Medical Device Quality, Regulatory and Product Development Blog | Greenlight Guru

Cost Containment: Right-Sizing Medical Device Cybersecurity with Chris Gates

Written by Etienne Nichols | September 7, 2026

Medical device cybersecurity is no longer an optional feature or a last-minute checkbox prior to market entry. Hosted by Etienne Nichols, this episode features Chris Gates, founder and CEO of arsMedSecurity, who delivers a practical, engineering-first perspective on embedding security directly into the development lifecycle. Gates highlights that deferring cybersecurity efforts until the end of development leads to severe financial penalties, extended regulatory delays, and potential company failure.

The discussion demystifies common misconceptions held by executive teams and "bean counters," such as the myth that off-network devices or small companies are exempt from cyber threats. Under current FDA expectations and the eStar submission process, any medical device containing software is subject to stringent pre-market cybersecurity requirements. Gates illustrates how unexpected 180-day regulatory holds impact a company's daily burn rate, showing that proactive security measures are far cheaper than reactive fixes.

Looking ahead, the conversation explores the evolving threat landscape driven by Large Language Models (LLMs) and advanced exploits that reduce vulnerability exploitation windows from years to minutes. Gates provides concrete steps for medical device manufacturers to take control of their product security, emphasizing early threat modeling, continuous risk management, and the alignment of software development SOPs with recognized international standards.

Watch the Video:

Listen now:

Love this episode? Leave a review on iTunes!

Have suggestions or topics you’d like to hear about? Email us at podcast@greenlight.guru.

Key Timestamps

  • 00:31 - Introduction to medical device cybersecurity: "Pay now or pay more later."
  • 01:42 - Overview of Medical Device Cybersecurity for Engineers and Manufacturers (2nd Edition).
  • 02:37 - Why security must be led from an engineering-first perspective.
  • 03:47 - Right-sizing cybersecurity for medical device startups vs. enterprise budgets.
  • 05:45 - Debunking common executive and bean-counter cybersecurity myths.
  • 09:12 - Calculating the true cost of an FDA 180-day delay against your daily burn rate.
  • 11:30 - Clarifying Food, Drug, and Cosmetic Act Section 524B and FDA cyber device definitions.
  • 14:20 - Aligning secure software development lifecycle (SDLC) processes with ISO/IEC 81001-5-1.
  • 16:45 - Evaluating code-fix cost multipliers: Catching vulnerabilities in design vs. post-market.
  • 18:20 - Hidden financial costs: Stock devaluation, cost of capital, and brand damage.
  • 20:10 - The impact of LLMs on zero-day exploit velocity and vulnerability chaining.
  • 23:15 - Required eStar cybersecurity artifacts and lifecycle mapping.
  • 25:00 - Case Study: How ignoring cybersecurity ruined a cardiac ablation system startup.
  • 28:30 - Practical first steps: Cybersecurity risk management plans and STRIDE threat modeling.

Top takeaways from this episode

  • Calculate Delay Impact via Burn Rate: Evaluate cybersecurity risk against your organization's daily burn rate multiplied by a potential 180-day FDA submission delay to understand the true financial cost of non-compliance.
  • Software Triggers Cyber Requirements: Do not assume a device is exempt from cybersecurity requirements because it lacks active internet connectivity; any device running software falls under FDA pre-market expectations.
  • Perform Threat Modeling Before Hardware Freeze: Execute system-level threat modeling (e.g., STRIDE methodology) during the initial design phase before finalizing active hardware components and component selections.
  • Adopt Recognized SDLC Standards: Establish standard operating procedures (SOPs) that map secure development activities directly to ISO/IEC 81001-5-1 and ISO 62304 frameworks.

References:

  • Medical Device Cybersecurity for Engineers and Manufacturers (2nd Edition): Practical reference handbook authored by Chris Gates detailing implementation techniques for device developers.
  • ISO/IEC 81001-5-1: Health software and health IT systems safety, effectiveness, and security standard for secure development lifecycles.
  • STRIDE Threat Model: A system decomposition methodology developed by Microsoft to identify data-in-motion and data-at-rest security threats per system element.
  • Host LinkedIn Profile: Connect with Etienne Nichols on LinkedIn

MedTech 101 Section

Software Bill of Materials (SBOM)

An SBOM is similar to an ingredient list printed on a food wrapper, but for software. Instead of listing flour and sugar, it lists every third-party code library, open-source module, and software component embedded inside a medical device. If a security weakness is discovered in one specific software "ingredient," the manufacturer can instantly check their SBOM to see if their device is affected.

STRIDE Threat Modeling

STRIDE is a structured blueprinting method engineers use to uncover weak points in a medical device before building it. Think of it like examining every door, window, and pipe in a house to see how a burglar might break in. STRIDE evaluates six specific threat categories:

  • Spoofing (pretending to be someone else),

  • Tampering (altering data),

  • Repudiation (denying an action occurred),

  • Information Disclosure (exposing private data),

  • Denial of Service (crashing the device), and

  • Elevation of Privilege (gaining unauthorized control).

