---
title: "Cybersecurity Isn't an IT Problem Anymore with Melissa…"
description: "Host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "Organization",
          "@id": "https://mdcpodcast.com/#org-site",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "url": "https://mdcpodcast.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://mdcpodcast.com/apple-touch-icon.png",
            "width": 180,
            "height": 180
          },
          "sameAs": [
            "https://www.youtube.com/@bluegoatcyber",
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://mdcpodcast.com/rss.xml"
          ],
          "parentOrganization": {
            "@id": "https://bluegoatcyber.com/#org"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://bluegoatcyber.com/#org",
          "name": "Blue Goat Cyber",
          "url": "https://bluegoatcyber.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://bluegoatcyber.com/logo.png"
          }
        },
        {
          "@type": "WebSite",
          "@id": "https://mdcpodcast.com/#website",
          "url": "https://mdcpodcast.com",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://mdcpodcast.com/#org-site"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": {
              "@type": "EntryPoint",
              "urlTemplate": "https://mdcpodcast.com/search?q={search_term_string}"
            },
            "query-input": "required name=search_term_string"
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "WebPage",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#webpage",
          "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "name": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "description": "Host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution…",
          "inLanguage": "en",
          "isPartOf": {
            "@id": "https://mdcpodcast.com/#website"
          },
          "about": {
            "@id": "https://mdcpodcast.com/#podcast"
          },
          "publisher": {
            "@id": "https://bluegoatcyber.com/#org"
          },
          "primaryImageOfPage": {
            "@type": "ImageObject",
            "url": "https://i2.ytimg.com/vi/QJ11o5HJt-8/hqdefault.jpg"
          },
          "mainEntity": {
            "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#episode"
          },
          "breadcrumb": {
            "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#breadcrumb"
          },
          "datePublished": "2026-06-25T16:30:20Z",
          "dateModified": "2026-06-25T16:30:20Z"
        },
        {
          "@type": "Organization",
          "@id": "https://bluegoatcyber.com/#org",
          "name": "Blue Goat Cyber",
          "url": "https://bluegoatcyber.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://bluegoatcyber.com/logo.png",
            "width": 512,
            "height": 512
          },
          "sameAs": [
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://www.youtube.com/@bluegoatcyber"
          ]
        },
        {
          "@type": "Organization",
          "@id": "https://mdcpodcast.com/#org-site",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "url": "https://mdcpodcast.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://mdcpodcast.com/apple-touch-icon.png",
            "width": 180,
            "height": 180
          },
          "sameAs": [
            "https://www.youtube.com/@bluegoatcyber",
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://mdcpodcast.com/rss.xml"
          ],
          "parentOrganization": {
            "@id": "https://bluegoatcyber.com/#org"
          }
        },
        {
          "@type": "WebSite",
          "@id": "https://mdcpodcast.com/#website",
          "url": "https://mdcpodcast.com",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://mdcpodcast.com/#org-site"
          },
          "about": {
            "@id": "https://mdcpodcast.com/#podcast"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": {
              "@type": "EntryPoint",
              "urlTemplate": "https://mdcpodcast.com/search?q={search_term_string}"
            },
            "query-input": "required name=search_term_string"
          }
        },
        {
          "@type": "PodcastEpisode",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#episode",
          "name": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "headline": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "description": "Host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution…",
          "abstract": "In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy. Melissa brings a unique perspective shaped by her career in highly regulated industries, including banking, civil engineering, and most notably, the high-stakes world of casino gaming. The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. The discussion frames cybersecurity not as a siloed IT problem, but as a central component of business risk, finance, and operations. This is highlighted by the trend of Chief Information Security Officers (CISOs) now reporting to Chief Financial Officers (CFOs), underscoring that security is fundamentally about managing financial risk and ensuring business continuity.\n\nThe main argument of the episode is the necessity of shifting from a mindset of pure prevention to one of business resilience—accepting that incidents are a matter of 'when,' not 'if,' and planning for how to maintain operations during and after an attack. Melissa draws parallels between the gaming industry, with its zero tolerance for downtime and immediate revenue loss during an incident, and the equally critical MedTech and healthcare sectors. She explains that attackers specifically target these regulated industries because the immense pressure to avoid operational disruption, regulatory fines, and loss of patient or customer trust provides them with significant leverage for extortion. Christian and his guest explore how attackers are not just trying to exploit a technical weakness, but are strategically looking for pressure points within a business to force a response, such as a ransom payment.\n\nThroughout the conversation, Melissa outlines a practical, proactive approach to cybersecurity. She emphasizes that organizations must first achieve complete visibility of their digital environment to “know what they have,” including all connected devices and third-party vendor systems. Once the full attack surface is understood, the next step is to prioritize the protection of critical systems that would cause the most harm to the business if compromised. Furthermore, she advocates for regularly practicing incident response through internal simulations and tabletop exercises to ensure teams are prepared to act under real pressure. The discussion also touches on the changing landscape of cyber insurance, cautioning that it is not a silver bullet. Insurers are becoming more stringent, often denying claims to companies that have neglected their security duties. Ultimately, the episode serves as a call to action for leadership across all industries to integrate cybersecurity into their operational DNA, fostering a culture of security that goes beyond mere compliance checklists.",
          "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "mainEntityOfPage": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "episodeNumber": 75,
          "datePublished": "2026-06-25T16:30:20Z",
          "dateModified": "2026-06-25T16:30:20Z",
          "thumbnailUrl": "https://i2.ytimg.com/vi/QJ11o5HJt-8/hqdefault.jpg",
          "image": "https://i2.ytimg.com/vi/QJ11o5HJt-8/hqdefault.jpg",
          "inLanguage": "en",
          "keywords": "medical device cybersecurity, FDA cybersecurity, SBOM, threat modeling, Blue Goat Cyber, Med Device Cyber Podcast, Episode 75, Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "duration": "PT41M25S",
          "timeRequired": "PT41M25S",
          "speakable": {
            "@type": "SpeakableSpecification",
            "cssSelector": [
              "#takeaways-heading",
              "#synopsis-heading"
            ]
          },
          "additionalProperty": [
            {
              "@type": "PropertyValue",
              "name": "hasSummary",
              "value": true
            },
            {
              "@type": "PropertyValue",
              "name": "hasTranscript",
              "value": true
            },
            {
              "@type": "PropertyValue",
              "name": "hasKeyTakeaways",
              "value": true
            }
          ],
          "hasPart": [
            {
              "@type": "CreativeWork",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#summary",
              "name": "Summary: Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
              "description": "In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy. Melissa brings a unique perspective shaped by her career in highly regulated industries, including banking, civil engineering, and most notably, the high-stakes world of casino gaming. The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. The discussion frames cybersecurity not as a siloed IT problem, but as a central component of business risk, finance, and operations. This is highlighted by the trend of Chief Information Security Officers (CISOs) now reporting to Chief Financial Officers (CFOs), underscoring that security is fundamentally about managing financial risk and ensuring business continuity.\n\nThe main argument of the episode is the necessity of shifting from a mindset of pure prevention to one of business resilience—accepting that incidents are a matter of 'when,' not 'if,' and planning for how to maintain operations during and after an attack. Melissa draws parallels between the gaming industry, with its zero tolerance for downtime and immediate revenue loss during an incident, and the equally critical MedTech and healthcare sectors. She explains that attackers specifically target these regulated industries because the immense pressure to avoid operational disruption, regulatory fines, and loss of patient or customer trust provides them with significant leverage for extortion. Christian and his guest explore how attackers are not just trying to exploit a technical weakness, but are strategically looking for pressure points within a business to force a response, such as a ransom payment.\n\nThroughout the conversation, Melissa outlines a practical, proactive approach to cybersecurity. She emphasizes that organizations must first achieve complete visibility of their digital environment to “know what they have,” including all connected devices and third-party vendor systems. Once the full attack surface is understood, the next step is to prioritize the protection of critical systems that would cause the most harm to the business if compromised. Furthermore, she advocates for regularly practicing incident response through internal simulations and tabletop exercises to ensure teams are prepared to act under real pressure. The discussion also touches on the changing landscape of cyber insurance, cautioning that it is not a silver bullet. Insurers are becoming more stringent, often denying claims to companies that have neglected their security duties. Ultimately, the episode serves as a call to action for leadership across all industries to integrate cybersecurity into their operational DNA, fostering a culture of security that goes beyond mere compliance checklists.",
              "inLanguage": "en"
            },
            {
              "@type": "MediaObject",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8/transcript#transcript",
              "name": "Transcript: Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
              "description": "Full transcript of episode 75 of The Med Device Cyber Podcast.",
              "encodingFormat": "text/plain",
              "inLanguage": "en",
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8/transcript",
              "contentUrl": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8/transcript"
            },
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#chapter-1",
              "name": "I don't know if you guys heard about this in the gaming",
              "startOffset": 0,
              "endOffset": 132,
              "position": 1,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=0"
            },
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#chapter-2",
              "name": "Yes, my background is in regulated industries",
              "startOffset": 131,
              "endOffset": 311,
              "position": 2,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=131"
            },
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#chapter-3",
              "name": "And so they they get really in the weeds and I've had",
              "startOffset": 310,
              "endOffset": 438,
              "position": 3,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=310"
            }
          ],
          "associatedMedia": {
            "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video"
          },
          "video": {
            "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video"
          },
          "sameAs": [
            "https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW"
          ],
          "potentialAction": [
            {
              "@type": "ListenAction",
              "name": "Watch on YouTube",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW",
