Health Podcast Library
Episode 472

#472: Cost Containment: Right-Sizing Medical Device Cybersecurity with Chris Gates

Sep 21, 2026
40:03

Episode Description

Medical device cybersecurity is no longer an optional feature or a last-minute checkbox prior to market entry. Hosted by Etienne Nichols, this episode features Chris Gates, founder and CEO of arsMedSecurity, who delivers a practical, engineering-first perspective on embedding security directly into the development lifecycle. Gates highlights that deferring cybersecurity efforts until the end of development leads to severe financial penalties, extended regulatory delays, and potential company failure.

The discussion demystifies common misconceptions held by executive teams and "bean counters," such as the myth that off-network devices or small companies are exempt from cyber threats. Under current FDA expectations and the eStar submission process, any medical device containing software is subject to stringent pre-market cybersecurity requirements. Gates illustrates how unexpected 180-day regulatory holds impact a company's daily burn rate, showing that proactive security measures are far cheaper than reactive fixes.

Looking ahead, the conversation explores the evolving threat landscape driven by Large Language Models (LLMs) and advanced exploits that reduce vulnerability exploitation windows from years to minutes. Gates provides concrete steps for medical device manufacturers to take control of their product security, emphasizing early threat modeling, continuous risk management, and the alignment of software development SOPs with recognized international standards.

Takeaways

  • Calculate Delay Impact via Burn Rate: Evaluate cybersecurity risk against your organization's daily burn rate multiplied by a potential 180-day FDA submission delay to understand the true financial cost of non-compliance.
  • Software Triggers Cyber Requirements: Do not assume a device is exempt from cybersecurity requirements because it lacks active internet connectivity; any device running software falls under FDA pre-market expectations.
  • Perform Threat Modeling Before Hardware Freeze: Execute system-level threat modeling (e.g., STRIDE methodology) during the initial design phase before finalizing active hardware components and component selections.
  • Adopt Recognized SDLC Standards: Establish standard operating procedures (SOPs) that map secure development activities directly to ISO/IEC 81001-5-1 and ISO 62304 frameworks.

References

  • Medical Device Cybersecurity for Engineers and Manufacturers (2nd Edition): Practical reference handbook authored by Chris Gates detailing implementation techniques for device developers.
  • ISO/IEC 81001-5-1: Health software and health IT systems safety, effectiveness, and security standard for secure development lifecycles.
  • STRIDE Threat Model: A system decomposition methodology developed by Microsoft to identify data-in-motion and data-at-rest security threats per system element.
  • Host LinkedIn Profile: Connect with Etienne Nichols on LinkedIn.

Feedback Call-to-Action

We want to hear from you! What cybersecurity challenges is your team currently navigating during product development? Send your questions, feedback, or topic suggestions directly to us at podcast@greenlight.guru. Every email is reviewed by our team, and we regularly incorporate listener-submitted questions into upcoming episodes and expert Q&A segments.

Sponsors

This episode is brought to you by Greenlight Guru.

Proudly Supported by

Patrons of Health Podcast Library

AAOS Career Podcast
Achieving Health
OrthoInfo
AAOS Now Podcast
Stronger After Stroke
Aging Like a Pro

Supporting Shows

Thriving with Addiction with Dr. Jonathan Avery
This Just In Radio Show
HIT Like a Girl Pod: Empowering Women in Health IT
Coffee Break: Breaking the Cycle of Bullying in Healthcare, One Cup at a Time
Speak Up For Your Health
Beyond The Paper Gown Podcast
Faces of Digital Health
Cuts and Consults
Hopeful Hints
Healthcare for Humans