</p><p>(07:20) Global Growth of Med Tech</p><p>Med tech expansion in the Middle East, Africa, and Asia.</p><p><br></p><p>(12:46) Cybersecurity Awareness and Startup Risk</p><p>How many med tech innovators fail to consider cybersecurity early.</p><p><br></p><p>(18:18) Documented Cases of Patient Harm</p><p>Challenging the narrative that medical device hacks haven’t caused patient harm.</p><p><br></p><p>(36:13) Vision for MedTech World </p><p>Dylan shares the mission behind MedTech World and its expansion goals.</p><p><br></p><p>Thanks to Dr. Dylan Attard for being on the show. </p><p><br></p><p>Visit his website: <a href="https://www.dylanattard.com/" rel="noopener noreferrer" target="_blank">https://www.dylanattard.com/</a> </p><p>Connect with him on LinkedIn: <a href="https://www.linkedin.com/in/dylattard/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/dylattard/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What cybersecurity challenges face hospitals and medical devices today that medtech innovators should know about?</p><p>Today’s guest is Dr. Dylan Attard, who swapped his scalpel for startups when he founded MedTech World, a global conference series elevating healthcare innovation. He’s passionate about connecting startups with investors and sparking conversations that turn bold ideas into life-saving solutions.</p><p>In this episode, Dr. Attard shares his transition from surgeon to founder of MedTech World and offers a global perspective on med tech growth, innovation, and cybersecurity. Along with Christian and Trevor, he explores how startups can safeguard patient lives—and their bottom line—by thinking about cybersecurity from day one.</p><p>(07:20) Global Growth of Med Tech</p><p>Med tech expansion in the Middle East, Africa, and Asia.</p><p><br></p><p>(12:46) Cybersecurity Awareness and Startup Risk</p><p>How many med tech innovators fail to consider cybersecurity early.</p><p><br></p><p>(18:18) Documented Cases of Patient Harm</p><p>Challenging the narrative that medical device hacks haven’t caused patient harm.</p><p><br></p><p>(36:13) Vision for MedTech World </p><p>Dylan shares the mission behind MedTech World and its expansion goals.</p><p><br></p><p>Thanks to Dr. Dylan Attard for being on the show. </p><p><br></p><p>Visit his website: <a href="https://www.dylanattard.com/" rel="noopener noreferrer" target="_blank">https://www.dylanattard.com/</a> </p><p>Connect with him on LinkedIn: <a href="https://www.linkedin.com/in/dylattard/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/dylattard/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">ee8ec786-372c-448c-94b2-cfb72f27343f</guid><itunes:image href="https://artwork.captivate.fm/55ca516b-ff8b-49ab-a575-a4755c600c63/cGuiXRaazfUstx1WtgjS3Dg5.jpg"/><pubDate>Tue, 12 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/ee8ec786-372c-448c-94b2-cfb72f27343f.mp3" length="86357390" type="audio/mpeg"/><itunes:duration>44:54</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>32</itunes:episode><podcast:episode>32</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-17cfdab0-eb0d-42b1-8e27-22cec625c49c.json" type="application/json+chapters"/></item><item><title>Webinar: Medical Device Risk Assessments - Cybersecurity, Compliance &amp; Patient Safety</title><itunes:title>Webinar: Medical Device Risk Assessments - Cybersecurity, Compliance &amp; Patient Safety</itunes:title><description><![CDATA[<p>Medical devices are becoming more connected, but with that connectivity comes risk.</p><p>In this episode, Christian and Trevor dive into risk assessments for medical devices—a crucial process in ensuring both patient safety and cybersecurity compliance.</p><p>They discuss:</p><p>* The difference between risk management and risk assessment</p><p>* How risk scoring works using exploitability vs. impact</p><p>* Why traditional cybersecurity metrics don’t fully apply to medical devices</p><p>* The importance of traceability and compliance with ISO 14971 &amp; AAMI TIR57</p><p>* How SBOMs and vulnerability assessments fit into a cybersecurity strategy</p><p>* Real-world examples of risk prioritization in medical devices</p><p><br></p><p>Risk assessments aren’t just about identifying vulnerabilities—they’re about understanding their real-world impact on patients and ensuring compliance with regulatory bodies like the FDA.</p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>Medical devices are becoming more connected, but with that connectivity comes risk.</p><p>In this episode, Christian and Trevor dive into risk assessments for medical devices—a crucial process in ensuring both patient safety and cybersecurity compliance.</p><p>They discuss:</p><p>* The difference between risk management and risk assessment</p><p>* How risk scoring works using exploitability vs. impact</p><p>* Why traditional cybersecurity metrics don’t fully apply to medical devices</p><p>* The importance of traceability and compliance with ISO 14971 &amp; AAMI TIR57</p><p>* How SBOMs and vulnerability assessments fit into a cybersecurity strategy</p><p>* Real-world examples of risk prioritization in medical devices</p><p><br></p><p>Risk assessments aren’t just about identifying vulnerabilities—they’re about understanding their real-world impact on patients and ensuring compliance with regulatory bodies like the FDA.</p><p><br></p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">600a43d4-826f-4ac3-8d3e-db48cdff0075</guid><itunes:image href="https://artwork.captivate.fm/345398d5-bd9b-40c7-a2d7-0e80e2ae2025/SbBNctAJobFGoC3R3xEO9h0R.jpg"/><pubDate>Thu, 07 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/600a43d4-826f-4ac3-8d3e-db48cdff0075.mp3" length="48186711" type="audio/mpeg"/><itunes:duration>33:28</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>Understanding Cybersecurity Measures and Metrics for Medical Devices</title><itunes:title>Understanding Cybersecurity Measures and Metrics for Medical Devices</itunes:title><description><![CDATA[<p>How do measures and metrics differ, and why is this distinction crucial for FDA submissions?</p><p>In this episode, Christian and Trevor demystify the difference between cybersecurity measures and metrics in the context of FDA guidance. They explore what the FDA expects in submissions, emphasizing patch timelines, vulnerability tracking, and post-market data collection. They also discuss the importance of actionability over mere compliance and include real-world challenges like device downtime and risk in different environments.</p><p>Key points: </p><p>(0:30) Measures vs Metrics Defined</p><p>* Measures are raw figures like time or count; metrics are calculated from measures.</p><p><br></p><p>(4:06) FDA Guidance and Patch Timelines</p><p>* FDA expects metrics like percentage of patched vulnerabilities and two patch-related durations.</p><p><br></p><p>(7:49) Real-Time Alerts </p><p>* Devices should notify users immediately of anomalies to compensate for lack of SOC monitoring.</p><p><br></p><p>(14:01) When to Include Metrics in Submissions</p><p>* Metrics aren’t always required during initial submission unless data is available.</p><p><br></p><p>(18:07) Downtime, Rebooting, and Risk Profiles</p><p>* Reboot times and system recovery durations should be treated as key measures.</p><p>* Risk profiles shift based on device use environment. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></description><content:encoded><![CDATA[<p>How do measures and metrics differ, and why is this distinction crucial for FDA submissions?</p><p>In this episode, Christian and Trevor demystify the difference between cybersecurity measures and metrics in the context of FDA guidance. They explore what the FDA expects in submissions, emphasizing patch timelines, vulnerability tracking, and post-market data collection. They also discuss the importance of actionability over mere compliance and include real-world challenges like device downtime and risk in different environments.</p><p>Key points: </p><p>(0:30) Measures vs Metrics Defined</p><p>* Measures are raw figures like time or count; metrics are calculated from measures.</p><p><br></p><p>(4:06) FDA Guidance and Patch Timelines</p><p>* FDA expects metrics like percentage of patched vulnerabilities and two patch-related durations.</p><p><br></p><p>(7:49) Real-Time Alerts </p><p>* Devices should notify users immediately of anomalies to compensate for lack of SOC monitoring.</p><p><br></p><p>(14:01) When to Include Metrics in Submissions</p><p>* Metrics aren’t always required during initial submission unless data is available.</p><p><br></p><p>(18:07) Downtime, Rebooting, and Risk Profiles</p><p>* Reboot times and system recovery durations should be treated as key measures.</p><p>* Risk profiles shift based on device use environment. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">37aea4ac-3b16-4f0d-bd5f-d2ccf7ddc104</guid><itunes:image href="https://artwork.captivate.fm/cb3e6175-358a-4ace-8cff-05d21cf55695/vqgRFd8dYR3yXzUnSYqyMuyd.jpg"/><pubDate>Tue, 05 Aug 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/37aea4ac-3b16-4f0d-bd5f-d2ccf7ddc104.mp3" length="46410914" type="audio/mpeg"/><itunes:duration>24:08</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>31</itunes:episode><podcast:episode>31</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-9f7faa38-b5fe-4ae2-90c7-02814d457b00.json" type="application/json+chapters"/></item><item><title>Webinar: Mastering Threat Modeling for Medical Device Cybersecurity</title><itunes:title>Webinar: Mastering Threat Modeling for Medical Device Cybersecurity</itunes:title><description><![CDATA[<p>Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, explore the critical topic of threat modeling in medical device cybersecurity.</p><p>This session covers essential practices and frameworks that ensure the safety and security of medical devices, aligning with FDA guidelines.</p><p>We cover the DFD3 standard for threat diagramming and the STRIDE framework for identifying potential threats. Learn how to visualize and assess risks effectively, understand trust boundaries, and implement robust security measures to protect sensitive patient data.</p><p>Blue Goat Cyber is a group of cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>For more content on medical device cybersecurity, check out The Med Device Cyber Podcast, your essential resource. In each episode, we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, subscribing to the Med Device Cyber Podcast will help you safeguard patient safety.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p>]]></description><content:encoded><![CDATA[<p>Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, explore the critical topic of threat modeling in medical device cybersecurity.</p><p>This session covers essential practices and frameworks that ensure the safety and security of medical devices, aligning with FDA guidelines.</p><p>We cover the DFD3 standard for threat diagramming and the STRIDE framework for identifying potential threats. Learn how to visualize and assess risks effectively, understand trust boundaries, and implement robust security measures to protect sensitive patient data.</p><p>Blue Goat Cyber is a group of cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>For more content on medical device cybersecurity, check out The Med Device Cyber Podcast, your essential resource. In each episode, we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, subscribing to the Med Device Cyber Podcast will help you safeguard patient safety.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">c03b626a-43e8-4ac9-aee6-9b1463ce9765</guid><itunes:image href="https://artwork.captivate.fm/6ee8ba2b-40b0-48e5-bc65-918d2026c918/S8ITpIyMhmM0Ul3IxgJ7yzsR.jpg"/><pubDate>Thu, 31 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/c03b626a-43e8-4ac9-aee6-9b1463ce9765.mp3" length="62345367" type="audio/mpeg"/><itunes:duration>43:18</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>FDA Cybersecurity Gets Real with Monica Montañez of NAMSA</title><itunes:title>FDA Cybersecurity Gets Real with Monica Montañez of NAMSA</itunes:title><description><![CDATA[<p>How have medical device cybersecurity requirements changed since 2023, and what does this mean for your product development?</p><p>In this episode, Christian and Trevor welcome Monica Montañez from NAMSA to unpack the evolving landscape of FDA cybersecurity requirements. From new laws introduced in 2023 to the ambiguous language in FDA guidance, they dig into what it really takes to meet expectations for cyber device submissions. </p><p>(0:32) NAMSA and Industry Shifts</p><p>* Monica introduces NAMSA’s role in regulatory and quality consulting.</p><p>(5:12) FDA Guidance vs. Legal Mandate</p><p>* The confusion around FDA’s "recommended" language.</p><p>* How internet-connectivity defines cyber devices—including USB and Bluetooth.</p><p><br></p><p>(12:57) Classifications, Interfaces, and Testing Gaps</p><p>* The dangers of assuming interfaces are disabled.</p><p>* Why early cybersecurity design is now critical for approval.</p><p><br></p><p>(18:08) New Submission Expectations</p><p>* What’s now required in a submission: threat models, risk assessments, lifecycle documentation.</p><p>* Trevor explains how these requirements balloon documentation to hundreds of pages.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Monica Montañez for being on the show. </p><p><br></p><p>Learn more about Monica on NAMSA’s website:</p><p><a href="https://namsa.com/expertise/team/monica-r-montanez/" rel="noopener noreferrer" target="_blank">https://namsa.com/expertise/team/monica-r-montanez/</a> </p><p>Connect with Monica on LinkedIn: <a href="https://www.linkedin.com/in/monica-montanez-ms-rs-rac-cqa-4389336" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/monica-montanez-ms-rs-rac-cqa-4389336</a>  </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How have medical device cybersecurity requirements changed since 2023, and what does this mean for your product development?</p><p>In this episode, Christian and Trevor welcome Monica Montañez from NAMSA to unpack the evolving landscape of FDA cybersecurity requirements. From new laws introduced in 2023 to the ambiguous language in FDA guidance, they dig into what it really takes to meet expectations for cyber device submissions. </p><p>(0:32) NAMSA and Industry Shifts</p><p>* Monica introduces NAMSA’s role in regulatory and quality consulting.</p><p>(5:12) FDA Guidance vs. Legal Mandate</p><p>* The confusion around FDA’s "recommended" language.</p><p>* How internet-connectivity defines cyber devices—including USB and Bluetooth.</p><p><br></p><p>(12:57) Classifications, Interfaces, and Testing Gaps</p><p>* The dangers of assuming interfaces are disabled.</p><p>* Why early cybersecurity design is now critical for approval.</p><p><br></p><p>(18:08) New Submission Expectations</p><p>* What’s now required in a submission: threat models, risk assessments, lifecycle documentation.</p><p>* Trevor explains how these requirements balloon documentation to hundreds of pages.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Monica Montañez for being on the show. </p><p><br></p><p>Learn more about Monica on NAMSA’s website:</p><p><a href="https://namsa.com/expertise/team/monica-r-montanez/" rel="noopener noreferrer" target="_blank">https://namsa.com/expertise/team/monica-r-montanez/</a> </p><p>Connect with Monica on LinkedIn: <a href="https://www.linkedin.com/in/monica-montanez-ms-rs-rac-cqa-4389336" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/monica-montanez-ms-rs-rac-cqa-4389336</a>  </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">8312bdde-e310-4dba-b8ce-0ed6abe67550</guid><itunes:image href="https://artwork.captivate.fm/3be08e3d-70a1-48c3-b065-6ea4cf8b4dc2/Y7JoqWnOEF5wdQXUFpDqZZsd.jpg"/><pubDate>Tue, 29 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/8312bdde-e310-4dba-b8ce-0ed6abe67550.mp3" length="63022512" type="audio/mpeg"/><itunes:duration>32:47</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>30</itunes:episode><podcast:episode>30</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-8b6ac8d3-2652-4b63-b2ad-83fbc5567a83.json" type="application/json+chapters"/></item><item><title>Webinar: Risk Management Frameworks For Medical Device Safety &amp; Security</title><itunes:title>Webinar: Risk Management Frameworks For Medical Device Safety &amp; Security</itunes:title><description><![CDATA[<p>Join Trevor Slattery, Director of Cybersecurity, and Christian Espinosa, CEO of Blue Goat Cyber, for a comprehensive webinar on medical device cybersecurity. </p><p>Trevor and Christian explore the critical interplay between safety and security risk management, offering guidance on conducting effective risk assessments that address vulnerabilities across both domains. </p><p>This presentation will give you a deeper understanding of key standards like ISO 14971 and AAMI TIR57 and learn how to implement robust risk management frameworks. Equip yourself with the knowledge needed to ensure both patient safety and data security in medical devices!</p><p>Blue Goat Cyber is a group of cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ </p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 </p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ </p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ </p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ </p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber </p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ </p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial </p><p><br></p><p>For more content on medical device cybersecurity, check out The Med Device Cyber Podcast, your essential resource. In each episode, we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, subscribing to the Med Device Cyber Podcast will help you safeguard patient safety. </p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p>]]></description><content:encoded><![CDATA[<p>Join Trevor Slattery, Director of Cybersecurity, and Christian Espinosa, CEO of Blue Goat Cyber, for a comprehensive webinar on medical device cybersecurity. </p><p>Trevor and Christian explore the critical interplay between safety and security risk management, offering guidance on conducting effective risk assessments that address vulnerabilities across both domains. </p><p>This presentation will give you a deeper understanding of key standards like ISO 14971 and AAMI TIR57 and learn how to implement robust risk management frameworks. Equip yourself with the knowledge needed to ensure both patient safety and data security in medical devices!</p><p>Blue Goat Cyber is a group of cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ </p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 </p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ </p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ </p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ </p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber </p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/ </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/ </p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial </p><p><br></p><p>For more content on medical device cybersecurity, check out The Med Device Cyber Podcast, your essential resource. In each episode, we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, subscribing to the Med Device Cyber Podcast will help you safeguard patient safety. </p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">099810cf-6d28-4b96-8165-da97004fdca8</guid><itunes:image href="https://artwork.captivate.fm/3afdb4e4-f3e7-4866-8f4c-fbb98b97f4b8/tGok5hAfaqj0wlCG1FWfAu-D.jpg"/><pubDate>Thu, 24 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/099810cf-6d28-4b96-8165-da97004fdca8.mp3" length="62345367" type="audio/mpeg"/><itunes:duration>43:18</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>What the FDA Wants in Security Architecture Views for Devices</title><itunes:title>What the FDA Wants in Security Architecture Views for Devices</itunes:title><description><![CDATA[<p>What are the four security architecture views that the FDA prioritizes, and how do they impact your device's design?</p><p>This episode explores the FDA-defined security architecture views essential for medical device cybersecurity. Christian and Trevor break down the four views—global system, updatability/patchability, multi-patient harm, and secure use cases—with real-world examples and practical advice. </p><p>Key points: </p><p>(5:25) The Global System View</p><p>* Companion apps and cloud infrastructure must be part of the device scope.</p><p>* Many device manufacturers overlook update infrastructure in this view.</p><p>* Distinguishing in-scope versus out-of-scope components is a common challenge.</p><p>(12:52) Updatability and Patchability</p><p>* Secure update procedures must cover the entire lifecycle.</p><p>* FDA wants manufacturers to consider both infrastructure and delivery integrity.</p><p>* A weak development environment can compromise update trustworthiness.</p><p><br></p><p>(18:21) Multi-Patient Harm Scenarios</p><p>* Risk is based on the scope and scale of potential compromise.</p><p>* Even small devices can cause large-scale issues depending on their connectivity.