                "actionPlatform": [
                  "https://schema.org/DesktopWebPlatform",
                  "https://schema.org/MobileWebPlatform"
                ]
              }
            },
            {
              "@type": "ListenAction",
              "name": "Listen on Spotify",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://open.spotify.com/search/Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast",
                "actionPlatform": [
                  "https://schema.org/DesktopWebPlatform",
                  "https://schema.org/MobileWebPlatform"
                ]
              }
            },
            {
              "@type": "ListenAction",
              "name": "Listen on Apple Podcasts",
              "target": {
                "@type": "EntryPoint",
                "urlTemplate": "https://podcasts.apple.com/us/search?term=Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast",
                "actionPlatform": [
                  "https://schema.org/DesktopWebPlatform",
                  "https://schema.org/MobileWebPlatform"
                ]
              }
            }
          ],
          "partOfSeries": {
            "@type": "PodcastSeries",
            "@id": "https://mdcpodcast.com/#podcast",
            "name": "The Med Device Cyber Podcast",
            "url": "https://mdcpodcast.com",
            "webFeed": "https://mdcpodcast.com/rss.xml",
            "sameAs": [
              "https://www.youtube.com/playlist?list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW",
              "https://open.spotify.com/search/Med%20Device%20Cyber%20Podcast",
              "https://podcasts.apple.com/us/search?term=Med%20Device%20Cyber%20Podcast"
            ]
          },
          "relatedLink": [
            "https://mdcpodcast.com/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0",
            "https://mdcpodcast.com/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8",
            "https://mdcpodcast.com/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg",
            "https://mdcpodcast.com/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps"
          ],
          "publisher": {
            "@id": "https://bluegoatcyber.com/#org"
          }
        },
        {
          "@type": "VideoObject",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video",
          "name": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "description": "Host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution…",
          "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "contentUrl": "https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW",
          "embedUrl": "https://www.youtube.com/embed/QJ11o5HJt-8",
          "thumbnailUrl": [
            "https://i2.ytimg.com/vi/QJ11o5HJt-8/hqdefault.jpg"
          ],
          "uploadDate": "2026-06-25T16:30:20Z",
          "inLanguage": "en",
          "duration": "PT41M25S",
          "transcript": "Guest: I don't know if you guys heard about this in the gaming industry. They got in through a fish tank. Somebody got in to the fish tank and it was connected to their network.\n\nChristian: Cybersecurity used to be like supplementary to quality for a medical device. And now they're integrated. Cybersecurity is part of quality. So the quality and the effectiveness and the safety of this device, cybersecurity is part of that.\n\nGuest: Cybersecurity used to be an IT function, right? It was an IT team. But now CISOs are reporting to CFOs, because they're handling risk, their insurance policy, the money side of things. So we're seeing this shift, and I think AI is helping that shift.\n\nGuest: Hey there, and welcome back to another episode of the Med Device Cyber podcast. Uh, as usual, we have our two co-hosts, myself, Trevor Slattery, and Christian Espinosa. And today we are joined by a very special guest, Melissa Aarskog. I'd love to hear a little bit about you and, uh, just first a quick check in, how's your morning going so far?\n\nGuest: My morning is going fabulous. Thank you for asking. Excited to be here today and talk to you two about cybersecurity.\n\nChristian: You're coming from Austin, right? I think. Is it Austin?\n\nGuest: Yes, yep.\n\nChristian: Yeah, a little bit earlier for us today. It's, uh, like 7:00 in the morning for us.\n\nGuest: Love to hear a little bit about what you're working on and know that you're involved in cybersecurity, so it'll be a fun conversation. We're also obviously involved in cybersecurity, more on the medical side, but you're a little bit more, uh, outside of the medical space. Is that correct?\n\nGuest: Yes. My background is in regulated industries. I started my career in banking and then pivoted into civil engineering and then found my way into gambling and gaming and then found my way into cybersecurity. And so I've spent a lot of time in the casino gaming industry where it's a 24-hour, 7 days a week, 365 days a year business with, you know, financial systems, customer data, and really zero tolerance for downtime. It's a similar kind of to the healthcare industry, it's always up, always taking care of patients. And so, you know, when something goes wrong in the gambling industry, it's immediate revenue stops, regulators get involved, customers feel it, and it really forces a different type of mindset. And so you stop thinking about, let's perfectly protect, to, let's start thinking about how this is going to keep the business running, no matter what happens.\n\nChristian: I know when we were, uh, talking a little bit beforehand, you mentioned gambling is probably more regulated than medtech. And I was curious if you could expand upon that a little bit.\n\nGuest: Attackers are really hitting regulated industries. So there's a lot of industries that are regulated. Um, in gambling, um, before you can launch a casino or sell a product, there's a long, rigorous licensing process. Depending on what state you're in, each state has different regulations. You know, in some cases, some states will go back 10, 20 years. You know, if you made a thousand cash deposit into your bank account, they want to know what the cash was and why you deposited it. And so they get really in the weeds. And I've had several CEOs who have been married 30, 40 years tell me, gosh, you know, these regulators know more than my wife does about everything I've ever done in my entire life. So they really turn over every single rock to make sure the people that are operating and running these casinos online and, um, land-based are operating at a high level of integrity. Um, they're going about doing it the right way. And so, you know, I guess the question, why do attackers keep hitting these industries?\n\nBecause they create pressure, right? I think attackers don't just look at or find the weaknesses. They look for environments that they can disrupt, um, and force a response, not only from the casino, but from regulators. So oftentimes regulators, you know, get involved quickly, um, and in, and regulated industries, they have high value data. They're always operating. They have the oversight from regulators and so there's really no tolerance for downtime. So attackers and perpetrators know that if they go after, you know, a space like that, they're going to be, you know, the casino's going to be forced to respond quicker versus just generally going into, you know, targeting anybody. So in gaming, if a system goes down, revenue could stop and that could be something like a million dollars a day or multiple million dollars a day depending on where your casino is. And the real loss is tens of millions of dollars in loss of, you know, gambling and systems. I forget the exact number, but I think it's, you know, cybercrime is projected to be, um, a 15 trillion business by 2030. I think it's about 15 trillion is projected.\n\nChristian: It's pretty good.\n\nGuest: So it sounds like Maybe I'm on the wrong side of the fence.\n\nChristian: Yeah, I know. I I think about that sometimes. Uh, 'cause I have a lot of skills, but I I don't I shouldn't use them for nefarious purposes, you know?\n\nChristian: It sounds like though, the from what you're saying Melissa that the attackers are looking for leverage. Like you said, pressure point. And I I think that's true in medtech and healthcare as well. Like if I can get ransomware on a healthcare delivery organization, a large hospital, now they can't intake any patients, patients may die. So the hospital is forced to do something relatively quickly because the consequences are dire. And those consequences, it's not lost revenue, it's, you know, potentially patient life or patient care versus gambling, you know, it's like Amazon goes down every minute. It's a million dollars they lose or something like that. So it is giving them more of a pressure, so it forces a response more so than attacking, you know, a dry cleaning business or something that has a website.\n\nGuest: Exactly. And I think, um, you know, it's not the industry so much, it's the pressure that happens when something breaks. And so, you know, I don't work in med device, but what still stands out to me is exactly what you just said, people's lives are on the line. So the end, you know, we got to make sure the patients have what they need and it's a similar risk environment outside of lives, right? Um, but you still have connected systems, you still have regulated systems, and you still have the low tolerance for failure.\n\nChristian: I think in medtech, uh, and probably in most industries, the assuming something will go wrong point of view doesn't exist from my perspective in cybersecurity. Maybe in in gambling, everybody else assumes nothing's going to go wrong though, it seems like because they don't have, like you were referring to like cyber resilience or a way to keep operational operations running in a similar capacity. It seems like in most industries they haven't even thought of that and then a cyber attack happens and it's like, oh, now what do we do, right?\n\nGuest: Yeah, and that's a really fantastic point. Like we should unpack that a bit because, you know, I would say gaming doesn't do this perfectly for the record, and, um, compliance does not equal cyber like they're secure. So if you're compliant, you're not necessarily secure, but if you're secure, you're often compliant. So compliance is really the baseline. And attackers don't really care if you pass a compliance audit, right? They just want in to get whatever they want to get.\n\nBut I think, you know, cybersecurity is treated as a technical thing. And I know if I talk to a lot of the CEOs of casinos, they, you know, not all of them, but some of them would say, oh, that's an IT thing, or that's a compliance thing. And, you know, my compliance guys handle that, or my security guys handle that, but it's not because cyber impacts revenue, it impacts operations, it impacts trust. And so if something happens, it's not just IT responding, it's leadership that has to handle it. So cyber incidents are leadership events, and they're not, you know, technical ones or just IT problems. And so I think having that mindset and realizing that, you know, cybersecurity is an ongoing thing. We got to continue to get, you know, more secure. And the minute that we think that we have, we have everything secured, something happens, or, you know, things change and AI becomes a big thing. It is a big thing in our industry now. And so now we got to think about securing AI tools and... so I think it's an ongoing thing to harden our environment and to make it secure.\n\nChristian: I think what are the challenges in medtech and healthcare is you've it's kind of like at your home, you've got all these devices, uh, these IoT devices from other manufacturers that you can't like install endpoint protection on or do anything with. It's like you're relying on somebody else really to make sure that device is secure. With medtech, or medical device manufacturer is responsible for the device. The hospital has to accept the risk to put it on their environment, and they have no means of really managing that device. They just have to assume it's secure. They can do their own scanning of it, but it creates this creates a situation where you've got all these devices by various manufacturers on your environment, and you have this like constant fear, at least I would if I was a healthcare delivery, um, IT administrator, that one of these devices has a has a vulnerability, which may affect my entire enterprise network at some point.\n\nGuest: Yeah, and I I always go back to the question, what do the attackers want? What are they really after that's inside whatever the product? Whether it's a voting machine or a medtech device or a casino, um, they're actually very focused on what they want, right? So segmenting things in a way that keeps whatever they're after in that device separate from the network. So putting devices on a network that houses, you know, important information is probably not a good idea. But segmenting it, right? in a way that, maybe they only get whatever's on that device. So I think it's really getting focused on, you know, what are these attackers after and they're after the data that's inside whatever the product is. They want access to that data because they want to, you know, scale, they want to go from that device to the this to that, to the this to get more information because ultimately they want leverage for something. So data is always, in this is my own opinion, is always kind of the starting point.