Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 76

    Building Medical Devices Right the First Time with Helen Souris

    With Helen Souris - Bringing an innovative medical device to market takes far more than a great idea. It requires regulatory strategy, cybersecurity, quality systems, and commercial planning from the very beginning. In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Helen Souris, CEO of CardiHab and Board Mem

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Listen now

    Key takeaways

    • Regulatory strategy, cybersecurity, and quality systems need to be integrated from the initial planning stages of medical device development, not as afterthoughts.
    • Many digital health startups struggle because they misunderstand the complexities of medical device regulation.
    • Cybersecurity is a critical factor in medical device procurement and should be addressed proactively.
    • Failing to incorporate compliance requirements early in the development lifecycle can lead to significant financial losses and product recalls.
    • Building medical devices correctly from the start is more cost-effective and efficient than attempting to rebuild or retrofit compliance later.
    • Wearable technologies intended for health monitoring should be approached with a medical lens, considering their potential regulatory classifications.
    • Analogies like "stadium hacking" and "fake Wi-Fi demonstrations" highlight the tangible risks associated with inadequate cybersecurity in medical devices.

    Bringing an innovative medical device to market takes far more than a great idea. It requires regulatory strategy, cybersecurity, quality systems, and commercial planning from the very beginning.

    In this episode of the Med Device Cyber Podcast, Christian Espinosa is joined by Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), to discuss why so many promising digital health companies struggle when they leave the startup phase and enter the realities of regulation.

    Helen shares her experience leading a digital therapeutics company, raising investment in Australia, navigating software as a medical device regulations and helping startups avoid costly mistakes that can delay or even derail commercial success.

    The conversation explores why cybersecurity is becoming a deciding factor in procurement, how founders should think about regulatory strategy before writing a single line of code, why quality management systems cannot be bolted on later, and the real-world consequences of ignoring compliance until it's too late.

    Whether you're building a medical device, digital therapeutic, AI healthcare platform or connected medical technology, this episode offers practical advice for creating products that are secure, compliant and built to scale.

    In This Episode:

    • 00:57 Helen's journey from pharma to digital therapeutics

    • 04:33 The realities of raising MedTech investment in Australia

    • 09:06 Why choosing the right investor matters

    • 13:22 Why many digital health startups misunderstand regulation

    • 15:21 Why cybersecurity comes up in every customer conversation

    • 16:15 Why founders still leave cybersecurity until the end

    • 16:53 Building regulation, quality and cybersecurity from Day One

    • 18:31 The $93 million company forced to pull its product

    • 21:09 Explaining medical devices through the user journey

    • 22:50 The stadium hacking analogy that changes perspectives

    • 25:13 Why wearables need a medical lens

    • 26:57 The fake Wi-Fi demonstration everyone should remember

    • 28:20 Why rebuilding is always more expensive than building properly

    • 29:30 Christian's biggest takeaways

    Notable quotes

    “Cybersecurity comes up in every customer conversation. It's not a 'CISO to CISO' conversation; it is now becoming part of a regular procurement conversation.”
    - Helen Souris
    “If you don't build regulation, quality, and cybersecurity in from day one, you build a very expensive product that may not be able to get to market.”
    - Helen Souris
    “It is always more expensive to rebuild than to build properly from the ground up.”
    - Helen Souris
    “The number one thing is that cybersecurity cannot be an afterthought.”
    - Christian Espinosa

    Frequently asked questions

    Bring this work to your device

    Need help with penetration testing?

    Blue Goat Cyber delivers medical device penetration testing for medical device manufacturers - from threat modeling to FDA-ready reports.

    Medical Device Penetration Testing

    More on Penetration Testing

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.