Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    About / Core Values

    The values behind every Blue Goat engagement.

    Our core values live in two forms: beliefs (what we hold true) and operating principles (how we act on them). Grounded in MedTech cybersecurity scenarios so the standard is unambiguous.

    A note from the founder

    Why patient safety is the anchor - not a slogan.

    I am alive because of a medical device. That is not a marketing line; it is the reason Blue Goat Cyber exists and the reason this page opens with Patient Safety instead of Rigor or Excellence. Every threat model, SBOM, and pen test we deliver eventually maps back to someone like me on the other end of the device.

    That lens costs us business - deliberately. We have turned down prospects who wanted a checkbox package to clear the FDA and made it clear they did not want to hear about residual risk to patients. We have walked away from engagements where the client pressured us to soften findings that had clinical impact. Those are not stories we tell to sound principled; they are the reason our current clients stay.

    The values, beliefs, and principles below are what we hire against, review against, and escalate against. If any of them feel abstract, read the scenarios - that is where the standard becomes unambiguous.

    Christian Espinosa
    Founder & CEO, Blue Goat Cyber
    Last updated
    July 2026
    The framework

    Values, beliefs, and principles - and how they connect.

    A value is what we care about. A belief is what we hold to be true. A principle is how we behave. Three layers, one system - each layer makes the one above it testable.

    Layer 1

    Values

    What we care about most. The priorities that break tiebreaks when goals collide.

    Layer 2

    Beliefs

    What we hold to be true about MedTech cybersecurity. The worldview that justifies the values.

    Layer 3

    Principles

    How we act, day to day. Testable behaviors any teammate can be reviewed against.

    Core values

    What we care about.

    Seven values - one anchor, six supporting. When any two conflict, Patient Safety wins.

    Anchor value

    Patient Safety

    The anchor value. Every other value bends to this one.

    Rigor

    Compliance is the floor, not the ceiling.

    Integrity

    Say what you'll do, then do it - or say why you can't.

    Partnership

    We work with client teams, not around them.

    Ingenuity

    Security is the runway that lets MedTech innovation ship.

    Vigilance

    The cheapest fix is the one caught in design.

    Excellence

    Patients' lives depend on our work. That standard applies to every artifact.

    How they align

    One picture: principles enact beliefs, beliefs serve values.

    Read left to right: the behavior we hold ourselves to, the belief that justifies it, and the value it protects.

    Patient Safety sits above every principle. When a principle collides with a safety question, safety wins - always.

    How we use this page

    • Team evaluation. Every quarterly review references these fourteen standards. Growth areas map back to specific beliefs or principles.
    • Hiring decisions. Interview loops probe candidates against these scenarios. A brilliant technologist who cannot align on patient safety or excellence is not a fit.
    • Engagement decisions. When we face a hard trade-off with a client, we come back to this page.
    Core beliefs

    What we hold to be true.

    Seven beliefs that shape how we approach every medical device cybersecurity engagement. Each belief serves a value - and is enacted by one or more of our operating principles.

    Core belief 1 of 7Serves value: Patient Safety

    Patient safety comes first

    Every decision we make is filtered through the question: does this protect the patient using the device?

    When commercial pressure, deadlines, or convenience collide with a real safety question, patient safety wins. We escalate hazards early even when it slows a submission or an engagement.

    Scenarios from our work

    Situation: A pen-tester finds an unauthenticated BLE command that can silence an infusion pump alarm two days before the client's FDA submission deadline.

    What this looks like

    Immediately notify the client's PM and cybersecurity lead, add the finding to the risk register with a clinical hazard analysis, and recommend a submission hold or targeted mitigation - even though it delays the client's launch.

    Not this

    Downgrading the severity so the finding fits into the residual risk table and the deadline stays intact.

    Situation: A client asks us to remove a Critical CVE from the SBOM report because the affected component is 'not really exploitable'.

    What this looks like

    Keep the CVE, document the exploitability rationale under ANSI/AAMI SW96, and let the FDA reviewer see the reasoning.

    Not this

    Silently deleting the row to make the report look cleaner.

