
Sign up to save your podcasts
Or
Christian Espinosa, founder of Blue Goat Cyber and leading voice in medical device cybersecurity, joins Etienne Nichols to unpack the urgent and often misunderstood topic of cybersecurity in MedTech. From FDA’s 2023 regulatory overhaul to real-world hacking scenarios that could harm patients, Christian provides practical advice for innovators, RA/QA professionals, and software teams. He also shares why waiting until the last minute on cybersecurity could cost startups millions—or even kill a project entirely.
Whether you're a quality professional trying to build compliant systems or an innovator racing toward FDA submission, this episode lays out exactly what you need to know to stay ahead of cyber threats and within regulatory guardrails.
Key Timestamps:
Standout Quotes:
“Cybersecurity for medical devices isn’t about data breaches—it’s about patient harm. You could paralyze someone or misdiagnose sepsis. This isn’t theoretical.”— Christian Espinosa, on the real risks of insecure devicesTop Takeaways:
References & Resources:
MedTech 101 – Understanding SBOM (Software Bill of Materials):
Think of an SBOM like a nutrition label on food. Just as you want to know if a product contains allergens or preservatives, FDA wants to know what libraries and components are in your software. A clean, complete SBOM identifies both security vulnerabilities and potential licensing conflicts—like borrowing ingredients you’re not legally allowed to use. Want a visual explanation? Consider a flowchart showing third-party libraries linking into your main software repository, flagged with vulnerability scores.
Poll Question:
Is cybersecurity currently integrated into your product development process—
A) From Day 1
B) Only near submission
C) We outsource and hope for the best
D) What cybersecurity?
What’s your biggest challenge when it comes to building cybersecurity into your product lifecycle? Email us your thoughts at [email protected].
Feedback:
If this episode sparked new insights or raised questions, we’d love to hear from you. Send us your feedback or suggest a topic at [email protected]. We personally respond to every email and appreciate your ideas for future guests and discussions.
Sponsored by Greenlight Guru:
Most companies spend more time preparing for audits than in the audit itself. Greenlight Guru Quality lets you link cybersecurity and quality evidence directly to requirements, making you “always audit-ready.” Learn more at www.greenlight.guru.
Christian Espinosa, founder of Blue Goat Cyber and leading voice in medical device cybersecurity, joins Etienne Nichols to unpack the urgent and often misunderstood topic of cybersecurity in MedTech. From FDA’s 2023 regulatory overhaul to real-world hacking scenarios that could harm patients, Christian provides practical advice for innovators, RA/QA professionals, and software teams. He also shares why waiting until the last minute on cybersecurity could cost startups millions—or even kill a project entirely.
Whether you're a quality professional trying to build compliant systems or an innovator racing toward FDA submission, this episode lays out exactly what you need to know to stay ahead of cyber threats and within regulatory guardrails.
Key Timestamps:
Standout Quotes:
“Cybersecurity for medical devices isn’t about data breaches—it’s about patient harm. You could paralyze someone or misdiagnose sepsis. This isn’t theoretical.”— Christian Espinosa, on the real risks of insecure devicesTop Takeaways:
References & Resources:
MedTech 101 – Understanding SBOM (Software Bill of Materials):
Think of an SBOM like a nutrition label on food. Just as you want to know if a product contains allergens or preservatives, FDA wants to know what libraries and components are in your software. A clean, complete SBOM identifies both security vulnerabilities and potential licensing conflicts—like borrowing ingredients you’re not legally allowed to use. Want a visual explanation? Consider a flowchart showing third-party libraries linking into your main software repository, flagged with vulnerability scores.
Poll Question:
Is cybersecurity currently integrated into your product development process—
A) From Day 1
B) Only near submission
C) We outsource and hope for the best
D) What cybersecurity?
What’s your biggest challenge when it comes to building cybersecurity into your product lifecycle? Email us your thoughts at [email protected].
Feedback:
If this episode sparked new insights or raised questions, we’d love to hear from you. Send us your feedback or suggest a topic at [email protected]. We personally respond to every email and appreciate your ideas for future guests and discussions.
Sponsored by Greenlight Guru:
Most companies spend more time preparing for audits than in the audit itself. Greenlight Guru Quality lets you link cybersecurity and quality evidence directly to requirements, making you “always audit-ready.” Learn more at www.greenlight.guru.