Memorable quotes from this episode

"It's not just secure by design; it's secured by design is cheaper than waiting to the end and finding out and getting those questions from the FDA." Christopher Gates

"If the gating item for the FDA is if your device has software in it. Period. Do you have software? ... software only." Christopher Gates

Feedback Call-to-Action

 We want to hear from you! What challenges have you faced when balancing user feedback against clinical and regulatory requirements? Send your thoughts, topic suggestions, or questions to podcast@greenlight.guru. Every email goes directly to our team, and we personally review listener notes for future episodes.

Sponsors

This episode is brought to you by Greenlight Guru.

Navigating the transition from an early-stage hardware concept to an FDA-cleared device requires rigorous quality control and clinical data management. Greenlight Guru provides purpose-built Quality Management System (QMS)Christopher Gates: and Electronic Data Capture (EDC) solutions designed specifically for medical device companies. Whether you are conducting initial user research, executing DFM, or preparing regulatory submissions, Greenlight Guru helps you bring safe, life-changing devices to market faster. Learn more at greenlight.guru.

 

Transcript

Etienne Nichols: Hey everyone, welcome back to the Global Medical Device Podcast. My name is Etienne Nichols. I'm the host for today's episode. Today we're gonna be talking a little bit about cybersecurity. And we've talked kicked and kicked around the idea of calling this medical device cybersecurity pay now or pay more later, security by design, savings by default. we're gonna get into a little bit of you know how you can actually do this effectively and efficiently.

Those are two different things and something that my guest today, Chris Gates, can help you do with both. So, he's the founder and CEO of arsMedSecurity, a consultancy he built to build help medical device manufacturers put real cybersecurity into practice, not just another checkbox as you're building your medical device. Chris has spent 20 years as an embedded security architect and senior software engineer at Illuminati Engineering before moving into device specific security leadership.

That includes eight years at Velentium, first as principal system security architect, then as director of product security. He's also spent a few months at Analytics as director of cybersecurity before starting at arsMedSecurity or arsMedSecurity in 2025. He's also the author of the handbook on cybersecurity. And I don't have the title in front of me. I can't believe I did this, Chris, do you wanna…

Christopher Gates: Tell me about medical device, cybersecurity for engineers and manufacturers. Now in the second edition. Now in the second edition.

Etienne Nichols: I think I think the first interview I ever did with you is when it had just come out, possibly. So yeah anyway, yeah.

Christopher Gates: It it's been extremely successful. And in fact, let me just move the slide forward off the title slide here and you can see a picture of the book.

Etienne Nichols: Yeah, and I'll just throw this out there for those listening. Now we do have slides. If you want to pause this and go get on YouTube and watch the video, you'll be able to see some good slides, good graphs that Chris has. If you're not able to do that and you can only hear the audio, we're gonna do our best to walk through the slides.

So just a reminder to myself as we go through this. one thing I want to throw out because I'm gonna let Chris take it away with his background, but one thing I like about Chris's approach is he and his team come at security from the engineering side first. They're development engineers who happen to be security and experts.

So, they speak the same language as the engineers they work with and build security in from the start. So, Chris, welcome to the show. Glad you're here.

Christopher Gates: Can I get you to join my organization as my marketing VP? That's fantastic. I the only thing that's not on there is I've worked on probably hundreds of medical device development over the decades. I was an engineer. And so, as a result of that, I've worked with many, many different manufacturers, both as employee and as a consultant.

And it has been a long and fun journey. So, I always kind of it's humorous when I go into these things because people know me of cybersecurity. And it's like I was coding medical, you know, Class III devices, life support devices before you were born. So don't try to explain to me what you're doing. Okay.

Etienne Nichols: It's amazing to meet. So, we did a webinar for Greenlight Guru not too long ago. If you're interested, we'll put a link to that in the show notes so you can see Chris's presentation there as well. everybody seems to know him. In the comments, it's just blown up with people who've worked with him, who knew him and the attendees. I think we had eighteen hundred people registered to that that webinar. So, it's very popular topic wise or Chris wise, I'm not sure. But yeah, let's

I know you have some things you want to talk about. What actually do you wanna mention a little bit more about your background or you what d where you wanna go from here?

Christopher Gates: No, let's just let's dive into it here. I mean, yes, you've pretty much covered my entire background. I've been doing this forever. I created this company, arsMedSecurity, to assist manufacturers with reaching the marketplace. And these days it is much more challenging than ever. And what we're talking about here today is a topic that you don't hear from other cybersecurity vendors.

For the simple reason they don't want to address the fact of how much they're costing you. All right. We pull down a lot of money. All right. And one of the things that has bothered me is back previously when I was working for companies and didn't have control over such things, I was forced to give presentations to startups where they're a two-person startup and I'm quoting hundreds of thousands of dollars in cybersecurity. Why?