\n\nLike in gaming, it's the player data, the financial activity, loyalty accounts, you know, tribal information, IP. and in your industry it could be the patient data, their identity. It's all monetizable, right? So they want to get that access because they want something with it and so once they're in they move across system, escalating privileges to figure out how your environment actually works. And so in our industry, they've stayed in environments for hundreds of days, learning how things work and then they use what they know inside that environment to to gain leverage in some capacity, and then they just extort the casinos and ask for, you know, Bitcoin or however they're asking for whatever they're asking for.\n\nAnd so it's it's really no longer about, hey, we took your data. It's more about we're going to disrupt your business and if you don't pay us what we're asking by when we tell you to, we're going to shut your casino down and And it's probably, it's the same thing I would guess in the med device. So you know, the difference is it's really the same. It's just what are we protecting and how can we best protect it? And it's not putting everything on one network and making it work, right?\n\nTrevor: Right. It one thing that comes up a lot in the medtech space and something that we hear a lot from the companies we work with is, you know, obviously there are going to be different consequences if an oxygen pump is hacked into instead of your pacemaker gets hacked into.\n\nBut a lot of the times the manufacturer with the oxygen pump will go, well, it's just an oxygen pump. There's no like there's no harm. It's such a low-risk device that if somebody hacks into it, what's really going to be the big deal. And that may be true, but I love what you said about starting one point, jumping to another, and move your way through. If you have that oxygen pump in a connected hospital environment, which most of them are at this point, 74 percent of medical devices connect to the internet in some way or another. And so all that oxygen pump needs to be is the weakest link in the chain. That just needs to be something that the hacker can get into and then it moves over into the active directory system and then it moves in to your electronic health records and that's what they want to see.\n\nGuest: Right! And so, I mean it I don't know if you guys heard about this in the gaming industry, they got in through a fish tank. Right? And they've got in through you know, whatever other, there's many different ways we've seen things, we've seen social engineering in gaming, but it's what happened with the fish tank incident? I think our our listeners might want to learn a little bit more about that. Yeah, so somebody got into the fish tank and it was connected to their network, right? And they just exactly. Like the systems that manage the fish tank, the the pumping the air through it and the circulation and all that stuff. Yup. And same with HVAC that's connected to the network and the hotel system and they just scale, exactly what Trevor just said, they scale to get what they want and it's really the lowest point of entry. And so a lot of times it's like, I think about, you know, a bear is attacking all three of us, whoever runs the fastest wins, right? Um, and it's like that in gaming. We've seen it in a lot of the industry where the perpetrators just drive up a highway that has a lot of casinos. One casino gets hit, the next one doesn't, the next casino does. Why does the one in the middle not get hit, but the other two on the outside did, it's because the one in the middle had a little bit more security than the other two and it was taking them a lot longer to get into the environment. And they weren't getting anywhere as fast as they needed to. So they went down the road to someone else that was easier. And so sometimes it's not having, you know, the best and most secure environments because it's it's interesting. I would say 10 years ago I got into cybersecurity. I'd say like 14 years ago and I started really reading and learning about it. Um, and we weren't talking about the same things we were talking about today, the passwords were one, two, three, four, the passwords were password, right? We are way beyond let's get the passwords right, um, in the world that we're in today. And we're seeing huge companies like Stryker, which is in your space, have huge things happen to them in March and it's not only, you know, the regulatory piece, it's employees now suing the company that they work for for not properly keeping their data safe and secure. And so we're seeing, you know, where before it was just the regulators, the industry. Now we're seeing it on both sides of the street. So the companies that aren't doing their due diligence or requiring their third-party vendors to be secure, they're they're coming both directions now, right?\n\nChristian: Right and that's a good point because a lot of manufacturers in our industry, they have to go through the FDA to get cleared. The FDA says their device is secure, but that's like one check mark. The healthcare delivery organization often has this requirement that any device on their network has to exceed what the FDA was looking for. And a lot of the manufacturers don't consider like that end goal and what the requirements really are, because they might and often are, most of them are higher than what the FDA looks for. So they have to like reverse engineer what do I need to design in my product from a cybersecurity perspective because this hospital expects these controls in place that the FDA doesn't even care about as an example.\n\nGuest: Yeah, and you know, if you look at like, it's it's so interesting because we're talking very, in some capacity, very basic things. And when I look at the future, like of where we're going by the end of, you know, 2026, you know, where are we going? We're more connected than we've ever been. All of our information is more exposed. Everything is becoming interconnected, which, of course, increases the attack surface. And attackers are getting faster, right? I know when I think about, you know, social engineering exercises that have happened to me or text messaged I used to get, you know, the Microsoft logo was the wrong colors or the spelling was wrong and I could spot it quickly, right? And, and now, you know, I work in this industry and I work in the space. Some things I'm getting sent, I'm like, well, that's so good. Because AI is accelerating both sides of the street. And so it is also widening the gap between organizations that are prepared versus organizations that are not prepared. And so cyber maturity is really becoming a competitive advantage in every industry, not just, you know, gaming and and, um, healthcare. It's it's it's it's important and, you know, I think we talk about doing these patches and doing passwords and let's do some training. I believe, you know, we're beyond the like, let's talk about passwords and training. Like, we are so far, the train has left the station. If you don't have like the password, you know, requirements in place, like that is like such a low lift. Like, we we just got to get this stuff going. Um, so I think about, you know, a-a lot of the world's working on fire-or-flight and responding and being transactional with their day-to-day. And it's not until we kind of take the reigns of our our lives and our jobs that we can make the change. And I think it's the same too for people in their personal lives, right? So if you're an employee of a company and they, you know, can't keep your information safe, it's up for you to put checks and balances in place in your personal life. Um, so you're safe, right? And I think, you know, I talk a lot, um, to, you know, senior citizens who are very trusting to people that call. And we've seen a lot with deep fakes and technology and being able to social engineer information out of people. Um, so when I, when I think of the future, I really wish to hope for people to take it seriously, to take it really seriously for their own personal life. And if you're working for a company that's not taking it seriously, to maybe be the person that raises your hand, and, and and I'm a, an engineer-brained person. So I'm a technical person that it didn't used to be my personality to go to leadership to see, see something, say something because technical people are more introverted. I know that's such a flat statement, but we're like, we're more introverted, uh, than extroverted. But it's really imperative now that if you're in IT or security or, you know, you run an attack division that you really build these cases around what you see to leadership and so they understand and if they're not responding, you know, continue to do it and really CYA because I've seen a lot of people in my industry let go for cyber incidences, but they're their company wouldn't let them build the, buy the products and build the strategy and do the things to be secure. And so I think kind of to your point Trevor, I think it's, you know, we're all humans and we're just doing what bubbles up to the top of our desk every day, and then when we get to it, we get to it. Right?\n\nChristian: Well that's the whole busy versus productive argument. But I think, Melissa, from our conversation, what about you, Melissa, any key takeaways.\n\nGuest: Gosh, so many thoughts here. Um, you know, if you could take one idea away from our talk, don't ask how to prevent the incident, but ask how your business continues when it goes wrong. That's where the real resilience starts is understanding, you know, business has to continue and we need to build a plan around it. And so, and maybe like second to that, I would say, um, you know, cybersecurity isn't about eliminating risk. I think everybody's trying to eliminate every possible risk there is, but in life, there is always risk, right? It's about kind of being ready and understanding when it shows up. And so the organizations that are going to win as we kind of move through, you know, cybersecurity and AI, are the ones that keep operating under pressure, but that are making these teeny tiny tweaks with cybersecurity and then bringing the staff up with them, right? So if you have to, you know, buy your staff a coffee for doing their cybersecurity training, or you have to, you know, teach them see something, say something, it's a culture, right? Buy them a coffee. It's a lot cheaper than a cybersecurity breach.\n\nChristian: For sure. I think for me, uh, you were talking about going behind the scenes in the casinos. And I I know like, you're on camera all the time at a casino, but your analogy of being on a zoom in is like a freckle on someone that it just makes me think, I'm not sure if I want to go to a casino anymore. They're probably like monitoring my heart rate remotely, my, you know, my temperature to see if I'm nervous and everything. So like, I'm super paranoid now about casinos. They're probably zooming in and have like every ounce of data from me from a biometric perspective and everything else to see if I'm, you know, nervous and everything. I'm I'm sure they're measuring these things and people probably don't even think about it.\n\nGuest: But think about, that's a really good point. So think about your life right now. You are on camera every day, all the time, wherever you go in the world, all the time. Whether it's a restaurant, or an airport, or your car that has GPS on it, all of us can be found at any specific moment, right? We're walking around in businesses and places and spaces that have cameras. And so our lives are very, I mean if you have a smartphone, you're giving away a lot of your power, right? Um, because all your apps track you and what you do and what you look at and, so just know, you know, we're all in the same boat and we're all in it together.\n\nChristian: I see. Awesome. Well, thanks so much Melissa for coming on as a guest. And thanks everyone for tuning in. Thank you for having me. Thanks Trevor, as usual, for being a co-host. And uh, we hope to see you on the next one.\n\nGuest: I think we are a little bit lucky in the, in the medtech space. The requirements are so tight around what you can do and what you can't do. And we were talking about this yesterday, everybody sees the FDA is this dragon to go slay and it's this big hurdle to get over. And so when we're working with companies and we say, okay, you know, here's your pen test report, oftentimes, and more often than not, it's their first time ever doing a pen test. They've never seen a network test, they've never seen, they they barely know what cybersecurity is. They just know these guys get FDA. And so we say here's your report, and they go, we scrubbed it. We basically tore down the device and rebuilt it. Everything is gone. Try again. And we go okay, great, that's what we like to see. But sometimes we do see the inverse happen as well, kind of like you said. And it's especially hard because we'll have some manufacturers come back and say we don't want to fix these and we go, then you're not going to sell this product. There's, it's a little black or white. You fix it, you don't have a device anymore. Those are the two options. The FDA does not mess around with it.