---
title: "The Med Device Cyber Podcast"
description: "Expert conversations on medical device cybersecurity, FDA premarket guidance, SBOMs, threat modeling, and penetration testing. Hosted by Blue Goat Cyber."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "Organization",
          "@id": "https://mdcpodcast.com/#org-site",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "url": "https://mdcpodcast.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://mdcpodcast.com/apple-touch-icon.png",
            "width": 180,
            "height": 180
          },
          "sameAs": [
            "https://www.youtube.com/@bluegoatcyber",
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://mdcpodcast.com/rss.xml"
          ],
          "parentOrganization": {
            "@id": "https://bluegoatcyber.com/#org"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://bluegoatcyber.com/#org",
          "name": "Blue Goat Cyber",
          "url": "https://bluegoatcyber.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://bluegoatcyber.com/logo.png"
          }
        },
        {
          "@type": "WebSite",
          "@id": "https://mdcpodcast.com/#website",
          "url": "https://mdcpodcast.com",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://mdcpodcast.com/#org-site"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": {
              "@type": "EntryPoint",
              "urlTemplate": "https://mdcpodcast.com/search?q={search_term_string}"
            },
            "query-input": "required name=search_term_string"
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "PodcastSeries",
          "@id": "https://mdcpodcast.com/#podcast",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "description": "Expert conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOMs, threat modeling, and penetration testing - hosted by Blue Goat Cyber.",
          "url": "https://mdcpodcast.com",
          "inLanguage": "en-US",
          "image": {
            "@type": "ImageObject",
            "url": "https://mdcpodcast.com/og-image.jpg",
            "width": 1200,
            "height": 630
          },
          "webFeed": "https://mdcpodcast.com/rss.xml",
          "subscribeUrl": "https://mdcpodcast.com/rss.xml",
          "author": [
            {
              "@type": "Person",
              "@id": "https://mdcpodcast.com/hosts/christian-espinosa#person",
              "name": "Christian Espinosa",
              "jobTitle": "Founder & CEO",
              "url": "https://mdcpodcast.com/hosts/christian-espinosa",
              "sameAs": [
                "https://www.linkedin.com/in/christianespinosa/"
              ],
              "worksFor": {
                "@id": "https://bluegoatcyber.com/#org"
              }
            }
          ],
          "creator": {
            "@id": "https://mdcpodcast.com/hosts/christian-espinosa#person"
          },
          "actor": {
            "@id": "https://mdcpodcast.com/hosts/christian-espinosa#person"
          },
          "publisher": {
            "@type": "Organization",
            "@id": "https://bluegoatcyber.com/#org",
            "name": "Blue Goat Cyber",
            "url": "https://bluegoatcyber.com",
            "logo": {
              "@type": "ImageObject",
              "url": "https://bluegoatcyber.com/logo.png"
            }
          },
          "numberOfEpisodes": 83,
          "hasPart": [
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/the-3-commercialization-mistakes-killing-medtech-startups-with-ryan-roghaar-ep-8-olGgDd2l1RQ#episode",
              "name": "The 3 Commercialization Mistakes Killing MedTech Startups with Ryan Roghaar | Ep 83",
              "url": "https://mdcpodcast.com/episodes/the-3-commercialization-mistakes-killing-medtech-startups-with-ryan-roghaar-ep-8-olGgDd2l1RQ",
              "datePublished": "2026-08-27T18:47:55Z",
              "timeRequired": "PT51M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/25-of-job-candidates-are-fake-medtech-hiring-in-the-age-of-ai-with-darwin-shurig-EMWUOE-S2LY#episode",
              "name": "25% of Job Candidates Are Fake? MedTech Hiring in the Age of AI with Darwin Shurig | Ep 82",
              "url": "https://mdcpodcast.com/episodes/25-of-job-candidates-are-fake-medtech-hiring-in-the-age-of-ai-with-darwin-shurig-EMWUOE-S2LY",
              "datePublished": "2026-08-20T17:27:57Z",
              "timeRequired": "PT48M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-great-medical-technology-never-reaches-patients-with-amel-havkic-ep-81-sdZ9CDNHLbQ#episode",
              "name": "Why Great Medical Technology Never Reaches Patients with Amel Havkic | Ep 81",
              "url": "https://mdcpodcast.com/episodes/why-great-medical-technology-never-reaches-patients-with-amel-havkic-ep-81-sdZ9CDNHLbQ",
              "datePublished": "2026-08-13T17:19:18Z",
              "timeRequired": "PT41M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-medical-ai-still-needs-a-human-in-the-loop-tyler-harmon-ep-80-MD4AXMsivho#episode",
              "name": "Why Medical AI Still Needs a Human in the Loop | Tyler Harmon | Ep 80",
              "url": "https://mdcpodcast.com/episodes/why-medical-ai-still-needs-a-human-in-the-loop-tyler-harmon-ep-80-MD4AXMsivho",
              "datePublished": "2026-08-06T16:00:29Z",
              "timeRequired": "PT44M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0#episode",
              "name": "Why the Smartest Candidate May Be the Wrong Hire with Samantha Silk | Ep 79",
              "url": "https://mdcpodcast.com/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0",
              "datePublished": "2026-07-30T17:53:21Z",
              "timeRequired": "PT46M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0#episode",
              "name": "How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78",
              "url": "https://mdcpodcast.com/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0",
              "datePublished": "2026-07-23T15:36:19Z",
              "timeRequired": "PT52M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/could-a-hacker-change-what-a-patient-sees-with-frederik-ceyssens-ep-77-aKI9uMxr1Jg#episode",
              "name": "Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77",
              "url": "https://mdcpodcast.com/episodes/could-a-hacker-change-what-a-patient-sees-with-frederik-ceyssens-ep-77-aKI9uMxr1Jg",
              "datePublished": "2026-07-16T15:34:34Z",
              "timeRequired": "PT39M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI#episode",
              "name": "Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris",
              "url": "https://mdcpodcast.com/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI",
              "datePublished": "2026-07-10T14:00:37Z",
              "timeRequired": "PT31M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#episode",
              "name": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
              "datePublished": "2026-06-25T16:30:20Z",
              "timeRequired": "PT41M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/cancer-drugs-can-damage-the-heart-this-startup-wants-to-fix-it-with-ryan-neely-G28hsQ7qwQU#episode",
              "name": "Cancer Drugs Can Damage the Heart - This Startup Wants to Fix It with Ryan Neely",
              "url": "https://mdcpodcast.com/episodes/cancer-drugs-can-damage-the-heart-this-startup-wants-to-fix-it-with-ryan-neely-G28hsQ7qwQU",
              "datePublished": "2026-06-18T16:00:32Z",
              "timeRequired": "PT32M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk#episode",
              "name": "The Legal Hoops and Hurdles of MedTech Commercialization with JJ Amell",
              "url": "https://mdcpodcast.com/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk",
              "datePublished": "2026-06-04T15:30:25Z",
              "timeRequired": "PT49M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/the-dangerous-gap-in-global-medtech-security-awareness-with-shahbaz-ahmed-m-ofstbQpvI#episode",
              "name": "The Dangerous Gap in Global MedTech Security Awareness with Shahbaz Ahmed",
              "url": "https://mdcpodcast.com/episodes/the-dangerous-gap-in-global-medtech-security-awareness-with-shahbaz-ahmed-m-ofstbQpvI",
              "datePublished": "2026-05-28T16:00:46Z",
              "timeRequired": "PT40M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/the-age-of-digital-health-humanity-with-philippe-gerwill-ilVXaWtDpno#episode",
              "name": "The Age of Digital Health Humanity with Philippe Gerwill",
              "url": "https://mdcpodcast.com/episodes/the-age-of-digital-health-humanity-with-philippe-gerwill-ilVXaWtDpno",
              "datePublished": "2026-05-21T16:42:13Z",
              "timeRequired": "PT48M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-medtech-needs-specialists-with-zoltan-kevei-and-saby-toth-of-bishop-and-co-7-2b9qpYRQBVc#episode",
              "name": "Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | 70",
              "url": "https://mdcpodcast.com/episodes/why-medtech-needs-specialists-with-zoltan-kevei-and-saby-toth-of-bishop-and-co-7-2b9qpYRQBVc",