Because the bean counters won't let me right size this for people. And it's like, I know they don't have the money. I'm wasting my time. I'm wasting their time. So, as an engineer, that to me just does not work. All right. It has to be right sized. And especially these days, what with grants being pulled, what with the economy being in tatters, all of this needs to be allowed for. All of these projects. And I'm frequently here, here I am as a medical device developer.

I get to work with these companies and see their new products and I'm frequently amazed by what they're creating. It's not just the next pulse oximeter. This is cut cutting edge stuff that people are working on. And implantables, exterior devices, neurostems, those kind of things that are just it's astounding what they're working on and what they're achieving and improving patients' quality of life. So, for me, this is more than a business. It's a calling. It always has been. I mean, decades ago I could have, you know, gone to Lockheed and made the latest landmine or something, or the latest fighter plane, or but that's not what I do. I want to be able to know that I left this world and helped people while I was here. And to that end, arsMedSecurity is all about that. How do I get security into every manufacturer's hands, not just the people who want to drop hundreds of thousands of dollars on me? So that's what we're talking about here today.

And that's it's for you. It's for the rest of you. And you come in all shapes and sizes.

First off, the cheapest fix is the early one. Okay. Do not wait. And if you're scared of cybersecurity, you think, we don't know what to do with this. We've been putting it off. I've heard this so many times over the years. Do not do that. That's the worst thing you can do. It impacts your product, your schedule, your budget, the quality of your product, the quality of the cybersecurity, even your regulatory approval, all of this gets impacted negatively. Don't do that. Get in early. Find out what it is.

Bring people like me. And I've brought in clients where like, well, we're just getting started. Perfect. Well, we won't have anything for you. And I understand. Yeah, you'll be back to me in nine months, 18 months, whatever. Fine. Okay. But we're going to get you started right. And then that speeds up everything you need to do and keeps your cost down. This is so important. It's not just secure by design. It's secured by design is cheaper than waiting to the end and finding out and getting those questions from the FDA. And that's what we're going through here today.

So, what you're going to hear back from the bean counters that you work for as a medical device manufacturer is you know, we don't connect to the internet, so we don't need cybersecurity. I'm gonna touch on that a few times here. We've never had a breach, so the risks feel theoretical. We are a small company, we can't afford cybersecurity, or who would attack us? I love that one. That's also a good one. We are submitting to the FDA next Tuesday. We don't have time for cybersecurity. yes, you do. You just don't need don't know it yet. Wait till they come back to you here.

Our safety risk is low, so we don't need cybersecurity. Wrong. We'll handle it in the next release. Wrong. There's not going to be a next release. that's an engineering problem, not a business one. And I've had CEOs tell me, I know my engineering team. They did everything secure initially. Really? Show me an artifact. Show me proof of that. Well, they just do. Uh-huh. Never it is. Okay.

You can't rely upon your engineers. Your engineers have got enough problems as it is trying to make this device. They can't keep up on all of this changing environment for cybersecurity and know how to do this. They need guidance, they need some helping hand here to get them so they can include this as part of their daily activities. we just need to paper over the cybersecurity topics. A huge number of clients come in and think, I'm just gonna create paper for them or PDFs.

And that's it. That's all you need to do for cybersecurity. No, it is not. Things actually change. You can have huge impacts on the structure, the implementation, the topology, the nature of the hardware. I've got one right now that onboarded last week that they came through, and their microcontroller would not work at all for this. So, we work through it, and it's right now a change to the bombs, the bill of materials. That's it. Okay.

But it enables them in the future here as they go forward to then support cybersecurity going forward. Our engineering team always creates: so, we started this project years ago and we didn't need cybersecurity then. Yep, I just finished up one that started 14 years ago. And trust me, everything's out of date. Doesn't matter when you started. I've had some people think that the two 2023 date when the FDA started actively enforcement.

Is actually some sort of get out of jail free time that if it's before 2023, yeah, you started it then, so you don't need to do anything. No, uh-uh, nope, not at all. And in fact, even before 2023, the FDA was getting real pedantic about how to enforce cybersecurity. It's just that that became really official on October 1st, 2023. But their refuse to accept decision doesn't ask for a fix. And it's not even a refuse to accept anymore.

eSTAR itself self-filters. If you can't fill out eStar, that's the refuse to accept because you don't have all the deliverables that eStar is looking for. So, this is the law. It's not a future suggestion. One of the things to take away from this is what is your daily burn rate? And what does that delay cost you? Do you know what it costs you every day of operation? Most of the startups I talk to do. They're counting every penny and they want to know.

So, if all of a sudden, they think they're going to get away with something, and I say, okay, so the FDA comes back and comes back with some cybersecurity questions for you, can you handle that 180-day delay that you're going to get with your existing burn rate? It's an easy calculation. Your burn rate times 180. Can you do that? Or are you going to be gone? These are the things that matter. even though it's a 180-day period.

I've yet to see anybody get back inside of 179 days. everybody I don't know why. I actually had a few years ago one come to me, and it was on a Thursday, and they had this and I says, Great, how much time, you know, we got how much of the hundred and eighty days left? Do I have like a hundred, and seventy days left to dance this and go, no, it ends next Tuesday. On Thursday. Why do you…

Etienne Nichols: Yeah, why? Yeah, the weekend.