\n\nChristian: Well, sometimes they don't, they can't fix it because they're six years into product development. And they got one year of runway left and they're going to have to redo things and go back a whole year because they didn't consider it from the beginning. You know, in the FDA and in cybersecurity you're supposed to be designed into the product, not bolted on. But if these regulations came out and you're five years into a seven-year development, what do you do, right? When you're telling them to redo everything. It's a massive lift.\n\nGuest: But, a little teeny tiny changes and little teeny tiny steps compound over time, right? So I think it's the whole analogy of eat an elephant one bite at a time. So there's one side of like, let's just ignore it and keep going. And then there's the other side, okay, let's just, now that we have the information, let's continue from here. Let's make what we can change right. And and and fix, continue forward with what we can, but what can we do better and how can we get better over time and, you know, having that attitude of like, we need to do better, we need to be more secure is really important. And I, I don't know about, I'm interested to get your perspective on this, like in my industry, you know, a lot of the industry is like, okay, now that we know we have all these vulnerabilities, we're going to go buy a cyber policy, cyber insurance policy to protect us. They won't, they won't, you can't buy it unless you fix most of those things, or at least say you do. Because then they're not going to, they're not going to support the claim if you have one.\n\nGuest: Yeah, that's exactly where I was going. So now they're going to fill out, like when I started, uh, with due diligence forms, they were one page. One page of due diligence forms. Now some of them are six to 20 pages. The insurance providers are actually doing their own scans to make sure it looks good based on what you told them and then when something does happen, because it's not if, it's when, then they're going to deny your claim because you didn't do A, B, C, D. And so what's happened is a lot of times people haven't taken the questionnaire seriously or they haven't taken cyber seriously because they have this, you know, policy that's going to protect them. And then I see a lot of insurance companies rejecting claims now. Just like in, in the automobile industry, right? There's a lot of claims rejected, right? 'Cause there's a lot of fraud in that industry. And it's the same thing with gaming and gambling, if you're not doing what you're supposed to, like cybersecurity e-learning training for your staff, right? And then you said you did that in your questionnaire, the insurance company is going to say, hey, like, you have a thousand employees and 500 of them didn't sign off on this training. Why, you're negligent. We're not going to reimburse you.\n\nTrevor: Yeah. I think a lot of companies try to treat cyber insurance as this silver bullet that they can just slap on top of the company and go, great, we're good. If we get hacked, we've got insurance for it. And that's still not even taking in the intangible harm to getting hacked outside of just, oh sure, we'll get reimbursed for whatever financial loss. If someone needs to pay the ransomware, it's our insurance. It's not us. But you're still the one who got hacked. You're still the one who's lost that trust with your customers. You're still the one whose data has been stolen. And so there's so much that I don't think people really think about this stuff. They just go, you know, oh, we don't want to lose money, we don't want to fall out of compliance, we don't want to get, you know, we don't want to violate HIPAA or whatever. So let's just put this sticker on top of it and put our heads in the sand and hope everything works out, and it just never, it never does.\n\nGuest: But think about it, we're all humans, right? We're all trying to do our best job at whatever we're doing, right? And what happens even in our personal lives, the things that are most important, we we we do, right? So it that's just how life works. Things bubble up that are most important. And then when it's really 911 and we got to, you know, the stove's on fire, we run over there and you know, put the fire out, right? And so I think, you know, all these things, it is really the same. It's just what are we protecting and how can we best protect it? And it's not putting everything on one network and making it work, right? But the same vulnerabilities, and if you knew ones exist. It's not having the best and most secure environments because it's it's interesting. I would say 10 years ago, I got into cybersecurity, like 14 years ago and I started really reading and learning about it. Um, and we weren't talking about the same things we were talking about today. The passwords were one, two, three, four, the passwords were password. We are way beyond let's get the passwords right. Um, in the world that we're in today. And we're seeing huge companies like Stryker, which is in your space, have huge things happen to them, um, in March and it's not only, you know, the regulatory piece, it's employees now suing the company that they work for for not properly keeping their data safe and secure. And so we're seeing, you know, where before it was the regulators, the industry. Now we're seeing it on both sides of the street. So the companies that aren't doing their due diligence or requiring their third-party vendors to be secure are their, they're coming both directions now, right?",
          "isPartOf": {
            "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#episode"
          },
          "publisher": {
            "@id": "https://bluegoatcyber.com/#org"
          },
          "hasPart": [
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video-chapter-1",
              "name": "I don't know if you guys heard about this in the gaming",
              "startOffset": 0,
              "endOffset": 132,
              "position": 1,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=0"
            },
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video-chapter-2",
              "name": "Yes, my background is in regulated industries",
              "startOffset": 131,
              "endOffset": 311,
              "position": 2,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=131"
            },
            {
              "@type": "Clip",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#video-chapter-3",
              "name": "And so they they get really in the weeds and I've had",
              "startOffset": 310,
              "endOffset": 438,
              "position": 3,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=310"
            }
          ]
        },
        {
          "@type": "BreadcrumbList",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#breadcrumb",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "Home",
              "item": "https://mdcpodcast.com"
            },
            {
              "@type": "ListItem",
              "position": 2,
              "name": "Episodes",
              "item": "https://mdcpodcast.com/#episodes"
            },
            {
              "@type": "ListItem",
              "position": 3,
              "name": "Episode 75",
              "item": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8"
            }
          ]
        },
        {
          "@type": "ItemList",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#more-like-this",
          "name": "More like this - episodes related to Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
          "itemListOrder": "https://schema.org/ItemListOrderDescending",
          "numberOfItems": 4,
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "url": "https://mdcpodcast.com/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0",
              "item": {
                "@type": "PodcastEpisode",
                "@id": "https://mdcpodcast.com/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0#episode",
                "url": "https://mdcpodcast.com/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0",
                "name": "Unpacking Post-Market Management and Incident Response for Medical Devices | Ep. 23",
                "episodeNumber": 43,
                "description": "Covers similar themes to episode 75.",
                "image": "https://i.ytimg.com/vi/m30wfBFoim0/hqdefault.jpg",
                "partOfSeries": {
                  "@type": "PodcastSeries",
                  "name": "The Med Device Cyber Podcast",
                  "url": "https://mdcpodcast.com"
                }
              }
            },
            {
              "@type": "ListItem",
              "position": 2,
              "url": "https://mdcpodcast.com/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8",
              "item": {
                "@type": "PodcastEpisode",
                "@id": "https://mdcpodcast.com/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8#episode",
                "url": "https://mdcpodcast.com/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8",
                "name": "Early Cyber Strategies for MedTech Trailblazers | Ep. 18",
                "episodeNumber": 14,
                "description": "Covers similar themes to episode 75.",
                "image": "https://i.ytimg.com/vi/yw6-QKV1XI8/hqdefault.jpg",
                "partOfSeries": {
                  "@type": "PodcastSeries",
                  "name": "The Med Device Cyber Podcast",
                  "url": "https://mdcpodcast.com"
                }
              }
            },
            {
              "@type": "ListItem",
              "position": 3,
              "url": "https://mdcpodcast.com/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg",
              "item": {
                "@type": "PodcastEpisode",
                "@id": "https://mdcpodcast.com/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg#episode",
                "url": "https://mdcpodcast.com/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg",
                "name": "Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry | Ep. 34",
                "episodeNumber": 21,
                "description": "Covers similar themes to episode 75.",
                "image": "https://i.ytimg.com/vi/AP347YHZqNg/hqdefault.jpg",
                "partOfSeries": {
                  "@type": "PodcastSeries",
                  "name": "The Med Device Cyber Podcast",
                  "url": "https://mdcpodcast.com"
                }
              }
            },
            {
              "@type": "ListItem",
              "position": 4,
              "url": "https://mdcpodcast.com/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps",
              "item": {
                "@type": "PodcastEpisode",
                "@id": "https://mdcpodcast.com/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps#episode",
                "url": "https://mdcpodcast.com/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps",
                "name": "AI in Medical Devices: Opportunities & Regulation with Matt Lemay | Ep. 22",
                "episodeNumber": 5,
                "description": "Covers similar themes to episode 75.",
                "image": "https://i.ytimg.com/vi/m4GqZBJz_Ps/hqdefault.jpg",
                "partOfSeries": {
                  "@type": "PodcastSeries",
                  "name": "The Med Device Cyber Podcast",
                  "url": "https://mdcpodcast.com"
                }
              }
            }
          ]
        },
        {
          "@type": "FAQPage",
          "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq",
          "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "mainEntityOfPage": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
          "mainEntity": [
            {
              "@type": "Question",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq-1",
              "name": "What is the episode \"Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug\" about?",
              "position": 1,
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy."
              }
            },
            {
              "@type": "Question",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq-2",
              "name": "What are the key takeaways from Episode 75?",
              "position": 2,
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust. Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one. Highly regulated industries like gaming and..."
              }
            },
            {
              "@type": "Question",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq-3",
              "name": "Who should listen to this episode?",
              "position": 3,
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. It's most useful for medical device manufacturers, cybersecurity engineers, regulatory affairs professionals, and MedTech founders..."
              }
            },
            {
              "@type": "Question",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq-4",
              "name": "What does this episode say about cybersecurity has shifted from a supplementary IT function?",
              "position": 4,
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust."
              }
            },
            {
              "@type": "Question",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#faq-5",
              "name": "What does this episode say about businesses should adopt a resilience mindset, focusing on?",
              "position": 5,
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one."
              }
            }
          ]
        }
      ]
    }
  ]
---