    Core belief 2 of 7Serves value: Ingenuity

    Security enables innovation

    Cybersecurity is not a brake on MedTech innovation - it is the runway that lets new devices reach patients safely.

    We say 'yes, and here is the secure path' more than we say 'no'. We help clients ship AI-enabled imaging, connected wearables, and SaMD by designing security in, not bolting it on at the end.

    Scenarios from our work

    Situation: An early-stage SaMD startup wants to ship a cloud-connected companion app but has no security program.

    What this looks like

    Give them a right-sized SPDF that fits a 6-person team - threat model, SBOM, secure coding checklist - so they can build fast without rebuilding later for FDA.

    Not this

    Handing them an enterprise-scale program they cannot execute and telling them to come back when they are bigger.

    Situation: A product manager wants to add a novel wireless protocol that has no established security guidance.

    What this looks like

    Threat-model the protocol, document residual risk, and give them a path to submit - not a blanket refusal.

    Not this

    'That is not standard, so we cannot support it.'

    Core belief 3 of 7Serves value: Integrity

    Trust is earned through action

    Trust is built by what we deliver, not by what we promise. Every artifact, every meeting, every commitment.

    We do what we say we will do, when we said we would do it. If we cannot, we tell the client before the deadline, not after.

    Scenarios from our work

    Situation: A deliverable is going to slip by three days because a lab test surfaced a deeper issue.

    What this looks like

    Email the client 72 hours before the original due date with the reason, the revised date, and the mitigation - so they can replan.

    Not this

    Delivering late with an apology and no advance warning.

    Situation: A prospect asks us if we have done exactly their kind of device before.

    What this looks like

    Say honestly what we have and have not done, and how we would de-risk the gap.

    Not this

    Overstating experience to win the deal.

    Core belief 4 of 7Serves value: Vigilance

    Proactive prevents future threats

    The cheapest vulnerability to fix is the one caught in design. The most expensive is the one caught in the field.

    We push threat modeling, SBOM, and secure coding upstream. We push postmarket monitoring and coordinated vulnerability disclosure so a device stays safe for its full lifecycle - not just at submission.

    Scenarios from our work

    Situation: A client's device has been on the market for three years and no one has looked at its SBOM since launch.

    What this looks like

    Recommend an IEC 81001-5-1 lifecycle refresh: regenerate the SBOM, re-run VEX triage, update the CVD process, and file a postmarket update if warranted.

    Not this

    Only quoting them when the FDA sends a warning letter.

    Situation: A client wants to skip threat modeling because 'the device is simple'.

    What this looks like

    Do a scoped STRIDE session anyway - 90 minutes catches more than the client expects and prevents a costly FDA deficiency letter.

    Not this

    Agreeing to skip and hoping FDA does not ask.

    Core belief 5 of 7Serves value: Rigor

    Compliance is the floor, not the ceiling

    FDA guidance, AAMI SW96, and IEC 81001-5-1 are the minimum bar - real security work starts above them.

    Passing an FDA review is table stakes. We deliver artifacts that would still hold up if the device were attacked in the field, audited by an EU MDR notified body, or reviewed by a hospital security team.

    Scenarios from our work

    Situation: A client asks for a 'checkbox' threat model that will pass the FDA reviewer but nothing more.

    What this looks like

    Deliver a threat model that meets FDA, AAMI SW96, and IEC 81001-5-1 - and that the client's engineers can actually use to fix defects.

    Not this

    A 12-page STRIDE spreadsheet with no data flow diagram and no mitigations traced to design.

    Situation: An engagement passes the letter of FDA guidance but leaves an obvious hospital-network exposure unaddressed.

    What this looks like

    Flag it, recommend the mitigation, and document the residual risk even if it is out of scope for the current submission.

    Not this

    'It is out of scope, not our problem.'

    Situation: A prospect wants a checkbox package to clear the FDA and pushes back when we raise residual risk to patients.

    What this looks like

    Decline the engagement. We have turned down multiple prospects who framed cybersecurity as a submission hurdle rather than a patient-safety obligation - and we will keep doing it.

