The Med Device Cyber Podcast

Blue Goat Cyber

In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology. This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.

  1. -6 j

    From Science Fiction to Visual Prosthesis with Frederik Ceyssens | Ep. 77

    What if a blind person could use a pair of glasses where information is transmitted wirelessly to an implant in the visual cortex, allowing them to perceive shapes, movement, and elements of their surroundings? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Frederik Ceyssens, CEO and co-founder of ReVision Implant, about the development of a visual prosthesis designed to restore useful vision by stimulating the brain directly. Frederik explores why his team chose to bypass the eyes and optic nerve, how flexible electrode arrays can stimulate thousands of points within the visual cortex, and what researchers have learned through long-term animal studies. The conversation also explores the cybersecurity risks surrounding neurotechnology. An attacker could potentially interfere with wireless communication, alter the device’s algorithm, or increase stimulation to unsafe levels. The implant may also remain inside a patient for decades, creating difficult questions about encryption, software updates, and technologies that may become obsolete during the device’s lifetime. In This Episode: 00:38 Frederik’s background in neural implant research02:31 Why ReVision Implant targets the visual cortex instead of the eye04:26 Developing flexible brain electrodes through long-term testing06:48 Raising €4 million to advance the technology07:42 Preparing for the first proof of concept with a human volunteer09:24 How the glasses and brain implant work together11:04 What vision through the implant may look like12:33 Why colour and depth perception remain difficult16:16 The cybersecurity implications of a visual prosthesis17:43 How an attacker could manipulate the device20:25 The hardest parts of developing neurotechnology22:42 How the implant was tested using monkeys26:12 Designing an implant that can last 15 to 25 years28:28 Why today’s encryption may not remain secure for decades30:16 Why replacing the implant would require months of rehabilitation34:51 How close the technology is to science fiction36:07 The next steps towards testing with blind volunteers Find Frederik Ceyssens on Linkedin: https://www.linkedin.com/in/frederikceyssens/ Find ReVision Implant at: https://revisionimplant.com The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    From Science Fiction to Visual Prosthesis with Frederik Ceyssens | Ep. 77
  2. 10 juil.

    Building Medical Devices Right the First Time with Helen Souris | Ep 76

    Bringing an innovative medical device to market takes far more than a great idea. It requires regulatory strategy, cybersecurity, quality systems, and commercial planning from the very beginning. In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), to discuss why so many promising digital health companies struggle when they leave the startup phase and enter the realities of regulation. Helen shares her experience leading a digital therapeutics company, raising investment in Australia, navigating software as a medical device regulations and helping startups avoid costly mistakes that can delay or even derail commercial success. The conversation explores why cybersecurity is becoming a deciding factor in procurement, how founders should think about regulatory strategy before writing a single line of code, why quality management systems cannot be bolted on later, and the real-world consequences of ignoring compliance until it's too late. Whether you're building a medical device, digital therapeutic, AI healthcare platform or connected medical technology, this episode offers practical advice for creating products that are secure, compliant and built to scale. In This Episode: 00:57 Helen's journey from pharma to digital therapeutics04:33 The realities of raising MedTech investment in Australia09:06 Why choosing the right investor matters13:22 Why many digital health startups misunderstand regulation15:21 Why cybersecurity comes up in every customer conversation16:15 Why founders still leave cybersecurity until the end16:53 Building regulation, quality and cybersecurity from Day One18:31 The $93 million company forced to pull its product21:09 Explaining medical devices through the user journey22:50 The stadium hacking analogy that changes perspectives25:13 Why wearables need a medical lens26:57 The fake Wi-Fi demonstration everyone should remember28:20 Why rebuilding is always more expensive than building properly29:30 Christian's biggest takeaways Find Helen Souris here on LinkedIn: https://www.linkedin.com/in/helen-souris/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/

    Building Medical Devices Right the First Time with Helen Souris | Ep 76
  3. 25 juin