</p><p><br></p><p>(23:09) Secure Use Case Views and Closing Advice</p><p>* Every device function should have a corresponding security consideration.</p><p>* Functional requirements can guide secure use case documentation.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are the four security architecture views that the FDA prioritizes, and how do they impact your device's design?</p><p>This episode explores the FDA-defined security architecture views essential for medical device cybersecurity. Christian and Trevor break down the four views—global system, updatability/patchability, multi-patient harm, and secure use cases—with real-world examples and practical advice. </p><p>Key points: </p><p>(5:25) The Global System View</p><p>* Companion apps and cloud infrastructure must be part of the device scope.</p><p>* Many device manufacturers overlook update infrastructure in this view.</p><p>* Distinguishing in-scope versus out-of-scope components is a common challenge.</p><p>(12:52) Updatability and Patchability</p><p>* Secure update procedures must cover the entire lifecycle.</p><p>* FDA wants manufacturers to consider both infrastructure and delivery integrity.</p><p>* A weak development environment can compromise update trustworthiness.</p><p><br></p><p>(18:21) Multi-Patient Harm Scenarios</p><p>* Risk is based on the scope and scale of potential compromise.</p><p>* Even small devices can cause large-scale issues depending on their connectivity.</p><p><br></p><p>(23:09) Secure Use Case Views and Closing Advice</p><p>* Every device function should have a corresponding security consideration.</p><p>* Functional requirements can guide secure use case documentation.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">5cd7f573-675a-460d-a1f1-be828d770411</guid><itunes:image href="https://artwork.captivate.fm/c532b3bd-7c65-4169-a6e4-e79ac73182e7/2A8supKtpzutAzeiKNoLbFQn.jpg"/><pubDate>Tue, 22 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/5cd7f573-675a-460d-a1f1-be828d770411.mp3" length="53685902" type="audio/mpeg"/><itunes:duration>27:55</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>29</itunes:episode><podcast:episode>29</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-495e238a-0afb-4be5-955a-2262cb0e30c7.json" type="application/json+chapters"/></item><item><title>Webinar: 5 Key FDA Cybersecurity Standards with Jordan John</title><itunes:title>Webinar: 5 Key FDA Cybersecurity Standards with Jordan John</itunes:title><description><![CDATA[<p>How can you integrate relevant cybersecurity standards early in your medical device development process? Also, how do FDA cybersecurity standards help reduce the time to market for new medical devices?</p><p>In this episode, Trevor Slattery, CTO of Blue Goat Cyber, and Jordan John, Director of Regulatory Affairs and Compliance at Blue Goat Cyber, explore: </p><p>* The importance of integrating standards into the QMS from the start.</p><p>* How TIR57 complements ISO 14971 for security risk management.</p><p>* Why cybersecurity must be operational, not just documented.</p><p>* IEC 62304 and its role in secure software lifecycle processes.</p><p>* ISO/IEC 81001-5-1 is covered as a framework for secure product development.</p><p>* NIST SP 800-115 is explored as a guide for FDA-compliant penetration testing.</p><p>* How FDA guidance ties all the standards together.</p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>How can you integrate relevant cybersecurity standards early in your medical device development process? Also, how do FDA cybersecurity standards help reduce the time to market for new medical devices?</p><p>In this episode, Trevor Slattery, CTO of Blue Goat Cyber, and Jordan John, Director of Regulatory Affairs and Compliance at Blue Goat Cyber, explore: </p><p>* The importance of integrating standards into the QMS from the start.</p><p>* How TIR57 complements ISO 14971 for security risk management.</p><p>* Why cybersecurity must be operational, not just documented.</p><p>* IEC 62304 and its role in secure software lifecycle processes.</p><p>* ISO/IEC 81001-5-1 is covered as a framework for secure product development.</p><p>* NIST SP 800-115 is explored as a guide for FDA-compliant penetration testing.</p><p>* How FDA guidance ties all the standards together.</p><p>This episode was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">83d461a3-2118-4b86-a1bb-baf6013f8f25</guid><itunes:image href="https://artwork.captivate.fm/6f7a5202-9a92-4be5-9b87-0f2c41b9ee45/9ht0WvsfZrHnuuQ6_VaFSGYn.jpg"/><pubDate>Thu, 17 Jul 2025 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/83d461a3-2118-4b86-a1bb-baf6013f8f25.mp3" length="95396631" type="audio/mpeg"/><itunes:duration>49:41</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>Shared Responsibility in Medical Device Cybersecurity with Greg Garcia</title><itunes:title>Shared Responsibility in Medical Device Cybersecurity with Greg Garcia</itunes:title><description><![CDATA[<p>How can shared responsibility models improve healthcare cybersecurity?</p><p>In this episode, Greg Garcia joins Christian and Trevor to break down the evolving landscape of medical device cybersecurity from a national policy perspective. Together, they discuss the legacy device challenge, shared accountability, and how sector-wide collaboration is critical to progress. The episode drives home the message that cybersecurity is not just technical—it’s foundational to patient safety and innovation.</p><p>Greg Garcia is one of the people shaping the future of critical infrastructure cybersecurity—and he’s got the track record to back it up. As executive director of the Health Sector Coordinating Council Cybersecurity Working Group, he’s all about connecting the dots between policy, industry, and patient safety.</p><p><br></p><p>Key points: </p><p><br></p><p>(1:30) Cyber in Critical Infrastructure</p><p>* Greg’s career path from Homeland Security to health sector leadership.</p><p>* The Health Sector Coordinating Council’s mission.</p><p><br></p><p>(10:35) The Legacy Device Dilemma</p><p>* Medical device cybersecurity suffers from the finger-pointing between HDOs and MDMs.</p><p>* Managing unsupported devices and contractual accountability.</p><p><br></p><p>(18:05) Budget Gaps and Cultural Challenges</p><p>* Rural hospitals and underfunded providers struggle to keep up with cybersecurity expectations.</p><p>* The case for regulatory mandates to level the playing field.</p><p><br></p><p>(31:47) Regulation, Risk, and Big Ideas</p><p>* The idea of Authorization to Operate (ATO) for health tech.</p><p>* Comparisons to Department of Defense (DoD) and FedRAMP models are raised as a vision for healthcare.</p><p><br></p><p>(40:12) Culture Over Compliance</p><p>* Why data shows low medical device exploitation—but that’s no reason to relax.</p><p>* How to make “secure by default” a reality.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Greg Garcia for being on the show. Connect with Greg Garcia on LinkedIn: <a href="https://www.linkedin.com/in/gregorytgarcia/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/gregorytgarcia/</a> </p><p>Learn about  the Health Sector Coordinating Council: <a href="https://healthsectorcouncil.org/" rel="noopener noreferrer" target="_blank">https://healthsectorcouncil.org/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can shared responsibility models improve healthcare cybersecurity?</p><p>In this episode, Greg Garcia joins Christian and Trevor to break down the evolving landscape of medical device cybersecurity from a national policy perspective. Together, they discuss the legacy device challenge, shared accountability, and how sector-wide collaboration is critical to progress. The episode drives home the message that cybersecurity is not just technical—it’s foundational to patient safety and innovation.</p><p>Greg Garcia is one of the people shaping the future of critical infrastructure cybersecurity—and he’s got the track record to back it up. As executive director of the Health Sector Coordinating Council Cybersecurity Working Group, he’s all about connecting the dots between policy, industry, and patient safety.</p><p><br></p><p>Key points: </p><p><br></p><p>(1:30) Cyber in Critical Infrastructure</p><p>* Greg’s career path from Homeland Security to health sector leadership.</p><p>* The Health Sector Coordinating Council’s mission.</p><p><br></p><p>(10:35) The Legacy Device Dilemma</p><p>* Medical device cybersecurity suffers from the finger-pointing between HDOs and MDMs.</p><p>* Managing unsupported devices and contractual accountability.</p><p><br></p><p>(18:05) Budget Gaps and Cultural Challenges</p><p>* Rural hospitals and underfunded providers struggle to keep up with cybersecurity expectations.</p><p>* The case for regulatory mandates to level the playing field.</p><p><br></p><p>(31:47) Regulation, Risk, and Big Ideas</p><p>* The idea of Authorization to Operate (ATO) for health tech.</p><p>* Comparisons to Department of Defense (DoD) and FedRAMP models are raised as a vision for healthcare.</p><p><br></p><p>(40:12) Culture Over Compliance</p><p>* Why data shows low medical device exploitation—but that’s no reason to relax.</p><p>* How to make “secure by default” a reality.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Greg Garcia for being on the show. Connect with Greg Garcia on LinkedIn: <a href="https://www.linkedin.com/in/gregorytgarcia/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/gregorytgarcia/</a> </p><p>Learn about  the Health Sector Coordinating Council: <a href="https://healthsectorcouncil.org/" rel="noopener noreferrer" target="_blank">https://healthsectorcouncil.org/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">3465fd39-6c27-481e-af6b-ee8d2326678f</guid><itunes:image href="https://artwork.captivate.fm/0addf2df-ecfd-4a3c-a98a-4969f0ca2fc7/ae7VOdsOFyFyHdEqS-FL0HWM.jpg"/><pubDate>Tue, 15 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/3465fd39-6c27-481e-af6b-ee8d2326678f.mp3" length="101649159" type="audio/mpeg"/><itunes:duration>52:54</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>28</itunes:episode><podcast:episode>28</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-cc7ecf2e-64b4-4c2d-952e-081d713b7487.json" type="application/json+chapters"/></item><item><title>Total Product Lifecycle Security: From Design to Disposal</title><itunes:title>Total Product Lifecycle Security: From Design to Disposal</itunes:title><description><![CDATA[<p>How well does your security strategy cover the entire product lifespan—from concept to decommissioning?</p><p>This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks. </p><p>Key points: </p><p><br></p><p>(1:50) Intro to TPLC and SPDF</p><p>* The importance of TPLC and SPDF in secure development.</p><p><br></p><p>(7:00) Update Vulnerabilities and OTA Risks</p><p>* An example of compromised keys in an otherwise secure over-the-air (OTA) process.</p><p>* Trade-offs between update convenience and security.</p><p><br></p><p>(12:16) Threat Modeling </p><p>* Threat modeling’s application to development environments.</p><p>* The overlooked risks of data storage locations and natural disasters.</p><p><br></p><p>(17:24) Infrastructure Challenges </p><p>* How clients struggled with infrastructure across hospital environments.</p><p>* How scripts and hardcoded passwords can introduce risk.</p><p><br></p><p>(19:56) Building a SPDF That Works</p><p>* Best practices: coding standards, multi-layer review, and automated testing.</p><p>* Secure development is like planning for your own death—it’s hard, but necessary.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How well does your security strategy cover the entire product lifespan—from concept to decommissioning?</p><p>This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks. </p><p>Key points: </p><p><br></p><p>(1:50) Intro to TPLC and SPDF</p><p>* The importance of TPLC and SPDF in secure development.</p><p><br></p><p>(7:00) Update Vulnerabilities and OTA Risks</p><p>* An example of compromised keys in an otherwise secure over-the-air (OTA) process.</p><p>* Trade-offs between update convenience and security.</p><p><br></p><p>(12:16) Threat Modeling </p><p>* Threat modeling’s application to development environments.</p><p>* The overlooked risks of data storage locations and natural disasters.</p><p><br></p><p>(17:24) Infrastructure Challenges </p><p>* How clients struggled with infrastructure across hospital environments.</p><p>* How scripts and hardcoded passwords can introduce risk.</p><p><br></p><p>(19:56) Building a SPDF That Works</p><p>* Best practices: coding standards, multi-layer review, and automated testing.</p><p>* Secure development is like planning for your own death—it’s hard, but necessary.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">18a5095a-bc44-456b-8475-fe4ed0131d0f</guid><itunes:image href="https://artwork.captivate.fm/d279eff1-8af6-4c7a-9271-b52d2ab64a97/yUsOP5xq-TsayV-iH0OOHLtP.jpg"/><pubDate>Tue, 08 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/18a5095a-bc44-456b-8475-fe4ed0131d0f.mp3" length="67260457" type="audio/mpeg"/><itunes:duration>35:00</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>27</itunes:episode><podcast:episode>27</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-a015bd4d-ff64-49ee-9c8b-9661d365fcb7.json" type="application/json+chapters"/></item><item><title>Why Cybersecurity and Quality Are One and the Same</title><itunes:title>Why Cybersecurity and Quality Are One and the Same</itunes:title><description><![CDATA[<p>How can medical device startups avoid missteps in cybersecurity, quality, and compliance? </p><p>In this episode, Trevor Slattery speaks with Ashkon Rasooli about the intersection of quality systems and cybersecurity in medical devices. They unpack why treating cybersecurity as a bolt-on checklist is ineffective and even dangerous. They also discuss regulatory realities, risk management frameworks, and how early-stage teams can avoid costly pitfalls by planning smarter from the start.</p><p>Ashkon Rasooli is the CEO of EnGenius Solutions, a boutique consulting firm focused on medical device software development. With a background in both hands-on coding and compliance, Ashkon helps medtech startups navigate quality systems and regulatory strategy. </p><p><br></p><p>Key points: </p><p><br></p><p>(0:31) Why Regulations and Cybersecurity Are Intertwined</p><p>* How EnGenius helps small medtech companies plan early.</p><p>* Challenging the idea that cybersecurity and QMS are separate disciplines.</p><p><br></p><p>(7:12) Planning Cybersecurity Early </p><p>* Business model, product design, and geography all shape your compliance path.</p><p><br></p><p>(12:16) Culture Over Checklists in MedTech Security</p><p>* Ashkon’s “Non-BS Manifesto” based on Agile principles.</p><p>* Real-world examples of ransomware causing patient harm.</p><p><br></p><p>(20:38) Why Probabilistic Risk Scoring Falls Short</p><p>* How exploitability trumps probability in FDA guidance.</p><p>* How cybersecurity attackers differ from typical safety failures.</p><p><br></p><p>(28:14) Planning Compliance</p><p>* Dick Cheney’s pacemaker becomes a cautionary tale of targeted threats.</p><p><br></p><p>Thanks to Ashkon Rasooli for being on the show. Connect with him: <a href="https://www.linkedin.com/in/ashkonrasooli/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/ashkonrasooli</a> </p><p>Check out EnGenius Solutions: <a href="https://www.engeniussolutions.com/" rel="noopener noreferrer" target="_blank">https://www.engeniussolutions.com</a></p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can medical device startups avoid missteps in cybersecurity, quality, and compliance? </p><p>In this episode, Trevor Slattery speaks with Ashkon Rasooli about the intersection of quality systems and cybersecurity in medical devices. They unpack why treating cybersecurity as a bolt-on checklist is ineffective and even dangerous. They also discuss regulatory realities, risk management frameworks, and how early-stage teams can avoid costly pitfalls by planning smarter from the start.</p><p>Ashkon Rasooli is the CEO of EnGenius Solutions, a boutique consulting firm focused on medical device software development. With a background in both hands-on coding and compliance, Ashkon helps medtech startups navigate quality systems and regulatory strategy. </p><p><br></p><p>Key points: </p><p><br></p><p>(0:31) Why Regulations and Cybersecurity Are Intertwined</p><p>* How EnGenius helps small medtech companies plan early.</p><p>* Challenging the idea that cybersecurity and QMS are separate disciplines.</p><p><br></p><p>(7:12) Planning Cybersecurity Early </p><p>* Business model, product design, and geography all shape your compliance path.</p><p><br></p><p>(12:16) Culture Over Checklists in MedTech Security</p><p>* Ashkon’s “Non-BS Manifesto” based on Agile principles.</p><p>* Real-world examples of ransomware causing patient harm.</p><p><br></p><p>(20:38) Why Probabilistic Risk Scoring Falls Short</p><p>* How exploitability trumps probability in FDA guidance.</p><p>* How cybersecurity attackers differ from typical safety failures.</p><p><br></p><p>(28:14) Planning Compliance</p><p>* Dick Cheney’s pacemaker becomes a cautionary tale of targeted threats.</p><p><br></p><p>Thanks to Ashkon Rasooli for being on the show. Connect with him: <a href="https://www.linkedin.com/in/ashkonrasooli/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/ashkonrasooli</a> </p><p>Check out EnGenius Solutions: <a href="https://www.engeniussolutions.com/" rel="noopener noreferrer" target="_blank">https://www.engeniussolutions.com</a></p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">aa53fc8d-0bda-4b79-a40e-578036850a4a</guid><itunes:image href="https://artwork.captivate.fm/07d18551-09da-460b-adb6-c51cddfc976f/xfkyRX4Gd4gxP6djmZQv-nKV.jpg"/><pubDate>Tue, 01 Jul 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/aa53fc8d-0bda-4b79-a40e-578036850a4a.mp3" length="71722358" type="audio/mpeg"/><itunes:duration>37:19</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>26</itunes:episode><podcast:episode>26</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-76927c2b-4f76-4078-9735-a25cec985ebe.json" type="application/json+chapters"/></item><item><title>Cybersecurity Labeling and MedTech Transparency</title><itunes:title>Cybersecurity Labeling and MedTech Transparency</itunes:title><description><![CDATA[<p>Why is cybersecurity labeling more than just a compliance checkbox for medical device companies?</p><p>In this episode, Christian and Trevor dive into the nuanced world of cybersecurity labeling for medical devices. They discuss the role of MDS2 and JSP2 documentation, labeling misconceptions, and how manufacturers can best disclose security information without overwhelming or misleading users.</p><p>Key points: </p><p><br></p><p>(6:30) Misconceptions About Cybersecurity Labeling</p><p>* Many manufacturers worry that disclosing risks will aid hackers, but that's flawed thinking.</p><p>* Distinctions between labeling as documentation and labeling as a control like a tamper-evident seal.</p><p>* Everyday product examples to illustrate why transparency in labeling matters.</p><p><br></p><p>(12:45) How Much Detail Is Enough?</p><p>* How deep a manufacturer should go with disclosures about encryption and risk.</p><p>* Why more detail is generally better and how to balance tech jargon with user readability.</p><p>* Different labeling needs based on whether a device is for consumers or hospitals.</p><p><br></p><p>(18:20) Context, Risk, and Communication</p><p>* Why not encrypting unnecessary data can backfire if a consumer is misinformed. </p><p>* How labeling must be contextual and tailored to a device’s function and data sensitivity.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* The Manufacturer Disclosure Statement for Medical Device Security (generally abbreviated as MDS2). </p><p>* The Medical Device and Health IT Joint Security Plan, version 2 (JSP2).</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></description><content:encoded><![CDATA[<p>Why is cybersecurity labeling more than just a compliance checkbox for medical device companies?</p><p>In this episode, Christian and Trevor dive into the nuanced world of cybersecurity labeling for medical devices. They discuss the role of MDS2 and JSP2 documentation, labeling misconceptions, and how manufacturers can best disclose security information without overwhelming or misleading users.</p><p>Key points: </p><p><br></p><p>(6:30) Misconceptions About Cybersecurity Labeling</p><p>* Many manufacturers worry that disclosing risks will aid hackers, but that's flawed thinking.</p><p>* Distinctions between labeling as documentation and labeling as a control like a tamper-evident seal.</p><p>* Everyday product examples to illustrate why transparency in labeling matters.</p><p><br></p><p>(12:45) How Much Detail Is Enough?</p><p>* How deep a manufacturer should go with disclosures about encryption and risk.</p><p>* Why more detail is generally better and how to balance tech jargon with user readability.</p><p>* Different labeling needs based on whether a device is for consumers or hospitals.