The Med Device Cyber Podcast

Blue Goat Cyber

In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology. This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.

  1. 5d ago

    The 7 Biggest Misconceptions About Medical Device Cybersecurity | Ep 86

    Medical device cybersecurity is still surrounded by some persistent misconceptions. In this solo episode, Christian Espinosa breaks down seven of the most common misunderstandings he continues to hear across MedTech, from what actually makes a device “cyber” to why cybersecurity cannot be treated as a final-stage compliance task. He also explains why medical device cybersecurity is fundamentally different from traditional IT security, and why getting these basics wrong can create problems long before a product reaches the market. In this episode: 00:07 What actually makes a medical device “cyber”? 02:12 Why medical device cybersecurity is about patient safety 05:21 Why cybersecurity cannot be a point-in-time exercise 06:27 Exploitability versus probability 08:30 Why pre-market clearance is not the finish line 10:43 Why software developers are not cybersecurity experts 11:47 Why traditional cybersecurity is different from medical device cybersecurity The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more about Blue Goat Cyber: https://bluegoatcyber.com Schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    The 7 Biggest Misconceptions About Medical Device Cybersecurity | Ep 86
  2. Sep 24

    Building Cyber Resilience Into Medical Devices with Joe Saunders | Ep 85

    What if a medical device could prevent an attacker from exploiting a vulnerability, even before a patch becomes available? Joe Saunders, CEO and co-founder of RunSafe Security, joins Christian Espinosa to explore a different approach to protecting the software inside medical devices and other critical infrastructure. Joe goes through how RunSafe's technology changes the way software functions load into memory, making certain exploits ineffective without introducing the performance demands typically associated with additional security software. But the implications extend beyond stopping an attack. For medical device manufacturers, vulnerability management can create significant development, testing, and regulatory challenges. Could preventing exploitation at runtime also reduce the burden of patching and help companies get products to market faster? The conversation explores the economics of cybersecurity, the threat of compromised software updates, and why increasingly capable attackers are forcing manufacturers to rethink how they protect devices already deployed in the field. In This Episode: 02:44 Protecting critical infrastructure and medical devices 05:25 Why traditional runtime security creates challenges 07:25 How RunSafe protects software without a running agent 11:05 Understanding memory-based exploits 20:59 The cost of constant patching and recertification 25:54 Reducing exploitation risk from 12,000 potential gadgets to zero 28:16 Cybersecurity and faster medical device approvals 30:45 Threats to critical infrastructure 36:24 The danger of compromised medical device updates 38:43 Why AI is accelerating the cybersecurity challenge 40:10 Building security into software from the beginning Connect on Linkedin with Joe Saunders: https://www.linkedin.com/in/joesaunders/ Learn more about RunSafe Security: https://runsafesecurity.com The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com . If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Building Cyber Resilience Into Medical Devices with Joe Saunders | Ep 85
  3. Sep 11

    Can We Detect Skin Cancer Without a Biopsy? with Stefan Mazy | Ep 84

    What if the biggest problem in skin cancer diagnosis is not finding suspicious lesions, but what happens after we find them? Stefan Mazy joins Christian Espinosa to discuss the personal experience that led him to explore a different approach to skin cancer testing after his mother underwent extensive surgery for an aggressive basal cell carcinoma. Stefan explains how his team is developing a microneedle patch designed to collect cellular tissue without a traditional surgical biopsy, and why he believes the current diagnostic pathway is struggling to scale as skin cancer awareness and testing increase. The conversation also explores the role of AI in identifying suspicious lesions, the trade-off between sensitivity and specificity, and why detecting more abnormalities could increase pressure on an already strained clinical pathway. Christian and Stefan also discuss cybersecurity in medical technology, manufacturing risks, brain-computer interfaces and why connected devices require founders to think beyond the device itself. In This Episode: * 03:33 Stefan’s mother’s skin cancer diagnosis * 08:14 Why he began searching for an alternative to biopsy * 10:08 The scale of unnecessary skin biopsies * 12:37 How the microneedle patch works * 15:13 Why uncertainty creates a diagnostic bottleneck * 23:44 Can AI reliably identify skin cancer? * 28:07 The problem with false positives * 31:50 Cybersecurity, brain-computer interfaces and future risk * 35:20 Stefan’s key takeaway on technology and healthcare Check out Stefan Mazy and DermaR here: https://www.linkedin.com/in/stefanmazy/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Can We Detect Skin Cancer Without a Biopsy? with Stefan Mazy | Ep 84
  4. Aug 27

    The Commercialization Gaps MedTech Founders Keep Missing with Ryan Roghaar | Ep 83