              "datePublished": "2026-05-14T16:30:27Z",
              "timeRequired": "PT42M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/science-before-hype-in-medtech-investing-with-varun-turlapati-of-chaanakya-capit-f8LwIy0zSX4#episode",
              "name": "Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital  | Ep. 69",
              "url": "https://mdcpodcast.com/episodes/science-before-hype-in-medtech-investing-with-varun-turlapati-of-chaanakya-capit-f8LwIy0zSX4",
              "datePublished": "2026-05-07T15:07:05Z",
              "timeRequired": "PT41M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/why-medtech-needs-more-than-approval-with-michael-branagan-harris-of-healthtech-pxG5VcG_6N4#episode",
              "name": "Why MedTech Needs More Than Approval with Michael Branagan Harris of HealthTech Strategies | 68",
              "url": "https://mdcpodcast.com/episodes/why-medtech-needs-more-than-approval-with-michael-branagan-harris-of-healthtech-pxG5VcG_6N4",
              "datePublished": "2026-04-30T02:15:00Z",
              "timeRequired": "PT49M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/de-risking-product-decisions-in-medtech-startups-with-brent-lavin-of-ironwood-me-qoGs15STxSg#episode",
              "name": "De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners | 67",
              "url": "https://mdcpodcast.com/episodes/de-risking-product-decisions-in-medtech-startups-with-brent-lavin-of-ironwood-me-qoGs15STxSg",
              "datePublished": "2026-04-23T02:30:00Z",
              "timeRequired": "PT44M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/vibe-coding-security-risks-and-malicious-code-injection-with-jake-rodriguez-of-t-xoCeaxjI1eI#episode",
              "name": "Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech | Ep.66",
              "url": "https://mdcpodcast.com/episodes/vibe-coding-security-risks-and-malicious-code-injection-with-jake-rodriguez-of-t-xoCeaxjI1eI",
              "datePublished": "2026-04-16T16:14:22Z",
              "timeRequired": "PT39M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/who-owns-patient-data-security-in-trials-with-rob-bedford-ceo-of-franklyn-health-J15kftTETFk#episode",
              "name": "Who Owns Patient Data Security in Trials with Rob Bedford, CEO of Franklyn Health | Ep.65",
              "url": "https://mdcpodcast.com/episodes/who-owns-patient-data-security-in-trials-with-rob-bedford-ceo-of-franklyn-health-J15kftTETFk",
              "datePublished": "2026-04-10T03:38:59Z",
              "timeRequired": "PT42M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/start-qms-early-to-avoid-reverse-documentation-with-dr-basant-bajpai-ep-64-_vfmxG94aHE#episode",
              "name": "Start QMS Early to Avoid Reverse Documentation with Dr. Basant Bajpai | Ep.64",
              "url": "https://mdcpodcast.com/episodes/start-qms-early-to-avoid-reverse-documentation-with-dr-basant-bajpai-ep-64-_vfmxG94aHE",
              "datePublished": "2026-04-02T17:04:33Z",
              "timeRequired": "PT35M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/early-design-decisions-that-shape-medical-device-success-with-chris-danek-ceo-of-6efQgb7sUS0#episode",
              "name": "Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel | Ep. 63",
              "url": "https://mdcpodcast.com/episodes/early-design-decisions-that-shape-medical-device-success-with-chris-danek-ceo-of-6efQgb7sUS0",
              "datePublished": "2026-03-26T15:57:09Z",
              "timeRequired": "PT51M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/ai-in-healthcare-why-humans-still-matter-with-brandon-fertig-senior-manager-at-p-D_kxhi332IA#episode",
              "name": "AI in Healthcare: Why Humans Still Matter with Brandon Fertig, Senior Manager at Philips | Ep. 62",
              "url": "https://mdcpodcast.com/episodes/ai-in-healthcare-why-humans-still-matter-with-brandon-fertig-senior-manager-at-p-D_kxhi332IA",
              "datePublished": "2026-03-19T14:59:15Z",
              "timeRequired": "PT43M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/how-to-design-devices-that-integrate-into-clinical-workflow-without-disruption-e-xamMQObdrJk#episode",
              "name": "How to Design Devices That Integrate Into Clinical Workflow Without Disruption  | Ep. 61",
              "url": "https://mdcpodcast.com/episodes/how-to-design-devices-that-integrate-into-clinical-workflow-without-disruption-e-xamMQObdrJk",
              "datePublished": "2026-03-12T16:17:51Z",
              "timeRequired": "PT38M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/how-to-move-stakeholders-from-awareness-to-sustained-adoption-without-friction-e-zip-gGljTgE#episode",
              "name": "How to Move Stakeholders from Awareness to Sustained Adoption Without Friction | Ep. 60",
              "url": "https://mdcpodcast.com/episodes/how-to-move-stakeholders-from-awareness-to-sustained-adoption-without-friction-e-zip-gGljTgE",
              "datePublished": "2026-03-06T18:36:22Z",
              "timeRequired": "PT41M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            },
            {
              "@type": "PodcastEpisode",
              "@id": "https://mdcpodcast.com/episodes/prevention-is-better-than-cure-applying-medical-principles-to-medtech-cybersecur-fKd61b0ttso#episode",
              "name": "Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity | Ep. 59",
              "url": "https://mdcpodcast.com/episodes/prevention-is-better-than-cure-applying-medical-principles-to-medtech-cybersecur-fKd61b0ttso",
              "datePublished": "2026-02-26T17:06:56Z",
              "timeRequired": "PT32M",
              "partOfSeries": {
                "@id": "https://mdcpodcast.com/#podcast"
              }
            }
          ],
          "mainEntityOfPage": {
            "@id": "https://mdcpodcast.com/#episode-list"
          }
        },
        {
          "@type": "ItemList",
          "@id": "https://mdcpodcast.com/#episode-list",
          "name": "The Med Device Cyber Podcast episodes",
          "description": "Latest episodes of The Med Device Cyber Podcast, newest first.",
          "itemListOrder": "https://schema.org/ItemListOrderDescending",
          "numberOfItems": 25,
          "about": {
            "@id": "https://mdcpodcast.com/#podcast"
          },
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "url": "https://mdcpodcast.com/episodes/the-3-commercialization-mistakes-killing-medtech-startups-with-ryan-roghaar-ep-8-olGgDd2l1RQ",
              "name": "The 3 Commercialization Mistakes Killing MedTech Startups with Ryan Roghaar | Ep 83",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/the-3-commercialization-mistakes-killing-medtech-startups-with-ryan-roghaar-ep-8-olGgDd2l1RQ#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 2,
              "url": "https://mdcpodcast.com/episodes/25-of-job-candidates-are-fake-medtech-hiring-in-the-age-of-ai-with-darwin-shurig-EMWUOE-S2LY",
              "name": "25% of Job Candidates Are Fake? MedTech Hiring in the Age of AI with Darwin Shurig | Ep 82",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/25-of-job-candidates-are-fake-medtech-hiring-in-the-age-of-ai-with-darwin-shurig-EMWUOE-S2LY#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 3,
              "url": "https://mdcpodcast.com/episodes/why-great-medical-technology-never-reaches-patients-with-amel-havkic-ep-81-sdZ9CDNHLbQ",
              "name": "Why Great Medical Technology Never Reaches Patients with Amel Havkic | Ep 81",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-great-medical-technology-never-reaches-patients-with-amel-havkic-ep-81-sdZ9CDNHLbQ#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 4,
              "url": "https://mdcpodcast.com/episodes/why-medical-ai-still-needs-a-human-in-the-loop-tyler-harmon-ep-80-MD4AXMsivho",
              "name": "Why Medical AI Still Needs a Human in the Loop | Tyler Harmon | Ep 80",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-medical-ai-still-needs-a-human-in-the-loop-tyler-harmon-ep-80-MD4AXMsivho#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 5,
              "url": "https://mdcpodcast.com/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0",
              "name": "Why the Smartest Candidate May Be the Wrong Hire with Samantha Silk | Ep 79",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 6,
              "url": "https://mdcpodcast.com/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0",
              "name": "How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 7,
              "url": "https://mdcpodcast.com/episodes/could-a-hacker-change-what-a-patient-sees-with-frederik-ceyssens-ep-77-aKI9uMxr1Jg",
              "name": "Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/could-a-hacker-change-what-a-patient-sees-with-frederik-ceyssens-ep-77-aKI9uMxr1Jg#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 8,
              "url": "https://mdcpodcast.com/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI",
              "name": "Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 9,