Christopher Gates: I and that's exactly right. I did it did consume the weekend, and we got back and we fixed everything. Fortunately, they didn't have major problems. So, I got everything squared away and it all worked. But yeah, don't do that. So, scheduling your risk against your own launch date. You know, you need to if you don't make that launch date, what then? And then you have to look at what this is gonna cost you here. All right.

Control your costs before the venture capitalists and the private equity controls them for you. I'm not a big fan of bean counters. I've written articles on bean counters and cybersecurity, especially private equity. VC can be pretty good at times. It depends on the VC. Private equity is never good. They are always a bad influence and a bad outcome on you guys. So, make certain you control them. They don't control you up front.

So, you set expectations with your cybersecurity of what it's going to cost for what you intend to do. And again, it all gets back to your burn rate. If any of the following are true, you're not deciding whether to start. You're already falling behind. Okay. You're designing software components with known exploited vulnerabilities, or worse, you don't know because you've never really looked and you've just designed in a bunch of components.

And you have no idea whether it's on what's called the Kev catalog, known exploitable vulnerabilities. The Kev catalog is automatically scanned. The FDA will do it for you. Okay. You don't want that. You don't want them to be the first one to do that. It's stuff you actually have to put in your submission to eStar, where you call out everything that's known from known vulnerabilities to known exploited vulnerabilities. Those are two different things and how you're dealing with them.

You are counting on not being a cyber device. Food and Drug Cosmetic Act, Section 524B. This is the one where Congress gave HHS and thus the FDA the power to define and enforce medical device cybersecurity. And then they called out a couple other things like, you should have a risk management program, and you should have a software bill of materials. And those don't mean anything.

Because you remember that part about, they gave the FDA the capability to define what cybersecurity is? And that's what they've done. So, there is this narrow definition of three different terms that includes communications to the internet that make you a cyber device. You can ignore that completely. Okay. Take the whole concept of 524B out of your mind with the exception that that's the law that empowers the FDA to do what they're going to do to you for cybersecurity.

The authority, the Bible you should go is 524B. It is the latest pre-market cybersecurity guidance document from the FDA. Really the pre-market and the post-market, but it hasn't changed since 2016. So, the pre-market, the latest version, is February of this year. and there was one last year as well. They're pretty good about changing every one to two years and updating it as they go forward.

They don't talk about cyber device in there. you want to get your device approved in the United States, just ignore cyber device. If the gating item for the FDA is if your device has software in it. Period. Period. Do you have software? Not and communicates to the internet and has Bluetooth low energy and has cellular baseband. Nope, nope, nope. Software only.

All right. So, unless you're a block of wood, most likely your medical device has software in it somewhere and it's going to be applicable to all of these requirements. You need to look at this. If you don't have all these submissions created during your development lifecycle, it's a horrible hit on you. And like I said, it can affect your design. It can back you up where you think you are in development. you've already selected your hardware elements and your coding for them. Mistake. Okay. You need to do threat modeling before you ever get to actually selecting your active elements inside of your device. But you're coding, but you haven't created an SOP to address the secure development lifecycle. They the FDA wants to see that you have an SOP that aligns with industry standards.

There is really two, only one that was created for medical device software. And that's ISO IEC 8100015. It's fine. It looks just like 62304, which everybody should know. ISO 62304 has all the same activities, and it just tells you what cybersecurity work needs to go into which bin of those active of those different phases, what ISO calls activities. So yeah.

You need to be able to go through and have an SOP to do that and then develop to that and show the fact that you, you know, created artifacts in line with that development process. Not, I did it over the last year and now what? We don't have that SOP. We didn't work to it. So, you're already in violation. Your project's on a strict timeline but tight oversight from the investors PE. Set your expectations here.

There's going to be fees and costs associated with this. So how do we manage those fees? How do we get it down, so the bean counters are happy? Yeah, it's going to align up with the timelines that you need it to hit. If you don't do this stuff, the next time you deal with the FDA, it will not be pleasant.

We don't really have studies that talk about what this delays cost. I wish we did. Nobody likes to expose this kind of data. But a few years back, some studies were done by IBM that talked about fixing any kind of a mistake in code, not just vulnerabilities for cybersecurity, but any kind of code and how delaying it in your development increases the cost to fix it. And this is certainly true for cybersecurity.

Of course, the f worst case being at testing, you're catching it at 15 times. But for us, maybe it's not there. Maybe it's already in submission. So, it's going to be higher than 15 times. It's going to be a higher multiple of that. All right. This is bad. And it should it even get out, then you're talking about things like recalls. And there you go into the millions of dollars to do this. Very expensive. Okay. delays do not make these things cheaper.

Address them early. They are as inexpensive as you can make them, and you come up with a better product, and it's actually easier to do. Okay. None of this is in their security budget. It's the bill for delaying. But of course, you didn't budget for that either. Don't try to lie to the FDA. in 2025, the FDA turned over to the Department of Justice a $9 million settlement with Illumina for false claims about their cybersecurity. They lied to avoid.