    Why can a MedTech company have promising technology, a strong team and investor interest, yet still lose momentum when it matters most? Ryan Roghaar joins Christian Espinosa to examine the commercialization gaps that can quietly weaken a medical device company long before the technology itself becomes the problem. Ryan explains why companies often move through fundraising, regulatory strategy, sales and market entry in the wrong sequence, and why inconsistencies between a pitch deck, website, evidence and buyer messaging can immediately create doubt. The conversation explores what happens when claims outpace evidence, why MedTech companies struggle to define exactly who they are selling to, and how cybersecurity and AI are adding entirely new layers of risk to commercialization. In This Episode:07:43 Why Ryan moved into MedTech 10:32 Moving from marketing agency to MedTech consultancy 11:32 Why devices fail outside the technology itself 12:41 Does MedTech commercialization follow a sequence? 16:08 The evidence gap inside MedTech companies 17:10 How investors pressure-test startups 19:55 When a company tells four different stories 23:36 Can cybersecurity become a commercial differentiator? 24:11 Why medical device hacking feels different 27:24 Cybersecurity risks from MRIs to brain implants 32:21 The three biggest commercialization gaps Ryan is seeing 35:57 Why unclear buyers dilute your message 39:08 The pressure to take the wrong customer 42:47 Ryan’s three key takeaways for MedTech companies Check out Ryan Roghaar’s LinkedIn here: https://www.linkedin.com/in/ryanroghaar/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1*

    The Commercialization Gaps MedTech Founders Keep Missing with Ryan Roghaar | Ep 83
  5. Aug 20

    Why the Best MedTech Candidates Aren’t Applying to Your Jobs with Darwin Shurig | Ep 82

    What happens when AI starts screening job candidates who are also using AI to get through the screening process? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Darwin Shurig, founder of Top Talent Accelerant, about why recruiting in MedTech is becoming increasingly difficult and what companies can do to avoid costly hiring mistakes. Darwin explores why traditional “post and pray” recruitment is breaking down, how strong candidates can be screened out while weaker candidates use AI to get through the process, and why some highly specialized roles in AI, machine learning and cybersecurity are remaining open for months. The conversation also looks at the enormous cost of getting talent decisions wrong, why the best candidates often are not actively applying for jobs, and how showing candidates the real culture and expectations of a company can help create better alignment before an interview ever takes place. Darwin also shares the personal journey behind his book, The Modern-Day Job, and how major changes in his business and personal life led him to reconsider success, purpose and the importance of the people we choose to work with. In This Episode:01:13 Darwin’s journey from critical care to MedTech recruiting 04:38 Why recruiting has become such a crowded industry 06:55 The cost of getting the hiring process wrong 09:00 How AI is changing candidate screening 10:11 Why specialized MedTech roles can stay open for months 11:26 Why traditional hiring processes need to change 12:31 Creating a better candidate experience 13:48 The $9 billion impact associated with warning letters 14:49 Why the best candidates are not applying to your job posts 15:53 When AI starts interviewing AI 16:45 Remote hiring, geography and compensation 18:58 The story behind The Modern-Day Job 36:51 Why values and alignment matter when choosing people 40:33 Building teams around shared values and culture Check out Darwin Shurig’s LinkedIn here: https://www.linkedin.com/in/darwin-shurig The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Why the Best MedTech Candidates Aren’t Applying to Your Jobs with Darwin Shurig | Ep 82
  6. Aug 13

    The Hidden Barriers to Clinical Adoption with Amel Havkic | Ep 81

    Why do so many promising MedTech companies fail even when the technology is strong, the funding is there and the product is compliant? In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Amel Havkic, founder of EvoMed Consulting, about the hidden barriers that prevent medical technologies from achieving real clinical adoption. Amel explains why clinical adoption is often treated too late, how workflow friction can derail an otherwise strong product and why the founder’s greatest strength can sometimes become the company’s biggest strategic blind spot. The conversation also explores the KOL trap, the cost of forcing behavior change inside already overstretched clinical environments and why cybersecurity, reimbursement, usability and implementation cannot be treated as separate problems. In This Episode 01:08 Amel Havkic and VivoMed Consulting02:41 Why 75% of MedTech companies fail04:43 Clinical adoption, fundability and founder blind spots07:23 Why one solution must satisfy many stakeholders09:42 Economic viability and implementation friction12:37 The hidden cost of changing clinical behaviour15:43 The KOL trap and why pilots can mislead18:46 Alarm fatigue and real-world clinical environments20:46 Christian’s introduction to medical-device cybersecurity23:04 Why cybersecurity deficiencies derail submissions27:49 Building the right team around a MedTech founder32:38 Authenticity, intuition and choosing the right partners37:17 Why being human may become a superpower in the age of AI Check out Amel Havkic’s LinkedIn here. The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    The Hidden Barriers to Clinical Adoption with Amel Havkic | Ep 81
  7. Aug 6

