Skip to main content
    New episodes weekly

    The Med Device
    Cyber Podcast

    Frontline conversations on medical device cybersecurity, FDA premarket guidance, SBOMs, penetration testing, and the hard-won lessons that keep patients safe.

    Hosted by Blue Goat CyberFDA · IEC 62304 · ISO 14971
    The Catalogue

    Every episode, in one place.

    78 episodes & counting
    78 / 78 episodes
    Episode 78 thumbnail, How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78
    EP 078

    How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78

    Why do some teams remain overwhelmed even after introducing new productivity tools? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Sarah Ohanesian and Jeff Gibbard, co-founders of Super Productive, about the systems, communication habits and workplace dynamics that determine whether people can perform at their best. Sarah and Jeff explain why productivity depends on meaningful progress rather than constant activity. They share practical strategies for capturing tasks, prioritising important work, automating repetitive processes and removing the everyday friction that slows organisations down. The conversation also explores the workplace “hero” who repeatedly steps in to save the day. While that behaviour can appear valuable, it may prevent effective delegation, documentation and repeatable processes from developing. Sarah and Jeff discuss how recognition, identity and job security can influence these behaviours and why psychological safety is essential for addressing them. The episode examines neurodiversity at work, including why labels often fail to explain what an individual actually needs. Jeff describes how personal user guides can help employees communicate their preferences, working styles and potential sources of misunderstanding without being placed into a fixed category. In this episode: * Productivity versus busyness * Focusing on the work that matters * Automating repetitive processes * Removing friction from teams * The workplace hero problem * Delegation and psychological safety * Neurodiversity and neurodivergence * Personal user guides for employees * Improving communication between different working styles * Productivity in pharma and biotechnology * AI agents and the future of work * Social engineering in healthcare * AI-powered phishing attacks * Cybersecurity in an AI-driven world Learn more about Sarah Ohanesian, Jeff Gibbard and Super Productive at: https://getsuperproductive.com/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 77 thumbnail, Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77
    EP 077

    Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77

    Could a brain implant allow someone who is completely blind to see again? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Frederik Ceyssens, CEO and co-founder of ReVision Implant, about a visual prosthesis that connects camera-equipped glasses to electrodes implanted within the visual cortex. Rather than attempting to repair the eyes or optic nerve, ReVision Implant aims to stimulate the brain directly. Frederik explains how the technology could allow patients to perceive shapes, identify where people are standing, read large letters and navigate their surroundings more independently. The discussion also examines the cybersecurity risks of connecting external technology to an implant inside the brain. Could an attacker change the algorithm, interfere with what the patient sees or increase the stimulation to dangerous levels? How do manufacturers secure an implant expected to remain inside a patient for 15 years or longer? Frederik also shares what his team learned through long-term animal studies, why patients may need months of rehabilitation, and how recent funding will support the first stages of human testing. In this episode: * 00:38 Frederik’s background in neural implant research * 02:31 Why ReVision Implant targets the visual cortex instead of the eye * 04:26 Developing flexible brain electrodes through long-term testing * 06:48 Raising €4 million to advance the technology * 07:42 Preparing for the first proof of concept with a human volunteer * 09:24 How the glasses and brain implant work together * 11:04 What vision through the implant may look like * 12:33 Why colour and depth perception remain difficult * 16:16 The cybersecurity implications of a visual prosthesis * 17:43 How an attacker could manipulate the device * 20:25 The hardest parts of developing neurotechnology * 22:42 How the implant was tested using monkeys * 26:12 Designing an implant that can last 15 to 25 years * 28:28 Why today’s encryption may not remain secure for decades * 30:16 Why replacing the implant would require months of rehabilitation * 34:51 How close the technology is to science fiction * 36:07 The next steps towards testing with blind volunteers Find Frederik Ceyssens on Linkedin: https://www.linkedin.com/in/frederikceyssens/ Find ReVision Implant at: https://revisionimplant.com The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 76 thumbnail, Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris
    EP 076

    Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris

    What happens when a medical technology company raises $93 million... only to discover it isn't compliant with regulators? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), about one of the biggest challenges facing digital health companies today: building products that are commercially successful, clinically valuable and compliant from the very beginning. Helen explains why cybersecurity has become a requirement in customer procurement, why software as a medical device continues to confuse founders, and why quality management systems, regulatory strategy and cybersecurity must all be considered before products reach the market. The discussion also covers fundraising, choosing the right investors, digital therapeutics, AI in healthcare, wearables, cybersecurity awareness and practical examples that help founders understand when their product becomes a regulated medical device. In This Episode: 00:57 Helen's journey from pharma to digital therapeutics 04:33 The realities of raising MedTech investment in Australia 09:06 Why choosing the right investor matters 13:22 Why many digital health startups misunderstand regulation 15:21 Why cybersecurity comes up in every customer conversation 16:15 Why founders still leave cybersecurity until the end 16:53 Building regulation, quality and cybersecurity from Day One 18:31 The $93 million company forced to pull its product 21:09 Explaining medical devices through the user journey 22:50 The stadium hacking analogy that changes perspectives 25:13 Why wearables need a medical lens 26:57 The fake Wi-Fi demonstration everyone should remember 28:20 Why rebuilding is always more expensive than building properly 29:30 Christian's biggest takeaways Find Helen Souris here on LinkedIn: https://www.linkedin.com/in/helen-souris/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 75 thumbnail, Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug
    EP 075

    Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug

    Cybersecurity is no longer just an IT problem. It's a business resilience challenge. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Melissa Aarskaug to discuss what the medical device industry can learn from one of the world's most heavily regulated sectors: casino gaming. Melissa shares why attackers focus on pressure rather than weaknesses, how regulated industries are adapting to evolving cyber threats, and why organisations must shift their thinking from preventing attacks to maintaining operations when attacks inevitably happen. The conversation explores cyber resilience, leadership, AI, regulatory expectations, penetration testing, cyber insurance, and the growing role cybersecurity plays in overall business strategy. Christian also explains how medical device cybersecurity has evolved from a standalone requirement into an integral part of product quality. In This Episode: 00:00 Introduction 01:09 Lessons from protecting the gaming industry 01:58 Why attackers target regulated industries 05:22 Cybersecurity is about pressure, not industries 06:07 Compliance versus cyber resilience 08:08 Medical devices and connected ecosystems 12:29 The famous fish tank cyberattack 15:03 FDA expectations versus hospital expectations 16:04 AI, cyber maturity and the future of security 17:25 Four priorities every leader should focus on 21:24 Why penetration tests often fail to create change 24:38 Designing cybersecurity into products from the beginning 26:48 Why cyber insurance isn't a silver bullet 32:21 Why cybersecurity is now part of medical device quality 33:26 Cybersecurity is moving beyond IT and into the boardroom 37:42 Final thoughts and key takeaways Find Melissa Aarskaug here on LinkedIn: https://www.linkedin.com/in/melissa-aarskaug/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 74 thumbnail, Cancer Drugs Can Damage the Heart - This Startup Wants to Fix It with Ryan Neely
    EP 074

    Cancer Drugs Can Damage the Heart - This Startup Wants to Fix It with Ryan Neely

    Medical device founders spend years thinking about engineering, clinical validation, and FDA clearance. But what happens after you clear the regulatory hurdle? In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Ryan Neely, co-founder and CEO of Skribe Medical, to discuss the realities of bringing innovative medical technologies to market. Ryan shares how Skribe Medical is developing a wearable cardiac monitoring platform designed to help cancer patients and oncologists identify signs of treatment-related heart damage more efficiently. The conversation explores the challenges of building AI-powered medical devices, integrating new technologies into existing clinical workflows, and reducing friction for both patients and providers. The discussion also explores one of the most surprising cybersecurity insights of the episode: why hospital networks often present greater risks than home environments for connected medical devices. Ryan and Christian examine how cybersecurity considerations evolve as devices become more connected and why manufacturers must think beyond the device itself when assessing risk. In this episode, we cover: * The growing field of cardio-oncology and cardiac monitoring * Building a battery-free wearable medical device * Why clinical workflow matters as much as technical innovation * Cybersecurity risks in connected healthcare environments * Why hospital networks can create unexpected security challenges * FDA cybersecurity expectations and evolving guidance * Commercialization challenges facing MedTech startups * AI models, continuous improvement, and regulatory frameworks * Why FDA clearance is often just the beginning of the journey Episode Breakdown 00:00 – Introduction 01:53 – The hidden cardiac risks of cancer treatments 02:58 – Scribe Medical's wearable cardiac monitoring platform 03:53 – Future applications beyond oncology 04:45 – Battery-free device design and patient comfort 06:00 – Remote patient monitoring and reimbursement models 09:40 – Cybersecurity risks for connected medical devices 14:06 – Why hospital networks present unique security challenges 16:02 – FDA cybersecurity expectations and evolving regulations 19:03 – Regulatory changes and long MedTech development cycles 21:02 – Commercialization versus FDA approval 24:13 – AI models and the Predetermined Change Control Plan 25:55 – Clinical testing and validation challenges 28:14 – Closing thoughts and key takeaways Find Ryan Neely here on LinkedIn: https://www.linkedin.com/in/ryan-neely-ph-d-14464340/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 73 thumbnail, The Legal Hoops and Hurdles of MedTech Commercialization with JJ Amell
    EP 073