</p><p><br></p><p>(18:20) Context, Risk, and Communication</p><p>* Why not encrypting unnecessary data can backfire if a consumer is misinformed. </p><p>* How labeling must be contextual and tailored to a device’s function and data sensitivity.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* The Manufacturer Disclosure Statement for Medical Device Security (generally abbreviated as MDS2). </p><p>* The Medical Device and Health IT Joint Security Plan, version 2 (JSP2).</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">9d4bba88-c3e3-4482-a776-43270e5b1f0c</guid><itunes:image href="https://artwork.captivate.fm/3d7c6224-ce37-42aa-b7db-d1f786af00a7/0PUBAPmuMRvjYQrUYG0ghYWx.jpg"/><pubDate>Tue, 24 Jun 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/9d4bba88-c3e3-4482-a776-43270e5b1f0c.mp3" length="59792889" type="audio/mpeg"/><itunes:duration>31:06</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>25</itunes:episode><podcast:episode>25</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-ea7d6cb1-9565-4868-836e-3643df6cca7c.json" type="application/json+chapters"/></item><item><title>From Concept to Compliance: A Guide to Med Device Approval</title><itunes:title>From Concept to Compliance: A Guide to Med Device Approval</itunes:title><description><![CDATA[<p>Med device manufacturers, are you setting up your quality system early enough in product development? Also, are you misunderstanding the FDA’s "guidance" documents—and risking rejection?</p><p>Today’s guests are Mark Swanson and Steve Gompertz of QRx Partners, and they’re passionate about helping medtech companies dodge the regulatory and quality pitfalls that derail so many startups. This episode explores how to classify your device properly, why cybersecurity documentation is required even for isolated software, and the evolving role of AI in medical technology. </p><p>Key points: </p><p><br></p><p>(02:11) Startup Failure and What QRx Solves</p><p>* Why many early-stage medtech startups fail.</p><p>* Startup optimism is contrasted with the harsh funding and regulatory realities.</p><p><br></p><p>(12:16) Classification Chaos and Regulatory Missteps</p><p>* The confusion around FDA’s product code database.</p><p><br></p><p>(17:55) AI and Quality Systems</p><p>* What qualifies as actual AI vs. marketing fluff.</p><p>* How regulators handle AI in submissions.</p><p><br></p><p>(31:22) National Vs State Regulations</p><p>* The critical need for manufacturers to understand state regulations. </p><p>* Why quality and regulatory planning must precede design.</p><p><br></p><p>Thanks to Mark Swanson and Steve Gompertz for being on the show. </p><p><br></p><p>Connect with Mark on LinkedIn: <a href="https://www.linkedin.com/in/markswansoncmq/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/markswansoncmq</a></p><p>Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/stevegompertz/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/stevegompertz</a></p><p>Learn more about QRx Partners: <a href="https://www.qrxpartners.com/" rel="noopener noreferrer" target="_blank">https://www.qrxpartners.com</a></p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>Med device manufacturers, are you setting up your quality system early enough in product development? Also, are you misunderstanding the FDA’s "guidance" documents—and risking rejection?</p><p>Today’s guests are Mark Swanson and Steve Gompertz of QRx Partners, and they’re passionate about helping medtech companies dodge the regulatory and quality pitfalls that derail so many startups. This episode explores how to classify your device properly, why cybersecurity documentation is required even for isolated software, and the evolving role of AI in medical technology. </p><p>Key points: </p><p><br></p><p>(02:11) Startup Failure and What QRx Solves</p><p>* Why many early-stage medtech startups fail.</p><p>* Startup optimism is contrasted with the harsh funding and regulatory realities.</p><p><br></p><p>(12:16) Classification Chaos and Regulatory Missteps</p><p>* The confusion around FDA’s product code database.</p><p><br></p><p>(17:55) AI and Quality Systems</p><p>* What qualifies as actual AI vs. marketing fluff.</p><p>* How regulators handle AI in submissions.</p><p><br></p><p>(31:22) National Vs State Regulations</p><p>* The critical need for manufacturers to understand state regulations. </p><p>* Why quality and regulatory planning must precede design.</p><p><br></p><p>Thanks to Mark Swanson and Steve Gompertz for being on the show. </p><p><br></p><p>Connect with Mark on LinkedIn: <a href="https://www.linkedin.com/in/markswansoncmq/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/markswansoncmq</a></p><p>Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/stevegompertz/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/stevegompertz</a></p><p>Learn more about QRx Partners: <a href="https://www.qrxpartners.com/" rel="noopener noreferrer" target="_blank">https://www.qrxpartners.com</a></p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">fe9cede5-6b0f-4afc-9855-1095949cd966</guid><itunes:image href="https://artwork.captivate.fm/1567453d-fb05-41dd-b174-5086dde40cd2/LYhdYwVtMNqYE_4nFASGIOWl.jpg"/><pubDate>Tue, 17 Jun 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/fe9cede5-6b0f-4afc-9855-1095949cd966.mp3" length="76282301" type="audio/mpeg"/><itunes:duration>39:41</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>24</itunes:episode><podcast:episode>24</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-df13984a-26e0-4087-a916-ea5f8c6a5e9d.json" type="application/json+chapters"/></item><item><title>Unpacking Post-Market Management and Incident Response for Medical Devices</title><itunes:title>Unpacking Post-Market Management and Incident Response for Medical Devices</itunes:title><description><![CDATA[<p>What should you do when a vulnerability is discovered in a medical device after it's already on the market?</p><p>This dives into post-market management and incident response for medical devices, exploring what happens when a device is hacked or a vulnerability is reported. Christian Espinosa and Trevor Slattery discuss the processes involved in identifying, triaging, and remediating vulnerabilities, emphasizing the unique challenges faced in the medical device sector. </p><p>Key points: </p><p><br></p><p>(8:01) Sources of Vulnerabilities and Tracking</p><p>* There are various sources for discovering vulnerabilities, including software bill of materials, CISA-CAV, annual penetration tests, coordinated vulnerability disclosure databases, etc. </p><p>* Standards and guidance for post-market management, including TIR-97 and FDA guidance.</p><p><br></p><p>(13:08) Managing False Positives and Risk Triage</p><p>* False positives are instances where a testing tool or scanner indicates a problem that doesn't actually exist.</p><p>* The critical importance of thoroughly investigating false positives in the post-market phase to avoid unnecessary fixing non-issues.</p><p>* The triage process for vulnerabilities. </p><p><br></p><p>(21:11) Exploitability and Coordinated Vulnerability Disclosure</p><p>* How exploitability factors, like authentication levels, proximity, and attack complexity, can change in the post-market phase.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* TIR-97: AAMI standard for post-market cybersecurity management</p><p>* FDA Guidance: Postmarket Management of Cybersecurity in Medical Devices</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What should you do when a vulnerability is discovered in a medical device after it's already on the market?</p><p>This dives into post-market management and incident response for medical devices, exploring what happens when a device is hacked or a vulnerability is reported. Christian Espinosa and Trevor Slattery discuss the processes involved in identifying, triaging, and remediating vulnerabilities, emphasizing the unique challenges faced in the medical device sector. </p><p>Key points: </p><p><br></p><p>(8:01) Sources of Vulnerabilities and Tracking</p><p>* There are various sources for discovering vulnerabilities, including software bill of materials, CISA-CAV, annual penetration tests, coordinated vulnerability disclosure databases, etc. </p><p>* Standards and guidance for post-market management, including TIR-97 and FDA guidance.</p><p><br></p><p>(13:08) Managing False Positives and Risk Triage</p><p>* False positives are instances where a testing tool or scanner indicates a problem that doesn't actually exist.</p><p>* The critical importance of thoroughly investigating false positives in the post-market phase to avoid unnecessary fixing non-issues.</p><p>* The triage process for vulnerabilities. </p><p><br></p><p>(21:11) Exploitability and Coordinated Vulnerability Disclosure</p><p>* How exploitability factors, like authentication levels, proximity, and attack complexity, can change in the post-market phase.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* TIR-97: AAMI standard for post-market cybersecurity management</p><p>* FDA Guidance: Postmarket Management of Cybersecurity in Medical Devices</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">f32dac61-d309-401d-bdb6-a6046be9fe72</guid><itunes:image href="https://artwork.captivate.fm/c78d800e-e22a-4dea-93db-d4370db21d69/tppQnCvebxOr_HLG6-z29g4H.jpg"/><pubDate>Tue, 10 Jun 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/f32dac61-d309-401d-bdb6-a6046be9fe72.mp3" length="54220680" type="audio/mpeg"/><itunes:duration>28:12</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>23</itunes:episode><podcast:episode>23</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-0fbb2ccb-7543-4a1c-8d08-5bdc4e6bed6a.json" type="application/json+chapters"/></item><item><title>AI in Medical Devices: Opportunities &amp; Regulation with Matt Lemay</title><itunes:title>AI in Medical Devices: Opportunities &amp; Regulation with Matt Lemay</itunes:title><description><![CDATA[<p>What does responsible AI implementation look like in medical devices?</p><p>This episode explores the intersection of AI, cybersecurity, and medical device regulation with guest Matt Lemay, CEO of Lemay.ai. Hosts Christian Espinosa and Trevor Slattery of Blue Goat Cyber dig into how AI models are trained, certified, and deployed in clinical contexts—and what can go wrong. </p><p>Key points: </p><p><br></p><p>(7:29) Data, Security, and Deployment Risks</p><p>* Training data inconsistencies and data drift in AI models.</p><p>* Cybersecurity concerns tied to cloud deployment and version control.</p><p><br></p><p>(11:48) Can AI Prescribe Medication?</p><p>* Legal and liability implications of AI autonomy in healthcare.</p><p><br></p><p>(22:35) Risks and Regulation</p><p>* Expectations for AI-enabled device regulations in the EU and US.</p><p><br></p><p>(33:35) AI Answers </p><p>* Thoughts on how AI has a hard time admitting it doesn't know the answer to something. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Matt Lemay for being on the show. Connect with Matt on LinkedIn: <a href="https://www.linkedin.com/in/mnlemay/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/mnlemay/</a></p><p>Lemay AI: <a href="https://www.lemay.ai/" rel="noopener noreferrer" target="_blank">https://www.lemay.ai/</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What does responsible AI implementation look like in medical devices?</p><p>This episode explores the intersection of AI, cybersecurity, and medical device regulation with guest Matt Lemay, CEO of Lemay.ai. Hosts Christian Espinosa and Trevor Slattery of Blue Goat Cyber dig into how AI models are trained, certified, and deployed in clinical contexts—and what can go wrong. </p><p>Key points: </p><p><br></p><p>(7:29) Data, Security, and Deployment Risks</p><p>* Training data inconsistencies and data drift in AI models.</p><p>* Cybersecurity concerns tied to cloud deployment and version control.</p><p><br></p><p>(11:48) Can AI Prescribe Medication?</p><p>* Legal and liability implications of AI autonomy in healthcare.</p><p><br></p><p>(22:35) Risks and Regulation</p><p>* Expectations for AI-enabled device regulations in the EU and US.</p><p><br></p><p>(33:35) AI Answers </p><p>* Thoughts on how AI has a hard time admitting it doesn't know the answer to something. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Matt Lemay for being on the show. Connect with Matt on LinkedIn: <a href="https://www.linkedin.com/in/mnlemay/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/mnlemay/</a></p><p>Lemay AI: <a href="https://www.lemay.ai/" rel="noopener noreferrer" target="_blank">https://www.lemay.ai/</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">c1629e5e-4b60-4ed5-bf0b-949e77a6e363</guid><itunes:image href="https://artwork.captivate.fm/d3d7fa59-6a5e-4923-ae59-257cdefd822f/hH7jb2PDjaxeHLKyUDe1JB2Z.jpg"/><pubDate>Tue, 03 Jun 2025 03:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/c1629e5e-4b60-4ed5-bf0b-949e77a6e363.mp3" length="81927763" type="audio/mpeg"/><itunes:duration>42:38</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>22</itunes:episode><podcast:episode>22</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-582fce00-90d7-4f80-84fe-2e36e8b35192.json" type="application/json+chapters"/></item><item><title>Essential Software Documentation for Med Device Manufacturers</title><itunes:title>Essential Software Documentation for Med Device Manufacturers</itunes:title><description><![CDATA[<p>What documents should engineers prepare to get ready for submitting a medical device to the FDA?</p><p>In this episode, Christian and Trevor dig into the underestimated role software documentation plays in cybersecurity, especially in the medical device space. They highlight how incomplete or contextless documentation can hinder everything from SBOM utility to regulatory compliance. With sharp insights and real-world examples, they make the case for elevating documentation as a strategic priority.</p><p>Key points:</p><p>(00:43) The Real Purpose of Documentation</p><p>* Software documentation is often seen as a checklist item rather than a strategic tool.</p><p>* Good documentation enables continuity and reduces knowledge silos.</p><p><br></p><p>(07:04) Security Starts with Documentation</p><p>* A lack of context in software can undermine their usefulness for vulnerability management.</p><p>* Documentation quality links with product security posture and incident response readiness.</p><p><br></p><p>(13:41) Regulation and Standards for Medical Device Documentation</p><p>* Documentation shouldn’t only meet minimum regulatory requirements.</p><p>* Strong documentation supports faster and safer decision-making during audits or breaches.</p><p><br></p><p>(18:11) Best Practices</p><p>* Trevor lists areas where developers consistently miss documentation opportunities (e.g., deprecated functions, third-party code).</p><p>* Christian outlines how consistent, contextual documentation helps new team members come up to speed.</p><p><br></p><p>(23:59) FDA Requirements</p><p>* The hosts recommend integrating documentation into sprint planning and CI/CD pipelines.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts</p>]]></description><content:encoded><![CDATA[<p>What documents should engineers prepare to get ready for submitting a medical device to the FDA?</p><p>In this episode, Christian and Trevor dig into the underestimated role software documentation plays in cybersecurity, especially in the medical device space. They highlight how incomplete or contextless documentation can hinder everything from SBOM utility to regulatory compliance. With sharp insights and real-world examples, they make the case for elevating documentation as a strategic priority.</p><p>Key points:</p><p>(00:43) The Real Purpose of Documentation</p><p>* Software documentation is often seen as a checklist item rather than a strategic tool.</p><p>* Good documentation enables continuity and reduces knowledge silos.</p><p><br></p><p>(07:04) Security Starts with Documentation</p><p>* A lack of context in software can undermine their usefulness for vulnerability management.</p><p>* Documentation quality links with product security posture and incident response readiness.</p><p><br></p><p>(13:41) Regulation and Standards for Medical Device Documentation</p><p>* Documentation shouldn’t only meet minimum regulatory requirements.</p><p>* Strong documentation supports faster and safer decision-making during audits or breaches.</p><p><br></p><p>(18:11) Best Practices</p><p>* Trevor lists areas where developers consistently miss documentation opportunities (e.g., deprecated functions, third-party code).</p><p>* Christian outlines how consistent, contextual documentation helps new team members come up to speed.</p><p><br></p><p>(23:59) FDA Requirements</p><p>* The hosts recommend integrating documentation into sprint planning and CI/CD pipelines.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">5eb3bdd6-57e0-4bcf-a558-cfb71e36f21d</guid><itunes:image href="https://artwork.captivate.fm/4c35051f-edc0-4602-9a63-7a01985bceb9/IdCZy3YI2NSWR108myjfv-Gs.jpg"/><pubDate>Tue, 27 May 2025 04:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/5eb3bdd6-57e0-4bcf-a558-cfb71e36f21d.mp3" length="53175911" type="audio/mpeg"/><itunes:duration>27:39</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>21</itunes:episode><podcast:episode>21</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-3d7f22d0-4bc9-4a26-ab8e-04cfffd6cb36.json" type="application/json+chapters"/></item><item><title>The Human Factor in MedTech Design with Dylan Horvath</title><itunes:title>The Human Factor in MedTech Design with Dylan Horvath</itunes:title><description><![CDATA[<p>How can human-centered design influence medical device cybersecurity?</p><p>In this episode, Christian Espinosa chats with Dylan Horvath of Cortex Design about the powerful intersection of human-centered design and medical device cybersecurity. They explore how usability, trust, and empathy can shape safer, smarter devices from the start. Dylan also shares valuable insights into building design teams, learning from failure, and driving innovation in regulated industries.</p><p>Dylan Horvath is a passionate industrial designer who’s spent decades shaping how people interact with technology. As the founder and CEO of Cortex Design, he’s all about blending creativity and engineering to build medical devices that actually work for people. </p><p>(00:30) Design Thinking in MedTech</p><p>* Christian and Dylan discuss the similarities between design and cybersecurity.</p><p><br></p><p>(07:08) The Design Process</p><p>* How psychological safety and curiosity are foundations for team success.</p><p>* Cortex’s lean, iterative process and fast prototyping.</p><p><br></p><p>(14:18) Lessons Learned</p><p>* Dylan reflects on design failures and what they taught him.</p><p>* The balance between regulation and innovation in MedTech.</p><p><br></p><p>(21:26) Security and Usability</p><p>* Dylan’s thoughts on how threat modeling could better include design teams.</p><p>* The trade-offs between usability and strong security in med devices.</p><p><br></p><p>(26:36) Design Challenges</p><p>* User experience is critical, and overlooking it can lead to products that are difficult to use and unappealing to the market. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Dylan Horvath for being on the show. Connect with Dylan on LinkedIn: <a href="https://www.linkedin.com/in/dylan-horvath/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/dylan-horvath/</a> </p><p>Learn more about Cortex Design: <a href="https://cortex-design.com/" rel="noopener noreferrer" target="_blank">https://cortex-design.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can human-centered design influence medical device cybersecurity?</p><p>In this episode, Christian Espinosa chats with Dylan Horvath of Cortex Design about the powerful intersection of human-centered design and medical device cybersecurity. They explore how usability, trust, and empathy can shape safer, smarter devices from the start. Dylan also shares valuable insights into building design teams, learning from failure, and driving innovation in regulated industries.</p><p>Dylan Horvath is a passionate industrial designer who’s spent decades shaping how people interact with technology. As the founder and CEO of Cortex Design, he’s all about blending creativity and engineering to build medical devices that actually work for people. </p><p>(00:30) Design Thinking in MedTech</p><p>* Christian and Dylan discuss the similarities between design and cybersecurity.</p><p><br></p><p>(07:08) The Design Process</p><p>* How psychological safety and curiosity are foundations for team success.</p><p>* Cortex’s lean, iterative process and fast prototyping.</p><p><br></p><p>(14:18) Lessons Learned</p><p>* Dylan reflects on design failures and what they taught him.</p><p>* The balance between regulation and innovation in MedTech.</p><p><br></p><p>(21:26) Security and Usability</p><p>* Dylan’s thoughts on how threat modeling could better include design teams.</p><p>* The trade-offs between usability and strong security in med devices.</p><p><br></p><p>(26:36) Design Challenges</p><p>* User experience is critical, and overlooking it can lead to products that are difficult to use and unappealing to the market. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Dylan Horvath for being on the show. Connect with Dylan on LinkedIn: <a href="https://www.linkedin.com/in/dylan-horvath/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/dylan-horvath/</a> </p><p>Learn more about Cortex Design: <a href="https://cortex-design.com/" rel="noopener noreferrer" target="_blank">https://cortex-design.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">4a59674a-8c4a-4c26-851a-f673a7208ae0</guid><itunes:image href="https://artwork.captivate.fm/15e2c934-dbf4-4acb-92f3-2d960e2463c9/44zIO_QyCdlY32pecRlFjI2K.jpg"/><pubDate>Tue, 20 May 2025 04:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/4a59674a-8c4a-4c26-851a-f673a7208ae0.mp3" length="67781022" type="audio/mpeg"/><itunes:duration>35:16</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>20</itunes:episode><podcast:episode>20</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-6e2c4d9f-d1d2-464c-9101-75ef651392b0.json" type="application/json+chapters"/></item><item><title>Master Medical Device Cybersecurity: Avoid FDA Delays | Blue Goat Cyber Webinar</title><itunes:title>Master Medical Device Cybersecurity: Avoid FDA Delays | Blue Goat Cyber Webinar</itunes:title><description><![CDATA[<p>How can medical device manufacturers meet FDA cybersecurity requirements the first time around?</p><p>What are the most significant challenges medical device manufacturers face in ensuring FDA cybersecurity compliance?</p><p>In this webinar, Trevor Slattery, CTO of Blue Goat Cyber, dives into what it takes to master medical device cybersecurity and avoid costly delays with the FDA. He outlines common pitfalls companies face, including poor documentation, lack of threat modeling, and mismatched security controls. Watch this webinar for practical, actionable advice for navigating FDA expectations and building more secure, compliant devices.</p><p>Topics Trevor explores in this webinar: </p><p><br></p><p>(00:30) Why Devices Get FDA Cybersecurity Pushback</p><p><br></p><p>* Many devices are rejected due to poor threat models and vague documentation.</p><p><br></p><p>(06:36) What the FDA Is Really Looking For</p><p><br></p><p>* The FDA expects a structured, traceable cybersecurity story from architecture to testing.</p><p><br></p><p>(13:20) Building Strong Documentation and Threat Models</p><p><br></p><p>* Good threat modeling identifies specific risks and aligns them with appropriate mitigations.</p><p><br></p><p>* Fuzzy, generic statements about “zero trust” or “encryption” are red flags for reviewers.</p><p><br></p><p>(19:56) SBOMs, Known Vulnerabilities, and FDA Red Flags</p><p><br></p><p>* FDA reviewers expect to see every SBOM component mapped to known vulnerabilities.</p><p><br></p><p>* Missing VEX (Vulnerability Exploitability eXchange) documentation slows down reviews.</p><p><br></p><p>(26:54) What to Do If You’re Stuck or Behind Schedule</p><p><br></p><p>* If you’re behind, don't scramble—step back and rebuild the cybersecurity narrative.</p><p><br></p><p>* Professional guidance can help realign your strategy with FDA expectations.</p><p><br></p><p>This webinar was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>How can medical device manufacturers meet FDA cybersecurity requirements the first time around?</p><p>What are the most significant challenges medical device manufacturers face in ensuring FDA cybersecurity compliance?</p><p>In this webinar, Trevor Slattery, CTO of Blue Goat Cyber, dives into what it takes to master medical device cybersecurity and avoid costly delays with the FDA. He outlines common pitfalls companies face, including poor documentation, lack of threat modeling, and mismatched security controls. Watch this webinar for practical, actionable advice for navigating FDA expectations and building more secure, compliant devices.</p><p>Topics Trevor explores in this webinar: </p><p><br></p><p>(00:30) Why Devices Get FDA Cybersecurity Pushback</p><p><br></p><p>* Many devices are rejected due to poor threat models and vague documentation.</p><p><br></p><p>(06:36) What the FDA Is Really Looking For</p><p><br></p><p>* The FDA expects a structured, traceable cybersecurity story from architecture to testing.</p><p><br></p><p>(13:20) Building Strong Documentation and Threat Models</p><p><br></p><p>* Good threat modeling identifies specific risks and aligns them with appropriate mitigations.</p><p><br></p><p>* Fuzzy, generic statements about “zero trust” or “encryption” are red flags for reviewers.</p><p><br></p><p>(19:56) SBOMs, Known Vulnerabilities, and FDA Red Flags</p><p><br></p><p>* FDA reviewers expect to see every SBOM component mapped to known vulnerabilities.</p><p><br></p><p>* Missing VEX (Vulnerability Exploitability eXchange) documentation slows down reviews.</p><p><br></p><p>(26:54) What to Do If You’re Stuck or Behind Schedule</p><p><br></p><p>* If you’re behind, don't scramble—step back and rebuild the cybersecurity narrative.</p><p><br></p><p>* Professional guidance can help realign your strategy with FDA expectations.</p><p><br></p><p>This webinar was brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">f76baa72-6bfb-4724-82e8-31be8464f17f</guid><itunes:image href="https://artwork.captivate.fm/9ca0524c-5b3d-4c42-a14a-561b913e055c/zTIMX3bphHy0FrcRHMem5e4G.jpg"/><pubDate>Tue, 13 May 2025 09:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/f76baa72-6bfb-4724-82e8-31be8464f17f.mp3" length="63941655" type="audio/mpeg"/><itunes:duration>33:18</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType></item><item><title>Data Protection in Medical Devices: A Deep Dive with Kevin Derr</title><itunes:title>Data Protection in Medical Devices: A Deep Dive with Kevin Derr</itunes:title><description><![CDATA[<p>How can medical device companies own their data without compromising security?</p><p>In this episode, Kevin Derr from NeuronSphere joins Christian and Trevor to dive into the intersection of cybersecurity, compliance, and innovation in the medtech world. They also explore why data ownership and secure system architecture are foundational for FDA compliance and patient safety. </p><p>Key points: </p><p><br></p><p>(0:47) From Big MedTech to Startup</p><p>* Kevin shares his journey from Stryker and J&amp;J to co-founding NeuronSphere, which was built to simplify the creation of compliant data products for medtech engineers.</p><p>* NeuronSphere is like a toolkit allows companies to retain full data ownership while meeting FDA and cybersecurity requirements.</p><p><br></p><p>(5:21) Ownership, Trust, and Compliance</p><p>* Vendor solutions often fall short during V&amp;V, triggering costly compliance upgrades.</p><p>* NeuronSphere keeps ownership and compliance within the manufacturer's own infrastructure.</p><p><br></p><p>(11:12) Misconfigurations and Human Error</p><p>* Misconfigured S3 buckets and default credentials are common sources of breaches.</p><p>* Even the FBI and CIA have faced major data exposures from simple mistakes.</p><p>* Human error remains the biggest vulnerability.</p><p><br></p><p>(17:00) Balancing Security and Functionality</p><p>* FDA’s focus is patient safety and effectiveness, not just data protection.</p><p>* Secure coding is often deprioritized due to deadlines and lack of training.</p><p><br></p><p>(33:21) FDA Guidance </p><p>* The new FDA cybersecurity guidance is moving security discussions earlier in the development lifecycle.</p><p>* Startups are now forced to consider data flow and security posture before first-in-human trials.</p><p><br></p><p>Thanks to Kevin Derr for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevinderr/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevinderr/</a> </p><p><br></p><p>Learn about NeuronSphere: <a href="https://www.neuronsphere.io/" rel="noopener noreferrer" target="_blank">https://www.neuronsphere.io/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></description><content:encoded><![CDATA[<p>How can medical device companies own their data without compromising security?</p><p>In this episode, Kevin Derr from NeuronSphere joins Christian and Trevor to dive into the intersection of cybersecurity, compliance, and innovation in the medtech world. They also explore why data ownership and secure system architecture are foundational for FDA compliance and patient safety. </p><p>Key points: </p><p><br></p><p>(0:47) From Big MedTech to Startup</p><p>* Kevin shares his journey from Stryker and J&amp;J to co-founding NeuronSphere, which was built to simplify the creation of compliant data products for medtech engineers.</p><p>* NeuronSphere is like a toolkit allows companies to retain full data ownership while meeting FDA and cybersecurity requirements.</p><p><br></p><p>(5:21) Ownership, Trust, and Compliance</p><p>* Vendor solutions often fall short during V&amp;V, triggering costly compliance upgrades.</p><p>* NeuronSphere keeps ownership and compliance within the manufacturer's own infrastructure.</p><p><br></p><p>(11:12) Misconfigurations and Human Error</p><p>* Misconfigured S3 buckets and default credentials are common sources of breaches.</p><p>* Even the FBI and CIA have faced major data exposures from simple mistakes.</p><p>* Human error remains the biggest vulnerability.</p><p><br></p><p>(17:00) Balancing Security and Functionality</p><p>* FDA’s focus is patient safety and effectiveness, not just data protection.</p><p>* Secure coding is often deprioritized due to deadlines and lack of training.</p><p><br></p><p>(33:21) FDA Guidance </p><p>* The new FDA cybersecurity guidance is moving security discussions earlier in the development lifecycle.</p><p>* Startups are now forced to consider data flow and security posture before first-in-human trials.</p><p><br></p><p>Thanks to Kevin Derr for being on the show. Connect with Kevin on LinkedIn: <a href="https://www.linkedin.com/in/kevinderr/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/kevinderr/</a> </p><p><br></p><p>Learn about NeuronSphere: <a href="https://www.neuronsphere.io/" rel="noopener noreferrer" target="_blank">https://www.neuronsphere.io/</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">3d466a43-e875-4b4d-8e80-76410060ff88</guid><itunes:image href="https://artwork.captivate.fm/e332a1d9-3920-4320-a945-91b8bccd9086/CPMT29NzxCtYlGTtBsmACy_S.jpg"/><pubDate>Tue, 06 May 2025 04:00:00 -0700</pubDate><enclosure url="https://episodes.captivate.fm/episode/3d466a43-e875-4b4d-8e80-76410060ff88.mp3" length="88833433" type="audio/mpeg"/><itunes:duration>46:14</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>19</itunes:episode><podcast:episode>19</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-17b656cf-dbdd-4861-a8bc-59ae082a5aae.json" type="application/json+chapters"/></item><item><title>Early Cyber Strategies for MedTech Trailblazers</title><itunes:title>Early Cyber Strategies for MedTech Trailblazers</itunes:title><description><![CDATA[<p>What are some strategies founders can use to incorporate cybersecurity into the early stages of developing a medtech product? </p><p>In this episode, Christian and Trevor break down the critical role of cybersecurity in early-stage medtech startups. They explore why cybersecurity is often overlooked, what the real-world consequences are, and how startups can shift left to avoid costly pitfalls. From VC funding to FDA requirements, they offer a roadmap for founders who want to get it right from the start.</p><p>Key points: </p><p>(0:33) The Cybersecurity Awareness Gap</p><p>* Many early-stage medtech startups don't consider cybersecurity until it's too late.</p><p><br></p><p>(5:36) Budgeting for Cyber from the Start</p><p>* Cybersecurity costs extend beyond hiring a firm—developers must also build secure code.</p><p>* Developers with medtech experience and adherence to IEC/ISO standards are essential.</p><p><br></p><p>(10:18) Picking the Right Dev Partners</p><p>* Evaluate software firms based on documentation, process, and compliance with medtech standards.</p><p>* Founders need teams who think about security proactively, not reactively.</p><p><br></p><p>(15:42) Cybersecurity as a Funding Factor</p><p>* VCs now look for cybersecurity as part of the startup's roadmap.</p><p>* Cybersecurity must be iterative—not a one-time checkbox before FDA submission.</p><p><br></p><p>(20:22) Safety and Security </p><p>* Cybersecurity isn't just about software—hardware choices matter too.</p><p>* Awareness of risk classes (Class A, B, C) impacts cybersecurity needs.</p><p>* Safety and security are intertwined, especially when patient harm is possible.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* FDA Guidance on Cybersecurity in Medical Devices </p><p><br></p><p>* ISO 13485 – Medical Devices Quality Management Systems</p><p><br></p><p>* IEC 62304 – Medical Device Software Lifecycle Processes</p><p><br></p><p>* AAMI TIR57 – Principles for Medical Device Security Risk Management</p><p><br></p><p>* ISO 14971 – Application of Risk Management to Medical Devices</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are some strategies founders can use to incorporate cybersecurity into the early stages of developing a medtech product? </p><p>In this episode, Christian and Trevor break down the critical role of cybersecurity in early-stage medtech startups. They explore why cybersecurity is often overlooked, what the real-world consequences are, and how startups can shift left to avoid costly pitfalls. From VC funding to FDA requirements, they offer a roadmap for founders who want to get it right from the start.</p><p>Key points: </p><p>(0:33) The Cybersecurity Awareness Gap</p><p>* Many early-stage medtech startups don't consider cybersecurity until it's too late.</p><p><br></p><p>(5:36) Budgeting for Cyber from the Start</p><p>* Cybersecurity costs extend beyond hiring a firm—developers must also build secure code.</p><p>* Developers with medtech experience and adherence to IEC/ISO standards are essential.</p><p><br></p><p>(10:18) Picking the Right Dev Partners</p><p>* Evaluate software firms based on documentation, process, and compliance with medtech standards.</p><p>* Founders need teams who think about security proactively, not reactively.</p><p><br></p><p>(15:42) Cybersecurity as a Funding Factor</p><p>* VCs now look for cybersecurity as part of the startup's roadmap.</p><p>* Cybersecurity must be iterative—not a one-time checkbox before FDA submission.</p><p><br></p><p>(20:22) Safety and Security </p><p>* Cybersecurity isn't just about software—hardware choices matter too.</p><p>* Awareness of risk classes (Class A, B, C) impacts cybersecurity needs.</p><p>* Safety and security are intertwined, especially when patient harm is possible.</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* FDA Guidance on Cybersecurity in Medical Devices </p><p><br></p><p>* ISO 13485 – Medical Devices Quality Management Systems</p><p><br></p><p>* IEC 62304 – Medical Device Software Lifecycle Processes</p><p><br></p><p>* AAMI TIR57 – Principles for Medical Device Security Risk Management</p><p><br></p><p>* ISO 14971 – Application of Risk Management to Medical Devices</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">60f8a63b-ad60-41b3-95db-d14c250c8724</guid><itunes:image href="https://artwork.captivate.fm/0a36761f-8d13-475e-bbce-32cd95b771d7/GwRQLcbBy2fZbkGmiBBkzRZf.jpg"/><pubDate>Tue, 29 Apr 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/1925fe87-ffd8-43b2-8341-8c4d154b04ba/MDC-18-Audio.mp3" length="53288117" type="audio/mpeg"/><itunes:duration>27:44</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>18</itunes:episode><podcast:episode>18</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-1925fe87-ffd8-43b2-8341-8c4d154b04ba.json" type="application/json+chapters"/></item><item><title>Cybersecurity Challenges &amp; Trends in US Healthcare with Paul-Lukas Hoffschmidt</title><itunes:title>Cybersecurity Challenges &amp; Trends in US Healthcare with Paul-Lukas Hoffschmidt</itunes:title><description><![CDATA[<p>If you’re launching a medtech product, what should you know about market access, cybersecurity, reimbursement challenges, and customer education? </p><p>In this episode, Christian and Trevor discuss the challenges and opportunities facing medtech startups with guest Paul-Lukas Hoffschmidt, CEO of Alpha Sophia. This conversation covers trends in US healthcare, the importance of cybersecurity and interoperability, and strategies for successful product commercialization. </p><p>Key points: </p><p><br></p><p>(00:53) Intro to Alpha Sophia</p><p>* Alpha Sophia’s commercial intelligence platform assists medical device, digital health, and life sciences companies in identifying the right healthcare providers for their products. </p><p><br></p><p>(02:04) MedTech Trends</p><p>* The US healthcare market is increasingly important for medtech startups, partly due to slower regulatory processes in Europe. </p><p><br></p><p>(06:43) Hurdles Facing MedTech Startups</p><p>* Identifying the right potential customers (physicians, practices, hospitals) is a significant challenge. </p><p>* Gaining the attention of busy doctors requires a creative, omnichannel approach. </p><p><br></p><p>(12:11) Cybersecurity and Purchasing Decisions</p><p>* Potential buyers expect medical devices to be secure, viewing regulatory approval as a baseline. </p><p>* Interoperability is increasingly important as healthcare providers want devices that integrate into their existing systems. </p><p><br></p><p>(24:05) Integrating Cybersecurity Early</p><p>* Cybersecurity should be considered from the initial product requirements phase. </p><p><br></p><p>(32:53) Advice for MedTech Innovators</p><p>* Medtech innovation is a long journey requiring careful planning and resource management. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Paul-Lukas Hoffschmidt for being on the show. </p><p><br></p><p>Learn about Alpha Sophia’s intelligence platform: <a href="https://www.alphasophia.com/" rel="noopener noreferrer" target="_blank">https://www.Alpha Sophia.com/</a> </p><p>Connect with Paul-Lukas on LinkedIn: <a href="https://www.linkedin.com/in/hoffschmidt/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/hoffschmidt/</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>If you’re launching a medtech product, what should you know about market access, cybersecurity, reimbursement challenges, and customer education? </p><p>In this episode, Christian and Trevor discuss the challenges and opportunities facing medtech startups with guest Paul-Lukas Hoffschmidt, CEO of Alpha Sophia. This conversation covers trends in US healthcare, the importance of cybersecurity and interoperability, and strategies for successful product commercialization. </p><p>Key points: </p><p><br></p><p>(00:53) Intro to Alpha Sophia</p><p>* Alpha Sophia’s commercial intelligence platform assists medical device, digital health, and life sciences companies in identifying the right healthcare providers for their products. </p><p><br></p><p>(02:04) MedTech Trends</p><p>* The US healthcare market is increasingly important for medtech startups, partly due to slower regulatory processes in Europe. </p><p><br></p><p>(06:43) Hurdles Facing MedTech Startups</p><p>* Identifying the right potential customers (physicians, practices, hospitals) is a significant challenge. </p><p>* Gaining the attention of busy doctors requires a creative, omnichannel approach. </p><p><br></p><p>(12:11) Cybersecurity and Purchasing Decisions</p><p>* Potential buyers expect medical devices to be secure, viewing regulatory approval as a baseline. </p><p>* Interoperability is increasingly important as healthcare providers want devices that integrate into their existing systems. </p><p><br></p><p>(24:05) Integrating Cybersecurity Early</p><p>* Cybersecurity should be considered from the initial product requirements phase. </p><p><br></p><p>(32:53) Advice for MedTech Innovators</p><p>* Medtech innovation is a long journey requiring careful planning and resource management. </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Paul-Lukas Hoffschmidt for being on the show. </p><p><br></p><p>Learn about Alpha Sophia’s intelligence platform: <a href="https://www.alphasophia.com/" rel="noopener noreferrer" target="_blank">https://www.Alpha Sophia.com/</a> </p><p>Connect with Paul-Lukas on LinkedIn: <a href="https://www.linkedin.com/in/hoffschmidt/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/hoffschmidt/</a></p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">13888dbd-2b5b-44e4-8ad4-9c0190f8750e</guid><itunes:image href="https://artwork.captivate.fm/c956e44e-ec55-4e5c-b9f4-b2034f5986cb/r2wHdONHa89ICJM1zpSFare9.jpg"/><pubDate>Tue, 22 Apr 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/200a7de0-07c7-4b71-8732-799593f9cc96/MDC-17-Audio-V2.mp3" length="50503243" type="audio/mpeg"/><itunes:duration>34:58</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>17</itunes:episode><podcast:episode>17</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-200a7de0-07c7-4b71-8732-799593f9cc96.json" type="application/json+chapters"/></item><item><title>Collaboration is Key: Bridging the Gap Between Developers and Cybersecurity Experts</title><itunes:title>Collaboration is Key: Bridging the Gap Between Developers and Cybersecurity Experts</itunes:title><description><![CDATA[<p>What are some of the biggest barriers to effective collaboration between coders and cyber experts, and how can they be overcome?