              "url": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8",
              "name": "Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 10,
              "url": "https://mdcpodcast.com/episodes/cancer-drugs-can-damage-the-heart-this-startup-wants-to-fix-it-with-ryan-neely-G28hsQ7qwQU",
              "name": "Cancer Drugs Can Damage the Heart - This Startup Wants to Fix It with Ryan Neely",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/cancer-drugs-can-damage-the-heart-this-startup-wants-to-fix-it-with-ryan-neely-G28hsQ7qwQU#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 11,
              "url": "https://mdcpodcast.com/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk",
              "name": "The Legal Hoops and Hurdles of MedTech Commercialization with JJ Amell",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/the-legal-hoops-and-hurdles-of-medtech-commercialization-with-jj-amell-9GnsZGeFuVk#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 12,
              "url": "https://mdcpodcast.com/episodes/the-dangerous-gap-in-global-medtech-security-awareness-with-shahbaz-ahmed-m-ofstbQpvI",
              "name": "The Dangerous Gap in Global MedTech Security Awareness with Shahbaz Ahmed",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/the-dangerous-gap-in-global-medtech-security-awareness-with-shahbaz-ahmed-m-ofstbQpvI#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 13,
              "url": "https://mdcpodcast.com/episodes/the-age-of-digital-health-humanity-with-philippe-gerwill-ilVXaWtDpno",
              "name": "The Age of Digital Health Humanity with Philippe Gerwill",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/the-age-of-digital-health-humanity-with-philippe-gerwill-ilVXaWtDpno#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 14,
              "url": "https://mdcpodcast.com/episodes/why-medtech-needs-specialists-with-zoltan-kevei-and-saby-toth-of-bishop-and-co-7-2b9qpYRQBVc",
              "name": "Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | 70",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-medtech-needs-specialists-with-zoltan-kevei-and-saby-toth-of-bishop-and-co-7-2b9qpYRQBVc#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 15,
              "url": "https://mdcpodcast.com/episodes/science-before-hype-in-medtech-investing-with-varun-turlapati-of-chaanakya-capit-f8LwIy0zSX4",
              "name": "Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital  | Ep. 69",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/science-before-hype-in-medtech-investing-with-varun-turlapati-of-chaanakya-capit-f8LwIy0zSX4#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 16,
              "url": "https://mdcpodcast.com/episodes/why-medtech-needs-more-than-approval-with-michael-branagan-harris-of-healthtech-pxG5VcG_6N4",
              "name": "Why MedTech Needs More Than Approval with Michael Branagan Harris of HealthTech Strategies | 68",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/why-medtech-needs-more-than-approval-with-michael-branagan-harris-of-healthtech-pxG5VcG_6N4#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 17,
              "url": "https://mdcpodcast.com/episodes/de-risking-product-decisions-in-medtech-startups-with-brent-lavin-of-ironwood-me-qoGs15STxSg",
              "name": "De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners | 67",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/de-risking-product-decisions-in-medtech-startups-with-brent-lavin-of-ironwood-me-qoGs15STxSg#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 18,
              "url": "https://mdcpodcast.com/episodes/vibe-coding-security-risks-and-malicious-code-injection-with-jake-rodriguez-of-t-xoCeaxjI1eI",
              "name": "Vibe Coding Security Risks and Malicious Code Injection with Jake Rodriguez of Triangle Tech | Ep.66",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/vibe-coding-security-risks-and-malicious-code-injection-with-jake-rodriguez-of-t-xoCeaxjI1eI#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 19,
              "url": "https://mdcpodcast.com/episodes/who-owns-patient-data-security-in-trials-with-rob-bedford-ceo-of-franklyn-health-J15kftTETFk",
              "name": "Who Owns Patient Data Security in Trials with Rob Bedford, CEO of Franklyn Health | Ep.65",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/who-owns-patient-data-security-in-trials-with-rob-bedford-ceo-of-franklyn-health-J15kftTETFk#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 20,
              "url": "https://mdcpodcast.com/episodes/start-qms-early-to-avoid-reverse-documentation-with-dr-basant-bajpai-ep-64-_vfmxG94aHE",
              "name": "Start QMS Early to Avoid Reverse Documentation with Dr. Basant Bajpai | Ep.64",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/start-qms-early-to-avoid-reverse-documentation-with-dr-basant-bajpai-ep-64-_vfmxG94aHE#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 21,
              "url": "https://mdcpodcast.com/episodes/early-design-decisions-that-shape-medical-device-success-with-chris-danek-ceo-of-6efQgb7sUS0",
              "name": "Early Design Decisions that Shape Medical Device Success with Chris Danek, CEO of Bessel | Ep. 63",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/early-design-decisions-that-shape-medical-device-success-with-chris-danek-ceo-of-6efQgb7sUS0#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 22,
              "url": "https://mdcpodcast.com/episodes/ai-in-healthcare-why-humans-still-matter-with-brandon-fertig-senior-manager-at-p-D_kxhi332IA",
              "name": "AI in Healthcare: Why Humans Still Matter with Brandon Fertig, Senior Manager at Philips | Ep. 62",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/ai-in-healthcare-why-humans-still-matter-with-brandon-fertig-senior-manager-at-p-D_kxhi332IA#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 23,
              "url": "https://mdcpodcast.com/episodes/how-to-design-devices-that-integrate-into-clinical-workflow-without-disruption-e-xamMQObdrJk",
              "name": "How to Design Devices That Integrate Into Clinical Workflow Without Disruption  | Ep. 61",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/how-to-design-devices-that-integrate-into-clinical-workflow-without-disruption-e-xamMQObdrJk#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 24,
              "url": "https://mdcpodcast.com/episodes/how-to-move-stakeholders-from-awareness-to-sustained-adoption-without-friction-e-zip-gGljTgE",
              "name": "How to Move Stakeholders from Awareness to Sustained Adoption Without Friction | Ep. 60",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/how-to-move-stakeholders-from-awareness-to-sustained-adoption-without-friction-e-zip-gGljTgE#episode"
              }
            },
            {
              "@type": "ListItem",
              "position": 25,
              "url": "https://mdcpodcast.com/episodes/prevention-is-better-than-cure-applying-medical-principles-to-medtech-cybersecur-fKd61b0ttso",
              "name": "Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity | Ep. 59",
              "item": {
                "@id": "https://mdcpodcast.com/episodes/prevention-is-better-than-cure-applying-medical-principles-to-medtech-cybersecur-fKd61b0ttso#episode"
              }
            }
          ]
        },
        {
          "@type": "WebSite",
          "@id": "https://mdcpodcast.com/#website",
          "url": "https://mdcpodcast.com",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "inLanguage": "en-US",
          "publisher": {
            "@id": "https://mdcpodcast.com/#org-site"
          },
          "about": {
            "@id": "https://mdcpodcast.com/#podcast"
          },
          "potentialAction": {
            "@type": "SearchAction",
            "target": {
              "@type": "EntryPoint",
              "urlTemplate": "https://mdcpodcast.com/search?q={search_term_string}"
            },
            "query-input": "required name=search_term_string"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://mdcpodcast.com/#org-site",
          "name": "The Med Device Cyber Podcast",
          "alternateName": "MDC Podcast",
          "url": "https://mdcpodcast.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://mdcpodcast.com/apple-touch-icon.png",
            "width": 180,
            "height": 180
          },
          "sameAs": [
            "https://www.youtube.com/@bluegoatcyber",
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://mdcpodcast.com/rss.xml"
          ],
          "parentOrganization": {
            "@id": "https://bluegoatcyber.com/#org"
          }
        },
        {
          "@type": "Organization",
          "@id": "https://bluegoatcyber.com/#org",
          "name": "Blue Goat Cyber",
          "url": "https://bluegoatcyber.com",
          "logo": {
            "@type": "ImageObject",
            "url": "https://bluegoatcyber.com/logo.png"
          },
          "sameAs": [
            "https://www.linkedin.com/company/blue-goat-cyber",
            "https://www.youtube.com/@bluegoatcyber"
