Skip to main content
    Back to episode
    Episode 76 · July 10, 2026 · 31m listen · 4,799 words · ~24 min read

    Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris - Full Transcript | The Med Device Cyber Podcast

    Read the complete, searchable transcript of Episode 76 of The Med Device Cyber Podcast - expert conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOM management, threat modeling, and penetration testing.

    Prefer the listening experience? Open the episode page for the synopsis, key takeaways, topics, and Apple / YouTube listen links.

    Episode summary

    In this episode of the Blue Goat Cyber podcast, host Christian Espinosa interviews Helen Souris, a seasoned expert in the medical technology field. Helen serves as the CEO and Executive Director of Cardihab, a digital therapeutics company focused on helping patients recover from heart events, and also sits on the board of the Medical Technology Association of Australia (MTAA), where she chairs the Digital Health Advisory Group. With a rich background that includes roles at pharmaceutical giants like Eli Lilly and AstraZeneca, Helen brings a deep understanding of the entire product lifecycle, from initial research to commercialization. The conversation delves into the critical and often overlooked importance of integrating regulatory compliance and cybersecurity into the development of medical devices from the very beginning, rather than as an afterthought. Helen Souris makes a compelling case for a 'foundations-first' approach to MedTech product development. She highlights a common and costly mistake made by many startups: delaying considerations for cybersecurity and regulatory standards until just before market submission. To illustrate the severe consequences of this oversight, she shares a cautionary tale of a company that, after securing $93 million in capital, was forced to withdraw its product from the market upon discovering it was not compliant with FDA regulations. This real-world example underscores her central argument that building a product without these considerations from the ground up is a recipe for failure. It's not only financially devastating to re-engineer a product later, but it also erodes trust with customers and investors. Helen emphasizes that cybersecurity is no longer a peripheral issue but a core component of business development that comes up in every customer conversation, requiring constant reassurance through certifications and transparent practices like ISO standards. The discussion also explores the nuanced distinction between wellness applications and regulated medical devices. Helen provides a clear framework for differentiation by analyzing the 'user journey.' If a product's workflow involves a patient, a medical condition being diagnosed or treated, and interaction with clinicians like doctors or nurses, it operates within the healthcare system and must be classified as a medical device. This is contrasted with a general wellness app, which might track steps but lacks the clinical context. Ultimately, Helen argues that for the digital health and MedTech industries to thrive and innovate responsibly, founders and developers must treat cybersecurity and regulatory compliance as non-negotiable, foundational pillars of their product strategy, a lesson that is far less costly to learn at the beginning of the journey.

    Key takeaways from this episode

    • Medical device startups often mistakenly delay cybersecurity and regulatory planning, viewing them as final-stage hurdles rather than foundational design elements.
    • Ignoring compliance from the start can lead to catastrophic financial and reputational damage, such as having to pull a product from the market after significant investment.
    • Cybersecurity is now a critical part of the conversation with any customer or partner, and companies must be prepared to demonstrate their compliance and security practices.
    • It is far too expensive and difficult to re-engineer a product for regulatory and security compliance later; it must be designed-in from the ground up.
    • A product's classification as a 'wellness app' versus a 'medical device' depends on its user journey—if it involves patients, clinicians, and medical conditions, it is a medical device.
    • Raising capital for MedTech startups can be challenging, particularly in smaller markets like Australia, often necessitating a search for international investors.
    • The legal and regulatory framework for software as a medical device is not an optional feature but a legal requirement that companies must address to operate legally and safely.
    • Companies must understand their product's user journey in detail to correctly identify its regulatory classification and associated requirements.

    Full episode transcript

    Page 1 of 6· Paragraphs 1 - 11
    Helen: after 93 million dollars in capital, they realized they were not compliant with the FDA. pulled their product from market. Christian: Even though we tell people that it needs to be done early, people still come back and say, we don't need cyber security yet. We're not ready for it. We need it like right before submission. Helen: Cyber security comes up in every single conversation that we have with with a customer. We have to remind everybody about our certifications, ISO standards, about our practices around cyber because it's the number one thing that blocks the conversation if you don't get it right. You should never build a product without that consideration from the ground up, because it's too late to do it later. Christian: Welcome to the podcast, uh Helen. Glad to have you on here. I know we met in person uh in March time frame in Sydney. Uh we were down there, we went to a Formula One race in Melbourne and did a few other things for work and then we went to Singapore after that and Korea and back to the United States. We've been around the world a little bit. Helen: Fantastic. Wonderful to be here and thanks for inviting me along. Christian: Yeah, awesome. Maybe you can tell us, you do a couple things. I know you're part of MTAA and uh your own organization. So maybe you can tell us a little bit about, um, about both and your involvement with both and uh give us some perspective of what Medtech is like down under. We have a few cli- clients down under in Australia. Uh but there's be for our listeners be cool to hear your perspective as well. Helen: Well, my main job is I am the CEO of a company called Cardihab. We're a digital therapeutics company that helps people recover from heart attacks, heart events through apps and uh care programs that we deliver through technology. So that's what keeps me busy most of my time. But I'm also on the board of the Medical Technology Association of Australia, which is a peak body that represents medical device companies. and I'm the chair of their digital health advisory group. and I guess the opportunity for me to join the MTAA's board was really to represent the startup ecosystem in Australia, but also to demonstrate what digital health can bring to an industry that is a regulated industry. Uh the recent changes around regulation of software as a medical device or digital therapeutics or whatever you want to call them, um all has uh brought to a head I guess the the requirement for companies like ours, products like ours to be regulated and that's a very familiar territory for medical device companies who commercialize their products uh in any market. Christian: And what made you start or get into uh your company Cardihab? Like what was like the the moment you decided you want to start that company or a little bit of the origin story? Helen: Well, I actually had a long career in pharmaceutical, biotech, medical device companies working with Eli Lilly and AstraZeneca. and a lot of the companies um that used to be entrepreneurial would come to us at the at Eli Lilly or or Astra and ask us to buy their tech or buy their product or buy their drug. and uh I felt at that time there was a lot of things missing from the commercialization journey, that early stage. You know, I could do something with your product if you had these particular parameters in your clinical trial that will differentiate your product, or I could commercialize your device if it wasn't this shape or this size relative to the original device that you're trying to I guess complement. And so I found myself surrounded by these wonderful entrepreneurs that if they had the right advice in the early stages of their sort of product development journey, uh they would have a much faster path to commercialization. So I started a consulting company um when I left Astra to help startups specifically with uh commercialization, that early stage, uh getting your clinical trials right, getting your design right. And one of the um clients that I had at that time was Cardihab. and they'd come to me after they had spun out of the CSIRO. Uh the company had taken two founders from Siro across to be the CEO and CTO. and for a few years they had struggled with that translation where everyone who's done a I guess an academic research project that then tries to get into the commercial world uh struggles with that that difference between academia and the difference between the commercial realities of what enterprise type clients would um tolerate, I guess, accept, love, from a product.
    1 / 6