Doing anything for cybersecurity and got caught, because you know, everybody does. at the very least, some disgruntled employee will let the FDA know. Okay. Just count on it. It always gets out. Nothing gets hidden. So that gets expensive real fast. Those are the kind of things that can actually cost you. Don't get into that. What does it cost after the fact when we're out in the field? Well, there's hidden costs in there too. Things like…

Etienne Nichols: I just want to throw out too sorry, sorry to interrupt, Chris. But I was just looking at your slides, and you have a graph and I want you guys to go back and look at this graph. I don't know if you actually said fifteen times more is the multiplier after you're on the market.

Christopher Gates: And if it's past testing and it's now right, that's caught in testing. If it's now in submission and the FDA comes back and goes, and how are you doing authentication here? You go, yeah. Well, guess what? It's more than 15. Yeah. Okay. There's just been no white paper I can find, no study that'll tell you what that is. Thirty times, twenty times? I don't know, but it's gonna be higher. And you're gonna have to reperform that testing too.

So, it's It it's really expensive, yeah. Hidden costs. You're out in the field. Go ahead. So initially I had the real names of the companies on these graphs. And then because I don't like lawyers, I decided not to leave those names on there. This is all public information, but nobody likes to have it pointed out. All right. These are all Fortune five hundred medical device companies. the red line where you see there is where they a vulnerability was disclosed as far as their device goes that was being actively exploited.

All right, and what it did to their stock. this can hit you for days and months of stock prices. This is amazing where graphs like this get the attention of boards. a board may be really vicious and not care what the impacts are to human health, but they really care about what happens to stock. Company value and stock prices, you want to get their attention? This does it.

One of the things that you never really think about is, of course, you know, stock devaluation, mergers, and acquisitions can fall apart or really be hindered. St. Jude a few years ago ran into this when Abbott acquired them. legal exposure, loss of your reputation. But here's one they never thought of. Yet I'll tell you the money people in your organization do, the cost of money. Your reputation isn't just it hinders sales, it's also when you go out to get a loan.

To fund the next development effort in your organization, you pay a percentage on this. Guess what? Your reputation affects that. The cost of money. It goes up when you do things like this. It makes it harder for you to grow in the future. Don't do these. These are hidden costs that nobody ever talks about, but boy, are they there.

And of course, you can't have anything these days where you don't talk about LLMs, large language models. AI changes everything, especially the speed and depth which everything goes to, whether you're using it to create software or using it in some aspect to help with cybersecurity. Trust me, the attackers are benefiting more from it. Some of the things that have occurred, and here's the really scary chart.

That you look at it here, more than the 15 times chart, is back in 2018 from vulnerability disclosure to exploitation was 2.3 years. Nice and comfortable. Okay. We could find it, we could identify it, we could go as manufacturers lovingly rub it with a diaper, figure out what the mitigation is for it. And then we can push that out and we could hand deliver it to all of our thousands of our devices.

Or widgets scattered all over the globe. Heck, we could run around with flash drives and do 'cause you got two point three…

Etienne Nichols: Right.

Christopher Gates: Well, things have changed and that number keeps coming down, but LLMs have really reduced it now to where it's now in minutes. This makes things like patching and updates for cybersecurity mitigations pretty much worthless. Should you still do patching and updates? Yes. But to do it as a form of a mitigation against an an active attack, there's no point. All right. They are just too fast.

So, what does this mean? Well, this had huge ramifications for where we're going and how we design and how we create it. Today, the FDA is not addressing this. Everybody's trying to plug their ears and cover their eyes and nope, don't want to hear it. Okay. Because the solutions are costly and expensive. It means the devices have to go out to the market in a secure state. Not just we've created certain processes and we're going to hit the low-hanging fruit and all of that.

Everything has to be secured. The largely celebrated here about a month ago when ChatGPT broke out of its containers and went over and attacked Hugging Face. In three days, it used 17,600 exploits. This isn't I'm fixing the low hanging fruit anymore. It's the L the LLMs are gonna use everything against you. Everything.

There's really no point in even trying to do vulnerability prioritization anymore. It's like they'll chain these things together and it'll find a way in. You have to use LLMs to find these vulnerabilities, and you have to shut down all of them. Not just the ones you want to today, or the ones you want to prioritize or the ones you budgeted for. No. So this is only gonna get worse. LLMs get better pretty much every month here.

By the time you write something on them, it's pretty much out of date. I gave some training for another foreign government here a few months back. And one of the things they wanted to know about was LLMs. And I talked about it as in regards to cybersecurity. And when I got done, I said, and by next month, all of this will be completely out of date. So, there you are. Enjoy it while it lasts. and then once we get quantum computers, well, you think it's bad now. this stuff is going to be insanely quick.

