2122 - The Critical Role of Cybersecurity in Medical Devices with Blue Goat Cyber's Christian Espinosa

26 Mar 2025 路 18 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT 路 Add to Claude

In short

Podcast Summary: The Thoughtful Entrepreneur - Episode 2122

Episode Title

The Critical Role of Cybersecurity in Medical Devices with Blue Goat Cyber's Christian Espinosa

Episode Description

This episode centers on the critical importance of cybersecurity in medical devices, featuring Christian Espinosa, CEO of Blue Goat Cyber. The discussion emphasizes how modern healthcare technology, including surgical robots and implantable devices, is increasingly susceptible to cyber threats. Christian shares real-world examples, including a notable case involving former Vice President Dick Cheney's defibrillator vulnerability, underscoring the life-threatening potential of these cyber risks.

---

Key Themes and Insights

Cybersecurity's Growing Importance in Healthcare

  • Advanced Medical Technologies: The discussion highlights various medical devices that require robust cybersecurity, such as:
  • Surgical Robots
  • Implantable Devices (e.g., pacemakers)
  • Drug Infusion Pumps
  • Real-World Examples of Vulnerabilities:
  • Dick Cheney had his defibrillator's wireless feature disabled due to hacking fears.
  • Hacking into drug infusion pumps could lead to overdosing patients with critical medications.

Blue Goat Cyber's Role

  • Proactive Cybersecurity Integration: Blue Goat Cyber collaborates with both startups and established medical tech companies to embed cybersecurity measures early in device development.
  • Regulatory Compliance: Ensures that manufacturers meet necessary regulatory standards for patient safety and device integrity.

Christian's Personal Motivation

  • Christian Espinosa's personal health scare, involving deep vein thrombosis (DVT), has driven his passion for securing medical devices.
  • His experience emphasizes the real-life impact of cybersecurity vulnerabilities on patient safety.

Client Engagement and Resources

  • Client Support: Blue Goat Cyber assists clients from initial development through regulatory approval, offering services such as:
  • Threat modeling
  • Penetration testing
  • Documentation for compliance with regulatory standards (FDA, IEC, ISO).
  • Educational Resources: Offers white papers, podcasts, and webinars about FDA regulations and best practices in device security.

Industry Trends and Future Prospects

  • Increasing Cyber Threats: Christian emphasizes that as technology advances, the sophistication of cyber threats will also increase, underscoring the need for comprehensive cybersecurity measures.
  • Investment Considerations: Investors are increasingly scrutinizing startups for their cybersecurity plans, as neglecting this area could lead to significant financial repercussions.

---

About Christian Espinosa

  • Background: Founder and CEO of Blue Goat Cyber; recognized expert in medical device cybersecurity.
  • Publications: Author of "The Smartest Person in the Room" and "The In-Between: Life in the Micro."
  • Personal Interests: Adventurer with a passion for extreme sports and personal growth.

---

About Blue Goat Cyber

  • Services Offered:
  • Full-service medical device cybersecurity support throughout premarket and postmarket phases.
  • Compliance with FDA guidelines, IEC 62304, ISO 14971, and EU MDR/IVDR regulations.

Links Mentioned in the Episode

  • [Blue Goat Cyber Website](https://bluegoatcyber.com/)
  • [Blue Goat Cyber LinkedIn](https://www.linkedin.com/company/blue-goat-cyber/)
  • [Christian Espinosa LinkedIn](https://www.linkedin.com/in/christianespinosa/)

---

Conclusion This episode of The Thoughtful Entrepreneur sheds light on the critical intersection of cybersecurity and medical technology, advocating for proactive measures to secure life-saving devices. Christian Espinosa鈥檚 personal journey and professional expertise provide a compelling narrative on the importance of ensuring patient safety through rigorous cybersecurity practices.

