Blue Goat Cyber
The Med Device Cyber Podcast
In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each epis...
Author
Blue Goat Cyber
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Webinar: Medical Device Penetration Testing: What Every Manufacturer Must Know 14.08.2025 44:59
What are the unique challenges and regulatory requirements of medical device penetration testing? In this webinar episode with Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, CTO of Blue Goat Cyber, you’ll learn: * How Medical Device Penetration Testing Differs from Traditional IT Security. Unlike conventional IT security testing, medical device penetration testing pri...
From Surgery to MedTech Startups: Dr. Dylan Attard’s Journey 12.08.2025 44:54
What cybersecurity challenges face hospitals and medical devices today that medtech innovators should know about? Today’s guest is Dr. Dylan Attard, who swapped his scalpel for startups when he founded MedTech World, a global conference series elevating healthcare innovation. He’s passionate about connecting startups with investors and sparking conversations that turn bold ideas into life-saving s...
Webinar: Medical Device Risk Assessments - Cybersecurity, Compliance & Patient Safety 07.08.2025 33:28
Medical devices are becoming more connected, but with that connectivity comes risk. In this episode, Christian and Trevor dive into risk assessments for medical devices—a crucial process in ensuring both patient safety and cybersecurity compliance. They discuss: * The difference between risk management and risk assessment * How risk scoring works using exploitability vs. impact * Why traditional c...
Understanding Cybersecurity Measures and Metrics for Medical Devices 05.08.2025 24:08
How do measures and metrics differ, and why is this distinction crucial for FDA submissions? In this episode, Christian and Trevor demystify the difference between cybersecurity measures and metrics in the context of FDA guidance. They explore what the FDA expects in submissions, emphasizing patch timelines, vulnerability tracking, and post-market data collection. They also discuss the importance...
Webinar: Mastering Threat Modeling for Medical Device Cybersecurity 31.07.2025 43:18
Christian Espinosa, CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, explore the critical topic of threat modeling in medical device cybersecurity. This session covers essential practices and frameworks that ensure the safety and security of medical devices, aligning with FDA guidelines. We cover the DFD3 standard for threat diagramming and the STRIDE framewor...
FDA Cybersecurity Gets Real with Monica Montañez of NAMSA 29.07.2025 32:47
How have medical device cybersecurity requirements changed since 2023, and what does this mean for your product development? In this episode, Christian and Trevor welcome Monica Montañez from NAMSA to unpack the evolving landscape of FDA cybersecurity requirements. From new laws introduced in 2023 to the ambiguous language in FDA guidance, they dig into what it really takes to meet expectations fo...
Webinar: Risk Management Frameworks For Medical Device Safety & Security 24.07.2025 43:18
Join Trevor Slattery, Director of Cybersecurity, and Christian Espinosa, CEO of Blue Goat Cyber, for a comprehensive webinar on medical device cybersecurity. Trevor and Christian explore the critical interplay between safety and security risk management, offering guidance on conducting effective risk assessments that address vulnerabilities across both domains. This presentation will give you a de...
What the FDA Wants in Security Architecture Views for Devices 22.07.2025 27:55
What are the four security architecture views that the FDA prioritizes, and how do they impact your device's design? This episode explores the FDA-defined security architecture views essential for medical device cybersecurity. Christian and Trevor break down the four views—global system, updatability/patchability, multi-patient harm, and secure use cases—with real-world examples and practical advi...
Webinar: 5 Key FDA Cybersecurity Standards with Jordan John 17.07.2025 49:41
How can you integrate relevant cybersecurity standards early in your medical device development process? Also, how do FDA cybersecurity standards help reduce the time to market for new medical devices? In this episode, Trevor Slattery, CTO of Blue Goat Cyber, and Jordan John, Director of Regulatory Affairs and Compliance at Blue Goat Cyber, explore: * The importance of integrating standards into t...
Shared Responsibility in Medical Device Cybersecurity with Greg Garcia 15.07.2025 52:54
How can shared responsibility models improve healthcare cybersecurity? In this episode, Greg Garcia joins Christian and Trevor to break down the evolving landscape of medical device cybersecurity from a national policy perspective. Together, they discuss the legacy device challenge, shared accountability, and how sector-wide collaboration is critical to progress. The episode drives home the messag...
Total Product Lifecycle Security: From Design to Disposal 08.07.2025 35:00
How well does your security strategy cover the entire product lifespan—from concept to decommissioning? This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development env...
Why Cybersecurity and Quality Are One and the Same 01.07.2025 37:19
How can medical device startups avoid missteps in cybersecurity, quality, and compliance? In this episode, Trevor Slattery speaks with Ashkon Rasooli about the intersection of quality systems and cybersecurity in medical devices. They unpack why treating cybersecurity as a bolt-on checklist is ineffective and even dangerous. They also discuss regulatory realities, risk management frameworks, and h...
Cybersecurity Labeling and MedTech Transparency 24.06.2025 31:06
Why is cybersecurity labeling more than just a compliance checkbox for medical device companies? In this episode, Christian and Trevor dive into the nuanced world of cybersecurity labeling for medical devices. They discuss the role of MDS2 and JSP2 documentation, labeling misconceptions, and how manufacturers can best disclose security information without overwhelming or misleading users. Key poin...