</p><p>This episode explores the essential components of successful collaboration and teamwork. The discussion delves into common challenges teams face and practical strategies for improving communication and trust. </p><p>Key points that Christian and Trevor explore: </p><p><br></p><p>(00:31) Developer-Cybersecurity Divide</p><p>* The hosts open up about ego and emotional intelligence in cybersecurity and development.</p><p>* Developers often respond defensively to security findings, creating friction during collaboration.</p><p><br></p><p>(04:46) Incomplete Fixes and Communication Gaps</p><p>* Clients sometimes apply superficial fixes or disagree with findings due to misunderstanding the issue.</p><p>* Ultimately, clients must accept or reject risks, but they must fully understand them first.</p><p><br></p><p>(07:40) Is Dual Expertise Feasible?</p><p>* The distinct expertise needed for development and cybersecurity makes dual mastery unlikely.</p><p><br></p><p>(12:26) Business Pressure </p><p>* Unrealistic timelines often force teams to release insecure products under pressure from leadership.</p><p>* Compliance-driven cybersecurity efforts are seen as necessary evils rather than strategic investments.</p><p><br></p><p>(17:29) DevSecOps &amp; Misconfigurations</p><p>* Despite years of talk, DevSecOps adoption remains limited due to cost, culture, and lack of education.</p><p>* Misconfigurations and human error are far more common than code exploits in real-world breaches.</p><p><br></p><p>(22:11) Tools &amp; Tradeoffs</p><p>* Secure pipelines and scanning tools are helpful but not foolproof; many vulnerabilities still require human testing.</p><p>* Developers can drastically reduce risks by understanding and applying core cybersecurity best practices.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are some of the biggest barriers to effective collaboration between coders and cyber experts, and how can they be overcome?</p><p>This episode explores the essential components of successful collaboration and teamwork. The discussion delves into common challenges teams face and practical strategies for improving communication and trust. </p><p>Key points that Christian and Trevor explore: </p><p><br></p><p>(00:31) Developer-Cybersecurity Divide</p><p>* The hosts open up about ego and emotional intelligence in cybersecurity and development.</p><p>* Developers often respond defensively to security findings, creating friction during collaboration.</p><p><br></p><p>(04:46) Incomplete Fixes and Communication Gaps</p><p>* Clients sometimes apply superficial fixes or disagree with findings due to misunderstanding the issue.</p><p>* Ultimately, clients must accept or reject risks, but they must fully understand them first.</p><p><br></p><p>(07:40) Is Dual Expertise Feasible?</p><p>* The distinct expertise needed for development and cybersecurity makes dual mastery unlikely.</p><p><br></p><p>(12:26) Business Pressure </p><p>* Unrealistic timelines often force teams to release insecure products under pressure from leadership.</p><p>* Compliance-driven cybersecurity efforts are seen as necessary evils rather than strategic investments.</p><p><br></p><p>(17:29) DevSecOps &amp; Misconfigurations</p><p>* Despite years of talk, DevSecOps adoption remains limited due to cost, culture, and lack of education.</p><p>* Misconfigurations and human error are far more common than code exploits in real-world breaches.</p><p><br></p><p>(22:11) Tools &amp; Tradeoffs</p><p>* Secure pipelines and scanning tools are helpful but not foolproof; many vulnerabilities still require human testing.</p><p>* Developers can drastically reduce risks by understanding and applying core cybersecurity best practices.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">28241e38-0c1f-4314-a221-4c6df1a1bc59</guid><itunes:image href="https://artwork.captivate.fm/604a02e8-602b-4c36-a965-a027519a7e22/WTBQAw9QDqCT84GLLSrpRCGn.jpg"/><pubDate>Tue, 15 Apr 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/039707c7-d62c-4300-8f7d-be4e7c34a68a/MDC-16-Audio.mp3" length="57568983" type="audio/mpeg"/><itunes:duration>29:57</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>16</itunes:episode><podcast:episode>16</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-039707c7-d62c-4300-8f7d-be4e7c34a68a.json" type="application/json+chapters"/></item><item><title>Commercialize Your Medtech with Craig T Ingram</title><itunes:title>Commercialize Your Medtech with Craig T Ingram</itunes:title><description><![CDATA[<p>What are the 10 essential components of a successful commercialization plan in the medtech industry, and why are they often overlooked?</p><p>This episode explores the critical role of commercialization in the medtech industry. The conversation explores the reasons behind the high failure rate of medtech startups and emphasizes the importance of a comprehensive commercialization plan, cybersecurity considerations, and the pursuit of wisdom over speed. </p><p>Today’s guest is Craig T. Ingram, a medtech and healthcare technology consultant who helps companies avoid going broke by focusing on effective commercialization strategies. Craig is the Chief Commercialization Strategy and Growth Advisor for Int'l Commercialization Growth Partners. </p><p>Key points: </p><p><br></p><p>(3:21) The Commercialization Roadmap</p><p><br></p><p>* Many companies lack a written commercialization roadmap, focusing instead on sales and marketing plans. </p><p>* Key components of commercialization include regulatory affairs, product design, production, and alliances and partnerships, which are often overlooked. </p><p><br></p><p>(10:11) Cybersecurity </p><p><br></p><p>* Cybersecurity is not evil but a critical necessity, similar to insurance, to protect against malicious activity and data breaches. </p><p>* Cybersecurity can be viewed as a means of preventing malicious activity rather than just protecting data. </p><p><br></p><p>(24:51) Value vs Expertise</p><p><br></p><p>* Many manufacturers struggle to evaluate cybersecurity vendors, often prioritizing cost over specialized expertise. </p><p>* Applying the same commercialization strategies as large companies is ineffective for startups and small to medium-sized enterprises. </p><p><br></p><p>(34:20) Wisdom vs. Speed in Business</p><p><br></p><p>* The "move fast and break things" mentality prevalent in Silicon Valley can be detrimental to proper commercialization. </p><p>* Effective commercialization requires a focus on getting it right rather than being right, and a willingness to learn and adapt.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Craig T. Ingram for being on the show. Connect with Craig on LinkedIn: <a href="https://www.linkedin.com/in/craigtingram" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/craigtingram</a> </p><p><br></p><p>Learn about Int'l Commercialization Growth Partners: <a href="https://www.medicalsalesgrowth.com/" rel="noopener noreferrer" target="_blank">https://www.medicalsalesgrowth.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are the 10 essential components of a successful commercialization plan in the medtech industry, and why are they often overlooked?</p><p>This episode explores the critical role of commercialization in the medtech industry. The conversation explores the reasons behind the high failure rate of medtech startups and emphasizes the importance of a comprehensive commercialization plan, cybersecurity considerations, and the pursuit of wisdom over speed. </p><p>Today’s guest is Craig T. Ingram, a medtech and healthcare technology consultant who helps companies avoid going broke by focusing on effective commercialization strategies. Craig is the Chief Commercialization Strategy and Growth Advisor for Int'l Commercialization Growth Partners. </p><p>Key points: </p><p><br></p><p>(3:21) The Commercialization Roadmap</p><p><br></p><p>* Many companies lack a written commercialization roadmap, focusing instead on sales and marketing plans. </p><p>* Key components of commercialization include regulatory affairs, product design, production, and alliances and partnerships, which are often overlooked. </p><p><br></p><p>(10:11) Cybersecurity </p><p><br></p><p>* Cybersecurity is not evil but a critical necessity, similar to insurance, to protect against malicious activity and data breaches. </p><p>* Cybersecurity can be viewed as a means of preventing malicious activity rather than just protecting data. </p><p><br></p><p>(24:51) Value vs Expertise</p><p><br></p><p>* Many manufacturers struggle to evaluate cybersecurity vendors, often prioritizing cost over specialized expertise. </p><p>* Applying the same commercialization strategies as large companies is ineffective for startups and small to medium-sized enterprises. </p><p><br></p><p>(34:20) Wisdom vs. Speed in Business</p><p><br></p><p>* The "move fast and break things" mentality prevalent in Silicon Valley can be detrimental to proper commercialization. </p><p>* Effective commercialization requires a focus on getting it right rather than being right, and a willingness to learn and adapt.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Craig T. Ingram for being on the show. Connect with Craig on LinkedIn: <a href="https://www.linkedin.com/in/craigtingram" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/craigtingram</a> </p><p><br></p><p>Learn about Int'l Commercialization Growth Partners: <a href="https://www.medicalsalesgrowth.com/" rel="noopener noreferrer" target="_blank">https://www.medicalsalesgrowth.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">7fef2ec2-4873-413a-a18a-9306543ec549</guid><itunes:image href="https://artwork.captivate.fm/e1bac8f1-c40e-4ddd-aa04-9aabe0d90274/V5SLP39w7WOzzXKKLZK6a6mE.jpg"/><pubDate>Tue, 08 Apr 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/547e95b5-467d-4439-89c6-ea50e22e7708/MDC-15-Audio-1.mp3" length="86936405" type="audio/mpeg"/><itunes:duration>45:14</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>15</itunes:episode><podcast:episode>15</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-547e95b5-467d-4439-89c6-ea50e22e7708.json" type="application/json+chapters"/></item><item><title>The Growing Importance of Interoperability and Third-Party Component Security</title><itunes:title>The Growing Importance of Interoperability and Third-Party Component Security</itunes:title><description><![CDATA[<p>Why is interoperability increasing cybersecurity risks in healthcare, and what can we do about it?</p><p>Interoperability is making healthcare more efficient but also more vulnerable to cyber threats. In this episode, Christian and Trevor discuss how second-order attacks, misconfigured cloud systems, and poor data integrity controls can compromise medical devices. They also share practical steps manufacturers can take to protect their devices and networks.</p><p>Key points:</p><p><br></p><p>(02:00) Understanding Interoperability Risks</p><p>* The increasing number of connected medical devices and their security challenges.</p><p>* How interoperability expands the attack surface in hospital networks.</p><p><br></p><p>(10:30) Second-Order Attacks</p><p>* Why attacking one system can compromise another in unexpected ways.</p><p><br></p><p>(20:45) Industry Challenges</p><p>* The MGM cyberattack and how a single vulnerability led to widespread damage.</p><p><br></p><p>(30:20) Best Practices for Secure Interoperability</p><p>* Validating all data entering and exiting a medical device.</p><p>* Restricting access to USB ports and other high-risk connection points.</p><p>* The potential (and pitfalls) of blockchain for medical records.</p><p>* Why security awareness must evolve alongside interoperability.</p><p><br></p><p>Resources mentioned in this episode that you can Google:</p><p><br></p><p>* Showdan search engine for devices.</p><p><br></p><p>* MedTech World, a conference on medtech innovations.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts</p>]]></description><content:encoded><![CDATA[<p>Why is interoperability increasing cybersecurity risks in healthcare, and what can we do about it?</p><p>Interoperability is making healthcare more efficient but also more vulnerable to cyber threats. In this episode, Christian and Trevor discuss how second-order attacks, misconfigured cloud systems, and poor data integrity controls can compromise medical devices. They also share practical steps manufacturers can take to protect their devices and networks.</p><p>Key points:</p><p><br></p><p>(02:00) Understanding Interoperability Risks</p><p>* The increasing number of connected medical devices and their security challenges.</p><p>* How interoperability expands the attack surface in hospital networks.</p><p><br></p><p>(10:30) Second-Order Attacks</p><p>* Why attacking one system can compromise another in unexpected ways.</p><p><br></p><p>(20:45) Industry Challenges</p><p>* The MGM cyberattack and how a single vulnerability led to widespread damage.</p><p><br></p><p>(30:20) Best Practices for Secure Interoperability</p><p>* Validating all data entering and exiting a medical device.</p><p>* Restricting access to USB ports and other high-risk connection points.</p><p>* The potential (and pitfalls) of blockchain for medical records.</p><p>* Why security awareness must evolve alongside interoperability.</p><p><br></p><p>Resources mentioned in this episode that you can Google:</p><p><br></p><p>* Showdan search engine for devices.</p><p><br></p><p>* MedTech World, a conference on medtech innovations.</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com</p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session</p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.</p><p><br></p><p>Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/</p><p><br></p><p>Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/</p><p>Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/</p><p>Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/</p><p>Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber</p><p><br></p><p>Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9</p><p><br></p><p>Feedback? Questions? Contact: https://bluegoatcyber.com/contact/</p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/</p><p><br></p><p>Christian Espinosa on YouTube: http://www.youtube.com/@ChristianEspinosaOfficial</p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast.</p><p><br></p><p>Subscribe via Spotify: https://spoti.fi/3XX95g0</p><p>Subscribe via Apple Podcasts: https://apple.co/483OJ9I</p><p>Subscribe via YouTube: https://www.youtube.com/@BlueGoatCyber/podcasts</p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">0ea2fb9b-6ed2-4663-8a0b-2688e0496e4e</guid><itunes:image href="https://artwork.captivate.fm/9f59b56b-e9a5-449a-a5c0-efb470d593c4/MmTXu-p-BHjSKzjIhOn99r61.jpg"/><pubDate>Tue, 25 Mar 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/acdbc24d-0e77-4cc6-b9bd-3c4888cec61a/MDC-14-Audio.mp3" length="71384623" type="audio/mpeg"/><itunes:duration>37:09</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>14</itunes:episode><podcast:episode>14</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-acdbc24d-0e77-4cc6-b9bd-3c4888cec61a.json" type="application/json+chapters"/></item><item><title>SBOMs Unpacked: Myths, Risks, &amp; Benefits with Cortez Frazier Jr.</title><itunes:title>SBOMs Unpacked: Myths, Risks, &amp; Benefits with Cortez Frazier Jr.</itunes:title><description><![CDATA[<p>Why are Software Bill of Materials (SBOMs) critical for medical device security?</p><p>In this episode, Cortez Frazier Jr. joins Christian and Trevor to discuss SBOMs, vulnerability prioritization, and why companies should stop fearing software transparency. The conversation covers real-world security challenges, regulatory trends, and how organizations can protect themselves before a major breach forces them to act.</p><p>Cortez Frazier Jr. is a principal product manager at FOSSA, where he helps companies navigate software supply chain security with a mix of technical expertise and strategic foresight.</p><p>Key points: </p><p>* Overview of FOSSA and its role in software composition analysis.</p><p><br></p><p>* The increasing importance of SBOMs in regulatory compliance.</p><p><br></p><p>* (10:30) Understanding SBOMs </p><p><br></p><p>* How the SolarWinds attack changed the conversation around software transparency.</p><p><br></p><p>* Why some manufacturers are reluctant to release SBOMs.</p><p><br></p><p>* (20:45) Prioritizing Vulnerabilities </p><p><br></p><p>* The difference between CVEs and actual exploitability risks.</p><p><br></p><p>* Why blindly patching everything isn’t an effective security strategy.</p><p><br></p><p>* (30:20) Legal and Compliance Risks</p><p><br></p><p>* How open-source licenses can force companies to disclose their source code.</p><p><br></p><p>* What manufacturers need to do to avoid unexpected legal issues.</p><p><br></p><p>* (40:50) Future Trends </p><p><br></p><p>* How hospitals and customers will soon start demanding SBOMs.</p><p><br></p><p>* Cortez’s advice for companies looking to improve their cybersecurity posture.</p><p><br></p><p>Resources mentioned in this episode that you can Google: </p><p><br></p><p>* Executive Order 14028. </p><p><br></p><p>* SPDX and CycloneDX – Machine-readable SBOM formats</p><p><br></p><p>* EPSS (Exploit Predictability Scoring System) – A better way to assess vulnerability risk</p><p><br></p><p>* CISA Known Exploited Vulnerabilities List – The vulnerabilities that actually matter</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Cortez Frazier Jr. for being on the show. Connect with Cortez on LinkedIn: <a href="https://www.linkedin.com/in/cortezfrazierjr/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/cortezfrazierjr/</a> </p><p><br></p><p>Learn more about FOSSA: <a href="https://fossa.com/" rel="noopener noreferrer" target="_blank">https://fossa.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>Why are Software Bill of Materials (SBOMs) critical for medical device security?</p><p>In this episode, Cortez Frazier Jr. joins Christian and Trevor to discuss SBOMs, vulnerability prioritization, and why companies should stop fearing software transparency. The conversation covers real-world security challenges, regulatory trends, and how organizations can protect themselves before a major breach forces them to act.</p><p>Cortez Frazier Jr. is a principal product manager at FOSSA, where he helps companies navigate software supply chain security with a mix of technical expertise and strategic foresight.</p><p>Key points: </p><p>* Overview of FOSSA and its role in software composition analysis.</p><p><br></p><p>* The increasing importance of SBOMs in regulatory compliance.</p><p><br></p><p>* (10:30) Understanding SBOMs </p><p><br></p><p>* How the SolarWinds attack changed the conversation around software transparency.</p><p><br></p><p>* Why some manufacturers are reluctant to release SBOMs.</p><p><br></p><p>* (20:45) Prioritizing Vulnerabilities </p><p><br></p><p>* The difference between CVEs and actual exploitability risks.</p><p><br></p><p>* Why blindly patching everything isn’t an effective security strategy.</p><p><br></p><p>* (30:20) Legal and Compliance Risks</p><p><br></p><p>* How open-source licenses can force companies to disclose their source code.</p><p><br></p><p>* What manufacturers need to do to avoid unexpected legal issues.</p><p><br></p><p>* (40:50) Future Trends </p><p><br></p><p>* How hospitals and customers will soon start demanding SBOMs.</p><p><br></p><p>* Cortez’s advice for companies looking to improve their cybersecurity posture.</p><p><br></p><p>Resources mentioned in this episode that you can Google: </p><p><br></p><p>* Executive Order 14028. </p><p><br></p><p>* SPDX and CycloneDX – Machine-readable SBOM formats</p><p><br></p><p>* EPSS (Exploit Predictability Scoring System) – A better way to assess vulnerability risk</p><p><br></p><p>* CISA Known Exploited Vulnerabilities List – The vulnerabilities that actually matter</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Cortez Frazier Jr. for being on the show. Connect with Cortez on LinkedIn: <a href="https://www.linkedin.com/in/cortezfrazierjr/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/cortezfrazierjr/</a> </p><p><br></p><p>Learn more about FOSSA: <a href="https://fossa.com/" rel="noopener noreferrer" target="_blank">https://fossa.com/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">f4b99a74-bca8-4dc0-8fa8-b26f9d01bbd0</guid><itunes:image href="https://artwork.captivate.fm/822aeff2-8818-4d6e-a1a4-6ea9f7fe222c/LJauTYedbk2tC2Or1TIbNDHT.jpg"/><pubDate>Tue, 18 Mar 2025 08:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/b8a53e2c-6205-4680-8124-f459d75621de/MDC-13-Audio-1.mp3" length="81104902" type="audio/mpeg"/><itunes:duration>42:12</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>13</itunes:episode><podcast:episode>13</podcast:episode><podcast:season>1</podcast:season></item><item><title>Postmarket Surveillance and Anomaly Detection for Medical Devices</title><itunes:title>Postmarket Surveillance and Anomaly Detection for Medical Devices</itunes:title><description><![CDATA[<p>What are some of the biggest cybersecurity risks medical devices face after they hit the market?