[Skip to main content](#main-content)

[![The Med Device Cyber Podcast](/assets/bgc-logo-BrKdoJVC.png)

The Med Device Cyber Podcast

Hosted by Blue Goat CyberSM



](/)

[Episodes](/episodes)[Hosts](/hosts)[About](/about)[Be a Guest](/be-a-guest)[Listen](/#listen)

Search... ⌘K

[(844) 939-4628](tel:+18449394628)[Schedule Discovery](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

[All Episodes](/#episodes)

Episode 075 · June 25, 2026 · 41m listen

# Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug

Listen on 

[YouTube ](https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)[Apple Podcasts ](https://podcasts.apple.com/us/search?term=Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)[RSS ](https://mdcpodcast.com/rss.xml)

## Key Takeaways

### Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern[](#cybersecurity-has-shifted-from-a-supplementary-it-function-t)

impacting finance, operations, and customer trust.

### Businesses should adopt a resilience mindset[](#businesses-should-adopt-a-resilience-mindset)

focusing on how to continue operations during a security incident rather than solely on preventing one.

### Highly regulated industries like gaming and healthcare are prime targets for cyberattacks because...[](#highly-regulated-industries-like-gaming-and-healthcare-are-p)

Highly regulated industries like gaming and healthcare are prime targets for cyberattacks because the immense pressure to avoid downtime provides leverage for attackers.

### Any connected device, even something as seemingly innocuous as a fish tank[](#any-connected-device-even-something-as-seemingly-innocuous-a)

can serve as the weakest link for a network breach.

### A fundamental step to effective security is achieving full visibility of all assets and systems to...[](#a-fundamental-step-to-effective-security-is-achieving-full-v)

A fundamental step to effective security is achieving full visibility of all assets and systems to understand the entire attack surface and prioritize critical risks.

### Attackers strategically look for business pressure points to exploit[](#attackers-strategically-look-for-business-pressure-points-to)

understanding this helps in building a more focused and effective defense.

### Cyber insurance is not a substitute for proactive security[](#cyber-insurance-is-not-a-substitute-for-proactive-security)

Insurers increasingly require proof of due diligence and may deny claims if security measures are inadequate.

### Cybersecurity is becoming a business-wide responsibility[](#cybersecurity-is-becoming-a-business-wide-responsibility)

with CISOs increasingly reporting to CFOs, reflecting its direct impact on financial risk and liability.

## Episode Summary

In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy. Melissa brings a unique perspective shaped by her career in highly regulated industries, including banking, civil engineering, and most notably, the high-stakes world of casino gaming. The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. The discussion frames cybersecurity not as a siloed IT problem, but as a central component of business risk, finance, and operations. This is highlighted by the trend of Chief Information Security Officers (CISOs) now reporting to Chief Financial Officers (CFOs), underscoring that security is fundamentally about managing financial risk and ensuring business continuity. The main argument of the episode is the necessity of shifting from a mindset of pure prevention to one of business resilience—accepting that incidents are a matter of 'when,' not 'if,' and planning for how to maintain operations during and after an attack. Melissa draws parallels between the gaming industry, with its zero tolerance for downtime and immediate revenue loss during an incident, and the equally critical MedTech and healthcare sectors. She explains that attackers specifically target these regulated industries because the immense pressure to avoid operational disruption, regulatory fines, and loss of patient or customer trust provides them with significant leverage for extortion. Christian and his guest explore how attackers are not just trying to exploit a technical weakness, but are strategically looking for pressure points within a business to force a response, such as a ransom payment. Throughout the conversation, Melissa outlines a practical, proactive approach to cybersecurity. She emphasizes that organizations must first achieve complete visibility of their digital environment to “know what they have,” including all connected devices and third-party vendor systems. Once the full attack surface is understood, the next step is to prioritize the protection of critical systems that would cause the most harm to the business if compromised. Furthermore, she advocates for regularly practicing [incident response](/topics/fda-postmarket) through internal simulations and tabletop exercises to ensure teams are prepared to act under real pressure. The discussion also touches on the changing landscape of cyber insurance, cautioning that it is not a silver bullet. Insurers are becoming more stringent, often denying claims to companies that have neglected their security duties. Ultimately, the episode serves as a call to action for leadership across all industries to integrate cybersecurity into their operational DNA, fostering a culture of security that goes beyond mere compliance checklists.

### Chapters

1.  [0:00](/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=0)I don't know if you guys heard about this in the gaming 
2.  [2:11](/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=131)Yes, my background is in regulated industries 
3.  [5:10](/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8?t=310)And so they they get really in the weeds and I've had 

## Frequently Asked Questions

Quick answers drawn from this episode.

-   ### What is the episode "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug" about? 
    
    In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy.
    
-   ### What are the key takeaways from Episode 75? 
    
    Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust. Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one. Highly regulated industries like gaming and...
    
-   ### Who should listen to this episode? 
    
    The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. It's most useful for medical device manufacturers, cybersecurity engineers, regulatory affairs professionals, and MedTech founders...
    
-   ### What does this episode say about cybersecurity has shifted from a supplementary IT function? 
    
    Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust.
    
-   ### What does this episode say about businesses should adopt a resilience mindset, focusing on? 
    
    Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one.
    

## Listeners also asked

Quick answers pulled from related episodes.

-   ### What does Episode 43 cover about "Unpacking Post-Market Management and Incident Response for Medical Devices"?
    
    In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery of Blue Goat Cyber provide a comprehensive overview of post-market management and incident response in the context of medical device cybersecurity. They address the critical...
    
    [From Episode 043 · Unpacking Post-Market Management and Incident Response for Medical Devices | Ep. 23](/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0)
-   ### What does Episode 14 cover about "Early Cyber Strategies for MedTech Trailblazers"?
    
    In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery from Blue Goat Cyber address a critical issue facing early-stage MedTech startups: the tendency to treat cybersecurity as an afterthought. They argue passionately that security...
    
    [From Episode 014 · Early Cyber Strategies for MedTech Trailblazers | Ep. 18](/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8)
-   ### What does Episode 21 cover about "Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry"?
    
    In this episode of the Med Device Cyber Podcast, host Christian Espinosa, a Project Management Professional (PMP) himself, interviews Steve Curry, the founder of Mustard Seed, a firm dedicated to improving project management within the life sciences. The central theme of the...
    
    [From Episode 021 · Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry | Ep. 34](/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg)

## Share this episode

Pre-fills with: "Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust." 

[Post on X](https://twitter.com/intent/tweet?text=%22Cybersecurity%20has%20shifted%20from%20a%20supplementary%20IT%20function%20to%20a%20core%20business%20and%20risk%20management%20concern%2C%20impacting%20finance%2C%20operations%2C%20and%20customer%20trust.%22%0A%0ACybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20-%20Episode%2075%20of%20The%20Med%20Device%20Cyber%20Podcast&url=https%3A%2F%2Fmdcpodcast.com%2Fepisodes%2Fcybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8)[LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fmdcpodcast.com%2Fepisodes%2Fcybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8)[Email](mailto:?subject=Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20-%20Episode%2075%20of%20The%20Med%20Device%20Cyber%20Podcast&body=%22Cybersecurity%20has%20shifted%20from%20a%20supplementary%20IT%20function%20to%20a%20core%20business%20and%20risk%20management%20concern%2C%20impacting%20finance%2C%20operations%2C%20and%20customer%20trust.%22%0A%0ACybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20-%20Episode%2075%20of%20The%20Med%20Device%20Cyber%20Podcast%0A%0Ahttps%3A%2F%2Fmdcpodcast.com%2Fepisodes%2Fcybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8)Copy link

Show original YouTube description

Cybersecurity is no longer just an IT problem. It's a business resilience challenge. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Melissa Aarskaug to discuss what the medical device industry can learn from one of the world's most heavily regulated sectors: casino gaming. Melissa shares why attackers focus on pressure rather than weaknesses, how regulated industries are adapting to evolving cyber threats, and why organisations must shift their thinking from preventing attacks to maintaining operations when attacks inevitably happen. The conversation explores cyber resilience, leadership, AI, regulatory expectations, penetration testing, cyber insurance, and the growing role cybersecurity plays in overall business strategy. Christian also explains how medical device cybersecurity has evolved from a standalone requirement into an integral part of product quality. In This Episode: Find Melissa Aarskaug here on LinkedIn: https://www.linkedin.com/in/melissa-aarskaug/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1

[Open dedicated transcript page](/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8/transcript)