          ]
        },
        {
          "@type": "FAQPage",
          "@id": "https://mdcpodcast.com/#faq",
          "mainEntity": [
            {
              "@type": "Question",
              "name": "What is medical device cybersecurity?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Medical device cybersecurity is the practice of protecting connected medical devices, their software, and the data they handle from attack, misuse, and unauthorized access. It spans secure design, threat modeling, SBOM management, penetration testing, and postmarket vulnerability response, all aligned with FDA expectations and standards like IEC 62304, ISO 14971, and AAMI TIR57."
              }
            },
            {
              "@type": "Question",
              "name": "What does the FDA require for premarket cybersecurity submissions?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "FDA premarket submissions (510(k), De Novo, PMA) typically require a Secure Product Development Framework (SPDF), threat model, cybersecurity risk assessment, SBOM, vulnerability assessment, security testing evidence, architecture views, and a postmarket cybersecurity management plan. The 524B eSTAR template formalizes much of this for 2026 and beyond."
              }
            },
            {
              "@type": "Question",
              "name": "What is an SBOM and why does the FDA require one?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "A Software Bill of Materials (SBOM) is a machine-readable inventory of every component, including third-party and open-source libraries, used in your device. The FDA requires it so manufacturers and operators can quickly identify exposure to new vulnerabilities (like Log4Shell) and demonstrate ongoing component-level risk management."
              }
            },
            {
              "@type": "Question",
              "name": "How is threat modeling different from a risk assessment?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "A threat model identifies how an adversary could attack your device (using frameworks like STRIDE, attack trees, or kill chains). A cybersecurity risk assessment then evaluates the likelihood and patient-safety impact of those threats and ties controls back to ISO 14971. Both are required for a credible FDA cybersecurity submission."
              }
            },
            {
              "@type": "Question",
              "name": "Who should listen to The Med Device Cyber Podcast?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Product security engineers, regulatory and quality leads, MedTech founders, and engineering teams building connected medical devices, anyone who needs to translate FDA cybersecurity expectations into shippable, secure products."
              }
            },
            {
              "@type": "Question",
              "name": "How often are new episodes released?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "New episodes are published weekly, available on Spotify, Apple Podcasts, YouTube, and most major podcast platforms."
              }
            },
            {
              "@type": "Question",
              "name": "What is the FDA 524B eSTAR template?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Section 524B of the FD&C Act requires cyber device manufacturers to submit specific cybersecurity information with premarket applications. The 524B eSTAR template operationalizes those requirements with structured fields for SPDF evidence, SBOM, threat model, security testing, and postmarket plans, becoming the de facto submission format for 2026 and beyond."
              }
            },
            {
              "@type": "Question",
              "name": "What is the difference between 510(k), De Novo, and PMA cybersecurity expectations?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "All three pathways now require a full cybersecurity package under 524B, but the depth scales with risk. 510(k) submissions for moderate-risk devices need standard SPDF artifacts; De Novo adds justification for novel risk controls; PMA submissions for high-risk devices typically require deeper penetration testing, more rigorous threat modeling, and tighter postmarket commitments."
              }
            },
            {
              "@type": "Question",
              "name": "Do I need penetration testing for my FDA submission?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Yes. The FDA expects evidence of security testing appropriate to the device's risk and architecture, including vulnerability scanning, fuzz testing, software composition analysis, and penetration testing of exposed interfaces (network, wireless, USB, BLE). Results, methodology, and remediation status all become part of your submission."
              }
            },
            {
              "@type": "Question",
              "name": "What standards apply to medical device cybersecurity?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Core references include AAMI TIR57 (cybersecurity risk management), AAMI SW96, IEC 62304 (medical device software lifecycle), ISO 14971 (risk management), IEC 81001-5-1 (health software security), and NIST SP 800-53/800-30 for control selection. The FDA also points to UL 2900 and the Joint Security Plan (JSP) for industry guidance."
              }
            },
            {
              "@type": "Question",
              "name": "What is a Secure Product Development Framework (SPDF)?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "An SPDF is a documented set of processes that integrates security into every phase of the product lifecycle, requirements, design, implementation, verification, release, and postmarket. The FDA expects manufacturers to define, follow, and provide evidence of an SPDF that produces secure-by-design devices and demonstrable security risk management."
              }
            },
            {
              "@type": "Question",
              "name": "How does postmarket cybersecurity management work?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Postmarket management covers monitoring for new vulnerabilities (CVEs, threat intel), coordinated vulnerability disclosure, patching cadence, customer communication, and reportability decisions to the FDA. Manufacturers must maintain a documented plan and demonstrate active SBOM monitoring across the device's supported lifetime."
              }
            },
            {
              "@type": "Question",
              "name": "What is coordinated vulnerability disclosure (CVD)?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "CVD is the formal process for receiving, triaging, fixing, and publishing information about vulnerabilities reported by external researchers. The FDA expects medical device manufacturers to publish a clear CVD policy, designate a contact, and operate the process consistent with ISO/IEC 29147 and 30111."
              }
            },
            {
              "@type": "Question",
              "name": "How does AI/ML change medical device cybersecurity?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "AI/ML-enabled devices add attack surface (model inputs, training data, inference pipelines) and new failure modes (data poisoning, adversarial examples, model drift). The FDA's January 2025 AI guidance asks for transparency on model behavior, lifecycle change control, real-world monitoring, and explicit cybersecurity controls around model assets and training infrastructure."
              }
            },
            {
              "@type": "Question",
              "name": "What is IEC 62304 and how does it relate to cybersecurity?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "IEC 62304 governs the medical device software lifecycle, planning, requirements, architecture, implementation, verification, configuration management, and problem resolution. Cybersecurity activities (threat modeling, security requirements, secure coding, security testing) are layered on top of, and traceable through, the same lifecycle artifacts."
              }
            },
            {
              "@type": "Question",
              "name": "Can guests come on the show?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "Yes. We feature MedTech founders, product security leaders, regulatory experts, researchers, and clinicians. If you're working on something interesting at the intersection of medical devices and cybersecurity, reach out to Blue Goat Cyber to pitch a topic."
              }
            },
            {
              "@type": "Question",
              "name": "Where can I get help applying what I hear on the podcast?",
              "acceptedAnswer": {
                "@type": "Answer",
                "text": "The Med Device Cyber Podcast is produced by Blue Goat Cyber, which provides full-service medical device cybersecurity, threat modeling, SBOM development, penetration testing, FDA submission documentation, and postmarket programs. Schedule a discovery session at bluegoatcyber.com to discuss your device."
              }
            }
          ]
        }
      ]
    }
  ]
---