</p><p>This episode dives into the challenges of postmarket surveillance for medical devices. Christian and Trevor discuss vulnerabilities that emerge after deployment, how manufacturers and hospitals handle updates, and why continuous security testing is essential. They also cover penetration testing and the evolving regulatory landscape for medical device cybersecurity.</p><p>Key points: </p><p><br></p><p>* The importance of postmarket surveillance in medical device cybersecurity.</p><p><br></p><p>* How vulnerabilities in third-party libraries can create security risks.</p><p><br></p><p>* The FDA’s push for over-the-air (OTA) updates and the associated attack vectors.</p><p><br></p><p>* The necessity of a Coordinated Vulnerability Disclosure (CVD) system.</p><p><br></p><p>* Why hospitals struggle with unpatchable medical devices in their networks.</p><p><br></p><p>* The role of Software Bill of Materials (SBOM) in monitoring supply chain security.</p><p><br></p><p>* How penetration testing identifies new threats even after a device is launched.</p><p><br></p><p>* How attackers exploit known vulnerabilities in medical devices.</p><p><br></p><p>* The misconception that cybersecurity is a one-time effort rather than an ongoing process.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:30) Medical Device Vulnerabilities</p><p>(05:45) Over-the-Air Updates</p><p>(10:20) Coordinated Vulnerability Disclosure </p><p>(15:15) SBOM in Medical Device Security</p><p>(20:45) Why Hospitals Struggle with Unpatchable Devices</p><p>(25:30) Continuous Penetration Testing</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* CISA Known Exploited Vulnerabilities List: <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer" target="_blank">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a> </p><p><br></p><p>* NTIA Software Bill of Materials Guidelines: <a href="https://www.ntia.gov/page/software-bill-materials" rel="noopener noreferrer" target="_blank">https://www.ntia.gov/page/software-bill-materials</a> </p><p><br></p><p>* FDA Cybersecurity Guidance for Medical Devices: <a href="https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity" rel="noopener noreferrer" target="_blank">https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are some of the biggest cybersecurity risks medical devices face after they hit the market?</p><p>This episode dives into the challenges of postmarket surveillance for medical devices. Christian and Trevor discuss vulnerabilities that emerge after deployment, how manufacturers and hospitals handle updates, and why continuous security testing is essential. They also cover penetration testing and the evolving regulatory landscape for medical device cybersecurity.</p><p>Key points: </p><p><br></p><p>* The importance of postmarket surveillance in medical device cybersecurity.</p><p><br></p><p>* How vulnerabilities in third-party libraries can create security risks.</p><p><br></p><p>* The FDA’s push for over-the-air (OTA) updates and the associated attack vectors.</p><p><br></p><p>* The necessity of a Coordinated Vulnerability Disclosure (CVD) system.</p><p><br></p><p>* Why hospitals struggle with unpatchable medical devices in their networks.</p><p><br></p><p>* The role of Software Bill of Materials (SBOM) in monitoring supply chain security.</p><p><br></p><p>* How penetration testing identifies new threats even after a device is launched.</p><p><br></p><p>* How attackers exploit known vulnerabilities in medical devices.</p><p><br></p><p>* The misconception that cybersecurity is a one-time effort rather than an ongoing process.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:30) Medical Device Vulnerabilities</p><p>(05:45) Over-the-Air Updates</p><p>(10:20) Coordinated Vulnerability Disclosure </p><p>(15:15) SBOM in Medical Device Security</p><p>(20:45) Why Hospitals Struggle with Unpatchable Devices</p><p>(25:30) Continuous Penetration Testing</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* CISA Known Exploited Vulnerabilities List: <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer" target="_blank">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a> </p><p><br></p><p>* NTIA Software Bill of Materials Guidelines: <a href="https://www.ntia.gov/page/software-bill-materials" rel="noopener noreferrer" target="_blank">https://www.ntia.gov/page/software-bill-materials</a> </p><p><br></p><p>* FDA Cybersecurity Guidance for Medical Devices: <a href="https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity" rel="noopener noreferrer" target="_blank">https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">7b850f7a-e2bd-4f84-8f12-c9733453f895</guid><itunes:image href="https://artwork.captivate.fm/64ae75ff-ee3d-4d4e-9c3c-f6e1771afb84/x8NVRdOHnrK1Gf_tH-H6YWIg.jpg"/><pubDate>Tue, 04 Mar 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/b39fb50c-40ba-485b-8ee0-93ee4cbdefee/MDC-12-Audio.mp3" length="66644927" type="audio/mpeg"/><itunes:duration>34:41</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>12</itunes:episode><podcast:episode>12</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-b39fb50c-40ba-485b-8ee0-93ee4cbdefee.json" type="application/json+chapters"/></item><item><title>Advanced Threat Modeling in Medical Devices</title><itunes:title>Advanced Threat Modeling in Medical Devices</itunes:title><description><![CDATA[<p>What is threat modeling, how does it differ from penetration testing, and why are both necessary? </p><p>This episode dives into the nuances of advanced threat modeling for medical devices. Christian and Trevor discuss essential frameworks, the importance of early cybersecurity integration, and real-world examples of vulnerabilities in healthcare environments. </p><p>Key points: </p><p>* Threat modeling involves stepping into the mindset of an attacker to identify and mitigate vulnerabilities.</p><p><br></p><p>* Entry points like Bluetooth, USB ports, and sloppy coding are critical concerns in medical device cybersecurity.</p><p><br></p><p>* Frameworks such as STRIDE and MITRE ATT&amp;CK help categorize and analyze potential threats.</p><p><br></p><p>* Penetration testing provides deeper insights than vulnerability scanning.</p><p><br></p><p>* Hospital networks are inherently insecure.</p><p><br></p><p>* Denial-of-service and delayed-service attacks can directly impact patient safety, especially for critical devices.</p><p><br></p><p>* Supply chain vulnerabilities, including insecure firmware and software, present significant risks.</p><p><br></p><p>* A layered security approach, akin to physical safes and home security, enhances device protection.</p><p><br></p><p>* Real-world threat modeling extends beyond cybersecurity, as illustrated by examples like fire escapes and shark encounters.</p><p><br></p><p>Chapters: </p><p><br></p><p>(01:24) Home Base Security</p><p>(02:46) Defining Threat Modeling </p><p>(06:24) Entry Points </p><p>(13:10) STRIDE Framework</p><p>(19:05) Penetration Testing vs. Vulnerability Scanning</p><p>(25:14) Holistic Vulnerability Analysis</p><p>(27:27) Real-Time Threat Modeling</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* "MITRE Playbook for Threat Modeling Medical Devices"</p><p><br></p><p>* STRIDE Threat Modeling Framework</p><p><br></p><p>* MITRE ATT&amp;CK Framework: <a href="https://attack.mitre.org" rel="noopener noreferrer" target="_blank">https://attack.mitre.org</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What is threat modeling, how does it differ from penetration testing, and why are both necessary? </p><p>This episode dives into the nuances of advanced threat modeling for medical devices. Christian and Trevor discuss essential frameworks, the importance of early cybersecurity integration, and real-world examples of vulnerabilities in healthcare environments. </p><p>Key points: </p><p>* Threat modeling involves stepping into the mindset of an attacker to identify and mitigate vulnerabilities.</p><p><br></p><p>* Entry points like Bluetooth, USB ports, and sloppy coding are critical concerns in medical device cybersecurity.</p><p><br></p><p>* Frameworks such as STRIDE and MITRE ATT&amp;CK help categorize and analyze potential threats.</p><p><br></p><p>* Penetration testing provides deeper insights than vulnerability scanning.</p><p><br></p><p>* Hospital networks are inherently insecure.</p><p><br></p><p>* Denial-of-service and delayed-service attacks can directly impact patient safety, especially for critical devices.</p><p><br></p><p>* Supply chain vulnerabilities, including insecure firmware and software, present significant risks.</p><p><br></p><p>* A layered security approach, akin to physical safes and home security, enhances device protection.</p><p><br></p><p>* Real-world threat modeling extends beyond cybersecurity, as illustrated by examples like fire escapes and shark encounters.</p><p><br></p><p>Chapters: </p><p><br></p><p>(01:24) Home Base Security</p><p>(02:46) Defining Threat Modeling </p><p>(06:24) Entry Points </p><p>(13:10) STRIDE Framework</p><p>(19:05) Penetration Testing vs. Vulnerability Scanning</p><p>(25:14) Holistic Vulnerability Analysis</p><p>(27:27) Real-Time Threat Modeling</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* "MITRE Playbook for Threat Modeling Medical Devices"</p><p><br></p><p>* STRIDE Threat Modeling Framework</p><p><br></p><p>* MITRE ATT&amp;CK Framework: <a href="https://attack.mitre.org" rel="noopener noreferrer" target="_blank">https://attack.mitre.org</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">38d5011e-d2c3-4586-8aee-a109c40749b8</guid><itunes:image href="https://artwork.captivate.fm/01373a20-f809-447d-9570-9d2c861f158a/Qy09w6w2Fn0Mhgtugjb_-ZiL.jpg"/><pubDate>Tue, 18 Feb 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/177166d9-21fc-4171-a610-f645646d25a7/MDC-Episode-11-Audio.mp3" length="57591969" type="audio/mpeg"/><itunes:duration>29:58</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>11</itunes:episode><podcast:episode>11</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-177166d9-21fc-4171-a610-f645646d25a7.json" type="application/json+chapters"/></item><item><title>How Trump &amp; RFK Jr Affect AI Med Device Guidelines</title><itunes:title>How Trump &amp; RFK Jr Affect AI Med Device Guidelines</itunes:title><description><![CDATA[<p>How might the second Donald Trump administration and Robert F. Kennedy Jr. impact the medtech cybersecurity world? </p><p>In this episode, Christian and Trevor discuss how the Trump administration and RFK Jr.’s policies could reshape medical device cybersecurity and regulation. They explore potential Food and Drug Administration restructuring, the impact of tariffs on China, and new scrutiny on supply chains and AI components. </p><p>Key points: </p><p>* The Trump administration’s focus on efficiency and deregulation may clash with RFK Jr.’s push for stricter safety rules.</p><p><br></p><p>* FDA restructuring is rumored, with potential divisions for food, drugs, and medical devices.</p><p><br></p><p>* Increased oversight may make it harder for startups to bring devices to market.</p><p><br></p><p>* Tariffs on Chinese components could drive up costs and slow down innovation.</p><p><br></p><p>* Cybersecurity concerns around AI models like DeepSeek raise new challenges.</p><p><br></p><p>* The potential elimination of the CSRB could shift more cybersecurity responsibilities to private companies.</p><p><br></p><p>* Elon Musk’s Department of Government Efficiency (DOGE) and its potential impact on FDA processes.</p><p><br></p><p>Chapters: </p><p><br></p><p>(03:30) What Trump &amp; RFK Jr Policies Mean for MedTech</p><p>(07:50) Tariffs on China</p><p>(13:15) Supply Chain Risks</p><p>(19:45) FDA Restructuring</p><p>(25:00) The Future of Incident Response &amp; Cybersecurity in Medical Devices</p><p>(30:10) Advice for Startups</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How might the second Donald Trump administration and Robert F. Kennedy Jr. impact the medtech cybersecurity world? </p><p>In this episode, Christian and Trevor discuss how the Trump administration and RFK Jr.’s policies could reshape medical device cybersecurity and regulation. They explore potential Food and Drug Administration restructuring, the impact of tariffs on China, and new scrutiny on supply chains and AI components. </p><p>Key points: </p><p>* The Trump administration’s focus on efficiency and deregulation may clash with RFK Jr.’s push for stricter safety rules.</p><p><br></p><p>* FDA restructuring is rumored, with potential divisions for food, drugs, and medical devices.</p><p><br></p><p>* Increased oversight may make it harder for startups to bring devices to market.</p><p><br></p><p>* Tariffs on Chinese components could drive up costs and slow down innovation.</p><p><br></p><p>* Cybersecurity concerns around AI models like DeepSeek raise new challenges.</p><p><br></p><p>* The potential elimination of the CSRB could shift more cybersecurity responsibilities to private companies.</p><p><br></p><p>* Elon Musk’s Department of Government Efficiency (DOGE) and its potential impact on FDA processes.</p><p><br></p><p>Chapters: </p><p><br></p><p>(03:30) What Trump &amp; RFK Jr Policies Mean for MedTech</p><p>(07:50) Tariffs on China</p><p>(13:15) Supply Chain Risks</p><p>(19:45) FDA Restructuring</p><p>(25:00) The Future of Incident Response &amp; Cybersecurity in Medical Devices</p><p>(30:10) Advice for Startups</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">e9052757-6442-45e5-84d9-02b6ddaaaa63</guid><itunes:image href="https://artwork.captivate.fm/7b64df12-4a3e-44eb-a1a7-090f4c4ef2c7/tWTSUsHEhMQYyLGYN6p6thpP.jpg"/><pubDate>Tue, 04 Feb 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/73c1a144-c4dd-440b-87c4-b219f7037a41/MDC-10-Audio.mp3" length="45795234" type="audio/mpeg"/><itunes:duration>31:44</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>10</itunes:episode><podcast:episode>10</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-73c1a144-c4dd-440b-87c4-b219f7037a41.json" type="application/json+chapters"/></item><item><title>FDA AI Guidance Explained: What It Means for Medical Device Cybersecurity</title><itunes:title>FDA AI Guidance Explained: What It Means for Medical Device Cybersecurity</itunes:title><description><![CDATA[<p>How does the FDA’s latest AI guidance on medical devices impact manufacturers and cybersecurity challenges in healthcare?</p><p>In this episode, Christian and Trevor discuss the latest FDA AI guidance and how it will impact real-world AI applications in healthcare. </p><p>Key points: </p><p>* The FDA’s new guidance on AI in medical devices, released in January 2025.</p><p><br></p><p>* Differences between artificial intelligence (AI) and machine learning (ML).</p><p><br></p><p>* Historical context of AI, including early examples like Microsoft’s Clippy.</p><p><br></p><p>* Potential risks of AI in healthcare, including data poisoning, model inversion, and evasion.</p><p><br></p><p>* Challenges of ensuring AI integrity, confidentiality, and availability.</p><p><br></p><p>* The concept of model bias and how it impacts diagnostic accuracy.</p><p><br></p><p>* Practical cybersecurity strategies for AI-enabled medical devices.</p><p><br></p><p>* Importance of ongoing post-market monitoring to address performance drift.</p><p><br></p><p>* Value of consulting cybersecurity experts early in the development lifecycle.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:52) AI’s Role in Healthcare</p><p><br></p><p>(05:50) Historical Context: From Clippy to ChatGPT</p><p><br></p><p>(08:15) Understanding AI Models and Training Data</p><p><br></p><p>(11:00) Risks: Data Poisoning and Hallucinations</p><p><br></p><p>(18:06) Mitigating Bias and Narrowing AI Applications</p><p><br></p><p>(23:39) Model Evasion and Performance Drift</p><p><br></p><p>(37:55) Securing AI Across the Product Lifecycle</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* The U.S. Food and Drug Administration 2025 AI Guidance: <a href="https://bit.ly/FDA-AI-medical-devices" rel="noopener noreferrer" target="_blank">https://bit.ly/FDA-AI-medical-devices</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How does the FDA’s latest AI guidance on medical devices impact manufacturers and cybersecurity challenges in healthcare?</p><p>In this episode, Christian and Trevor discuss the latest FDA AI guidance and how it will impact real-world AI applications in healthcare. </p><p>Key points: </p><p>* The FDA’s new guidance on AI in medical devices, released in January 2025.</p><p><br></p><p>* Differences between artificial intelligence (AI) and machine learning (ML).</p><p><br></p><p>* Historical context of AI, including early examples like Microsoft’s Clippy.</p><p><br></p><p>* Potential risks of AI in healthcare, including data poisoning, model inversion, and evasion.</p><p><br></p><p>* Challenges of ensuring AI integrity, confidentiality, and availability.</p><p><br></p><p>* The concept of model bias and how it impacts diagnostic accuracy.</p><p><br></p><p>* Practical cybersecurity strategies for AI-enabled medical devices.</p><p><br></p><p>* Importance of ongoing post-market monitoring to address performance drift.</p><p><br></p><p>* Value of consulting cybersecurity experts early in the development lifecycle.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:52) AI’s Role in Healthcare</p><p><br></p><p>(05:50) Historical Context: From Clippy to ChatGPT</p><p><br></p><p>(08:15) Understanding AI Models and Training Data</p><p><br></p><p>(11:00) Risks: Data Poisoning and Hallucinations</p><p><br></p><p>(18:06) Mitigating Bias and Narrowing AI Applications</p><p><br></p><p>(23:39) Model Evasion and Performance Drift</p><p><br></p><p>(37:55) Securing AI Across the Product Lifecycle</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* The U.S. Food and Drug Administration 2025 AI Guidance: <a href="https://bit.ly/FDA-AI-medical-devices" rel="noopener noreferrer" target="_blank">https://bit.ly/FDA-AI-medical-devices</a> </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">1ae8ae9a-c6d7-4f89-9815-50a1b1d98ed4</guid><itunes:image href="https://artwork.captivate.fm/0224c9c0-8622-4aa7-b1f7-83c4b674d531/Hd-jy-YD5lQ2pSv0e9-QwKZF.jpg"/><pubDate>Thu, 30 Jan 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/6fc355a8-4489-468f-8fc1-16994c94345e/MDC-Episode-9-Audio.mp3" length="80573170" type="audio/mpeg"/><itunes:duration>41:55</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>9</itunes:episode><podcast:episode>9</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-6fc355a8-4489-468f-8fc1-16994c94345e.json" type="application/json+chapters"/></item><item><title>The Human Factor: Why Cybersecurity Awareness is Key in Medical Device Manufacturing</title><itunes:title>The Human Factor: Why Cybersecurity Awareness is Key in Medical Device Manufacturing</itunes:title><description><![CDATA[<p>How does human behavior impact medical device cybersecurity? Also, why do cybersecurity awareness programs often fail to make a lasting impact?</p><p>This episode dives into the human factor in medical device cybersecurity. Christian and Trevor discuss how human error and resistance to change contribute to vulnerabilities in healthcare networks and medical devices. They share real-life stories and actionable insights to encourage collaboration and better security practices across teams.</p><p>Key points: </p><p><br></p><p>* The human factor is often the weakest link in cybersecurity, with social engineering attacks frequently succeeding.</p><p><br></p><p>* Cybersecurity awareness training often fails to produce meaningful changes in behavior.</p><p><br></p><p>* Network segmentation is a critical step in reducing the impact of breaches in healthcare environments.</p><p><br></p><p>* Integrating secure coding practices into software development from the outset.</p><p><br></p><p>* Legacy medical devices often lack basic security controls, creating significant vulnerabilities.</p><p><br></p><p>* FDA guidance is driving improvements in medtech cybersecurity but often meets resistance.</p><p><br></p><p>* Penetration testing reveals common issues like default credentials and poorly configured networks.</p><p><br></p><p>* Budget constraints often lead to insufficient investment in cybersecurity—until after a breach occurs.</p><p><br></p><p>* Cultural resistance to change hinders the adoption of necessary security measures.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:03) Defining the Human Factor in Cybersecurity</p><p>(04:37) Why Cybersecurity Is Seen as a Necessary Evil</p><p>(07:52) Penetration Testing Stories from Hospital Networks</p><p>(12:55) Addressing Human Error in IT and Engineering Teams</p><p>(16:41) The Importance of Secure Coding in Software Development</p><p>(19:02) FDA Guidance and Its Impact on MedTech Security</p><p>(23:03) The Need for Cultural Change</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How does human behavior impact medical device cybersecurity? Also, why do cybersecurity awareness programs often fail to make a lasting impact?