Listeners are encouraged to engage with Blue Goat Cyber for insights and support tailored to their cybersecurity needs in the medtech space.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:05Hey there, thoughtful listener. Are you looking for introductions to partners, investors, influencers, influencers, influencers, and clients? Well, I've had private conversations with over 2 ,000 leaders asking them where their best business comes from. I've got a free video you can watch with no opt-in required where I'll share the exact steps necessary to be 100 % inbound in your industry over the next six to eight months with no spam, no ads, and no sales. What I teach has worked for me for over 15 years and has helped me create eight figures in revenue for my own companies. Just head to upmyinfluence.com and watch my free class on how to create endless high ticket sales appointments.

0:51Also, don't forget, the thoughtful entrepreneur is always looking for great guests. Go to upmyinfluence.com and click on podcast. I'd love to have you.

1:06With us right now, it's Christian Espinosa. Christian, you are the founder and CEO of Blue Goat Cyber. Your website is bluegoatcyber.com. You provide full-service medical device cybersecurity for pre-market submissions and post-market management. Well, I can't wait to learn what that's all about. Christian, thank you for joining us. Yeah, thanks so much for having me on, Josh. Yeah, well, give us an overview of your work. What is Blue Goat Cyber? Blue Goat Cyber is my second cybersecurity business. We focus on medical device cybersecurity. So this could be a surgical robot, an implantable like a pacemaker or neural stimulator or drug infusion pump.

1:48All these things need to be secure from a cybersecurity perspective. So we work with manufacturers to make sure these products are secure before they make it on the market and then after they're on the market as well. Okay, so I am not familiar with this world. Can you give a... Okay, so imagine it's career day, and you're speaking to, let's say, a crowd of eighth graders. So help us understand this world. Why do you need cybersecurity in some of these, which don't sound super technical, medical-type systems? Yeah, I'll give a couple examples. One of them is our former Vice President of the United States, Dick Cheney.

2:33He had an implantable defibrillator. We all know he had a lot of heart problems. And there was a legitimate risk where somebody could remotely connect to his defibrillator and shock him to death. So he had the wireless capability disabled from his defibrillator. so the threat is real also another common issue we had in the past which has been resolved is like with a drug infusion pump if you have a drug infusion pump it monitors the flow rate of a drug into your blood via the iv and if you're on a like something like morphine for pain and somebody hacks in that device and increases the flow rate of morphine to the maximum you could od a morphine it could kill you same thing with a surgical robot we're almost to the point now where we have surgical robots that are autonomous.

3:18So a robot is performing surgery on your spine, for instance, if somebody hacks into that, they could paralyze you. Oh my gosh. And you've got some, you've got some patents, uh, that, that you use, uh, and, uh, you're well published as well. Uh, have there been instances where something nefarious has happened? I mean, this sounds like the premise of a spy thriller. There have been instances. One of the biggest ransomware attacks affected a lot of the hospitals. And the problem with that is if I have a patient that arrives in an ambulance that had a heart attack and the intake is delayed at the hospital because all their systems are locked out, every second counts and patients have died in those scenarios.

4:09Oh, yeah. Well, that would be a case. Don't do ransomware on hospitals, you jerks. All right. So, Christian, tell me about, as a business, tell me about Blue Goat Cyber and how you work with clients. And, you know, I know that, you know, in the past you've done government contracting. You're a service-disabled veteran-owned small business. I am we were talking beforehand I'm in the application process for that right now. But do you mind maybe just talking about the business? Yeah, it's my second cybersecurity business. I built one in 2014 and sold it in 2020 to a publicly traded company. We did medical device cybersecurity with that company, but it wasn't my focus.

4:57Now, my focus is on medical device cybersecurity. When I worked for the parent company that I sold my previous company to, I developed six blood clots in my left leg and almost died. And thanks to a medical. Yeah. So you had a DVT? Yes. DVT, six of my veins. Yep. So DVT stands for, so I had a superficial, I had superficial vein thrombosis last year after a long flight to Vegas and back. Wow. Not, not fun. Very. So was yours superficial or deep? Deep. Yeah, it was, it was super painful. Can we do a quick, would you mind, Christian, before you explain the rest of your story, would you mind just doing a quick PSA?