    Why Consumer AI Is Not a Medical Device with Tyler Harmon | Ep 80

    AI is moving quickly, but medical devices cannot afford to treat every new model like an ordinary software update. In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Tyler Harmon, CEO and co-founder of IASO Automated Medical Systems, about the risks and responsibilities surrounding AI as a medical device. Tyler explains why consumer tools such as ChatGPT and Claude should not be treated as clinical diagnostic systems, even when a doctor remains involved in the final decision. He also explores why a human in the loop does not automatically make an AI system safe when the underlying model was never designed or cleared for that medical use. The conversation examines how predetermined change control plans can support safer AI updates, why developers must understand the difference between frontier models and AI harnesses, and what can go wrong when a medical-device company builds on top of a third-party model. In This Episode 00:48 Tyler Harmon and IASO Automated Medical Systems03:34 What qualifies as AI as a medical device?04:44 Predetermined change control plans06:08 When should an AI medical device be updated?09:00 Why medical AI is not new11:32 Why medical AI still needs human oversight17:40 Doctors using ChatGPT to interpret X-rays20:09 Frontier models and AI harnesses24:16 The challenge of developing proprietary AI29:21 Why medical AI can take years to reach the market34:28 Using consumer LLMs outside their intended licence39:25 Licensing third-party AI for medical-device use40:41 Final lessons for medical-AI developers Check out Tyler Harmon’s LinkedIn here: https://www.linkedin.com/in/tyler-h-938bbb43/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Why Consumer AI Is Not a Medical Device with Tyler Harmon | Ep 80
  8. Jul 30

    Why Technical Intelligence Is Not Enough with Samantha Silk | Ep 79

    A strong résumé may get someone an interview, but technical ability alone does not determine whether they will succeed within an organization. In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Samantha Silk, CEO of Apex Pro Placement, about recruitment, emotional intelligence, and the challenge of identifying the right people for highly technical roles. Samantha explains why an unfilled critical position can cost an organization thousands of dollars every day, when using a specialist recruiter makes financial sense, and why job descriptions often fail to reflect what the company actually needs. She discusses the importance of listening to hiring managers, setting realistic expectations and evaluating candidates beyond the qualifications listed on paper. The conversation explores why highly intelligent professionals sometimes struggle to explain complex ideas, how poor communication can limit careers and why emotional intelligence plays such an important role in leadership, investment and team performance. Christian and Samantha examine gut instinct in hiring, the risks of overriding warning signs, the growing volume of AI-generated recruitment noise and why human judgment remains essential when someone’s livelihood or a company’s future is at stake. In This Episode 00:57 Samantha’s path from cybersecurity recruiting to life sciences04:07 When using an external recruiter makes sense05:39 How an open critical role can cost up to $5,000 per day09:41 Why effective hiring starts with listening to the client11:57 Why most job descriptions fail to describe the real role13:34 Emotional intelligence in recruitment and leadership18:53 Why technical experts must communicate in simple language21:24 Investor pressure and unethical recruitment practices26:25 Using intuition and gut instinct when hiring32:03 How constant screen use affects attention and connection37:22 AI-generated résumés, recruitment noise and human oversight39:58 What rock climbing teaches us about trust in cybersecurity42:36 Final lessons on communication, EQ and technical careers45:04 Christian’s vision for AI agents running a company46:41 Why social engineering succeeds against hospitals47:20 How AI is making phishing more personalized48:21 Why AI is changing every part of business49:25 Final lessons on curiosity, assumptions and friction Check out Samantha Silk’s LinkedIn here - https://www.linkedin.com/in/samanthawein/ The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com. If you’re interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session Christian Espinosa is the CEO and founder of Blue Goat Cyber. Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/ Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/ Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/ Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/ Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1

    Why Technical Intelligence Is Not Enough with Samantha Silk | Ep 79

Ratings & Reviews

5
out of 5
2 Ratings

About

In a time where healthcare and technology are deeply intertwined, understanding medical device cybersecurity is not just important—it's essential. Welcome to The Med Device Cyber Podcast, your go-to resource for understanding the complexities of this critical field of cyber security. As the definitive podcast on medical device security, we explore everything from identifying and mitigating vulnerabilities to navigating this ever-evolving regulatory landscape. Hosted by Christian Espinosa, Founder & CEO of Blue Goat Cyber, and Trevor Slattery, Director of Medical Device Cybersecurity, each episode features expert insights into the latest cybersecurity threats, innovative solutions, and best practices for protecting the medical devices that are at the heart of modern healthcare. Whether you're a healthcare provider, a device manufacturer, a cybersecurity professional, or just someone looking to learn about the importance of cybersecurity in human lives, this podcast empowers you with the knowledge and tools to ensure patient safety and secure the future of medical technology. This podcast is brought to you by Blue Goat Cyber, specializing in providing elite cybersecurity solutions.