    Not this

    Taking the revenue, softening findings that have clinical impact, and calling it 'meeting the client where they are.'

    Core belief 6 of 7Serves value: Partnership

    Collaboration drives success

    The best cybersecurity outcomes come from working with the client's engineers, regulatory team, and quality team - not around them.

    We embed with the client. We teach as we deliver. We treat the client's team as partners, and we treat our own team as one team.

    Scenarios from our work

    Situation: A client engineer disagrees with a threat model finding.

    What this looks like

    Sit down together, walk the DFD, and either update the model or update the engineer's understanding - whichever the evidence supports.

    Not this

    'The report is final, take it up with your PM.'

    Situation: Another BGC teammate is behind on their part of a shared deliverable.

    What this looks like

    Offer help, cover a section, or flag the risk to the PM early - the client sees one BGC.

    Not this

    'That's their piece, not mine.'

    Core belief 7 of 7Serves value: Excellence

    The stakes demand excellence

    Patients' lives depend on our work. That standard applies to every report, every meeting, every email.

    We do not ship sloppy work. We proofread. We fact-check citations. We rerun the tool one more time before we deliver.

    Scenarios from our work

    Situation: A report is 'good enough' at 5pm on Friday.

    What this looks like

    One more pass Monday morning to catch the typo in the executive summary and the stale CVE reference in the appendix.

    Not this

    Sending it Friday because it is done enough.

    Situation: A client asks a question and we do not know the answer.

    What this looks like

    'I do not know - I will confirm and get back to you by end of day tomorrow,' followed by an actual answer.

    Not this

    Guessing an answer to look confident.

    How we operate

    Team operating principles.

    The day-to-day behaviors every Blue Goat team member lives by - and is evaluated against. Each principle enacts one of the beliefs above.

    Obsess over critical details

    In MedTech cybersecurity, the details are the deliverable. A wrong CPE, a missing DFD boundary, or a mis-cited FDA section can cost a client months.

    Situation: Drafting a Cybersecurity Management Plan that cites FDA guidance.

    What this looks like

    Cite the current Feb 3, 2026 premarket cybersecurity guidance - not the retired 2023 version - and quote the exact section.

    Not this

    'FDA guidance says...' without a specific citation.

    Principle 2 of 7Enacts: Trust is earned through actionValue: Integrity

    Own the problem, find the solution

    When something breaks - a report, a delivery, a client call - the first person who sees it owns it until it is fixed or handed off cleanly.

    Situation: A client emails on a Sunday saying the SBOM in their submission has a broken CPE.

    What this looks like

    Acknowledge Sunday, fix Monday morning, close the loop with the client and the internal QA process.

    Not this

    'That is a different team, I will forward it Monday.'

    Principle 3 of 7Enacts: Collaboration drives successValue: Partnership

    Listen carefully, respond clearly

    Regulatory, engineering, and executive stakeholders each ask questions in their own language. Hear the real question before answering.

    Situation: A CEO asks 'are we secure?' and an engineer asks 'is CVE-2024-XXXX exploitable in our build?'

    What this looks like

    Answer the CEO in outcomes ('here is our residual risk and how it is trending'); answer the engineer in specifics ('yes, via this call path, mitigated by this control').

    Not this

    Giving both stakeholders the same technical answer.

    Principle 4 of 7Enacts: Security enables innovationValue: Ingenuity

    Adapt the approach, never the standard

    The FDA landscape, threat landscape, and MedTech tech stack all change. Rigid playbooks fail - but the bar for what 'done right' means never moves. We flex the method, not the standard.

    Situation: A device uses a legacy RTOS that is not on any of our standard tool matrices, and an FDA deficiency letter lands mid-project.

    What this looks like

    Adapt the threat model and SBOM approach to fit the RTOS, and use the deficiency letter as a chance to rebuild the client's artifact library so the next submission is faster.

    Not this

    'Our tooling does not support that, so we cannot help,' or answering the deficiency in isolation and moving on.

    Principle 5 of 7Enacts: Patient safety comes firstValue: Patient Safety

    Escalate safety concerns before they're convenient

    If something could hurt a patient, it gets raised now - not after the release, not after the audit, not when the timing is easier. Silence is not neutrality.