This is going to bring computations that at least take hundreds of milliseconds now, will take nothing. Okay. They'll be down in the single-digit microseconds that things will be accomplished, and security mitigations will be defeated. So today the FDA is still working to yesterday's war. They're still using yesterday's processes and deliverables because things like this are slow to change. But the FDA folks, especially in the DMDC cybersecurity division, of the FDA, they're smart folks.

They know what they're doing. This will change; this will change with it. Get ready because you think it's a lot to do now. Wait till you see what's coming. So, design your devices for this as you go forward and understand this stuff is just insane. So, looking at what eStar needs today, these are all the artifacts that eStar needs today. Remember, you have software, you need to create all of those.

And of course, there's work behind all of those. Those aren't just documents. And those documents can affect how your implementation goes, how your hardware works, how your system is, the topology is laid out. I've put pretty colored bubbles around them to show what life cycle phases and development these need to be created in. If you create them in those lifecycle phases, it doesn't really slow anything down too much. It pretty much goes through, and the costs are kept low, and your development moves along at the expected pace.

If you have to wait till the end and go back and do all this stuff, it's going to be wildly invasive to when you think you're going to submit or reach market and how your budgets are going to play out. The best thing you can do is start doing this stuff as you're going through each of these life phases and start working on them. If you don't know how to do it, get somebody who does. What's the downside to ignoring this?

There's a company that's in Carlsbad, California, called Acutis. Great name, right? I have the distinct feeling somebody there was a fan of Star Trek and like like the Borg or something, because you know, Locutus was Picard's name. Acutus sounds. But anyway, here a few years ago, they were working on a cardiac ablation system. back in the day when I created medical equipment, I worked on one as well. Not as pretty as this, though.

This looked like a really nice cardiac ablation system. This is a device that goes into your femoral artery, goes up into your heart while it's beating, and then expands out. That's that weird little balloon thing you see there. And those are all sensors and it maps the electrical flow through the inside of your heart as your heart beats. And if you have something like AFib, cardiac arrhythmias, it can find the inappropriate flow of electricity in the heart muscle. And then the tip in the front there goes to that point and cauterizes it.

And puts high-resistive areas in your heart muscle so the heart beats correctly. Great for patients who are quality of life, huge difference, as opposed to not having any energy, can't get up, can't move, can't run. You can now be a normal human being. So, this company was doing it, looked like a really good system, and they completely ignored cybersecurity. I should point out, by the way, since I do live by my NDAs.

I've never talked to these folks. They don't know me. I don't know them. I'd never signed an NDA with them. Their neighbor, on the other hand, I know quite well. And when they laid off all of their employees, they went over and told their neighbor exactly the backstory of what happened. So, they ignored cybersecurity. They went to market right after the FDA really started getting severe about enforcement of cybersecurity, October of 2023. Really bad timing.

Even six months earlier would have been better, but and they completely ignored it. And supposedly it was just under five hundred thousand in cybersecurity costs that was going to be incurred through a competitor of mine, not me. Again, I had no involvement. and I love this example because normally I'm encumbered by NDAs and I can't talk about bad things. I can talk all day long about these folks. And it's all public knowledge. So, all of this stuff came out.

And they've gone through at least two rounds now of layoffs. There might have been a third by now. They're down to, I think, staff, like in the single digits, just nobody's left. The patients who could have benefited from this device aren't going to get it. The employees who were working there aren't going to get their paycheck, and you know make Christmas for it. They all got laid off. Notice when they got laid off, November, right before Christmas, right? Always nice when companies lay you off right before Christmas. Really nice for the kids.

So, they're all off. The principals of the company didn't get to make their bonus and all the huge amount of money they were expecting to make from this thing. And it is that project is effectively dead. So, all of this, because the people who were managing this project didn't look into cybersecurity ahead of time. There is nothing about this device that couldn't be fixed and incorporated in if they had started early.

And just incorporated cybersecurity as they went forward. There's nothing magical about that box. I've done hundreds of devices like this, and you can secure them with no problem. But they didn't, they ignored it. Worst thing you can do, and it can destroy you and what your company is doing. So, what can you do now? I throw up all this fear, uncertainty, and doubt, all this FUD your way about all the bad things that can happen, and then show you it's not just hypothetical, it's real. These are real things and they can really happen to you.

What can you do now? Well, now create a cybersecurity risk management plan. Start that. It needs to be an E-Star. You need to start working on this and aligning to how you're going to be doing your development. If you don't have an SOP for secure framework development, make your risk management plan that SOP. All right. Cover all the things. Have an alignment with ISO 81000151. Call it all out there. It's preferable that you have the SOP and then the Cybersecurity Risk Management Plan goes down.

But that's fine. One of the things the FDA is looking for in the cybersecurity risk management plan, they tell you for each, by the way, each one of these documents, what needs to be in it. And some of the stuff you have them put to put in there is what you're going to do as a manufacturer for cybersecurity once you're approved and you're in the marketplace, post-market. What are all these activities? Ongoing testing, ongoing monitoring, ongoing patching and updating. All of this stuff needs to go on a periodic basis.

