Blue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 27

    Total Product Lifecycle Security: From Design to Disposal

    With MedTech leader - How well does your security strategy cover the entire product lifespan - from concept to decommissioning? This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity.

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Trevor Slattery, COO at Blue Goat Cyber

    Reviewed by Trevor Slattery

    COO · Blue Goat Cyber

    Last reviewed: May 1, 2026

    Listen now

    How well does your security strategy cover the entire product lifespan - from concept to decommissioning?

    This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks.

    Key points:

    (1:50) Intro to TPLC and SPDF

    • The importance of TPLC and SPDF in secure development.

    (7:00) Update Vulnerabilities and OTA Risks

    • An example of compromised keys in an otherwise secure over-the-air (OTA) process.

    • Trade-offs between update convenience and security.

    (12:16) Threat Modeling

    • Threat modeling’s application to development environments.

    • The overlooked risks of data storage locations and natural disasters.

    (17:24) Infrastructure Challenges

    • How clients struggled with infrastructure across hospital environments.

    • How scripts and hardcoded passwords can introduce risk.

    (19:56) Building a SPDF That Works

    • Best practices: coding standards, multi-layer review, and automated testing.

    • Secure development is like planning for your own death - it’s hard, but necessary.

    Bring this work to your device

    Need help with fda premarket cybersecurity?

    Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.

    FDA Premarket Cybersecurity Services

    More on FDA Premarket Cybersecurity

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ submissions.