From Concept to Compliance: A Guide to Med Device Approval 17.06.2025 39:41
Med device manufacturers, are you setting up your quality system early enough in product development? Also, are you misunderstanding the FDA’s "guidance" documents—and risking rejection? Today’s guests are Mark Swanson and Steve Gompertz of QRx Partners, and they’re passionate about helping medtech companies dodge the regulatory and quality pitfalls that derail so many startups. This episode explo...
Unpacking Post-Market Management and Incident Response for Medical Devices 10.06.2025 28:12
What should you do when a vulnerability is discovered in a medical device after it's already on the market? This dives into post-market management and incident response for medical devices, exploring what happens when a device is hacked or a vulnerability is reported. Christian Espinosa and Trevor Slattery discuss the processes involved in identifying, triaging, and remediating vulnerabilities, em...
AI in Medical Devices: Opportunities & Regulation with Matt Lemay 03.06.2025 42:38
What does responsible AI implementation look like in medical devices? This episode explores the intersection of AI, cybersecurity, and medical device regulation with guest Matt Lemay, CEO of Lemay.ai. Hosts Christian Espinosa and Trevor Slattery of Blue Goat Cyber dig into how AI models are trained, certified, and deployed in clinical contexts—and what can go wrong. Key points: (7:29) Data, Securi...
Essential Software Documentation for Med Device Manufacturers 27.05.2025 27:39
What documents should engineers prepare to get ready for submitting a medical device to the FDA? In this episode, Christian and Trevor dig into the underestimated role software documentation plays in cybersecurity, especially in the medical device space. They highlight how incomplete or contextless documentation can hinder everything from SBOM utility to regulatory compliance. With sharp insights...
The Human Factor in MedTech Design with Dylan Horvath 20.05.2025 35:16
How can human-centered design influence medical device cybersecurity? In this episode, Christian Espinosa chats with Dylan Horvath of Cortex Design about the powerful intersection of human-centered design and medical device cybersecurity. They explore how usability, trust, and empathy can shape safer, smarter devices from the start. Dylan also shares valuable insights into building design teams, l...
Master Medical Device Cybersecurity: Avoid FDA Delays | Blue Goat Cyber Webinar 13.05.2025 33:18
How can medical device manufacturers meet FDA cybersecurity requirements the first time around? What are the most significant challenges medical device manufacturers face in ensuring FDA cybersecurity compliance? In this webinar, Trevor Slattery, CTO of Blue Goat Cyber, dives into what it takes to master medical device cybersecurity and avoid costly delays with the FDA. He outlines common pitfalls...
Data Protection in Medical Devices: A Deep Dive with Kevin Derr 06.05.2025 46:14
How can medical device companies own their data without compromising security? In this episode, Kevin Derr from NeuronSphere joins Christian and Trevor to dive into the intersection of cybersecurity, compliance, and innovation in the medtech world. They also explore why data ownership and secure system architecture are foundational for FDA compliance and patient safety. Key points: (0:47) From Big...
Early Cyber Strategies for MedTech Trailblazers 29.04.2025 27:44
What are some strategies founders can use to incorporate cybersecurity into the early stages of developing a medtech product? In this episode, Christian and Trevor break down the critical role of cybersecurity in early-stage medtech startups. They explore why cybersecurity is often overlooked, what the real-world consequences are, and how startups can shift left to avoid costly pitfalls. From VC f...
Cybersecurity Challenges & Trends in US Healthcare with Paul-Lukas Hoffschmidt 22.04.2025 34:58
If you’re launching a medtech product, what should you know about market access, cybersecurity, reimbursement challenges, and customer education? In this episode, Christian and Trevor discuss the challenges and opportunities facing medtech startups with guest Paul-Lukas Hoffschmidt, CEO of Alpha Sophia. This conversation covers trends in US healthcare, the importance of cybersecurity and interoper...
Collaboration is Key: Bridging the Gap Between Developers and Cybersecurity Experts 15.04.2025 29:57
What are some of the biggest barriers to effective collaboration between coders and cyber experts, and how can they be overcome? This episode explores the essential components of successful collaboration and teamwork. The discussion delves into common challenges teams face and practical strategies for improving communication and trust. Key points that Christian and Trevor explore: (00:31) Develope...
Commercialize Your Medtech with Craig T Ingram 08.04.2025 45:14
What are the 10 essential components of a successful commercialization plan in the medtech industry, and why are they often overlooked? This episode explores the critical role of commercialization in the medtech industry. The conversation explores the reasons behind the high failure rate of medtech startups and emphasizes the importance of a comprehensive commercialization plan, cybersecurity cons...
The Growing Importance of Interoperability and Third-Party Component Security 25.03.2025 37:09
Why is interoperability increasing cybersecurity risks in healthcare, and what can we do about it? Interoperability is making healthcare more efficient but also more vulnerable to cyber threats. In this episode, Christian and Trevor discuss how second-order attacks, misconfigured cloud systems, and poor data integrity controls can compromise medical devices. They also share practical steps manufac...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.