And you commit to it in that cybersecurity risk management plan. Do that now. That way, as you're developing it, at least you can start to create the artifacts that you're that that's going to det detail, and you can start putting that in and you lessen the cost and the pain. work on the interoperability threat model, or really what that is, is a system threat model. That's a way of using a technique called stride by element per element to go through and decompose your existing system.

And show where there are cybersecurity issues. Use a technique like Stride from Microsoft and go through your entire system. This goes all the way down to internal components. There's nothing magical about your enclosure on your medical device. Those of us who attack things can go inside of it. Okay. So inside of it, look at all of your data in motion and data at rest. Where are things being buffered? Where are they being communicated? And that's all included in your threat model.

That will tell you so much about your design and where security needs to be put. It is by far the most useful thing we create in cybersecurity, and the impacts on your implementation of your medical device all come out of that. It's just huge. So, this work all gets included in your documentation. So, you do it, it informs your development. It makes your development cheaper and faster. It also has to be done for the submission. So, it pays for itself twice.

From there on out, what are the rest of the stuff you have to do? I showed you that pretty colored list with the bubbles in it of all the activities or documents you need to create from activities. Your next step depends upon your funding, your team, and what development phase you're in. Obviously, you want to start early, but what if you're not? how competent is your team? Do you have enough people to do work in-house? Can we move this in-house? What is your funding? Are you a two-person startup and you want to bring stuff in-house as much as possible because you don't have the funding?

Do you have the funding? All of these change what the engagements look like. Most of my competitors will not deal with you as a startup. You don't have the money; they're not really interested in you. All right. I take a different perspective in that those people really need to be addressed as well. So, what do you look for in people like me, cybersecurity experts, decades of experience?

This doesn't happen because, gee, I thought this was great. There's a cybersecurity competitor of mine out there who brags about the fact that he was in a hospital a couple of years ago with some ailment and he was looking at these all these medical devices and thinking, what could go wrong? And that's why he got into cybersecurity. And I'm like, wow, that's it. That's the skills you bring to it. All right. No, you want engineers, okay? You want people who look at the design, understand what it means, understand the hardware, understand the software, understand the system levels. Okay.

Technical expertise and medical device engineering and not just IT, not just information technology, but operational technology, OT security. It's different. Okay? Can't beat that into you enough. If you think you're gonna go get somebody cheap and IT to do something, they ran Metasploit and it cost me $10,000. Great, you've wasted your time and your money. Okay? No, you need somebody who understands the regulation and OT cybersecurity.

Make certain your cybersecurity partner does not have venture capital, but a special especially no private equity. PE, they are bean counters who are there only to extract money. That means how they're going to treat you as not a person, not a partner. They're going to see you as just dollar signs and try to extract money from you. There is one organization that's a competitor of mine out right now that charges $80,000 a year for a subscription fee. So, you can talk to them.

Which is yeah, exactly. That's the look you should make. Good work if you can get it. I how many times do I work do work with Greenlight Guru and come through and say, Hey, if you've got questions and I'll do it again today, email me. I'll answer You know, if it's something…

Etienne Nichols: Yeah.

Christopher Gates: Took me like an hour and a half to write up, but it's like, no, that's ridiculous that you put those kinds of hurdles in front of organizations to do cybersecurity. Don't treat yourself, you know, with so much hubris that I'm so much better than you because I know this niche thing and you don't. Okay. No. Okay. The person you save might be yourself. Okay. I have a grandson who was saved, and this story's been on multiple podcasts. You may have heard it somewhere else.

But it was saved by instrumentation, that stuff I knew. When I walked into the NICU, I looked around and went, I know that one and that one and that one because I made it. Okay. The attending nurse says you can stay here. He's in the isolate. He's fine now, by the way. He's studying to be a doctor. So, he's in nursing right now. So, he's fine, but he, yeah, he had a pneumothorax, his lung hadn't sealed up. So yeah, you don't want somebody who's treating you as something to be harvested.

And that's what private equity does. So, ask about When you're looking for a partner, they shouldn't be offended. They should tell you where their money's coming from. Who controls it? Who sits on your board, right? the past history of an organization. There are some of my competitors sit out there that come from some interesting backgrounds. feel free to s do a search on medical device cybersecurity and muddy waters. you'll see what that is.

About 10 years ago, one of the companies sold short a stock and then manipulated that stock by releasing vulnerabilities for it. You saw those graphs of what that does to stock prices. So, if you release that adversary and hype, it all up, you can influence the stock. And they got caught with them. And I'm not calling out the name of the company, but it's out there and very public. It's since then that company's gone through a lot of changes, including in their management.

But does it ever really change the culture of that company? if your company is that kind of a vicious organization to begin with, I don't see it suddenly becoming Mother Teresa. you don't want a company to try to make their annual income on your project. And trust me, there are some folks who do that. The Locutus is a good example of that. I mean, good God, that's a lot of money. Okay. how dare they think that that was something they needed to do.