[Skip to main content](#main-content)

[![The Med Device Cyber Podcast](/assets/bgc-logo-BrKdoJVC.png)

The Med Device Cyber Podcast

Hosted by Blue Goat CyberSM



](/)

[Episodes](/episodes)[Hosts](/hosts)[About](/about)[Be a Guest](/be-a-guest)[Listen](/#listen)

Search... ⌘K

[(844) 939-4628](tel:+18449394628)[Schedule Discovery](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

New episodes weekly 

# The Med Device  
Cyber Podcast 

Frontline conversations on medical device cybersecurity, FDA premarket guidance, SBOMs, penetration testing, and the hard-won lessons that keep patients safe.

[RSS ](https://mdcpodcast.com/rss.xml)[Apple Podcasts ](https://podcasts.apple.com/us/search?term=Med%20Device%20Cyber%20Podcast)[Spotify ](https://open.spotify.com/search/Med%20Device%20Cyber%20Podcast)[YouTube ](https://www.youtube.com/playlist?list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)

Hosted by [Blue Goat Cyber](https://bluegoatcyber.com) • FDA · IEC 62304 · ISO 14971 

The Catalogue

## Every episode, in one place.

83  episodes & counting

Filters

83  / 83 episodes 

Newest first 

All series All hosts 

All years All months 

Any length 

AllYouTubeSpotifyApple

[Open in full search page](/search)

[

![Episode 83 thumbnail, The 3 Commercialization Mistakes Killing MedTech Startups with Ryan Roghaar | Ep 83](https://i.ytimg.com/vi/olGgDd2l1RQ/maxresdefault.jpg)

EP 083

Aug 27, 2026

### The 3 Commercialization Mistakes Killing MedTech Startups with Ryan Roghaar | Ep 83

What makes an investor lose confidence in a MedTech company before the technology itself is even questioned? Christian Espinosa is joined by Ryan Roghaar, founder of RŌG Health, to examine the commercialization gaps that can undermine promising medical device companies. Ryan breaks down three recurring problems his team sees across MedTech businesses: unclear narratives, poor buyer clarity and claims that move faster than the available evidence. They also explore the pressure startups face to chase revenue outside their original strategy, the importance of keeping messaging aligned across pitch decks and websites, and why cybersecurity is becoming increasingly difficult to separate from commercialization as medical devices become more connected and AI-driven. In This Episode: \* 07:43 Why Ryan moved into MedTech \* 10:32 Moving from marketing agency to MedTech consultancy \* 11:32 Why devices fail outside the technology itself \* 12:41 Does MedTech commercialization follow a sequence? \* 16:08 The evidence gap inside MedTech companies \* 17:10 How investors pressure-test startups \* 19:55 When a company tells four different stories \* 23:36 Can cybersecurity become a commercial differentiator? \* 24:11 Why medical device hacking feels different \* 27:24 Cybersecurity risks from MRIs to brain implants \* 32:21 The three biggest commercialization gaps Ryan is seeing \* 35:57 Why unclear buyers dilute your message \* 39:08 The pressure to take the wrong customer \* 42:47 Ryan’s three key takeaways for MedTech companies Check out Ryan Roghaar’s LinkedIn here: https://www.linkedin.com/in/ryanroghaar/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1\*



](/episodes/the-3-commercialization-mistakes-killing-medtech-startups-with-ryan-roghaar-ep-8-olGgDd2l1RQ)

[YouTube ](https://www.youtube.com/watch?v=olGgDd2l1RQ&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/The%203%20Commercialization%20Mistakes%20Killing%20MedTech%20Startups%20with%20Ryan%20Roghaar%20%7C%20Ep%2083%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=The%203%20Commercialization%20Mistakes%20Killing%20MedTech%20Startups%20with%20Ryan%20Roghaar%20%7C%20Ep%2083%20Med%20Device%20Cyber%20Podcast)

[

![Episode 82 thumbnail, 25% of Job Candidates Are Fake? MedTech Hiring in the Age of AI with Darwin Shurig | Ep 82](https://i.ytimg.com/vi/EMWUOE-S2LY/maxresdefault.jpg)

EP 082

Aug 20, 2026

### 25% of Job Candidates Are Fake? MedTech Hiring in the Age of AI with Darwin Shurig | Ep 82

25% of job candidates are fake. Some companies are now reaching the point where AI is interviewing AI So what does that mean for MedTech companies trying to find highly specialized talent? Christian Espinosa is joined by Darwin Shurig, founder of Top Talent Accelerant, to explore how AI is reshaping recruitment and why traditional hiring processes are increasingly struggling to identify the right people. They discuss why top candidates often never see your job posting, how AI can simultaneously improve and damage candidate screening, and why roles in areas such as cybersecurity, machine learning and AI can remain vacant for five, seven or even eight months. Darwin also explains why hiring should begin with a much clearer picture of company culture, leadership and expectations, allowing candidates and employers to identify alignment before wasting hours on interviews that were never going to result in the right hire. In This Episode: \* 01:13 Darwin’s journey from critical care to MedTech recruiting \* 04:38 Why recruiting has become such a crowded industry \* 06:55 The cost of getting the hiring process wrong \* 09:00 How AI is changing candidate screening \* 10:11 Why specialized MedTech roles can stay open for months \* 11:26 Why traditional hiring processes need to change \* 12:31 Creating a better candidate experience \* 13:48 The $9 billion impact associated with warning letters \* 14:49 Why the best candidates are not applying to your job posts \* 15:53 When AI starts interviewing AI \* 16:45 Remote hiring, geography and compensation \* 18:58 The story behind The Modern-Day Job \* 36:51 Why values and alignment matter when choosing people \* 40:33 Building teams around shared values and culture Check out Darwin Shurig’s LinkedIn here: https://www.linkedin.com/in/darwin-shurig The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/25-of-job-candidates-are-fake-medtech-hiring-in-the-age-of-ai-with-darwin-shurig-EMWUOE-S2LY)

[YouTube ](https://www.youtube.com/watch?v=EMWUOE-S2LY&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/25%25%20of%20Job%20Candidates%20Are%20Fake%3F%20MedTech%20Hiring%20in%20the%20Age%20of%20AI%20with%20Darwin%20Shurig%20%7C%20Ep%2082%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=25%25%20of%20Job%20Candidates%20Are%20Fake%3F%20MedTech%20Hiring%20in%20the%20Age%20of%20AI%20with%20Darwin%20Shurig%20%7C%20Ep%2082%20Med%20Device%20Cyber%20Podcast)

[

![Episode 81 thumbnail, Why Great Medical Technology Never Reaches Patients with Amel Havkic | Ep 81](https://i.ytimg.com/vi/sdZ9CDNHLbQ/maxresdefault.jpg)

EP 081

Aug 13, 2026

### Why Great Medical Technology Never Reaches Patients with Amel Havkic | Ep 81

Why do technically strong, well-funded and compliant MedTech companies still fail? Christian Espinosa is joined by Amel Havkic, founder of EvoMed Consulting, to unpack the blind spots that can stop promising medical technologies from ever reaching sustainable clinical adoption. Amel explains why getting regulatory approval is only part of the journey. A device can work perfectly in a controlled environment and still fail when it meets the reality of hospital workflows, reimbursement, cybersecurity, overstretched staff and resistance to behavioural change. They also examine why pilots and key opinion leaders can sometimes create a false sense of confidence, how founder bias can shape strategic decisions and why the people surrounding a MedTech company may ultimately determine whether the technology succeeds. In This Episode: \* 01:08 Amel Havkic and VivoMed Consulting \* 02:41 Why 75% of MedTech companies fail \* 04:43 Clinical adoption, fundability and founder blind spots \* 07:23 Why one solution must satisfy many stakeholders \* 09:42 Economic viability and implementation friction \* 12:37 The hidden cost of changing clinical behaviour \* 15:43 The KOL trap and why pilots can mislead \* 18:46 Alarm fatigue and real-world clinical environments \* 20:46 Christian’s introduction to medical-device cybersecurity \* 23:04 Why cybersecurity deficiencies derail submissions \* 27:49 Building the right team around a MedTech founder \* 32:38 Authenticity, intuition and choosing the right partners \* 37:17 Why being human may become a superpower in the age of AI Check out Amel Havkic’s LinkedIn here: linkedin.com/in/a-havkic/?skipRedirect=true The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/why-great-medical-technology-never-reaches-patients-with-amel-havkic-ep-81-sdZ9CDNHLbQ)

[YouTube ](https://www.youtube.com/watch?v=sdZ9CDNHLbQ&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Why%20Great%20Medical%20Technology%20Never%20Reaches%20Patients%20with%20Amel%20Havkic%20%7C%20Ep%2081%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Why%20Great%20Medical%20Technology%20Never%20Reaches%20Patients%20with%20Amel%20Havkic%20%7C%20Ep%2081%20Med%20Device%20Cyber%20Podcast)