5:39Because I think that there are other folks that need to understand why deep vein thrombosis is a very, very serious thing that always needs to get taken a look at. yeah mine at the time i had done like 24 ironman triathlons and i had just done like 120 burpees and the back of my left leg like behind my knee started hurting and i thought i just pulled a muscle but a friend of mine told me to go to the hospital it felt like a muscle pull to begin with and it just kept getting worse and a friend of mine convinced me to go to the hospital with the hospital and they said I had the six, the six clots, the risks with it.

6:20I asked the doctor what that meant. Cause I, I didn't know anything about blood clots. I didn't think someone like me that was active and fit would get blood clots. Yeah. And he kind of said in nonchalant ways that it meant I could die or have a stroke at any moment. So yeah, kind of, kind of freaked out. So yeah, it's extremely important. The concern as I understand it, Christian is that, so what you have is you have clots that are forming in your leg. If that breaks up, gets into your lungs, gets into your heart, it's a widow maker. That's right. You know, and I don't mean to be a little tough in our language, but listen, if part of you got on this podcast, because you were listening and you want to hear some great stuff about a Meg, you know, med tech and so forth and cybersecurity surprise, you just learned a little bonus lesson.

7:11And I hope you can pass it along to a friend that's listening. Please pass along what you've just learned to one other person. I'm sorry, Christian, back to the story. Oh, that's all right. That's all right. Yeah. So I, it took me a while to recover from the blood clots. I took blood thinners for about a year and I just decided one day I didn't want to take the blood thinners anymore. I'm not suggesting anyone else do this, but I just remember like throwing them across the room and saying, I'm not going to do this. Cause I was, I started feeling caged because like they told me I couldn't run. I couldn't travel.

7:42I couldn't do anything I wanted to do. So I just sat around being depressed, basically. So I got every single blood test possible done to my blood to see if there was a root cause. There was none. And then I got another Doppler ultrasound done on my leg to make sure there are no remaining clots. And since then, I get my blood tested routinely. And I do IV therapy for like NAD and other supplements that are supposed to help with these sort of issues. and just monitor my blood really. And that, once I got out of that depression and kind of reclaimed my health and my life, it gave me the confidence to start a new business.

8:17And I thought, well, maybe this is the universe telling me I should start a new business and focus on med tech because if it wasn't for a medical device or that device is recalled because somebody hacked into it, you know, I may not be here. Yeah, yeah. Well, this is quite amazing. So how does Blue Goat Cyber, like, how do you work with new clients? How do they find out about you? Like, how have you grown Blue Goat? We work with startups and large clients. A lot of companies have a brand new technology they want to bring to market, such as one of our clients has a technology that can basically dehydrate blood, turn it into a powder, and then reconstitute it later.

9:04So it solves the whole challenge of transporting blood and storing blood. So we work with startups like that, as well as established companies that have a line of products. The way people primarily find us is through searches on Google or ads. So I'm very niched down. We understand our market. And I personally spent about five months straight, 12 hours a day, doing search engine optimization on our website and figuring out all the hacks and tricks to really make us show up in Google. And once that happened, we started getting a lot of inbound leads. And then the momentum starts where one of the clients refers to somebody else.

9:45And now we're at the point of going to trade shows and really trying to increase our brand awareness. Yeah. Well, and I wonder if any of what we're talking about, what's kind of the state of the union for your world. I would imagine that the threats are probably only going to get more and more sophisticated and more and more of a concern. So it sounds like you're pretty well positioned to be like the guy for medical security. Yeah, that's my goal this year to become the market leader in the industry. Fortunately, the FDA and other regulatory authorities in other countries mandate that medical devices have cybersecurity buttoned up before they're cleared to go on the market?

10:37Because with traditional cybersecurity, somebody might steal your credit card information or your health information. It's kind of like, who cares, right? But if somebody hacks into an implantable and shocks you to death, it's a little more impactful, right? It's life or death, or they cause an in vitro diagnostic system to misdiagnose you. Then you may not get the course the treatment you need. So yeah, my plan is to take over the market. And last year, I mentioned my previous company, last year was really our first full year in business. We were at a higher revenue point than it took me six years to get with my first cybersecurity company.