</p><p>This episode dives into the human factor in medical device cybersecurity. Christian and Trevor discuss how human error and resistance to change contribute to vulnerabilities in healthcare networks and medical devices. They share real-life stories and actionable insights to encourage collaboration and better security practices across teams.</p><p>Key points: </p><p><br></p><p>* The human factor is often the weakest link in cybersecurity, with social engineering attacks frequently succeeding.</p><p><br></p><p>* Cybersecurity awareness training often fails to produce meaningful changes in behavior.</p><p><br></p><p>* Network segmentation is a critical step in reducing the impact of breaches in healthcare environments.</p><p><br></p><p>* Integrating secure coding practices into software development from the outset.</p><p><br></p><p>* Legacy medical devices often lack basic security controls, creating significant vulnerabilities.</p><p><br></p><p>* FDA guidance is driving improvements in medtech cybersecurity but often meets resistance.</p><p><br></p><p>* Penetration testing reveals common issues like default credentials and poorly configured networks.</p><p><br></p><p>* Budget constraints often lead to insufficient investment in cybersecurity—until after a breach occurs.</p><p><br></p><p>* Cultural resistance to change hinders the adoption of necessary security measures.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:03) Defining the Human Factor in Cybersecurity</p><p>(04:37) Why Cybersecurity Is Seen as a Necessary Evil</p><p>(07:52) Penetration Testing Stories from Hospital Networks</p><p>(12:55) Addressing Human Error in IT and Engineering Teams</p><p>(16:41) The Importance of Secure Coding in Software Development</p><p>(19:02) FDA Guidance and Its Impact on MedTech Security</p><p>(23:03) The Need for Cultural Change</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">69802348-631d-456b-942b-6b7863c20b6c</guid><itunes:image href="https://artwork.captivate.fm/5f6e6ec6-eb32-4d74-b89f-a24dbf790c8d/jVn8F1RnRx2vrezsn4UFSQ7u.jpg"/><pubDate>Tue, 21 Jan 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/0a1b41b8-bb34-408c-934a-bdaacbce5148/MDC-8-Audio.mp3" length="49644933" type="audio/mpeg"/><itunes:duration>25:49</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>8</itunes:episode><podcast:episode>8</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-0a1b41b8-bb34-408c-934a-bdaacbce5148.json" type="application/json+chapters"/></item><item><title>Startups, Regulations, &amp; Risk: Insights from MedTech Guru Etienne Nichols</title><itunes:title>Startups, Regulations, &amp; Risk: Insights from MedTech Guru Etienne Nichols</itunes:title><description><![CDATA[<p>What are some of the key challenges MedTech companies face in balancing innovation with compliance?</p><p>This episode dives into the intersection of quality management and cybersecurity in the MedTech industry. Hosts Christian Espinosa and Trevor Slattery are joined by Etienne Nichols, an expert from Greenlight Guru, who shares insights on regulatory compliance, risk management, and the importance of designing cybersecurity into medical devices.</p><p>Key points: </p><p><br></p><p>* The importance of building cybersecurity into medical devices from the design phase.</p><p><br></p><p>* How quality management systems (QMS) streamline compliance and audits.</p><p><br></p><p>* The role of ISO 13485 in MedTech and its differences from ISO 9001.</p><p><br></p><p>* FDA’s growing focus on cybersecurity in regulatory submissions.</p><p><br></p><p>* The economic risks of poor documentation and lack of traceability.</p><p><br></p><p>* Best practices for startups in adopting right-sized QMS solutions.</p><p><br></p><p>* The relationship between quality assurance (QA) and regulatory affairs (RA).</p><p><br></p><p>* How risk management frameworks like ISO 14971 and TIR-57 intersect.</p><p><br></p><p>* Why hospitals demand cybersecurity assessments before purchasing devices.</p><p><br></p><p>Chapters: </p><p><br></p><p>(01:01) Meet Etienne Nichols </p><p>(03:04) The Basics of Quality Management Systems (QMS)</p><p>(05:19) How QMS Integrates with Cybersecurity</p><p>(08:17) Designing Cybersecurity into Medical Devices</p><p>(12:21) Understanding CAPA and Post-Market Risk Management</p><p>(17:19) Startups vs. Large Companies: QMS Challenges</p><p>(24:10) Bridging Quality and Cybersecurity in MedTech</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* Quality Is Free: The Art of Making Quality Certain, by Philip B. Crosby. </p><p><br></p><p>* ISO 13485 (International standard for medical devices QMS).</p><p><br></p><p>* ISO 9001 (General quality management system standard).</p><p><br></p><p>* ISO 14971 (Risk management for medical devices).</p><p><br></p><p>* TIR-57 (Security risk management for medical devices).</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Etienne Nichols for being on the show. Connect with Etienne on LinkedIn: <a href="https://www.linkedin.com/in/etiennenichols/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/etiennenichols/</a> </p><p><br></p><p>Learn more about Greenlight Guru: <a href="https://www.greenlight.guru/" rel="noopener noreferrer" target="_blank">https://www.greenlight.guru/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are some of the key challenges MedTech companies face in balancing innovation with compliance?</p><p>This episode dives into the intersection of quality management and cybersecurity in the MedTech industry. Hosts Christian Espinosa and Trevor Slattery are joined by Etienne Nichols, an expert from Greenlight Guru, who shares insights on regulatory compliance, risk management, and the importance of designing cybersecurity into medical devices.</p><p>Key points: </p><p><br></p><p>* The importance of building cybersecurity into medical devices from the design phase.</p><p><br></p><p>* How quality management systems (QMS) streamline compliance and audits.</p><p><br></p><p>* The role of ISO 13485 in MedTech and its differences from ISO 9001.</p><p><br></p><p>* FDA’s growing focus on cybersecurity in regulatory submissions.</p><p><br></p><p>* The economic risks of poor documentation and lack of traceability.</p><p><br></p><p>* Best practices for startups in adopting right-sized QMS solutions.</p><p><br></p><p>* The relationship between quality assurance (QA) and regulatory affairs (RA).</p><p><br></p><p>* How risk management frameworks like ISO 14971 and TIR-57 intersect.</p><p><br></p><p>* Why hospitals demand cybersecurity assessments before purchasing devices.</p><p><br></p><p>Chapters: </p><p><br></p><p>(01:01) Meet Etienne Nichols </p><p>(03:04) The Basics of Quality Management Systems (QMS)</p><p>(05:19) How QMS Integrates with Cybersecurity</p><p>(08:17) Designing Cybersecurity into Medical Devices</p><p>(12:21) Understanding CAPA and Post-Market Risk Management</p><p>(17:19) Startups vs. Large Companies: QMS Challenges</p><p>(24:10) Bridging Quality and Cybersecurity in MedTech</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* Quality Is Free: The Art of Making Quality Certain, by Philip B. Crosby. </p><p><br></p><p>* ISO 13485 (International standard for medical devices QMS).</p><p><br></p><p>* ISO 9001 (General quality management system standard).</p><p><br></p><p>* ISO 14971 (Risk management for medical devices).</p><p><br></p><p>* TIR-57 (Security risk management for medical devices).</p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Etienne Nichols for being on the show. Connect with Etienne on LinkedIn: <a href="https://www.linkedin.com/in/etiennenichols/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/etiennenichols/</a> </p><p><br></p><p>Learn more about Greenlight Guru: <a href="https://www.greenlight.guru/" rel="noopener noreferrer" target="_blank">https://www.greenlight.guru/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">1b63e346-ccb7-4561-82d2-238aa3a60a04</guid><itunes:image href="https://artwork.captivate.fm/00730a24-9274-4dad-8ba8-1f9901a42681/93_u4G-2kGoQQAB1ohT0hynE.jpg"/><pubDate>Tue, 07 Jan 2025 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/39d9d3a9-168d-4b69-adb8-b66df52008fc/MDC-7-Audio.mp3" length="45957128" type="audio/mpeg"/><itunes:duration>31:53</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>7</itunes:episode><podcast:episode>7</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-39d9d3a9-168d-4b69-adb8-b66df52008fc.json" type="application/json+chapters"/></item><item><title>The Evolution of Medical Device Cyber Threats: Past, Present, and Future</title><itunes:title>The Evolution of Medical Device Cyber Threats: Past, Present, and Future</itunes:title><description><![CDATA[<p>How do medical device vulnerabilities pose life-threatening risks?</p><p>In this episode, Christian and Trevor again explore the fascinating and critical world of medical device cybersecurity. Specifically, they discuss past attacks, present challenges, and future risks, from vulnerable pacemakers to autonomous surgical robots. They highlight the importance of transparency, proactive security design, and responsible research in protecting the devices we trust with our lives.</p><p>Key points: </p><p><br></p><p>* The 2007 cybersecurity concerns surrounding Dick Cheney’s pacemaker.</p><p><br></p><p>* Barnaby Jack’s insulin pump and pacemaker hacking demonstrations.</p><p><br></p><p>* Vulnerabilities in legacy medical devices.</p><p><br></p><p>* The FDA’s guidance on medical device cybersecurity.</p><p><br></p><p>* The rise of AI in both offensive and defensive cybersecurity applications.</p><p><br></p><p>* Risks associated with autonomous surgical robots.</p><p><br></p><p>* Proximity-based security myths and the dangers of tools like BlueSniper Rifles.</p><p><br></p><p>Chapters: </p><p><br></p><p>(00:48) Dick Cheney’s Pacemaker Security Concerns</p><p><br></p><p>(02:55) Barnaby Jack’s Hacking Demonstrations</p><p>(05:36) Vulnerabilities in Insulin and Drug Infusion Pumps</p><p>(08:05) FDA’s 2023 Cybersecurity Guidance</p><p>(10:47) Challenges with Legacy Medical Devices</p><p>(15:32) Autonomous Surgical Robots and AI Risks</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* FDA’s 2023 Guidance on Medical Device Cybersecurity</p><p><br></p><p>* Black Hat Conference </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How do medical device vulnerabilities pose life-threatening risks?</p><p>In this episode, Christian and Trevor again explore the fascinating and critical world of medical device cybersecurity. Specifically, they discuss past attacks, present challenges, and future risks, from vulnerable pacemakers to autonomous surgical robots. They highlight the importance of transparency, proactive security design, and responsible research in protecting the devices we trust with our lives.</p><p>Key points: </p><p><br></p><p>* The 2007 cybersecurity concerns surrounding Dick Cheney’s pacemaker.</p><p><br></p><p>* Barnaby Jack’s insulin pump and pacemaker hacking demonstrations.</p><p><br></p><p>* Vulnerabilities in legacy medical devices.</p><p><br></p><p>* The FDA’s guidance on medical device cybersecurity.</p><p><br></p><p>* The rise of AI in both offensive and defensive cybersecurity applications.</p><p><br></p><p>* Risks associated with autonomous surgical robots.</p><p><br></p><p>* Proximity-based security myths and the dangers of tools like BlueSniper Rifles.</p><p><br></p><p>Chapters: </p><p><br></p><p>(00:48) Dick Cheney’s Pacemaker Security Concerns</p><p><br></p><p>(02:55) Barnaby Jack’s Hacking Demonstrations</p><p>(05:36) Vulnerabilities in Insulin and Drug Infusion Pumps</p><p>(08:05) FDA’s 2023 Cybersecurity Guidance</p><p>(10:47) Challenges with Legacy Medical Devices</p><p>(15:32) Autonomous Surgical Robots and AI Risks</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* FDA’s 2023 Guidance on Medical Device Cybersecurity</p><p><br></p><p>* Black Hat Conference </p><p><br></p><p>The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">912bfa0e-21fa-4410-807e-1a31d94bdb34</guid><itunes:image href="https://artwork.captivate.fm/167eed85-3ee1-439d-bd32-98bf740faba7/8g9LsQHLjDCc_vRb2AVJ9ncV.jpg"/><pubDate>Tue, 24 Dec 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/1859be03-8388-4616-98f6-5be36f096f30/MDC-6-Audio.mp3" length="46471246" type="audio/mpeg"/><itunes:duration>24:10</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>6</itunes:episode><podcast:episode>6</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-1859be03-8388-4616-98f6-5be36f096f30.json" type="application/json+chapters"/></item><item><title>Avoid the Dumb Tax: Cybersecurity Lessons for MedTech Startups with Steve Bell</title><itunes:title>Avoid the Dumb Tax: Cybersecurity Lessons for MedTech Startups with Steve Bell</itunes:title><description><![CDATA[<p>What are the most common mistakes medtech startups make in cybersecurity, and how can founders avoid them?</p><p>In this episode, Christian Espinosa and Trevor Slattery dive into the challenges medtech startups face with their guest, Steve Bell, a 35-year veteran of the industry. They explore the critical importance of integrating cybersecurity from the start, managing regulatory hurdles, and focusing on commercialization to avoid the “dumb tax” (paying for costly mistakes).  </p><p>Key points: </p><p><br></p><p>* The "dumb tax" too many startups pay for avoidable mistakes in planning and execution.</p><p><br></p><p>* Why medtech startups fail: lack of cybersecurity integration, poor communication, and insufficient preparation.</p><p><br></p><p>* The importance of understanding investor expectations. </p><p><br></p><p>* How to raise money effectively and why it’s the CEO's most crucial role.</p><p><br></p><p>* Cybersecurity should be incorporated during the requirements phase, not as a last-minute fix.</p><p><br></p><p>* Why commercialization, not R&amp;D, is the greatest challenge for medtech startups.</p><p><br></p><p>* How poor design decisions early on can derail regulatory approval timelines.</p><p><br></p><p>* Fractional cybersecurity and regulatory experts as valuable resources for startups.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:30) Steve Bell: A MedTech Veteran’s Journey</p><p>(08:00) Lessons from MedTech Mistakes</p><p>(14:00) Cybersecurity in Startups: Why Early Integration Matters</p><p>(19:00) The Cost of Poor Communication and Delays</p><p>(24:00) Investor Expectations </p><p>(28:00) Regulatory Hurdles</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* Steve Bell’s website, How To StartUp in MedTech: <a href="https://www.howtostartupinmedtech.com/" rel="noopener noreferrer" target="_blank">https://www.howtostartupinmedtech.com/</a> </p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Steve Bell for being on the show. Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/stevegbell/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/stevegbell/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are the most common mistakes medtech startups make in cybersecurity, and how can founders avoid them?</p><p>In this episode, Christian Espinosa and Trevor Slattery dive into the challenges medtech startups face with their guest, Steve Bell, a 35-year veteran of the industry. They explore the critical importance of integrating cybersecurity from the start, managing regulatory hurdles, and focusing on commercialization to avoid the “dumb tax” (paying for costly mistakes).  </p><p>Key points: </p><p><br></p><p>* The "dumb tax" too many startups pay for avoidable mistakes in planning and execution.</p><p><br></p><p>* Why medtech startups fail: lack of cybersecurity integration, poor communication, and insufficient preparation.</p><p><br></p><p>* The importance of understanding investor expectations. </p><p><br></p><p>* How to raise money effectively and why it’s the CEO's most crucial role.</p><p><br></p><p>* Cybersecurity should be incorporated during the requirements phase, not as a last-minute fix.</p><p><br></p><p>* Why commercialization, not R&amp;D, is the greatest challenge for medtech startups.</p><p><br></p><p>* How poor design decisions early on can derail regulatory approval timelines.</p><p><br></p><p>* Fractional cybersecurity and regulatory experts as valuable resources for startups.</p><p><br></p><p>Chapters: </p><p><br></p><p>(02:30) Steve Bell: A MedTech Veteran’s Journey</p><p>(08:00) Lessons from MedTech Mistakes</p><p>(14:00) Cybersecurity in Startups: Why Early Integration Matters</p><p>(19:00) The Cost of Poor Communication and Delays</p><p>(24:00) Investor Expectations </p><p>(28:00) Regulatory Hurdles</p><p><br></p><p>Resources mentioned in this episode: </p><p><br></p><p>* Steve Bell’s website, How To StartUp in MedTech: <a href="https://www.howtostartupinmedtech.com/" rel="noopener noreferrer" target="_blank">https://www.howtostartupinmedtech.com/</a> </p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Thanks to Steve Bell for being on the show. Connect with Steve on LinkedIn: <a href="https://www.linkedin.com/in/stevegbell/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/stevegbell/</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">a6a8fcce-7058-4a3d-8d13-f5dea1fae1bd</guid><itunes:image href="https://artwork.captivate.fm/ded23989-12b3-403a-996e-ee65bc725e29/bHmK6JVfMJUuvX0lB-GEQFyI.jpg"/><pubDate>Tue, 10 Dec 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/55d3aeff-4343-4684-97df-cc98c31117ed/MDC-Episode-5-Audio.mp3" length="70922093" type="audio/mpeg"/><itunes:duration>36:55</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>5</itunes:episode><podcast:episode>5</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-55d3aeff-4343-4684-97df-cc98c31117ed.json" type="application/json+chapters"/></item><item><title>Building Resilient Medical Devices: A Look at the Essential Technologies and Infrastructure</title><itunes:title>Building Resilient Medical Devices: A Look at the Essential Technologies and Infrastructure</itunes:title><description><![CDATA[<p>How can some of the biggest cybersecurity concerns with medical devices be addressed in the design phase? </p><p>In this episode, Christian and Trevor highlight the importance of addressing cybersecurity from the very beginning of the development process to prevent vulnerabilities later on. They explore how different technologies contribute to the security of devices, the importance of a resilient infrastructure, and future trends that could shape the landscape of medical device cybersecurity.</p><p>Key points: </p><p><br></p><p>* Addressing cybersecurity as a non-functional requirement in the design phase of medical devices. </p><p><br></p><p>* Understanding the three factors of authentication (something you know, something you have, something you are) and their relevance to medical devices. </p><p><br></p><p>* The common issue of broken authorization found in medical devices. </p><p><br></p><p>* The necessity of both encryption at rest (for data storage) and encryption in transit (for data transmission) in medical devices. </p><p><br></p><p>* Maintaining code, data, and execution integrity to prevent tampering and ensure the authenticity of medical device software and data. </p><p><br></p><p>* Audit trails in recording and protecting data modifications and access attempts. </p><p><br></p><p>* The need for comprehensive logging and detection mechanisms to capture anomalous behavior in medical devices. </p><p><br></p><p>* The importance of resilience and recovery mechanisms to protect medical devices from cyberattacks and ensure they can return to a known good state. </p><p><br></p><p>Chapters: </p><p><br></p><p>(1:14) The Importance of Cybersecurity in Medical Device Design </p><p>(5:11) Authentication in Medical Devices </p><p>(8:49) Authorization in Medical Devices </p><p>(11:54) Cryptography in Medical Devices </p><p>(14:02) Code, Data and Execution Integrity in Medical Devices </p><p>(17:54) Logging and Detection in Medical Devices </p><p>(21:36) Resilience and Recovery in Medical Devices </p><p>(23:23) Firmware and Software Updates in Medical Devices</p><p><br></p><p>Resource mentioned in this episode: </p><p><br></p><p>* FDA's Guidance on Cybersecurity for Medical Devices: https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>How can some of the biggest cybersecurity concerns with medical devices be addressed in the design phase? </p><p>In this episode, Christian and Trevor highlight the importance of addressing cybersecurity from the very beginning of the development process to prevent vulnerabilities later on. They explore how different technologies contribute to the security of devices, the importance of a resilient infrastructure, and future trends that could shape the landscape of medical device cybersecurity.