## Full Transcript

Show CopyDownload

Guest: I don't know if you guys heard about this in the gaming industry. They got in through a fish tank. Somebody got in to the fish tank and it was connected to their network. Christian: Cybersecurity used to be like supplementary to quality for a medical device. And now they're integrated. Cybersecurity is part of quality. So the quality and the effectiveness and the safety of this device, cybersecurity is part of that. Guest: Cybersecurity used to be an IT function, right? It was an IT team. But now CISOs are reporting to CFOs, because they're handling risk, their insurance policy, the money side of things. So we're seeing this shift, and I think AI is helping that shift. Guest: Hey there, and welcome back to another episode of the Med Device Cyber podcast. Uh, as usual, we have our two co-hosts, myself, Trevor Slattery, and Christian Espinosa. And today we are joined by a very special guest, Melissa Aarskog. I'd love to hear a little bit about you and, uh, just first a quick check in, how's your morning going so far? Guest: My morning is going fabulous. Thank you for asking. Excited to be here today and talk to you two about cybersecurity. Christian: You're coming from Austin, right? I think. Is it Austin? Guest: Yes, yep. Christian: Yeah, a little bit earlier for us today. It's, uh, like 7:00 in the morning for us. Guest: Love to hear a little bit about what you're working on and know that you're involved in cybersecurity, so it'll be a fun conversation. We're also obviously involved in cybersecurity, more on the medical side, but you're a little bit more, uh, outside of the medical space. Is that correct? Guest: Yes. My background is in regulated industries. I started my career in banking and then pivoted into civil engineering and then found my way into gambling and gaming and then found my way into cybersecurity. And so I've spent a lot of time in the casino gaming industry where it's a 24-hour, 7 days a week, 365 days a year business with, you know, financial systems, customer data, and really zero tolerance for downtime. It's a similar kind of to the healthcare industry, it's always up, always taking care of patients. And so, you know, when something goes wrong in the gambling industry, it's immediate revenue stops, regulators get involved, customers feel it, and it really forces a different type of mindset. And so you stop thinking about, let's perfectly protect, to, let's start thinking about how this is going to keep the business running, no matter what happens. Christian: I know when we were, uh, talking a little bit beforehand, you mentioned gambling is probably more regulated than medtech. And I was curious if you could expand upon that a little bit. Guest: Attackers are really hitting regulated industries. So there's a lot of industries that are regulated. Um, in gambling, um, before you can launch a casino or sell a product, there's a long, rigorous licensing process. Depending on what state you're in, each state has different regulations. You know, in some cases, some states will go back 10, 20 years. You know, if you made a thousand cash deposit into your bank account, they want to know what the cash was and why you deposited it. And so they get really in the weeds. And I've had several CEOs who have been married 30, 40 years tell me, gosh, you know, these regulators know more than my wife does about everything I've ever done in my entire life. So they really turn over every single rock to make sure the people that are operating and running these casinos online and, um, land-based are operating at a high level of integrity. Um, they're going about doing it the right way. And so, you know, I guess the question, why do attackers keep hitting these industries? Because they create pressure, right? I think attackers don't just look at or find the weaknesses. They look for environments that they can disrupt, um, and force a response, not only from the casino, but from regulators. So oftentimes regulators, you know, get involved quickly, um, and in, and regulated industries, they have high value data. They're always operating. They have the oversight from regulators and so there's really no tolerance for downtime. So attackers and perpetrators know that if they go after, you know, a space like that, they're going to be, you know, the casino's going to be forced to respond quicker versus just generally going into, you know, targeting anybody. So in gaming, if a system goes down, revenue could stop and that could be something like a million dollars a day or multiple million dollars a day depending on where your casino is. And the real loss is tens of millions of dollars in loss of, you know, gambling and systems. I forget the exact number, but I think it's, you know, cybercrime is projected to be, um, a 15 trillion business by 2030. I think it's about 15 trillion is projected. Christian: It's pretty good. Guest: So it sounds like Maybe I'm on the wrong side of the fence. Christian: Yeah, I know. I I think about that sometimes. Uh, 'cause I have a lot of skills, but I I don't I shouldn't use them for nefarious purposes, you know? Christian: It sounds like though, the from what you're saying Melissa that the attackers are looking for leverage. Like you said, pressure point. And I I think that's true in medtech and healthcare as well. Like if I can get ransomware on a healthcare delivery organization, a large hospital, now they can't intake any patients, patients may die. So the hospital is forced to do something relatively quickly because the consequences are dire. And those consequences, it's not lost revenue, it's, you know, potentially patient life or patient care versus gambling, you know, it's like Amazon goes down every minute. It's a million dollars they lose or something like that. So it is giving them more of a pressure, so it forces a response more so than attacking, you know, a dry cleaning business or something that has a website. Guest: Exactly. And I think, um, you know, it's not the industry so much, it's the pressure that happens when something breaks. And so, you know, I don't work in med device, but what still stands out to me is exactly what you just said, people's lives are on the line. So the end, you know, we got to make sure the patients have what they need and it's a similar risk environment outside of lives, right? Um, but you still have connected systems, you still have regulated systems, and you still have the low tolerance for failure. Christian: I think in medtech, uh, and probably in most industries, the assuming something will go wrong point of view doesn't exist from my perspective in cybersecurity. Maybe in in gambling, everybody else assumes nothing's going to go wrong though, it seems like because they don't have, like you were referring to like cyber resilience or a way to keep operational operations running in a similar capacity. It seems like in most industries they haven't even thought of that and then a cyber attack happens and it's like, oh, now what do we do, right? Guest: Yeah, and that's a really fantastic point. Like we should unpack that a bit because, you know, I would say gaming doesn't do this perfectly for the record, and, um, compliance does not equal cyber like they're secure. So if you're compliant, you're not necessarily secure, but if you're secure, you're often compliant. So compliance is really the baseline. And attackers don't really care if you pass a compliance audit, right? They just want in to get whatever they want to get. But I think, you know, cybersecurity is treated as a technical thing. And I know if I talk to a lot of the CEOs of casinos, they, you know, not all of them, but some of them would say, oh, that's an IT thing, or that's a compliance thing. And, you know, my compliance guys handle that, or my security guys handle that, but it's not because cyber impacts revenue, it impacts operations, it impacts trust. And so if something happens, it's not just IT responding, it's leadership that has to handle it. So cyber incidents are leadership events, and they're not, you know, technical ones or just IT problems. And so I think having that mindset and realizing that, you know, cybersecurity is an ongoing thing. We got to continue to get, you know, more secure. And the minute that we think that we have, we have everything secured, something happens, or, you know, things change and AI becomes a big thing. It is a big thing in our industry now. And so now we got to think about securing AI tools and... so I think it's an ongoing thing to harden our environment and to make it secure. Christian: I think what are the challenges in medtech and healthcare is you've it's kind of like at your home, you've got all these devices, uh, these IoT devices from other manufacturers that you can't like install endpoint protection on or do anything with. It's like you're relying on somebody else really to make sure that device is secure. With medtech, or medical device manufacturer is responsible for the device. The hospital has to accept the risk to put it on their environment, and they have no means of really managing that device. They just have to assume it's secure. They can do their own scanning of it, but it creates this creates a situation where you've got all these devices by various manufacturers on your environment, and you have this like constant fear, at least I would if I was a healthcare delivery, um, IT administrator, that one of these devices has a has a vulnerability, which may affect my entire enterprise network at some point. Guest: Yeah, and I I always go back to the question, what do the attackers want? What are they really after that's inside whatever the product? Whether it's a voting machine or a medtech device or a casino, um, they're actually very focused on what they want, right? So segmenting things in a way that keeps whatever they're after in that device separate from the network. So putting devices on a network that houses, you know, important information is probably not a good idea. But segmenting it, right? in a way that, maybe they only get whatever's on that device. So I think it's really getting focused on, you know, what are these attackers after and they're after the data that's inside whatever the product is. They want access to that data because they want to, you know, scale, they want to go from that device to the this to that, to the this to get more information because ultimately they want leverage for something. So data is always, in this is my own opinion, is always kind of the starting point. Like in gaming, it's the player data, the financial activity, loyalty accounts, you know, tribal information, IP. and in your industry it could be the patient data, their identity. It's all monetizable, right? So they want to get that access because they want something with it and so once they're in they move across system, escalating privileges to figure out how your environment actually works. And so in our industry, they've stayed in environments for hundreds of days, learning how things work and then they use what they know inside that environment to to gain leverage in some capacity, and then they just extort the casinos and ask for, you know, Bitcoin or however they're asking for whatever they're asking for. And so it's it's really no longer about, hey, we took your data. It's more about we're going to disrupt your business and if you don't pay us what we're asking by when we tell you to, we're going to shut your casino down and And it's probably, it's the same thing I would guess in the med device. So you know, the difference is it's really the same. It's just what are we protecting and how can we best protect it? And it's not putting everything on one network and making it work, right? Trevor: Right. It one thing that comes up a lot in the medtech space and something that we hear a lot from the companies we work with is, you know, obviously there are going to be different consequences if an oxygen pump is hacked into instead of your pacemaker gets hacked into. But a lot of the times the manufacturer with the oxygen pump will go, well, it's just an oxygen pump. There's no like there's no harm. It's such a low-risk device that if somebody hacks into it, what's really going to be the big deal. And that may be true, but I love what you said about starting one point, jumping to another, and move your way through. If you have that oxygen pump in a connected hospital environment, which most of them are at this point, 74 percent of medical devices connect to the internet in some way or another. And so all that oxygen pump needs to be is the weakest link in the chain. That just needs to be something that the hacker can get into and then it moves over into the active directory system and then it moves in to your electronic health records and that's what they want to see. Guest: Right! And so, I mean it I don't know if you guys heard about this in the gaming industry, they got in through a fish tank. Right? And they've got in through you know, whatever other, there's many different ways we've seen things, we've seen social engineering in gaming, but it's what happened with the fish tank incident? I think our our listeners might want to learn a little bit more about that. Yeah, so somebody got into the fish tank and it was connected to their network, right? And they just exactly. Like the systems that manage the fish tank, the the pumping the air through it and the circulation and all that stuff. Yup. And same with HVAC that's connected to the network and the hotel system and they just scale, exactly what Trevor just said, they scale to get what they want and it's really the lowest point of entry. And so a lot of times it's like, I think about, you know, a bear is attacking all three of us, whoever runs the fastest wins, right? Um, and it's like that in gaming. We've seen it in a lot of the industry where the perpetrators just drive up a highway that has a lot of casinos. One casino gets hit, the next one doesn't, the next casino does. Why does the one in the middle not get hit, but the other two on the outside did, it's because the one in the middle had a little bit more security than the other two and it was taking them a lot longer to get into the environment. And they weren't getting anywhere as fast as they needed to. So they went down the road to someone else that was easier. And so sometimes it's not having, you know, the best and most secure environments because it's it's interesting. I would say 10 years ago I got into cybersecurity. I'd say like 14 years ago and I started really reading and learning about it. Um, and we weren't talking about the