11:17So I'm trying to capitalize on all the dumb tax that I paid with my first company. Yeah. So to our friend that's listening, how would they know that they should probably, Christian, book a call with you? Well, our clients are typically medical device manufacturers or med tech innovators that their product has some sort of software component in it. anyone that is looking to develop a product or looking to get their product cleared by a regulatory authority, such as the FDA in the United States, should book a call with us because we can help them with all aspects of cybersecurity, all the testing, all the documentation, all the risk assessment.

12:01And we can even help if they contact us early enough with designing their system with cybersecurity in mind. So some of those design decisions are very important early on. Yeah. Yeah. Well, what would they do? What do you typically talk about in a first call? Yeah, we have on our website, there's a button to book a discovery call. We typically see what the client is or the prospect at this point is looking for and where we can help. And if we can help. In some cases, they're just like shopping around or in some cases, it's more of an educational based call because they don't know what they don't know.

12:43And they'll come back to us later on. So we discuss where they are with their product. If their product is like fully developed and they're two months out from like trying to get it approved, then that's typically a challenge for them because we're going to find a bunch of cybersecurity issues and it's going to take them more than two months to approve it, to fix it. So it's going to delay their submission and their time to get their device in the market. If they come to us early, then we can help guide them along while they're making decisions and design the device with cybersecurity in mind versus bolting it on at the end.

13:16Yeah. Okay. So your website, and also I know you've done some podcast episodes as well. Do you mind, to our friend that's listening, and maybe they're not ready for a conversation, but they'd like to learn more from you. I know you've got a resources tab as well. Like, what would you recommend that they take a look at? And, you know, maybe if they're not quite ready for a call just yet. Yeah, we have a couple of resources, and we're trying to increase the number of resources. On our website, there's a white paper that is very useful that shows common issues that medical device manufacturers have had with cybersecurity based on our experience.

13:52We've also got a podcast. We talk about various topics on the podcast. So if you're curious about the history of medical device hacking, we have a podcast on that specific topic. And we've got a webinar series that dives deep into each of the requirements for cybersecurity for a medical device to be approved by the FDA or the European equivalent, the MDR. Okay. Well, website, again, Blue Goat Cyber. You click on the blue button, it says Schedule Discovery Call. Fascinating, Christian. This whole world here. Look, I would dare say that if you're in med tech and you don't have a, say you've done your SWOT analysis and you don't have a busy tee box, I think you might want to revisit that a little bit.

14:43Because I would, with the liability and, you know, you trying to attract investors and stuff, if you don't have that lockdown, number one, book a call with Christian. But yeah, you're probably going to help them identify what needs to go in that threat box so that you can mitigate that so that it doesn't become a risk. Does Christian sound fair? That sounds fair. And you brought up a good point about investors. A lot of the VCs we work with, they are starting to look at a startup to make sure they have cybersecurity on their roadmap. Oh, yeah. That's their money. Yes. Yeah. That's their money.

15:19And if they don't have it on the roadmap, a lot of investors have been kind of bitten about it because at the very end, it's like, oh, it's going to cost us another$500 ,000 because we've totally forgot about cybersecurity. All right, Christian Espinosa, again, founder, CEO, Blue Goat Cyber. And again, the website, bluegoatcyber.com. It's been great having you, Christian. Thank you so much for joining us. Yeah, thank you, Josh.

15:49Thanks for listening to the Thoughtful Entrepreneur Show. If you are a thoughtful business owner or professional who would like to be on this daily program, please visit upmyinfluence.com and click on podcast. We believe that every person has a message that can positively impact the world. We love our community who listens and shares our program every day. Together, we are empowering one another as thoughtful leaders. And as I mentioned at the beginning of this program, if you're looking for introductions to partners, investors, influencers, and clients, I have had private conversations with over 2 ,000 leaders asking them where their best business comes from.