</p><p>Key points: </p><p><br></p><p>* Addressing cybersecurity as a non-functional requirement in the design phase of medical devices. </p><p><br></p><p>* Understanding the three factors of authentication (something you know, something you have, something you are) and their relevance to medical devices. </p><p><br></p><p>* The common issue of broken authorization found in medical devices. </p><p><br></p><p>* The necessity of both encryption at rest (for data storage) and encryption in transit (for data transmission) in medical devices. </p><p><br></p><p>* Maintaining code, data, and execution integrity to prevent tampering and ensure the authenticity of medical device software and data. </p><p><br></p><p>* Audit trails in recording and protecting data modifications and access attempts. </p><p><br></p><p>* The need for comprehensive logging and detection mechanisms to capture anomalous behavior in medical devices. </p><p><br></p><p>* The importance of resilience and recovery mechanisms to protect medical devices from cyberattacks and ensure they can return to a known good state. </p><p><br></p><p>Chapters: </p><p><br></p><p>(1:14) The Importance of Cybersecurity in Medical Device Design </p><p>(5:11) Authentication in Medical Devices </p><p>(8:49) Authorization in Medical Devices </p><p>(11:54) Cryptography in Medical Devices </p><p>(14:02) Code, Data and Execution Integrity in Medical Devices </p><p>(17:54) Logging and Detection in Medical Devices </p><p>(21:36) Resilience and Recovery in Medical Devices </p><p>(23:23) Firmware and Software Updates in Medical Devices</p><p><br></p><p>Resource mentioned in this episode: </p><p><br></p><p>* FDA's Guidance on Cybersecurity for Medical Devices: https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">f0f2ab40-9c98-4eaa-bc1c-9ee916ba6984</guid><itunes:image href="https://artwork.captivate.fm/14a756f1-4a27-4299-845c-10aad4d7e53a/zd7iFfm71VdrDEEliDzB2wFg.jpg"/><pubDate>Tue, 26 Nov 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/b65451c1-230a-40d2-9230-acbce315c708/MDC-4-Audio.mp3" length="57689217" type="audio/mpeg"/><itunes:duration>30:01</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><podcast:episode>4</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-b65451c1-230a-40d2-9230-acbce315c708.json" type="application/json+chapters"/></item><item><title>Navigating the Regulatory Landscape of Medical Device Cybersecurity</title><itunes:title>Navigating the Regulatory Landscape of Medical Device Cybersecurity</itunes:title><description><![CDATA[<p>What are the main categories of medical devices, and how do regulatory bodies govern them? </p><p>In this episode, Christian Espinosa and Trevor Slattery unpack the complex regulatory environment surrounding medical device cybersecurity. In discussing the key regulations, standards, and FDA guidelines that govern the industry, they explore how these regulations shape the design, development, and deployment of secure medical devices.</p><p>Topics discussed and key points: </p><p><br></p><p>* Incorporating cybersecurity from the beginning of the medical device development process. </p><p><br></p><p>* The challenges of integrating cybersecurity into medical devices after they have been developed. </p><p><br></p><p>* The impact of the FDA's new guidance on medical device cybersecurity and the increase in submission rejections. </p><p><br></p><p>* The different classifications of medical devices and their associated risks. </p><p><br></p><p>* How vulnerability can lead to more significant security risks. </p><p><br></p><p>* Real-world examples of medical device vulnerabilities.</p><p><br></p><p>* The role of regulations in improving the safety and security of medical devices. </p><p><br></p><p>Chapters: </p><p><br></p><p>(00:30) Medical Device Categories, Manufacturers, and Regulatory Bodies</p><p>(01:19) Early Cybersecurity Considerations</p><p>(03:54) Late Security Integration </p><p>(05:22) Regulatory Bodies in Medical Device Cybersecurity</p><p>(09:24) Classifications of Medical Devices</p><p>(12:38) Types of Premarket Submissions: 510K, PMA, and De Novo</p><p>(21:49) Vulnerability Chaining in an Acne Treatment Laser</p><p>(31:25) The Positive Impact of Regulations on Medical Device Security</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></description><content:encoded><![CDATA[<p>What are the main categories of medical devices, and how do regulatory bodies govern them? </p><p>In this episode, Christian Espinosa and Trevor Slattery unpack the complex regulatory environment surrounding medical device cybersecurity. In discussing the key regulations, standards, and FDA guidelines that govern the industry, they explore how these regulations shape the design, development, and deployment of secure medical devices.</p><p>Topics discussed and key points: </p><p><br></p><p>* Incorporating cybersecurity from the beginning of the medical device development process. </p><p><br></p><p>* The challenges of integrating cybersecurity into medical devices after they have been developed. </p><p><br></p><p>* The impact of the FDA's new guidance on medical device cybersecurity and the increase in submission rejections. </p><p><br></p><p>* The different classifications of medical devices and their associated risks. </p><p><br></p><p>* How vulnerability can lead to more significant security risks. </p><p><br></p><p>* Real-world examples of medical device vulnerabilities.</p><p><br></p><p>* The role of regulations in improving the safety and security of medical devices. </p><p><br></p><p>Chapters: </p><p><br></p><p>(00:30) Medical Device Categories, Manufacturers, and Regulatory Bodies</p><p>(01:19) Early Cybersecurity Considerations</p><p>(03:54) Late Security Integration </p><p>(05:22) Regulatory Bodies in Medical Device Cybersecurity</p><p>(09:24) Classifications of Medical Devices</p><p>(12:38) Types of Premarket Submissions: 510K, PMA, and De Novo</p><p>(21:49) Vulnerability Chaining in an Acne Treatment Laser</p><p>(31:25) The Positive Impact of Regulations on Medical Device Security</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p><br></p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p><br></p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p><br></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p><br></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">70dffba8-0889-4873-99b0-96cc14c000c6</guid><itunes:image href="https://artwork.captivate.fm/24d75218-e9df-427d-8096-ec0113dcd02d/zVcy7RL2bjYUx70155_YrZGa.jpg"/><pubDate>Tue, 12 Nov 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/62f3b615-2b14-4348-8d4a-05c2879b9320/MDC-Episode-3-Audio-1.mp3" length="63033885" type="audio/mpeg"/><itunes:duration>32:48</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><podcast:episode>3</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-62f3b615-2b14-4348-8d4a-05c2879b9320.json" type="application/json+chapters"/></item><item><title>Hidden Vulnerabilities in Medical Devices: Why Cybersecurity Matters</title><itunes:title>Hidden Vulnerabilities in Medical Devices: Why Cybersecurity Matters</itunes:title><description><![CDATA[<p>How vulnerable are current medical devices to cyberattacks, and what are the consequences of these exploits?</p><p>In this episode, Christian Espinosa and Trevor Slattery discuss the critical vulnerabilities in medical devices and the cybersecurity threats they face. From AI-assisted diagnostic tools to surgical robots, they delve into real-world examples and explain the consequences of exploited devices.</p><p>Topics discussed and key points: </p><p><br></p><p>* The vulnerabilities in legacy medical devices that predate current cybersecurity regulations.</p><p><br></p><p>* The growing use of AI in medical devices and its potential risks.</p><p><br></p><p>* Surgical robots and the dangers of remote telesurgery hacks.</p><p><br></p><p>* The impact of non-directed vs. directed cyberattacks on medical devices.</p><p><br></p><p>* Threat modeling and its role in identifying device vulnerabilities.</p><p><br></p><p>* Regulatory frameworks like the FDA’s recent cybersecurity guidelines.</p><p><br></p><p>* The significance of maintaining the confidentiality, integrity, and availability (CIA) of medical devices.</p><p><br></p><p>* The importance of securing medical devices in both healthcare and industrial settings.</p><p><br></p><p>Chapters: </p><p><br></p><p>02:30 - Exploiting Medical Devices: Types and Consequences</p><p>06:00 - The Role of AI in Medical Device Security</p><p>09:40 - Threat Modeling and Its Importance</p><p>13:50 - Non-Directed vs. Directed Attacks</p><p>16:35 - Real-World Exploits: Dick Cheney’s Pacemaker</p><p>19:00 - Broader Implications: Medical Devices Beyond Healthcare</p><p><br></p><p>Resources and cool things mentioned in this episode that you can Google: </p><p><br></p><p>* MITRE Threat Modeling Playbook for Medical Devices.</p><p><br></p><p>* FDA Medical Device Cybersecurity Guidelines (September 2023).</p><p><br></p><p>* "Vice," a movie about Vice President Dick Cheney, starring Christian Bale.</p><p><br></p><p>* The ABC News story about Dick Cheney's pacemaker.</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></description><content:encoded><![CDATA[<p>How vulnerable are current medical devices to cyberattacks, and what are the consequences of these exploits?</p><p>In this episode, Christian Espinosa and Trevor Slattery discuss the critical vulnerabilities in medical devices and the cybersecurity threats they face. From AI-assisted diagnostic tools to surgical robots, they delve into real-world examples and explain the consequences of exploited devices.</p><p>Topics discussed and key points: </p><p><br></p><p>* The vulnerabilities in legacy medical devices that predate current cybersecurity regulations.</p><p><br></p><p>* The growing use of AI in medical devices and its potential risks.</p><p><br></p><p>* Surgical robots and the dangers of remote telesurgery hacks.</p><p><br></p><p>* The impact of non-directed vs. directed cyberattacks on medical devices.</p><p><br></p><p>* Threat modeling and its role in identifying device vulnerabilities.</p><p><br></p><p>* Regulatory frameworks like the FDA’s recent cybersecurity guidelines.</p><p><br></p><p>* The significance of maintaining the confidentiality, integrity, and availability (CIA) of medical devices.</p><p><br></p><p>* The importance of securing medical devices in both healthcare and industrial settings.</p><p><br></p><p>Chapters: </p><p><br></p><p>02:30 - Exploiting Medical Devices: Types and Consequences</p><p>06:00 - The Role of AI in Medical Device Security</p><p>09:40 - Threat Modeling and Its Importance</p><p>13:50 - Non-Directed vs. Directed Attacks</p><p>16:35 - Real-World Exploits: Dick Cheney’s Pacemaker</p><p>19:00 - Broader Implications: Medical Devices Beyond Healthcare</p><p><br></p><p>Resources and cool things mentioned in this episode that you can Google: </p><p><br></p><p>* MITRE Threat Modeling Playbook for Medical Devices.</p><p><br></p><p>* FDA Medical Device Cybersecurity Guidelines (September 2023).</p><p><br></p><p>* "Vice," a movie about Vice President Dick Cheney, starring Christian Bale.</p><p><br></p><p>* The ABC News story about Dick Cheney's pacemaker.</p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p><p>Subscribe via YouTube: <a href="https://www.youtube.com/@BlueGoatCyber/podcasts" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber/podcasts</a> </p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">7219782c-af82-4d15-a49c-9414d7c86e0c</guid><itunes:image href="https://artwork.captivate.fm/baf0ad1f-d7d7-4d74-9c02-a02e852b6b33/AZ1HDap6qazKFRg-eabdCdoL.jpg"/><pubDate>Tue, 29 Oct 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/e8e86d4e-0d1f-485b-8991-0642f026a72a/MDC-Episode-2-Audio.mp3" length="44836579" type="audio/mpeg"/><itunes:duration>23:20</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><podcast:episode>2</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-e8e86d4e-0d1f-485b-8991-0642f026a72a.json" type="application/json+chapters"/></item><item><title>Cybersecurity for Medical Devices: Protecting Human Lives</title><itunes:title>Cybersecurity for Medical Devices: Protecting Human Lives</itunes:title><description><![CDATA[<p>How do medical device cybersecurity risks differ from traditional cybersecurity threats?</p><p>In this episode, Christian Espinosa and Trevor Slattery discuss the critical importance of cybersecurity for medical devices, sharing real-life stories and insights into how device vulnerabilities can impact patient safety. </p><p>Topics discussed and key points: </p><p>* Differences between traditional cybersecurity and medical device cybersecurity.</p><p><br></p><p>* The real-life consequences of medical device security failures, including life or death situations.</p><p><br></p><p>* Trevor's experience with tachycardia and the life-saving impact of ECG monitoring devices.</p><p><br></p><p>* Christian’s story about diagnosing six blood clots using a Doppler ultrasound device.</p><p><br></p><p>* How ransomware like WannaCry has compromised medical devices in hospital environments.</p><p><br></p><p>* Barnaby Jack’s research on vulnerabilities in pacemakers and insulin pumps.</p><p><br></p><p>* The significance of integrity and availability over confidentiality in medical device security.</p><p><br></p><p>* The challenges of securing Windows-based medical devices and embedded systems.</p><p><br></p><p>Chapters: </p><p><br></p><p>00:50 - Personal Medical Device Experiences</p><p>03:53 - Medical Device Security vs Traditional Cybersecurity</p><p>07:19 - Ransomware Impact on Medical Devices</p><p>09:50 - The Prevalence of Windows in Medical Devices</p><p>12:10 - Real-Life Medical Device Vulnerabilities</p><p>13:22 - Barnaby Jack’s Research and Device Vulnerabilities</p><p><br></p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></description><content:encoded><![CDATA[<p>How do medical device cybersecurity risks differ from traditional cybersecurity threats?</p><p>In this episode, Christian Espinosa and Trevor Slattery discuss the critical importance of cybersecurity for medical devices, sharing real-life stories and insights into how device vulnerabilities can impact patient safety. </p><p>Topics discussed and key points: </p><p>* Differences between traditional cybersecurity and medical device cybersecurity.</p><p><br></p><p>* The real-life consequences of medical device security failures, including life or death situations.</p><p><br></p><p>* Trevor's experience with tachycardia and the life-saving impact of ECG monitoring devices.</p><p><br></p><p>* Christian’s story about diagnosing six blood clots using a Doppler ultrasound device.</p><p><br></p><p>* How ransomware like WannaCry has compromised medical devices in hospital environments.</p><p><br></p><p>* Barnaby Jack’s research on vulnerabilities in pacemakers and insulin pumps.</p><p><br></p><p>* The significance of integrity and availability over confidentiality in medical device security.</p><p><br></p><p>* The challenges of securing Windows-based medical devices and embedded systems.</p><p><br></p><p>Chapters: </p><p><br></p><p>00:50 - Personal Medical Device Experiences</p><p>03:53 - Medical Device Security vs Traditional Cybersecurity</p><p>07:19 - Ransomware Impact on Medical Devices</p><p>09:50 - The Prevalence of Windows in Medical Devices</p><p>12:10 - Real-Life Medical Device Vulnerabilities</p><p>13:22 - Barnaby Jack’s Research and Device Vulnerabilities</p><p><br></p><p><br></p><p>This episode of The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting <a href="https://bluegoatcyber.com/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com</a> </p><p><br></p><p>If you’re interested in our services or partnering with us, schedule a Discovery Session: <a href="https://meetings.hubspot.com/blue-goat-cyber/discovery-session" rel="noopener noreferrer" target="_blank">https://meetings.hubspot.com/blue-goat-cyber/discovery-session</a> </p><p><br></p><p>Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Director of Medical Device Cybersecurity at Blue Goat Cyber. </p><p><br></p><p>Christian Espinosa on LinkedIn: <a href="https://www.linkedin.com/in/christianespinosa/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/christianespinosa/</a> </p><p><br></p><p>Blue Goat Cyber on LinkedIn: <a href="https://www.linkedin.com/company/blue-goat-cyber/" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/company/blue-goat-cyber/</a> </p><p>Blue Goat Cyber on Instagram: <a href="https://www.instagram.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.instagram.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on Facebook: <a href="https://www.facebook.com/bluegoatcyber/" rel="noopener noreferrer" target="_blank">https://www.facebook.com/bluegoatcyber/</a> </p><p>Blue Goat Cyber on YouTube: <a href="https://www.youtube.com/@BlueGoatCyber" rel="noopener noreferrer" target="_blank">https://www.youtube.com/@BlueGoatCyber</a> </p><p><br></p><p>Trevor Slattery on LinkedIn: <a href="https://www.linkedin.com/in/trevor-slattery-34852b1a9" rel="noopener noreferrer" target="_blank">https://www.linkedin.com/in/trevor-slattery-34852b1a9</a> </p><p><br></p><p>Feedback? Questions? Contact: <a href="https://bluegoatcyber.com/contact/" rel="noopener noreferrer" target="_blank">https://bluegoatcyber.com/contact/</a> </p><p><br></p><p>Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: <a href="https://christianespinosa.com/" rel="noopener noreferrer" target="_blank">https://christianespinosa.com/</a> </p><p><br></p><p>Christian Espinosa on YouTube: <a href="http://www.youtube.com/@ChristianEspinosaOfficial" rel="noopener noreferrer" target="_blank">http://www.youtube.com/@ChristianEspinosaOfficial</a> </p><p><br></p><p>The Med Device Cyber Podcast is your essential resource for medical device cybersecurity. Each episode we dive into the latest threats, solutions, and best practices to protect modern healthcare technology. Whether you're a provider, a manufacturer, or a cybersecurity professional, gain the knowledge to safeguard patient safety by subscribing to the Med Device Cyber Podcast. </p><p><br></p><p>Subscribe via Spotify: <a href="https://spoti.fi/3XX95g0" rel="noopener noreferrer" target="_blank">https://spoti.fi/3XX95g0</a></p><p>Subscribe via Apple Podcasts: <a href="https://apple.co/483OJ9I" rel="noopener noreferrer" target="_blank">https://apple.co/483OJ9I</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">d8630e29-4252-4bbf-b898-1192fb415ca0</guid><itunes:image href="https://artwork.captivate.fm/86f033b7-031a-46e6-8111-59b64d8b472f/fU6IVyiH2SigWuKwMycPwZtV.jpg"/><pubDate>Tue, 15 Oct 2024 04:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/38f44066-e62a-44be-98d2-cdbc23ae4f6e/MDC-Episode-1-Audio-1.mp3" length="31225060" type="audio/mpeg"/><itunes:duration>16:15</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><podcast:episode>1</podcast:episode><podcast:season>1</podcast:season><podcast:chapters url="https://transcripts.captivate.fm/chapter-38f44066-e62a-44be-98d2-cdbc23ae4f6e.json" type="application/json+chapters"/></item><item><title>Trailer - The Med Device Cyber Podcast</title><itunes:title>Trailer - The Med Device Cyber Podcast</itunes:title><description><![CDATA[<p>You rely on a medical device to stay healthy, but what if that device could be hacked? What if someone, miles away, could manipulate it, putting your loved one’s life at risk?</p><p>Welcome to the trailer for The Med Device Cyber Podcast, the podcast dedicated to medical device cybersecurity.</p><p>Join Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, as they reveal the hidden risks and solutions to protect our health. Every fortnight, Christian and Trevor bring you insights from industry experts, healthcare professionals, and cybersecurity leaders who are working on the front lines to protect patients.</p><p>Whether you’re in the medical field or simply want to protect your loved ones, we’ll give you practical advice on how to ensure medical devices are secure. Subscribe to The Med Device Cyber Podcast now on your favorite podcast platform!</p><p><br></p><p>Learn more about medical device cyber security solutions at <a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">bluegoatcyber.com</a></p>]]></description><content:encoded><![CDATA[<p>You rely on a medical device to stay healthy, but what if that device could be hacked? What if someone, miles away, could manipulate it, putting your loved one’s life at risk?</p><p>Welcome to the trailer for The Med Device Cyber Podcast, the podcast dedicated to medical device cybersecurity.</p><p>Join Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, as they reveal the hidden risks and solutions to protect our health. Every fortnight, Christian and Trevor bring you insights from industry experts, healthcare professionals, and cybersecurity leaders who are working on the front lines to protect patients.</p><p>Whether you’re in the medical field or simply want to protect your loved ones, we’ll give you practical advice on how to ensure medical devices are secure. Subscribe to The Med Device Cyber Podcast now on your favorite podcast platform!</p><p><br></p><p>Learn more about medical device cyber security solutions at <a href="https://bluegoatcyber.com" rel="noopener noreferrer" target="_blank">bluegoatcyber.com</a></p>]]></content:encoded><link><![CDATA[https://bluegoatcyber.com]]></link><guid isPermaLink="false">a9a752e2-1e5e-45ed-846b-b9f4bcadc82b</guid><itunes:image href="https://artwork.captivate.fm/342adb06-0f9a-42b7-a36d-9d208609071e/DOXwtetTHZbV2qzfzvNijnJY.jpg"/><pubDate>Tue, 01 Oct 2024 09:00:00 -0700</pubDate><enclosure url="https://podcasts.captivate.fm/media/3ee4a700-20b3-48df-b7ea-7a16d2865c48/MDC-Trailer.mp3" length="2529839" type="audio/mpeg"/><itunes:duration>01:19</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><podcast:season>1</podcast:season></item></channel></rss>