    Situation: Two weeks before a submission deadline, a pen-tester finds a Bluetooth pairing flaw that could let an attacker impersonate the clinician app.

    What this looks like

    Escalate to the client's regulatory and engineering leads the same day, document the safety impact, and re-scope the submission if the mitigation cannot land in time.

    Not this

    Logging it as 'medium' and hoping it gets picked up in the next release cycle so the deadline holds.

    Principle 6 of 7Enacts: Proactive prevents future threatsValue: Vigilance

    Learn fast, learn often

    FDA guidance updates, new CVEs, new AAMI standards, and new attack techniques land constantly. We read, share, and apply weekly.

    Situation: AAMI publishes a new consensus standard relevant to a client's device.

    What this looks like

    Someone on the team reads it within a week, posts a summary in the internal channel, and flags any affected client engagements.

    Not this

    Finding out about it three months later from a client.

    Principle 7 of 7Enacts: The stakes demand excellenceValue: Excellence

    Grow beyond your comfort zone

    Every team member should be doing something this quarter that they could not do last quarter.

    Situation: A pen-tester has never led a client-facing threat modeling workshop.

    What this looks like

    Pair them with a senior lead for the first two sessions, then let them run the third.

    Not this

    Keeping the pen-tester behind the keyboard indefinitely.

    How we use this in reviews and hiring

    Quarterly team reviews

    Each teammate is scored against the seven core beliefs and seven operating principles. Growth conversations start from a specific scenario, not a generic label.

    Hiring loops

    Interviewers pick two beliefs and two principles per candidate and probe with scenario-based questions. Technical strength alone does not carry a hire.

    Client engagement escalations

    When a trade-off is hard, the PM anchors the decision to a specific belief on this page and documents it in the engagement record.

    Onboarding

    Every new hire walks this page with their manager in week one and works through the scenarios they are most likely to face in their first 90 days.

    FAQ

    Checkbox clients, patient-safety lens, and how we decide to work together.

    The questions we hear most from prospects whose incentives do not line up with ours - and the honest answers.

    We just need a checkbox package to clear the FDA - can you do that?

    No. If the goal is to satisfy a reviewer without engaging with the residual risk to patients, we are not the right partner. Every engagement we take on treats FDA guidance, AAMI SW96, and IEC 81001-5-1 as the floor, and every finding is evaluated for clinical impact - not just documentation impact. We have turned down multiple prospects who wanted the checkbox and made it clear they did not want to hear about patient risk.

    What does the 'patient-safety lens' actually mean when you scope a project?

    Before we send a proposal we walk the intended use of the device, the clinical workflow, and the population it treats. Every threat, finding, and mitigation is then evaluated by asking 'what happens to the patient if this fails?' - not just 'what happens to the submission.' Our founder is alive because of a medical device, so that lens is not marketing; it is how we decide whether a project is worth taking and how we prioritize findings once we are in.

    How do you decide whether to work with a prospect?

    Three questions. First, is the team willing to hear residual risk to patients and act on it, even when it complicates the timeline? Second, will engineering and regulatory both be at the table, or is cybersecurity being treated as a paperwork exercise owned by one function? Third, are we allowed to document findings honestly - including ones that are inconvenient? If any of those are 'no,' we decline and refer the prospect elsewhere.

    Have you ever walked away from a client mid-engagement?

    Yes. When a client has pressured us to soften or remove findings that had clinical impact, we have ended the engagement rather than deliver an artifact we could not defend. It is rare, but it is the same commitment that keeps our long-term clients with us: what we sign, we stand behind.

    If Patient Safety is the anchor value, why isn't it your only value?

    Patient Safety is the tiebreaker when values conflict, but it does not do the work alone. Rigor, Vigilance, Integrity, Partnership, Ingenuity, and Excellence are what make patient-safety claims defensible under FDA review, notified body audit, and hospital security scrutiny. A page that only said 'we care about patients' would be a slogan; the seven-value system is how we make it operational.

    Keep exploring
    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.