same things we were talking about today, the passwords were one, two, three, four, the passwords were password, right? We are way beyond let's get the passwords right, um, in the world that we're in today. And we're seeing huge companies like Stryker, which is in your space, have huge things happen to them in March and it's not only, you know, the regulatory piece, it's employees now suing the company that they work for for not properly keeping their data safe and secure. And so we're seeing, you know, where before it was just the regulators, the industry. Now we're seeing it on both sides of the street. So the companies that aren't doing their due diligence or requiring their third-party vendors to be secure, they're they're coming both directions now, right? Christian: Right and that's a good point because a lot of manufacturers in our industry, they have to go through the FDA to get cleared. The FDA says their device is secure, but that's like one check mark. The healthcare delivery organization often has this requirement that any device on their network has to exceed what the FDA was looking for. And a lot of the manufacturers don't consider like that end goal and what the requirements really are, because they might and often are, most of them are higher than what the FDA looks for. So they have to like reverse engineer what do I need to design in my product from a cybersecurity perspective because this hospital expects these controls in place that the FDA doesn't even care about as an example. Guest: Yeah, and you know, if you look at like, it's it's so interesting because we're talking very, in some capacity, very basic things. And when I look at the future, like of where we're going by the end of, you know, 2026, you know, where are we going? We're more connected than we've ever been. All of our information is more exposed. Everything is becoming interconnected, which, of course, increases the attack surface. And attackers are getting faster, right? I know when I think about, you know, social engineering exercises that have happened to me or text messaged I used to get, you know, the Microsoft logo was the wrong colors or the spelling was wrong and I could spot it quickly, right? And, and now, you know, I work in this industry and I work in the space. Some things I'm getting sent, I'm like, well, that's so good. Because AI is accelerating both sides of the street. And so it is also widening the gap between organizations that are prepared versus organizations that are not prepared. And so cyber maturity is really becoming a competitive advantage in every industry, not just, you know, gaming and and, um, healthcare. It's it's it's it's important and, you know, I think we talk about doing these patches and doing passwords and let's do some training. I believe, you know, we're beyond the like, let's talk about passwords and training. Like, we are so far, the train has left the station. If you don't have like the password, you know, requirements in place, like that is like such a low lift. Like, we we just got to get this stuff going. Um, so I think about, you know, a-a lot of the world's working on fire-or-flight and responding and being transactional with their day-to-day. And it's not until we kind of take the reigns of our our lives and our jobs that we can make the change. And I think it's the same too for people in their personal lives, right? So if you're an employee of a company and they, you know, can't keep your information safe, it's up for you to put checks and balances in place in your personal life. Um, so you're safe, right? And I think, you know, I talk a lot, um, to, you know, senior citizens who are very trusting to people that call. And we've seen a lot with deep fakes and technology and being able to social engineer information out of people. Um, so when I, when I think of the future, I really wish to hope for people to take it seriously, to take it really seriously for their own personal life. And if you're working for a company that's not taking it seriously, to maybe be the person that raises your hand, and, and and I'm a, an engineer-brained person. So I'm a technical person that it didn't used to be my personality to go to leadership to see, see something, say something because technical people are more introverted. I know that's such a flat statement, but we're like, we're more introverted, uh, than extroverted. But it's really imperative now that if you're in IT or security or, you know, you run an attack division that you really build these cases around what you see to leadership and so they understand and if they're not responding, you know, continue to do it and really CYA because I've seen a lot of people in my industry let go for cyber incidences, but they're their company wouldn't let them build the, buy the products and build the strategy and do the things to be secure. And so I think kind of to your point Trevor, I think it's, you know, we're all humans and we're just doing what bubbles up to the top of our desk every day, and then when we get to it, we get to it. Right? Christian: Well that's the whole busy versus productive argument. But I think, Melissa, from our conversation, what about you, Melissa, any key takeaways. Guest: Gosh, so many thoughts here. Um, you know, if you could take one idea away from our talk, don't ask how to prevent the incident, but ask how your business continues when it goes wrong. That's where the real resilience starts is understanding, you know, business has to continue and we need to build a plan around it. And so, and maybe like second to that, I would say, um, you know, cybersecurity isn't about eliminating risk. I think everybody's trying to eliminate every possible risk there is, but in life, there is always risk, right? It's about kind of being ready and understanding when it shows up. And so the organizations that are going to win as we kind of move through, you know, cybersecurity and AI, are the ones that keep operating under pressure, but that are making these teeny tiny tweaks with cybersecurity and then bringing the staff up with them, right? So if you have to, you know, buy your staff a coffee for doing their cybersecurity training, or you have to, you know, teach them see something, say something, it's a culture, right? Buy them a coffee. It's a lot cheaper than a cybersecurity breach. Christian: For sure. I think for me, uh, you were talking about going behind the scenes in the casinos. And I I know like, you're on camera all the time at a casino, but your analogy of being on a zoom in is like a freckle on someone that it just makes me think, I'm not sure if I want to go to a casino anymore. They're probably like monitoring my heart rate remotely, my, you know, my temperature to see if I'm nervous and everything. So like, I'm super paranoid now about casinos. They're probably zooming in and have like every ounce of data from me from a biometric perspective and everything else to see if I'm, you know, nervous and everything. I'm I'm sure they're measuring these things and people probably don't even think about it. Guest: But think about, that's a really good point. So think about your life right now. You are on camera every day, all the time, wherever you go in the world, all the time. Whether it's a restaurant, or an airport, or your car that has GPS on it, all of us can be found at any specific moment, right? We're walking around in businesses and places and spaces that have cameras. And so our lives are very, I mean if you have a smartphone, you're giving away a lot of your power, right? Um, because all your apps track you and what you do and what you look at and, so just know, you know, we're all in the same boat and we're all in it together. Christian: I see. Awesome. Well, thanks so much Melissa for coming on as a guest. And thanks everyone for tuning in. Thank you for having me. Thanks Trevor, as usual, for being a co-host. And uh, we hope to see you on the next one. Guest: I think we are a little bit lucky in the, in the medtech space. The requirements are so tight around what you can do and what you can't do. And we were talking about this yesterday, everybody sees the FDA is this dragon to go slay and it's this big hurdle to get over. And so when we're working with companies and we say, okay, you know, here's your pen test report, oftentimes, and more often than not, it's their first time ever doing a pen test. They've never seen a network test, they've never seen, they they barely know what cybersecurity is. They just know these guys get FDA. And so we say here's your report, and they go, we scrubbed it. We basically tore down the device and rebuilt it. Everything is gone. Try again. And we go okay, great, that's what we like to see. But sometimes we do see the inverse happen as well, kind of like you said. And it's especially hard because we'll have some manufacturers come back and say we don't want to fix these and we go, then you're not going to sell this product. There's, it's a little black or white. You fix it, you don't have a device anymore. Those are the two options. The FDA does not mess around with it. Christian: Well, sometimes they don't, they can't fix it because they're six years into product development. And they got one year of runway left and they're going to have to redo things and go back a whole year because they didn't consider it from the beginning. You know, in the FDA and in cybersecurity you're supposed to be designed into the product, not bolted on. But if these regulations came out and you're five years into a seven-year development, what do you do, right? When you're telling them to redo everything. It's a massive lift. Guest: But, a little teeny tiny changes and little teeny tiny steps compound over time, right? So I think it's the whole analogy of eat an elephant one bite at a time. So there's one side of like, let's just ignore it and keep going. And then there's the other side, okay, let's just, now that we have the information, let's continue from here. Let's make what we can change right. And and and fix, continue forward with what we can, but what can we do better and how can we get better over time and, you know, having that attitude of like, we need to do better, we need to be more secure is really important. And I, I don't know about, I'm interested to get your perspective on this, like in my industry, you know, a lot of the industry is like, okay, now that we know we have all these vulnerabilities, we're going to go buy a cyber policy, cyber insurance policy to protect us. They won't, they won't, you can't buy it unless you fix most of those things, or at least say you do. Because then they're not going to, they're not going to support the claim if you have one. Guest: Yeah, that's exactly where I was going. So now they're going to fill out, like when I started, uh, with due diligence forms, they were one page. One page of due diligence forms. Now some of them are six to 20 pages. The insurance providers are actually doing their own scans to make sure it looks good based on what you told them and then when something does happen, because it's not if, it's when, then they're going to deny your claim because you didn't do A, B, C, D. And so what's happened is a lot of times people haven't taken the questionnaire seriously or they haven't taken cyber seriously because they have this, you know, policy that's going to protect them. And then I see a lot of insurance companies rejecting claims now. Just like in, in the automobile industry, right? There's a lot of claims rejected, right? 'Cause there's a lot of fraud in that industry. And it's the same thing with gaming and gambling, if you're not doing what you're supposed to, like cybersecurity e-learning training for your staff, right? And then you said you did that in your questionnaire, the insurance company is going to say, hey, like, you have a thousand employees and 500 of them didn't sign off on this training. Why, you're negligent. We're not going to reimburse you. Trevor: Yeah. I think a lot of companies try to treat cyber insurance as this silver bullet that they can just slap on top of the company and go, great, we're good. If we get hacked, we've got insurance for it. And that's still not even taking in the intangible harm to getting hacked outside of just, oh sure, we'll get reimbursed for whatever financial loss. If someone needs to pay the ransomware, it's our insurance. It's not us. But you're still the one who got hacked. You're still the one who's lost that trust with your customers. You're still the one whose data has been stolen. And so there's so much that I don't think people really think about this stuff. They just go, you know, oh, we don't want to lose money, we don't want to fall out of compliance, we don't want to get, you know, we don't want to violate HIPAA or whatever. So let's just put this sticker on top of it and put our heads in the sand and hope everything works out, and it just never, it never does. Guest: But think about it, we're all humans, right? We're all trying to do our best job at whatever we're doing, right? And what happens even in our personal lives, the things that are most important, we we we do, right? So it that's just how life works. Things bubble up that are most important. And then when it's really 911 and we got to, you know, the stove's on fire, we run over there and you know, put the fire out, right? And so I think, you know, all these things, it is really the same. It's just what are we protecting and how can we best protect it? And it's not putting everything on one network and making it work, right? But the same vulnerabilities, and if you knew ones exist. It's not having the best and most secure environments because it's it's interesting. I would say 10 years ago, I got into cybersecurity, like 14 years ago and I started really reading and learning about it. Um, and we weren't talking about the same things we were talking about today. The passwords were one, two, three, four, the passwords were password. We are way beyond let's get the passwords right. Um, in the world that we're in today. And we're seeing huge companies like Stryker, which is in your space, have huge things happen to them, um, in March and it's not only, you know, the regulatory piece, it's employees now suing the company that they work for for not properly keeping their data safe and secure. And so we're seeing, you know, where before it was the regulators, the industry. Now we're seeing it on both sides of the street. So the companies that aren't doing their due diligence or requiring their third-party vendors to be secure are their, they're coming both directions now, right?