Find a way to make this work as a vendor. Find a way to work with your manufacturer that's going to work inside of it. Go to bat for them with the FDA. Okay. Find things that may not be the best practice. Maybe it can't be, but you're going to try to make it work anyway. OT cybersecurity, not just IT. Remember, that's really important. If they don't understand OT, in other words, the physicality of a cyber physical device, you're going to get worthless information out of them.

And of course, with anything you're looking for a partner, not a vendor, really important in cybersecurity, because there's so much give and take that you have to work with inside of there. One of the things I do with my company here and arsMedSecurity is we address the whole area of startups. And starting next month, Cybersecurity Awareness Month is next October, we're introducing a new service that will be low-cost, fixed fee, activities performed.

By your people on site, training of a sort, really leading them through with video training as to what's needed, how to achieve all of the activities by your people. There will be soft hours involved where I can assist you and work with you to help achieve that. But mostly this is your activity, and I'm showing you how to do it. I'm not sitting up in the high tower saying you need to bring me, you know, $400,000 or 80,000 a year to do something. No, this is how you do it.

And if we can use your people to do it, that's fantastic. But maybe you don't have the people to do it. Okay. Maybe they're already swamped. You they just you don't have it. You're a two-person startup and there's nobody there to do it. So not one size does not fit all. This is great because this works really well with the low end. We don't have a lot of money because it's by far lower than anything else you've heard about on here.

It's very affordable for startups. So, we structure it in three different ways. The startup is number one here that you already talked about. Okay. We give you your training and get you set up and get you enabled for success. Number two is your 510K submission package. We give you everything you need, a submission-ready docs for the FDA by working with you and we just do it all for you. And then number three.

Is the cybersecurity expert on staff? It's that expert engagement. been laughingly calling this the girlfriend experience, right? you want to be able to text that girlfriend, you want the girlfriend present in every meeting. This is your security team on call. that's what we're doing. We're helping you. If you need to have this and you don't know where it is, that's great. number one is, of course, the most cost effective, it really keeps the cost down.

One of the things we're offering here is since October is Cybersecurity Awareness Month, and in honor of rolling out this new number one approach, the thing, anybody that engages in any way, shape, or form with this also gets a free coordinated vulnerability disclosure SOP that will tailor to work inside of your quality management system, or more importantly, your electronic quality management system. How could that play a factor here at Greenlight? I don't know. So, but it's gonna custom tailor it and work with you. This is something you need to have.

if you don't know what SOPs you need, you need to talk to somebody like me or send me an email. Uh-huh.

Contact us at sales at arsMedSecurity, the lovely banner at the bottom, that's Cybersecurity Awareness Awareness Month, securing the next 250 years, I assume. That's not medical devices, but okay. and that's where we sit. So, if you guys have any questions, feel free to knock it out to me here. and obviously, if you need help with a project, also feel free to reach out to me here. We're here to help you. You know folks who are getting a startup.

And are ignoring cybersecurity, are feeling they're going to be in a bad shape for it. Give them my information, have them reach out to me and let me assuage their fears and show them how we can right size this for their startup and get their device out on the marketplace. And that's it.

Etienne Nichols: Awesome, Chris. Really appreciate you working to right size the industry in this regard. That was one of our goals when it came to right sizing people's QMS. And so, I we it's near and dear to the hearts of those of us at Greenlight Guru. So, I really appreciate what you're doing. And those of you listening, really appreciate you hanging in there listening to this. You know, Chris kind of takes my job over when it comes to when he comes on the podcast. And that's okay. The first podcast we ever did, I'd never done one before. And so, you know, maybe you know it's good.

Christopher Gates: It's I do a few of these and you know like the last one had problem technical problems and it's like so I'm fixing them in on the fly while we're going here, right? And it's like fixing the technical problems. It's like you live; you roll with it. yeah, you do with what's needed. So, I love gr working with Greenlight Guru and you guys have been good friends for me for well over a decade now. so really enjoy working with you guys.

Etienne Nichols: It's awesome. Well, always appreciate you coming on the web on the podcast. and those of you listening, we'll put links to the show notes to all these different things that he mentioned. So, keep an eye out for that. And if you were listening and you didn't get to see some of these graphs, some of them are mildly terrifying. You need to go over to YouTube and watch those graphs, shoot Chris an email. Which he will reply.

Christopher Gates: The ability to exploit should be more than mildly terrifying. Yeah. Should be I can't sleep, kind of terrifying. Okay.

Etienne Nichols: Thank you so much. I'm just gonna go ahead and stop it right there because I don't think there's anything else to add at this point. Thank you so much, Chris. Really appreciate it.

Christopher Gates: Thank you for having me.

Etienne Nichols: We'll talk to you all later. Take care.

Christopher Gates: Okay. Bye bye.

 

 

About the Global Medical Device Podcast:

The Global Medical Device Podcast powered by Greenlight Guru is where today's brightest minds in the medical device industry go to get their most useful and actionable insider knowledge, direct from some of the world's leading medical device experts and companies.

Like this episode? Subscribe today on iTunes or Spotify.