[

![Episode 80 thumbnail, Why Medical AI Still Needs a Human in the Loop | Tyler Harmon | Ep 80](https://i.ytimg.com/vi/MD4AXMsivho/maxresdefault.jpg)

EP 080

Aug 6, 2026

### Why Medical AI Still Needs a Human in the Loop | Tyler Harmon | Ep 80

What happens when doctors use consumer AI tools to make clinical decisions? In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Tyler Harmon, CEO and co-founder of IASO Automated Medical Systems, to discuss the safety, regulatory, and cybersecurity challenges surrounding AI as a medical device. Tyler explains why keeping a human involved does not automatically make an AI system safe. If the model was never designed, validated, or cleared for medical diagnosis, human oversight may not solve the underlying problem. The discussion explores when an AI system becomes a regulated medical device, why companies should not update medical AI like a consumer app and what developers need to consider before building a product on top of someone else’s model. In This Episode: \* 00:48 Tyler Harmon and IASO Automated Medical Systems \* 03:34 What qualifies as AI as a medical device? \* 04:44 Predetermined change control plans \* 06:08 When should an AI medical device be updated? \* 09:00 Why medical AI is not new \* 11:32 Why medical AI still needs human oversight \* 17:40 Doctors using ChatGPT to interpret X-rays \* 20:09 Frontier models and AI harnesses \* 24:16 The challenge of developing proprietary AI \* 29:21 Why medical AI can take years to reach the market \* 34:28 Using consumer LLMs outside their intended licence \* 39:25 Licensing third-party AI for medical-device use \* 40:41 Final lessons for medical-AI developers Check out Tyler Harmon’s LinkedIn here: https://www.linkedin.com/in/tyler-h-938bbb43/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/why-medical-ai-still-needs-a-human-in-the-loop-tyler-harmon-ep-80-MD4AXMsivho)

[YouTube ](https://www.youtube.com/watch?v=MD4AXMsivho&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Why%20Medical%20AI%20Still%20Needs%20a%20Human%20in%20the%20Loop%20%7C%20Tyler%20Harmon%20%7C%20Ep%2080%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Why%20Medical%20AI%20Still%20Needs%20a%20Human%20in%20the%20Loop%20%7C%20Tyler%20Harmon%20%7C%20Ep%2080%20Med%20Device%20Cyber%20Podcast)

[

![Episode 79 thumbnail, Why the Smartest Candidate May Be the Wrong Hire with Samantha Silk | Ep 79](https://i.ytimg.com/vi/BtmXo69lBS0/maxresdefault.jpg)

EP 079

Jul 30, 2026

### Why the Smartest Candidate May Be the Wrong Hire with Samantha Silk | Ep 79

How much can an unfilled critical role really cost a MedTech organization? In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Samantha Silk, CEO of Apex Pro Placement, to discuss recruitment, emotional intelligence and the human judgment required to build strong technical teams. Samantha explains why companies may lose up to $5,000 a day while an important position remains open and why hiring the wrong person can create even greater costs through lost productivity, offboarding and restarting the recruitment process. The discussion covers what specialist recruiters actually do, why job descriptions are often inaccurate and how a good recruiter identifies the unspoken requirements behind a role. Samantha shares why she looks beyond technical credentials when evaluating candidates and why emotional intelligence often determines who rises into leadership. Christian and Samantha explore whether highly intelligent people are truly effective if they cannot communicate their ideas clearly. They discuss technical professionals hiding behind complex language, the importance of explaining scientific breakthroughs in simple terms and why communication can determine whether an innovation receives funding or reaches the market. The episode examines intuition in hiring, AI-generated résumés, fake candidates, recruitment scams and the need for human oversight when evaluating people. In This Episode: \* 00:57 Samantha’s path from cybersecurity recruiting to life sciences \* 04:07 When using an external recruiter makes sense \* 05:39 How an open critical role can cost up to $5,000 per day \* 09:41 Why effective hiring starts with listening to the client \* 11:57 Why most job descriptions fail to describe the real role \* 13:34 Emotional intelligence in recruitment and leadership \* 18:53 Why technical experts must communicate in simple language \* 21:24 Investor pressure and unethical recruitment practices \* 26:25 Using intuition and gut instinct when hiring \* 32:03 How constant screen use affects attention and connection \* 37:22 AI-generated résumés, recruitment noise and human oversight \* 39:58 What rock climbing teaches us about trust in cybersecurity \* 42:36 Final lessons on communication, EQ and technical careers \* 45:04 Christian’s vision for AI agents running a company \* 46:41 Why social engineering succeeds against hospitals \* 47:20 How AI is making phishing more personalised \* 48:21 Why AI is changing every part of business \* 49:25 Final lessons on curiosity, assumptions and friction Check out Samantha Silk’s Linkedin here - https://www.linkedin.com/in/samanthawein/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/why-the-smartest-candidate-may-be-the-wrong-hire-with-samantha-silk-ep-79-BtmXo69lBS0)

[YouTube ](https://www.youtube.com/watch?v=BtmXo69lBS0&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Why%20the%20Smartest%20Candidate%20May%20Be%20the%20Wrong%20Hire%20with%20Samantha%20Silk%20%7C%20Ep%2079%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Why%20the%20Smartest%20Candidate%20May%20Be%20the%20Wrong%20Hire%20with%20Samantha%20Silk%20%7C%20Ep%2079%20Med%20Device%20Cyber%20Podcast)

[

![Episode 78 thumbnail, How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78](https://i.ytimg.com/vi/lT7fwbpCdZ0/maxresdefault.jpg)

EP 078

Jul 23, 2026

### How Different Brains Build Better Teams with Sarah Ohanesian and Jeff Gibbard | Ep 78

Why do some teams remain overwhelmed even after introducing new productivity tools? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Sarah Ohanesian and Jeff Gibbard, co-founders of Super Productive, about the systems, communication habits and workplace dynamics that determine whether people can perform at their best. Sarah and Jeff explain why productivity depends on meaningful progress rather than constant activity. They share practical strategies for capturing tasks, prioritising important work, automating repetitive processes and removing the everyday friction that slows organisations down. The conversation also explores the workplace “hero” who repeatedly steps in to save the day. While that behaviour can appear valuable, it may prevent effective delegation, documentation and repeatable processes from developing. Sarah and Jeff discuss how recognition, identity and job security can influence these behaviours and why psychological safety is essential for addressing them. The episode examines neurodiversity at work, including why labels often fail to explain what an individual actually needs. Jeff describes how personal user guides can help employees communicate their preferences, working styles and potential sources of misunderstanding without being placed into a fixed category. In this episode: \* Productivity versus busyness \* Focusing on the work that matters \* Automating repetitive processes \* Removing friction from teams \* The workplace hero problem \* Delegation and psychological safety \* Neurodiversity and neurodivergence \* Personal user guides for employees \* Improving communication between different working styles \* Productivity in pharma and biotechnology \* AI agents and the future of work \* Social engineering in healthcare \* AI-powered phishing attacks \* Cybersecurity in an AI-driven world Learn more about Sarah Ohanesian, Jeff Gibbard and Super Productive at: https://getsuperproductive.com/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/how-different-brains-build-better-teams-with-sarah-ohanesian-and-jeff-gibbard-ep-lT7fwbpCdZ0)

[YouTube ](https://www.youtube.com/watch?v=lT7fwbpCdZ0&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/How%20Different%20Brains%20Build%20Better%20Teams%20with%20Sarah%20Ohanesian%20and%20Jeff%20Gibbard%20%7C%20Ep%2078%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=How%20Different%20Brains%20Build%20Better%20Teams%20with%20Sarah%20Ohanesian%20and%20Jeff%20Gibbard%20%7C%20Ep%2078%20Med%20Device%20Cyber%20Podcast)

[

![Episode 77 thumbnail, Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77](https://i.ytimg.com/vi/aKI9uMxr1Jg/maxresdefault.jpg)