    The Legal Hoops and Hurdles of MedTech Commercialization with JJ Amell

    Medical device commercialization is an engineering milestone, but it is also a legal minefield. In this episode, Christian Espinosa and Trevor Slattery welcome MedTech attorney JJ Amell to dissect the critical errors international founders make when entering the U.S. market. If you do not structure your corporate entities and secure your immigration pathways correctly from day one, federal bureaucracy will burn through your venture capital runway before you ever reach an FDA review. JJ outlines how Amell Law builds robust defensive frameworks around global mobility, corporate liability, and trademark protection. In this episode, we cover: * The Legal Zoom Trap: Why automated, check-the-box business formations fail to provide adequate liability shields for multi-million dollar medical operations. * Delaware vs. Texas: How recent case law regarding minority shareholder control is shifting the corporate gold standard toward the Lone Star State. * The Business Immigration Clock: Why O-1 founder visas and engineering team mobility must be negotiated at the absolute start of your commercial strategy. * Automated Pen Testing Failures: The exact financial consequences of submitting cheap security scans to the FDA, resulting in 180-day interactive review holds. * Public Scraper Scams: How bad actors weaponize public USPTO databases to manipulate foreign nationals during active application windows. Episode Breakdown: 00:00 - Intro 00:54 - Welcoming MedTech attorney JJ Amell 03:38 - Solving legal pain points for global innovators 06:11 - The three pillars of U.S. market entry 08:33 - The inverse market challenge: Moving from Europe to the U.S. 10:43 - Factoring in fiscal repercussions and international tax consultations 12:57 - State jurisdictions: Delaware standards vs Texas corporate law 16:21 - California red tape and the rise of alternative technology hubs 22:41 - Reverse engineering corporate strategy to avoid late-stage corrections 25:44 - The danger of automated penetration tests and interactive FDA reviews 29:39 - Deportation risks and B-1/B-2 tourist visa limitations 31:24 - Government bureaucracy timelines and USPTO trademark processing realities 33:04 - Public database scraping and the explosion of corporate filing scams 37:37 - AI voice cloning and deepfake vulnerabilities targeting tech executives 40:52 - Code Blue Chart: Documented cybersecurity fatalities in healthcare 44:25 - Closing thoughts and reconnecting with nature Find JJ Amell here on LinkedIn: https://www.linkedin.com/in/jjamellesq/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 72 thumbnail, The Dangerous Gap in Global MedTech Security Awareness with Shahbaz Ahmed
    EP 072

    The Dangerous Gap in Global MedTech Security Awareness with Shahbaz Ahmed

    Yes, medical device security is a technology problem, but it’s also a human psychology problem. In this episode, Christian and Trevor welcome Shahbaz Ahmed, a Strategic Leadership Advisor from Pakistan, to dissect the massive global gaps in cybersecurity awareness. If people do not understand the threat, they will not invest in the solution. Shahbaz outlines how his Leadership Studio uses human engineering to unify Eastern emotional intelligence and Western strategic logic, giving tech leaders the ultimate toolkit for global commercial operations. In this episode, we cover: * Why 90 percent of people are driven by emotion rather than data, and how that changes the way we must pitch cybersecurity compliance. * The critical distinction between technical leadership and broad vision leadership, and why technical experts often struggle to convince investors. * How capability can intentionally expand your daily capacity through structured priority frameworks like the Pomodoro technique. * The psychological reasons medical communities remain entirely oblivious to the 14 vulnerable devices sitting beside every single hospital bed. * Why absolute consistency outperforms sporadic peak performance every single time when securing digital health networks. Episode Breakdown: * 00:00 - Intro * 02:14 - Leadership styles: Eastern emotion vs Western logic * 05:07 - Human engineering and the science of emotional psychology * 08:31 - Capacity vs capability: breaking down our emotional fuses * 12:28 - Technical leadership vs broad vision leadership * 14:29 - The Ex Machina color theory analogy for cultural exposure * 19:10 - Hungry judges and decision fatigue: how state affects choice * 24:43 - How increasing capability expands human cognitive capacity * 26:35 - The shocking lack of medical device cybersecurity awareness globally * 31:12 - Why regulatory updates are outpacing downstream hospital practice * 35:27 - Breaking down big words to make security simple * 38:00 - Key takeaways: consistency as the ultimate weapon for success Find Shabaz Ahmed here on LinkedIn: https://www.linkedin.com/in/shahbaz-ahmed-4004ab86/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 71 thumbnail, The Age of Digital Health Humanity with Philippe Gerwill
    EP 071