    What MedTech Can Learn from the Casino Industry with Melissa Aarskaug | Ep 75

    For years, cybersecurity has been viewed as an IT responsibility. Today's threat landscape demands something very different. In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Melissa Aarskaug, a cybersecurity executive with extensive experience protecting highly regulated industries, including banking and casino gaming. Melissa shares lessons from an industry where operations run 24 hours a day, every day of the year, and where even a few minutes of downtime can have enormous financial consequences. The conversation explores why attackers increasingly target regulated industries, how cyber resilience differs from compliance, and why cybersecurity has evolved into a leadership issue rather than simply an IT function. Melissa explains why organisations should focus less on preventing every possible attack and more on ensuring the business can continue operating when incidents occur. Christian and Melissa also discuss how medical device manufacturers can learn from the gaming industry's approach to resilience, the growing role of AI in both cyber defence and cybercrime, why cybersecurity should be integrated into quality management systems, and how leadership teams can better prioritise cyber risk across their organisations. Whether you're a MedTech founder, cybersecurity professional, healthcare leader, or product developer, this episode offers practical insights into building more resilient organisations in an increasingly connected world. Episode Breakdown 00:00 Introduction01:09 Lessons from protecting the gaming industry01:58 Why attackers target regulated industries05:22 Cybersecurity is about pressure, not industries06:07 Compliance versus cyber resilience08:08 Medical devices and connected ecosystems12:29 The famous fish tank cyberattack15:03 FDA expectations versus hospital expectations16:04 AI, cyber maturity and the future of security17:25 Four priorities every leader should focus on21:24 Why penetration tests often fail to create change24:38 FDA compliance and designing security from the beginning26:48 Cyber insurance isn't a silver bullet32:21 Cybersecurity is becoming part of quality33:26 Why cybersecurity is moving beyond IT37:42 Final thoughts and key takeaways Find Melissa Aarskaug here on LinkedIn: https://www.linkedin.com/in/melissa-aarskaug/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    What MedTech Can Learn from the Casino Industry with Melissa Aarskaug | Ep 75
  4. 18 juin

    The Future of Cardio-Oncology Wearables with Ryan Neely | Ep 74

    Cancer treatment is already difficult enough without adding more hospital visits, more testing, and more delays. Yet many cancer therapies carry a significant risk of damaging the heart, forcing patients to undergo regular cardiac screening throughout their treatment journey. What if clinicians could monitor cardiac function with a simple wearable patch instead? In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with Ryan Neely, co-founder and CEO of Skribe Medical. Ryan shares his journey from neuroscience research and implantable neuroprosthetics to building a company focused on improving cardiac monitoring for cancer patients. The discussion explores the growing field of cardio-oncology and the challenges patients face when cancer treatment depends on frequent cardiac assessments. Ryan explains how Skribe Medical's wearable monitoring platform aims to reduce treatment delays while improving patient convenience through a battery-free, AI-powered patch designed to measure cardiac function. The conversation also takes a deep dive into cybersecurity considerations for connected medical devices. Ryan and Christian discuss common misconceptions about cybersecurity risk, why hospital networks often present greater challenges than home environments, and how device manufacturers should think about security as products evolve from standalone systems to connected healthcare technologies. Finally, the episode explores commercialization, reimbursement models, FDA engagement, and the reality that regulatory clearance is often just one milestone in a much longer journey toward successful adoption. Whether you're a MedTech founder, healthcare innovator, cybersecurity professional, or clinician, this episode offers valuable insights into the intersection of patient care, connected devices, and healthcare innovation. Episode Breakdown 00:00 – Introduction01:53 – The hidden cardiac risks of cancer treatments02:58 – Skribe Medical's wearable cardiac monitoring platform03:53 – Future applications beyond oncology04:45 – Battery-free device design and patient comfort06:00 – Remote patient monitoring and reimbursement models09:40 – Cybersecurity risks for connected medical devices14:06 – Why hospital networks present unique security challenges16:02 – FDA cybersecurity expectations and evolving regulations19:03 – Regulatory changes and long MedTech development cycles21:02 – Commercialization versus FDA approval24:13 – AI models and the Predetermined Change Control Plan25:55 – The realities of clinical testing and device validation28:14 – Final takeaways and lessons learned Find Ryan Neely here on LinkedIn: https://www.linkedin.com/in/ryan-neely-ph-d-14464340/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    The Future of Cardio-Oncology Wearables with Ryan Neely | Ep 74
  5. 4 juin

    Navigating U.S. Market Entry for MedTech Developers with JJ Amell | Ep 73

    When you develop a groundbreaking medical device, you assume the engineering and clinical data will carry you across the finish line. The legal landscape of U.S. market entry involves layers of corporate traps that most innovators completely overlook. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with JJ Amell, the founder of Amell Law, to unpack the complex realities of international corporate structuring, business immigration, and intellectual property protection. JJ shares his unique transition from building computers and working within his father's cardiology practice to guiding international medical technology firms through federal bureaucracy. The trio explores why setting up a basic LLC through automated online legal platforms leaves multi-million dollar startups exposed to catastrophic liability. They break down the tactical timing of securing O-1 founder visas and investor visas before state borders close behind you, and analyze the shifting corporate battleground between Delaware and Texas for control over majority shareholder decisions. The specifics may differ, but the challenge is the same: protecting what you've built. This conversation covers everything from Customs and Border Protection issues to defending service marks against public database scrapers. Episode Breakdown: 00:00 - Intro00:54 - Welcoming MedTech attorney JJ Amell03:38 - Solving legal pain points for global innovators06:11 - The three pillars of U.S. market entry08:33 - The inverse market challenge: Moving from Europe to the U.S.10:43 - Factoring in fiscal repercussions and international tax consultations12:57 - State jurisdictions: Delaware standards vs Texas corporate law16:21 - California red tape and the rise of alternative technology hubs22:41 - Reverse engineering corporate strategy to avoid late-stage corrections25:44 - The danger of automated penetration tests and interactive FDA reviews29:39 - Deportation risks and B-1/B-2 tourist visa limitations31:24 - Government bureaucracy timelines and USPTO trademark processing realities33:04 - Public database scraping and the explosion of corporate filing scams37:37 - AI voice cloning and deepfake vulnerabilities targeting tech executives40:52 - Code Blue Chart: Documented cybersecurity fatalities in healthcare44:25 - Closing thoughts and reconnecting with nature Find JJ Amell here on LinkedIn: https://www.linkedin.com/in/jjamellesq/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Navigating U.S. Market Entry for MedTech Developers with JJ Amell | Ep 73
  6. 28 mai