EP 077

Jul 16, 2026

### Could a Hacker Change What a Patient Sees? with Frederik Ceyssens | Ep 77

Could a brain implant allow someone who is completely blind to see again? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Frederik Ceyssens, CEO and co-founder of ReVision Implant, about a visual prosthesis that connects camera-equipped glasses to electrodes implanted within the visual cortex. Rather than attempting to repair the eyes or optic nerve, ReVision Implant aims to stimulate the brain directly. Frederik explains how the technology could allow patients to perceive shapes, identify where people are standing, read large letters and navigate their surroundings more independently. The discussion also examines the cybersecurity risks of connecting external technology to an implant inside the brain. Could an attacker change the algorithm, interfere with what the patient sees or increase the stimulation to dangerous levels? How do manufacturers secure an implant expected to remain inside a patient for 15 years or longer? Frederik also shares what his team learned through long-term animal studies, why patients may need months of rehabilitation, and how recent funding will support the first stages of human testing. In this episode: \* 00:38 Frederik’s background in neural implant research \* 02:31 Why ReVision Implant targets the visual cortex instead of the eye \* 04:26 Developing flexible brain electrodes through long-term testing \* 06:48 Raising €4 million to advance the technology \* 07:42 Preparing for the first proof of concept with a human volunteer \* 09:24 How the glasses and brain implant work together \* 11:04 What vision through the implant may look like \* 12:33 Why colour and depth perception remain difficult \* 16:16 The cybersecurity implications of a visual prosthesis \* 17:43 How an attacker could manipulate the device \* 20:25 The hardest parts of developing neurotechnology \* 22:42 How the implant was tested using monkeys \* 26:12 Designing an implant that can last 15 to 25 years \* 28:28 Why today’s encryption may not remain secure for decades \* 30:16 Why replacing the implant would require months of rehabilitation \* 34:51 How close the technology is to science fiction \* 36:07 The next steps towards testing with blind volunteers Find Frederik Ceyssens on Linkedin: https://www.linkedin.com/in/frederikceyssens/ Find ReVision Implant at: https://revisionimplant.com The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/could-a-hacker-change-what-a-patient-sees-with-frederik-ceyssens-ep-77-aKI9uMxr1Jg)

[YouTube ](https://www.youtube.com/watch?v=aKI9uMxr1Jg&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Could%20a%20Hacker%20Change%20What%20a%20Patient%20Sees%3F%20with%20Frederik%20Ceyssens%20%7C%20Ep%2077%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Could%20a%20Hacker%20Change%20What%20a%20Patient%20Sees%3F%20with%20Frederik%20Ceyssens%20%7C%20Ep%2077%20Med%20Device%20Cyber%20Podcast)

[

![Episode 76 thumbnail, Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris](https://i.ytimg.com/vi/MfaIJOiUluI/maxresdefault.jpg)

EP 076

Jul 10, 2026

### Why Most MedTech Startups Wait Too Long for Cybersecurity with Helen Souris

What happens when a medical technology company raises $93 million... only to discover it isn't compliant with regulators? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), about one of the biggest challenges facing digital health companies today: building products that are commercially successful, clinically valuable and compliant from the very beginning. Helen explains why cybersecurity has become a requirement in customer procurement, why software as a medical device continues to confuse founders, and why quality management systems, regulatory strategy and cybersecurity must all be considered before products reach the market. The discussion also covers fundraising, choosing the right investors, digital therapeutics, AI in healthcare, wearables, cybersecurity awareness and practical examples that help founders understand when their product becomes a regulated medical device. In This Episode: 00:57 Helen's journey from pharma to digital therapeutics 04:33 The realities of raising MedTech investment in Australia 09:06 Why choosing the right investor matters 13:22 Why many digital health startups misunderstand regulation 15:21 Why cybersecurity comes up in every customer conversation 16:15 Why founders still leave cybersecurity until the end 16:53 Building regulation, quality and cybersecurity from Day One 18:31 The $93 million company forced to pull its product 21:09 Explaining medical devices through the user journey 22:50 The stadium hacking analogy that changes perspectives 25:13 Why wearables need a medical lens 26:57 The fake Wi-Fi demonstration everyone should remember 28:20 Why rebuilding is always more expensive than building properly 29:30 Christian's biggest takeaways Find Helen Souris here on LinkedIn: https://www.linkedin.com/in/helen-souris/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/why-most-medtech-startups-wait-too-long-for-cybersecurity-with-helen-souris-MfaIJOiUluI)

[YouTube ](https://www.youtube.com/watch?v=MfaIJOiUluI&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Why%20Most%20MedTech%20Startups%20Wait%20Too%20Long%20for%20Cybersecurity%20with%20Helen%20Souris%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Why%20Most%20MedTech%20Startups%20Wait%20Too%20Long%20for%20Cybersecurity%20with%20Helen%20Souris%20Med%20Device%20Cyber%20Podcast)

[

![Episode 75 thumbnail, Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug](https://i.ytimg.com/vi/QJ11o5HJt-8/maxresdefault.jpg)

EP 075

Jun 25, 2026

### Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug

Cybersecurity is no longer just an IT problem. It's a business resilience challenge. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Melissa Aarskaug to discuss what the medical device industry can learn from one of the world's most heavily regulated sectors: casino gaming. Melissa shares why attackers focus on pressure rather than weaknesses, how regulated industries are adapting to evolving cyber threats, and why organisations must shift their thinking from preventing attacks to maintaining operations when attacks inevitably happen. The conversation explores cyber resilience, leadership, AI, regulatory expectations, penetration testing, cyber insurance, and the growing role cybersecurity plays in overall business strategy. Christian also explains how medical device cybersecurity has evolved from a standalone requirement into an integral part of product quality. In This Episode: 00:00 Introduction 01:09 Lessons from protecting the gaming industry 01:58 Why attackers target regulated industries 05:22 Cybersecurity is about pressure, not industries 06:07 Compliance versus cyber resilience 08:08 Medical devices and connected ecosystems 12:29 The famous fish tank cyberattack 15:03 FDA expectations versus hospital expectations 16:04 AI, cyber maturity and the future of security 17:25 Four priorities every leader should focus on 21:24 Why penetration tests often fail to create change 24:38 Designing cybersecurity into products from the beginning 26:48 Why cyber insurance isn't a silver bullet 32:21 Why cybersecurity is now part of medical device quality 33:26 Cybersecurity is moving beyond IT and into the boardroom 37:42 Final thoughts and key takeaways Find Melissa Aarskaug here on LinkedIn: https://www.linkedin.com/in/melissa-aarskaug/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub\_confirmation=1



](/episodes/cybersecurity-isnt-an-it-problem-anymore-with-melissa-aarskaug-QJ11o5HJt-8)

[YouTube ](https://www.youtube.com/watch?v=QJ11o5HJt-8&list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[Spotify ](https://open.spotify.com/search/Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)[Apple ](https://podcasts.apple.com/us/search?term=Cybersecurity%20Isn't%20an%20IT%20Problem%20Anymore%20with%20Melissa%20Aarskaug%20Med%20Device%20Cyber%20Podcast)

Show 9 more episodes

Showing 9 of 83

Produced by [Blue Goat Cyber](https://bluegoatcyber.com) — medical device cybersecurity consulting.

About the Show

## Where MedTech meets the  
adversary mindset.

Brought to you by [Blue Goat Cyber](https://bluegoatcyber.com), The Med Device Cyber Podcast unpacks the regulations, attacks, and engineering decisions shaping the future of connected medical devices.

From premarket submissions to postmarket vulnerability response, built for product security teams, regulatory leads, and the engineers in the trenches.

[

Medical Device Penetration Testing

Full-scope pentests across hardware, firmware, BLE/RF, mobile, APIs & cloud - delivered as an FDA-ready report.

Pen Testing Service

](https://bluegoatcyber.com/services/medical-device-penetration-testing)[

FDA Premarket Full-Service

Every artifact, test, and standard for your 510(k), De Novo, or PMA cybersecurity submission.