    The Age of Digital Health Humanity with Philippe Gerwill

    Can you use AI and still stay 96.5 percent authentic? Philippe Gerwill joins the Med Device Cyber Podcast to demonstrate how technology can make us more human. As a Digital Health Humanist and top-ranked influencer in Switzerland, Philippe shares a unique perspective on the future of MedTech. Success in this new era requires a mastery of unlearning old habits to make room for radical new capabilities. In this episode, we cover: * The Unlearning Skill: Why letting go of old knowledge is harder than learning new tech. * Managing the Chaos: How Philippe uses AI to balance advisory roles for nearly 30 different companies. * The ChatGPT Shift: Why patients are bypassing doctors and what clinicians need to do about it. * Digital Humanism for Doctors: Keeping the human in front of you in a world of big data. Episode Breakdown: * 00:00 The concept of unlearning as a vital skill for healthcare leaders. * 01:52 Philippe’s background at Novartis and transition into healthcare technology. * 03:35 Managing advisory roles for nearly 30 companies using an AI ecosystem. * 04:50 The Favikon ranking and maintaining a 96.5 percent authenticity score. * 07:49 Defining the role of a futurist in the modern era. * 09:21 The intersection of technology and gut feeling. * 18:15 Patient behavior: why consumers are driving the shift to AI in clinics. * 32:10 The mandate to use our brain and the risks of over-relying on tools. * 44:52 The productivity trap: spending more time reprompting than writing. The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Episode 70 thumbnail, Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | 70
    EP 070

    Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | 70

    Medical software looks deceptively accessible because the tools are familiar and the first build can happen quickly. What remains hard is building something that stands up to regulation, security scrutiny, and real clinical risk without collapsing under its own shortcuts. That is why partner choice matters so much. A weak vendor can create elegant-looking work that fails under audit. A generalist consultant can apply hardware logic to software problems and miss the practical steps that make compliance workable. The cost of the wrong partner is not only financial. It can distort the whole product path. The same pattern shows up in technical due diligence. A strong commercial story or healthy books can hide brittle architecture, outdated stacks, poor security posture, and avoidable rewrite risk. When no one checks the technology properly, weak foundations often remain invisible until they become expensive. The broad lesson is simple. Medical software reaches the market faster when the team stops treating software, regulatory, and cybersecurity decisions as separate streams and starts handling them as one connected system. Episode Breakdown 00:01 Welcome 04:14 Market access realities in Europe and the US 08:02 Early engagement with experts 10:48 Why security belongs near the beginning 12:24 AI use and misuse in software products 16:05 Why not every product needs AI 20:03 Building medical software with the right disciplines 22:28 What investors miss without technical diligence 24:00 Why old code can become a liability 29:20 How founders should assess vendors 32:28 Why software still gets judged like hardware 36:26 Software-specific review expertise 38:33 Closing takeaways 41:14 Finish The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Showing 9 of 78

    Produced by Blue Goat Cyber — medical device cybersecurity consulting.

    About the Show

    Where MedTech meets the
    adversary mindset.

    Brought to you by Blue Goat Cyber, The Med Device Cyber Podcast unpacks the regulations, attacks, and engineering decisions shaping the future of connected medical devices.

    From premarket submissions to postmarket vulnerability response, built for product security teams, regulatory leads, and the engineers in the trenches.

    Browse Episodes by Topic

    Jump straight to what matters for your role.

    Meet the Host

    Practitioner, not pundit.

    Every episode is hosted by an operator who does this work daily, leading FDA submissions, threat modeling sessions, and pen tests for real medical device manufacturers.

    Headshot of Christian Espinosa, Founder & CEO, Blue Goat Cyber

    Christian Espinosa

    Founder & CEO, Blue Goat Cyber
    LinkedIn

    U.S. Air Force veteran with decades of cybersecurity experience across defense, critical infrastructure, and MedTech. Founded Blue Goat Cyber in 2022 to help manufacturers build security in from the start and move through FDA review with confidence.

    FDA Premarket CybersecurityThreat ModelingRisk Management
    View profile
    Be a Guest

    Have a story worth sharing?

    We're always looking for medical device cybersecurity practitioners, regulatory leaders, and security researchers with a sharp point of view. Pitch us below.

    Be specific - e.g. "Threat modeling a Class II infusion pump for FDA premarket"

    0/2000 characters

    Frequently Asked

    MedTech cybersecurity, answered.

    Quick answers to the questions we hear most from product security, regulatory, and engineering teams.

    Listen Anywhere

    Pick your platform.

    New episodes drop weekly. Subscribe to never miss the next deep dive.