    The Psychology of Medical Device Security Awareness with Shahbaz Ahmed | Ep 72

    When you try to communicate cybersecurity risks to medical device manufacturers, do you feel like you are speaking ancient Hieroglyphics? You are not alone. In this episode of the Med Device Cyber Podcast, Christian and Trevor sit down with Shahbaz Ahmed, the Founder and CEO of Leadership Studi. Together, they explore the intersection of human psychology, cross-cultural leadership styles, and the massive awareness deficit currently facing global medical device cybersecurity. Shahbaz shares his unique framework on human engineering, detailing how the emotional depth of Eastern leadership can bridge with the logic-driven framework of the West to build stronger, international tech organizations. The trio explores why cybersecurity professionals struggle to make hospital buyers and developers care about vulnerabilities, why simple, human-centric messaging trumps complex technical jargon every single time, and whether you are a technical specialist looking to scale into broad leadership or an executive trying to keep patient devices secure across global borders. Episode Breakdown: 00:00 - Intro02:14 - Leadership styles: Eastern emotion vs Western logic05:07 - Human engineering and the science of emotional psychology08:31 - Capacity vs capability: breaking down our emotional fuses12:28 - Technical leadership vs broad vision leadership14:29 - The Ex Machina color theory analogy for cultural exposure19:10 - Hungry judges and decision fatigue: how state affects choice24:43 - How increasing capability expands human cognitive capacity26:35 - The shocking lack of medical device cybersecurity awareness globally31:12 - Why regulatory updates are outpacing downstream hospital practice35:27 - Breaking down big words to make security simple38:00 - Key takeaways: consistency as the ultimate weapon for success Find Shabaz Ahmed here on LinkedIn: https://www.linkedin.com/in/shahbaz-ahmed-4004ab86/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    The Psychology of Medical Device Security Awareness with Shahbaz Ahmed | Ep 72
  7. 21 mai

    The Age of Digital Health Humanity with Philippe Gerwill | Ep 71

    Philippe Gerwill manages to be a board advisor for nearly 30 companies without losing his humanity. In this episode of the Med Device Cyber Podcast, Christian Espinosa sits down with the world-renowned futurist to discuss why “unlearning” is the most vital skill for today’s healthcare leaders. They explore the shift from traditional medicine to consumer-led health and why patients are flocking to ChatGPT regardless of what their doctors think! Philippe explains how he maintains a presence on close to 30 company boards while using a massive AI ecosystem to scale his impact. This conversation is a reminder that the human piece is actually the only thing that matters in the end. Episode Breakdown: 00:00 The concept of unlearning as a vital skill for healthcare leaders.01:52 Philippe’s background at Novartis and transition into healthcare technology.03:35 Managing advisory roles for nearly 30 companies using an AI ecosystem.04:50 The Favikon ranking and maintaining a 96.5 percent authenticity score.07:49 Defining the role of a futurist in the modern era.09:21 The intersection of technology and gut feeling.18:15 Patient behavior: why consumers are driving the shift to AI in clinics.32:10 The mandate to use our brain and the risks of over-relying on tools. The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    The Age of Digital Health Humanity with Philippe Gerwill | Ep 71
  8. 14 mai

    Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co | Ep 70

    Medical software is still underestimated by teams that think generic engineering habits will carry over cleanly into a regulated environment. They do not. The work gets harder when requirements, traceability, security, testing discipline, and approval timelines all collide. A stronger strategy starts earlier, uses specialists sooner, and avoids making AI or code velocity the headline when architectural quality and compliance readiness are what determine whether a product can truly ship. Episode Breakdown 00:01 Opening 08:02 When to bring in partners 10:48 Cybersecurity as a timing issue 12:24 AI pressure and code quality 27:07 Documentation discipline 36:26 Why specialist review matters 38:33 Final reflections The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Trevor Slattery is the Chief Operating Officer at Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Trevor Slattery on LinkedIn: https://www.linkedin.com/in/trevor-slattery-34852b1a9 Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

À propos

In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology. This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.