Premarket Service

](https://bluegoatcyber.com/services/fda-premarket-cybersecurity-services)[

FDA Postmarket Support

Section 524B monitoring, vulnerability response, and SBOM upkeep for cleared devices.

Postmarket Service

](https://bluegoatcyber.com/services/fda-postmarket-cybersecurity-services)[

FDA Deficiency Response

24-hour diagnosis and reviewer-ready remediation for FDA cybersecurity deficiency letters.

Deficiency Response

](https://bluegoatcyber.com/services/fda-cybersecurity-deficiency-response)

Browse Episodes by Topic

### Jump straight to what matters for your role.

[

FDA Premarket Cybersecurity

Episodes on premarket cybersecurity submissions, the FDA Refuse to Accept policy, and what the agency actually expects in 510(k), De Novo, and PMA filings.

](/topics/fda-premarket)[

FDA Postmarket Cybersecurity

Coordinated vulnerability disclosure, patching legacy devices, and meeting FDA's postmarket cybersecurity expectations after launch.

](/topics/fda-postmarket)[

SBOM Management

Software Bills of Materials for medical devices: generation, monitoring, and using SBOMs as a continuous security tool, not a checkbox.

](/topics/sbom)[

Threat Modeling

STRIDE, attack trees, and risk-driven threat models that satisfy ISO 14971, IEC 62304, and FDA reviewers.

](/topics/threat-modeling)[

Penetration Testing

Device, network, wireless, and protocol penetration testing for medical devices - what to scope, who to trust, and how to report it.

](/topics/penetration-testing)

Meet the Host

## Practitioner, not pundit.

Every episode is hosted by an operator who does this work daily, leading FDA submissions, threat modeling sessions, and pen tests for real medical device manufacturers.

![Headshot of Christian Espinosa, Founder & CEO, Blue Goat Cyber](/assets/host-christian-T2WBrxkF.jpg)

### [Christian Espinosa](/hosts/christian-espinosa)

Founder & CEO, Blue Goat Cyber

[LinkedIn](https://www.linkedin.com/in/christianespinosa/)

U.S. Air Force veteran with decades of cybersecurity experience across defense, critical infrastructure, and MedTech. Founded Blue Goat Cyber in 2022 to help manufacturers build security in from the start and move through FDA review with confidence.

FDA Premarket Cybersecurity Threat Modeling Risk Management 

[View profile](/hosts/christian-espinosa)

Be a Guest

## Have a story worth sharing?

We're always looking for medical device cybersecurity practitioners, regulatory leaders, and security researchers with a sharp point of view. Pitch us below.

### What makes a great guest

-   01 
    
    Hands-on experience
    
    You've personally led FDA cybersecurity submissions, run threat models, or shipped secure connected devices - not just talked about them.
    
-   02 
    
    A specific story to tell
    
    A real submission, audit finding, vulnerability disclosure, or engineering decision - not a generic overview of your company.
    
-   03 
    
    Practical takeaways
    
    Listeners walk away with something they can apply Monday morning: a framework, checklist, lesson learned, or pitfall to avoid.
    
-   04 
    
    Comfortable being candid
    
    Willing to share what didn't work, where the regulations are unclear, and how the field is actually evolving - vendor-neutral perspective preferred.
    

We record remotely on Riverside and typically schedule 4 - 6 weeks out. Sessions run about 45 minutes, are professionally produced (never live), and release as a long-form episode on Apple, Spotify, and YouTube plus three social shorts. We do not accept paid placements or vendor pitches.

Full name\* 

Email\* 

Company

Role / title

Proposed topic\* 

Be specific - e.g. "Threat modeling a Class II infusion pump for FDA premarket"

Why this story, why you?\* 

0/2000 characters

LinkedIn URL

Website (optional)

I'm happy for Blue Goat Cyber to contact me about this pitch and to store the information I've submitted for review.

Submit pitch

Frequently Asked

## MedTech cybersecurity, answered.

Quick answers to the questions we hear most from product security, regulatory, and engineering teams.

### What is medical device cybersecurity?

### What does the FDA require for premarket cybersecurity submissions?

### What is an SBOM and why does the FDA require one?

### How is threat modeling different from a risk assessment?

### Who should listen to The Med Device Cyber Podcast?

### How often are new episodes released?

### What is the FDA 524B eSTAR template?

### What is the difference between 510(k), De Novo, and PMA cybersecurity expectations?

### Do I need penetration testing for my FDA submission?

### What standards apply to medical device cybersecurity?

### What is a Secure Product Development Framework (SPDF)?

### How does postmarket cybersecurity management work?

### What is coordinated vulnerability disclosure (CVD)?

### How does AI/ML change medical device cybersecurity?

### What is IEC 62304 and how does it relate to cybersecurity?

### Can guests come on the show?

### Where can I get help applying what I hear on the podcast?

Listen Anywhere

## Pick your platform.

New episodes drop weekly. Subscribe to never miss the next deep dive.

[

YouTube

Watch full episodes

Open →

](https://www.youtube.com/playlist?list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)[

Spotify

Stream anywhere

Open →

](https://open.spotify.com/search/Med%20Device%20Cyber%20Podcast)[

Apple Podcasts

Subscribe in Apple

Open →

](https://podcasts.apple.com/us/search?term=Med%20Device%20Cyber%20Podcast)

## Site footer and sitemap

The Med Device Cyber Podcast

Frontline conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOMs, threat modeling, and penetration testing - hosted by [Blue Goat Cyber](https://bluegoatcyber.com).

[Browse all episodes](/episodes)[Pitch as a guest](/be-a-guest)

Subscribe

[RSS](https://mdcpodcast.com/rss.xml)[Apple Podcasts](https://podcasts.apple.com/us/search?term=Med%20Device%20Cyber%20Podcast)[Spotify](https://open.spotify.com/search/Med%20Device%20Cyber%20Podcast)[YouTube](https://www.youtube.com/playlist?list=PLWQj_E9ypCcTB1m-s4920VYxm1xNHraBW)

### Topics

-   [FDA Premarket](/topics/fda-premarket)
-   [FDA Postmarket](/topics/fda-postmarket)
-   [SBOM](/topics/sbom)
-   [Threat Modeling](/topics/threat-modeling)
-   [Pen Testing](/topics/penetration-testing)

### The Show

-   [All Episodes](/episodes)
-   [Hosts](/hosts)
-   [Christian Espinosa](/hosts/christian-espinosa)
-   [All Guests](/guests)
-   [About the Podcast](/about)
-   [Be a Guest](/be-a-guest)
-   [Search Episodes](/search)

### Blue Goat Cyber Services

-   [Medical Device Penetration Testing](https://bluegoatcyber.com/services/medical-device-penetration-testing)
-   [FDA Premarket Cybersecurity (Full-Service)](https://bluegoatcyber.com/services/fda-premarket-cybersecurity-services)
-   [FDA Postmarket Cybersecurity Support](https://bluegoatcyber.com/services/fda-postmarket-cybersecurity-services)
-   [FDA Cybersecurity Deficiency Response](https://bluegoatcyber.com/services/fda-cybersecurity-deficiency-response)
-   [Schedule a discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)
-   [info@bluegoatcyber.com](mailto:info@bluegoatcyber.com)

Episode Archive

-   [2026 Episodes (31)](/search/year/2026)
-   [2025 Episodes (46)](/search/year/2025)
-   [2024 Episodes (6)](/search/year/2024)
-   [FDA Premarket - 2026](/search/topic/fda-premarket/year/2026)
-   [FDA Postmarket - 2026](/search/topic/fda-postmarket/year/2026)
-   [SBOM - 2026](/search/topic/sbom/year/2026)
-   [Threat Modeling - 2026](/search/topic/threat-modeling/year/2026)

© 2026 [Blue Goat Cyber](https://bluegoatcyber.com). All rights reserved. [Privacy](https://bluegoatcyber.com/privacy-policy/)[Terms](https://bluegoatcyber.com/terms-of-service/)