16:31I've got a free video that you can watch right now with no opt-in or email required where I'm going to share the exact steps necessary to be 100 % inbound in your industry over the next six to eight months with no spam, no ads, and no sales. What I teach has worked for me for more than 15 years and has helped me create eight figures in revenue for my own companies. Just head to upmyinfluence.com and watch my free class on how to create endless high-ticket sales appointments. Make sure to hit subscribe so that tomorrow morning, that's right, seven days a week, you are going to be inspired and motivated to succeed.

17:13I promise to bring positivity and inspiration to you for around 15 minutes every single day. Thanks for listening. And thank you for being a part of the Thoughtful Entrepreneur Movement.

From the publisher
Securing Life-Saving Technology: The Importance of Cybersecurity in Medical Devices

In this episode, host Josh speaks with Christian Espinosa, CEO of Blue Goat Cyber, about the growing importance of cybersecurity in medical devices. From surgical robots to implantable devices like pacemakers, Christian highlights how today's advanced healthcare technology is increasingly vulnerable to cyber threats. He shares real-world examples鈥攍ike the disabling of former Vice President Dick Cheney鈥檚 defibrillator wireless feature鈥攖o illustrate how life-threatening these vulnerabilities can be if not addressed properly.

Christian explains how Blue Goat Cyber partners with both startups and established medtech companies to integrate cybersecurity into the early stages of device development. This proactive approach helps manufacturers comply with regulatory standards and protect patients from potential cyberattacks. Christian's personal experience with a health scare deepened his commitment to securing medical devices and gives him a unique, patient-first perspective on the work his company does.

To support clients, Blue Goat Cyber offers white papers, podcasts, and webinars covering FDA regulations and device security best practices. Christian encourages medtech innovators to engage early and book discovery calls to assess their cybersecurity needs. As the healthcare industry continues to evolve, he stresses that cybersecurity is not just about compliance鈥攊t's essential for safeguarding lives and building trust in the devices patients depend on.


About Christian Espinosa:

Christian Espinosa is the founder and CEO of Blue Goat Cyber, a leading authority in cybersecurity and a recognized expert in medical device security. He is driving significant advancements that prioritize patient safety and data integrity, embodying a proactive and innovative approach to his work. As the author of "The Smartest Person in the Room" and "The In-Between: Life in the Micro," Christian boldly shares his evolution from competitive to compassionate leadership.

An avid adventurer, he thrives on extreme sports, heavy metal music, and spicy foods. His impressive credentials as a certified skydiver, PADI divemaster, and Ironman Triathlete demonstrate his unwavering commitment to personal growth and transformative leadership.


About Blue Goat Cyber:

Blue Goat Cyber provides full-service medical device cybersecurity support, addressing challenges throughout the premarket and postmarket phases. From managing Software Bill of Materials (SBOM) to conducting threat modeling, penetration testing, and Static Application Security Testing (SAST), we integrate cybersecurity into every stage of your product lifecycle. Our solutions ensure compliance with FDA guidelines, IEC 62304, ISO 14971, and EU MDR/IVDR regulations while safeguarding patient safety and device reliability.

Apply to be a Guest on The Thoughtful Entrepreneur: https://go.upmyinfluence.com/podcast-guest


Links Mentioned in this Episode:

Want to learn more? Check out Blue Goat Cyber website at https://bluegoatcyber.com//

Check out Blue Goat Cyber on LinkedIn at https://www.linkedin.com/company/blue-goat-cyber/

Check out Christian Espinosa on LinkedIn at https://www.linkedin.com/in/christianespinosa/

Don鈥檛 forget to subscribe to The Thoughtful Entrepreneur and thank you for listening. Tune in next time!


More from

More from The Thoughtful Entrepreneur

All 987 episodes
2122 - The Critical Role of Cybersecurity in Medical Devices with Blue Goat Cyber's Christian EspinosaThe Thoughtful Entrepreneur 路 18 min
Listen in VO