## Hosted by

[![Headshot of Christian Espinosa](/assets/host-christian-T2WBrxkF.jpg)

Christian Espinosa

Founder & CEO, Blue Goat Cyber



](/hosts/christian-espinosa)

## More from your host

Other episodes diving into Christian's areas of focus.

[![Headshot of Christian Espinosa](/assets/host-christian-T2WBrxkF.jpg)

More from Christian Espinosa

Founder & CEO, Blue Goat Cyber



](/hosts/christian-espinosa)[View profile →](/hosts/christian-espinosa)

[![Episode 79 thumbnail](https://i.ytimg.com/vi/BtmXo69lBS0/maxresdefault.jpg)](/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0)

[

EP 079 · Jul 30, 2026

### Why the Smartest Candidate May Be the Wrong Hire with Samantha Silk | Ep 79

](/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0)

[YouTube](https://www.youtube.com/watch?v=BtmXo69lBS0&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify](https://open.spotify.com/search/Why%20the%20Smartest%20Candidate%20May%20Be%20the%20Wrong%20Hire%20with%20Samantha%20Silk%20%7C%20Ep%2079%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=Why%20the%20Smartest%20Candidate%20May%20Be%20the%20Wrong%20Hire%20with%20Samantha%20Silk%20%7C%20Ep%2079%20Med%20Device%20Cyber%20Podcast)

[![Episode 78 thumbnail](https://i.ytimg.com/vi/lT7fwbpCdZ0/maxresdefault.jpg)](/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0)

[

EP 078 · Jul 23, 2026

### How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78

](/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0)

[YouTube](https://www.youtube.com/watch?v=lT7fwbpCdZ0&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify](https://open.spotify.com/search/How%20Different%20Brains%20Build%20Better%20Teams%20with%20Sarah%20Ohanesian%20and%20Jeff%20Gibbard%20%7C%20Ep%2078%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=How%20Different%20Brains%20Build%20Better%20Teams%20with%20Sarah%20Ohanesian%20and%20Jeff%20Gibbard%20%7C%20Ep%2078%20Med%20Device%20Cyber%20Podcast)

[![Episode 73 thumbnail](https://i.ytimg.com/vi/9GnsZGeFuVk/maxresdefault.jpg)](/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk)

[

EP 073 · Jun 4, 2026

### The Legal Hoops and Hurdles of MedTech Commercialization with JJ Amell

](/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk)

[YouTube](https://www.youtube.com/watch?v=9GnsZGeFuVk&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify](https://open.spotify.com/search/The%20Legal%20Hoops%20and%20Hurdles%20of%20MedTech%20Commercialization%20with%20JJ%20Amell%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=The%20Legal%20Hoops%20and%20Hurdles%20of%20MedTech%20Commercialization%20with%20JJ%20Amell%20Med%20Device%20Cyber%20Podcast)

## More like this

Episodes covering similar ground.

[![Episode 43 thumbnail](https://i.ytimg.com/vi/m30wfBFoim0/maxresdefault.jpg)](/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0)

[

EP 043 · Jun 10, 2025

### Unpacking Post-Market Management and Incident Response for Medical Devices | Ep. 23

](/episodes/unpacking-post-market-management-and-incident-response-for-medical-devices-ep-23-m30wfBFoim0)

[YouTube](https://www.youtube.com/watch?v=m30wfBFoim0)[Spotify](https://open.spotify.com/search/Unpacking%20Post-Market%20Management%20and%20Incident%20Response%20for%20Medical%20Devices%20%7C%20Ep.%2023%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=Unpacking%20Post-Market%20Management%20and%20Incident%20Response%20for%20Medical%20Devices%20%7C%20Ep.%2023%20Med%20Device%20Cyber%20Podcast)

Why this matches  covers similar themes around reporting, tolerance, step.

[![Episode 14 thumbnail](https://i.ytimg.com/vi/yw6-QKV1XI8/maxresdefault.jpg)](/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8)

[

EP 014 · Apr 29, 2025

### Early Cyber Strategies for MedTech Trailblazers | Ep. 18

](/episodes/early-cyber-strategies-for-medtech-trailblazers-ep-18-yw6-QKV1XI8)

[YouTube](https://www.youtube.com/watch?v=yw6-QKV1XI8)[Spotify](https://open.spotify.com/search/Early%20Cyber%20Strategies%20for%20MedTech%20Trailblazers%20%7C%20Ep.%2018%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=Early%20Cyber%20Strategies%20for%20MedTech%20Trailblazers%20%7C%20Ep.%2018%20Med%20Device%20Cyber%20Podcast)

Why this matches  covers similar themes around pressure, equally, culture.

[![Episode 21 thumbnail](https://i.ytimg.com/vi/AP347YHZqNg/maxresdefault.jpg)](/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg)

[

EP 021 · Aug 26, 2025

### Integrating Project Management to Strengthen Cybersecurity Outcomes with Steve Curry | Ep. 34

](/episodes/integrating-project-management-to-strengthen-cybersecurity-outcomes-with-steve-c-AP347YHZqNg)

[YouTube](https://www.youtube.com/watch?v=AP347YHZqNg)[Spotify](https://open.spotify.com/search/Integrating%20Project%20Management%20to%20Strengthen%20Cybersecurity%20Outcomes%20with%20Steve%20Curry%20%7C%20Ep.%2034%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=Integrating%20Project%20Management%20to%20Strengthen%20Cybersecurity%20Outcomes%20with%20Steve%20Curry%20%7C%20Ep.%2034%20Med%20Device%20Cyber%20Podcast)

Why this matches  covers similar themes around defense, immense, function.

[![Episode 5 thumbnail](https://i.ytimg.com/vi/m4GqZBJz_Ps/maxresdefault.jpg)](/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps)

[

EP 005 · Jun 3, 2025

### AI in Medical Devices: Opportunities & Regulation with Matt Lemay | Ep. 22

](/episodes/ai-in-medical-devices-opportunities-and-regulation-with-matt-lemay-ep-22-m4GqZBJz_Ps)

[YouTube](https://www.youtube.com/watch?v=m4GqZBJz_Ps)[Spotify](https://open.spotify.com/search/AI%20in%20Medical%20Devices%3A%20Opportunities%20%26%20Regulation%20with%20Matt%20Lemay%20%7C%20Ep.%2022%20Med%20Device%20Cyber%20Podcast)[Apple](https://podcasts.apple.com/us/search?term=AI%20in%20Medical%20Devices%3A%20Opportunities%20%26%20Regulation%20with%20Matt%20Lemay%20%7C%20Ep.%2022%20Med%20Device%20Cyber%20Podcast)

Why this matches  covers similar themes around industries, regulated, liability.

## Listen to this episode

[Watch on YouTube](https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Listen on Spotify](https://open.spotify.com/search/Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)[Apple Podcasts](https://podcasts.apple.com/us/search?term=Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)[Browse all episodes](/#episodes)

[

Newer · Episode 076

Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris



](/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI)[

Older · Episode 074

Cancer Drugs Can Damage the Heart - This Startup Wants to Fix It with Ryan Neely



](/episodes/cancer-drugs-can-damage-the-heart-this-startup-wants-to-fix-it-with-ryan-neely-G28hsQ7qwQU)

## Site footer and sitemap

The Med Device Cyber Podcast

Frontline conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOMs, threat modeling, and penetration testing - hosted by [Blue Goat Cyber](https://bluegoatcyber.com).

[Browse all episodes](/episodes)[Pitch as a guest](/be-a-guest)

Subscribe

[RSS](https://mdcpodcast.com/rss.xml)[Apple Podcasts](https://podcasts.apple.com/us/search?term=Med%20Device%20Cyber%20Podcast)[Spotify](https://open.spotify.com/search/Med%20Device%20Cyber%20Podcast)[YouTube](https://www.youtube.com/playlist?list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)

### Topics

-   [FDA Premarket](/topics/fda-premarket)
-   [FDA Postmarket](/topics/fda-postmarket)
-   [SBOM](/topics/sbom)
-   [Threat Modeling](/topics/threat-modeling)
-   [Pen Testing](/topics/penetration-testing)

### The Show

-   [All Episodes](/episodes)
-   [Hosts](/hosts)
-   [Christian Espinosa](/hosts/christian-espinosa)
-   [All Guests](/guests)
-   [About the Podcast](/about)
-   [Be a Guest](/be-a-guest)
-   [Search Episodes](/search)

### Blue Goat Cyber Services

-   [Medical Device Penetration Testing](https://bluegoatcyber.com/services/medical-device-penetration-testing)
-   [FDA Premarket Cybersecurity (Full-Service)](https://bluegoatcyber.com/services/fda-premarket-cybersecurity-services)
-   [FDA Postmarket Cybersecurity Support](https://bluegoatcyber.com/services/fda-postmarket-cybersecurity-services)
-   [FDA Cybersecurity Deficiency Response](https://bluegoatcyber.com/services/fda-cybersecurity-deficiency-response)
-   [Schedule a discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)
-   [info@bluegoatcyber.com](mailto:info@bluegoatcyber.com)

Episode Archive

-   [2026 Episodes (29)](/search/year/2026)
-   [2025 Episodes (46)](/search/year/2025)
-   [2024 Episodes (6)](/search/year/2024)
-   [FDA Premarket - 2026](/search/topic/fda-premarket/year/2026)
-   [FDA Postmarket - 2026](/search/topic/fda-postmarket/year/2026)
-   [SBOM - 2026](/search/topic/sbom/year/2026)
-   [Threat Modeling - 2026](/search/topic/threat-modeling/year/2026)

© 2026 [Blue Goat Cyber](https://bluegoatcyber.com). All rights reserved. [Privacy](https://bluegoatcyber.com/privacy-policy/)[Terms](https://bluegoatcyber.com/terms-of-service/)