The Med Device Cyber Podcast Podcast Por Blue Goat Cyber arte de portada

The Med Device Cyber Podcast

The Med Device Cyber Podcast

De: Blue Goat Cyber
Escúchala gratis

Acerca de esta escucha

In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology. This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.Copyright 2025 Blue Goat Cyber Economía Hygiene & Healthy Living Medicina Alternativa y Complementaria
Episodios
  • Total Product Lifecycle Security: From Design to Disposal
    Jul 8 2025

    How well does your security strategy cover the entire product lifespan—from concept to decommissioning?

    This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks.


    Key points:


    (1:50) Intro to TPLC and SPDF

    * The importance of TPLC and SPDF in secure development.


    (7:00) Update Vulnerabilities and OTA Risks

    * An example of compromised keys in an otherwise secure over-the-air (OTA) process.

    * Trade-offs between update convenience and security.


    (12:16) Threat Modeling

    * Threat modeling’s application to development environments.

    * The overlooked risks of data storage locations and natural disasters.


    (17:24) Infrastructure Challenges

    * How clients struggled with infrastructure across hospital environments.

    * How scripts and hardcoded passwords can introduce risk.


    (19:56) Building a SPDF That Works

    * Best practices: coding standards, multi-layer review, and automated testing.

    * Secure development is like planning for your own death—it’s hard, but necessary.


    The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com


    If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session


    Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.

    Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/


    Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/

    Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/

    Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/

    Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber


    Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9


    Feedback? Questions? Contact: https://bluegoatcyber.com/contact/


    Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage: https://christianespinosa.com/


    Christian Espinosa on YouTube:

    Más Menos
    35 m
  • Why Cybersecurity and Quality Are One and the Same
    Jul 1 2025

    How can medical device startups avoid missteps in cybersecurity, quality, and compliance?

    In this episode, Trevor Slattery speaks with Ashkon Rasooli about the intersection of quality systems and cybersecurity in medical devices. They unpack why treating cybersecurity as a bolt-on checklist is ineffective and even dangerous. They also discuss regulatory realities, risk management frameworks, and how early-stage teams can avoid costly pitfalls by planning smarter from the start.


    Ashkon Rasooli is the CEO of EnGenius Solutions, a boutique consulting firm focused on medical device software development. With a background in both hands-on coding and compliance, Ashkon helps medtech startups navigate quality systems and regulatory strategy.


    Key points:


    (0:31) Why Regulations and Cybersecurity Are Intertwined

    * How EnGenius helps small medtech companies plan early.

    * Challenging the idea that cybersecurity and QMS are separate disciplines.


    (7:12) Planning Cybersecurity Early

    * Business model, product design, and geography all shape your compliance path.


    (12:16) Culture Over Checklists in MedTech Security

    * Ashkon’s “Non-BS Manifesto” based on Agile principles.

    * Real-world examples of ransomware causing patient harm.


    (20:38) Why Probabilistic Risk Scoring Falls Short

    * How exploitability trumps probability in FDA guidance.

    * How cybersecurity attackers differ from typical safety failures.


    (28:14) Planning Compliance

    * Dick Cheney’s pacemaker becomes a cautionary tale of targeted threats.


    Thanks to Ashkon Rasooli for being on the show. Connect with him: https://www.linkedin.com/in/ashkonrasooli

    Check out EnGenius Solutions: https://www.engeniussolutions.com


    The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com


    If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session


    Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.


    Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/


    Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/

    Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/

    Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/

    Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber


    Trevor Slattery on LinkedIn:

    Más Menos
    37 m
  • Cybersecurity Labeling and MedTech Transparency
    Jun 24 2025

    Why is cybersecurity labeling more than just a compliance checkbox for medical device companies?

    In this episode, Christian and Trevor dive into the nuanced world of cybersecurity labeling for medical devices. They discuss the role of MDS2 and JSP2 documentation, labeling misconceptions, and how manufacturers can best disclose security information without overwhelming or misleading users.


    Key points:


    (6:30) Misconceptions About Cybersecurity Labeling

    * Many manufacturers worry that disclosing risks will aid hackers, but that's flawed thinking.

    * Distinctions between labeling as documentation and labeling as a control like a tamper-evident seal.

    * Everyday product examples to illustrate why transparency in labeling matters.


    (12:45) How Much Detail Is Enough?

    * How deep a manufacturer should go with disclosures about encryption and risk.

    * Why more detail is generally better and how to balance tech jargon with user readability.

    * Different labeling needs based on whether a device is for consumers or hospitals.


    (18:20) Context, Risk, and Communication

    * Why not encrypting unnecessary data can backfire if a consumer is misinformed.

    * How labeling must be contextual and tailored to a device’s function and data sensitivity.


    Resources mentioned in this episode:


    * The Manufacturer Disclosure Statement for Medical Device Security (generally abbreviated as MDS2).

    * The Medical Device and Health IT Joint Security Plan, version 2 (JSP2).


    The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity professionals specializing in providing elite cyber solutions for medical devices. Learn more about securing your product and business from cyber-criminals by visiting https://bluegoatcyber.com


    If you’re interested in our services or partnering with us, schedule a Discovery Session: https://meetings.hubspot.com/blue-goat-cyber/discovery-session


    Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Technology Officer / Director of MedTech Cybersecurity at Blue Goat Cyber.


    Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/


    Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/

    Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/

    Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/

    Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber


    Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9


    Feedback? Questions? Contact: https://bluegoatcyber.com/contact/


    Learn more about Christian Espinosa, buy his books, or invite him to speak on your stage:

    Más Menos
    31 m
Todavía no hay opiniones