Blue Goat Cyber logoBlue Goat CyberSMMedical Device Cybersecurity
    K
    Podcast · Episode 27

    Total Product Lifecycle Security: From Design to Disposal

    With MedTech leader - How well does your security strategy cover the entire product lifespan - from concept to decommissioning? This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity.

    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Listen now

    Key takeaways

    • Total Product Lifecycle (TPLC) security covers a product from initial concept to final decommissioning, integrating security throughout its entire lifespan.
    • The Secure Product Development Framework (SPDF) and Secure Software Development Lifecycle (SSDLC) are critical components of TPLC, embedding security into the iterative development process.
    • Neglecting a full-lifecycle security approach, particularly the often-overlooked decommissioning phase, is a primary reason for product vulnerabilities and potential data breaches.
    • Security considerations must extend beyond the product's code to include the development environment, update mechanisms, supply chain integrity, and physical security of developer equipment.
    • Startups and smaller companies face significant challenges in implementing comprehensive secure development practices due to cost, time constraints, and a focus on rapid market entry.
    • Even with robust processes, human error remains a significant vulnerability, necessitating continuous checks, multiple reviews, and strict adherence to security protocols.
    • Regulatory compliance and market access, including forthcoming FDA requirements, increasingly demand a demonstrable, end-to-end security posture throughout the TPLC.
    • Threat modeling should encompass the entire TPLC, including the device, associated systems, development, manufacturing processes, and potential environmental factors like natural disasters or geographic data hosting.

    How well does your security strategy cover the entire product lifespan - from concept to decommissioning?

    This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks.

    Key points:

    (1:50) Intro to TPLC and SPDF

    • The importance of TPLC and SPDF in secure development.

    (7:00) Update Vulnerabilities and OTA Risks

    • An example of compromised keys in an otherwise secure over-the-air (OTA) process.

    • Trade-offs between update convenience and security.

    (12:16) Threat Modeling

    • Threat modeling’s application to development environments.

    • The overlooked risks of data storage locations and natural disasters.

    (17:24) Infrastructure Challenges

    • How clients struggled with infrastructure across hospital environments.

    • How scripts and hardcoded passwords can introduce risk.

    (19:56) Building a SPDF That Works

    • Best practices: coding standards, multi-layer review, and automated testing.

    • Secure development is like planning for your own death - it’s hard, but necessary.

    Notable quotes

    “The SPDF, which is closely related to the Secure Software Development Lifecycle (SSDLC), is presented as an essential component of the TPLC. It provides a structured approach to ensure security is integrated into every stage of the product's ongoing development, rather than being treated as an afterthought.”
    - Trevor Slattery
    “I think it is extremely important to think about from concept to decommissioning, the security in that entire process because it is often forgot about once the product is sold.”
    - Christian Espinosa
    “Everything needs to be considered start to finish here. I think a really important part of it that is also often overlooked is what is the development environment like?”
    - Trevor Slattery
    “It does not matter how great the encryption is if the key is very simple and you can break it. And so we were able to just guess the key and then we pushed out we could push out our own updates across all of the fielded devices with whatever we wanted on it by tampering with what is going on in that update server.”
    - Christian Espinosa

    Frequently asked questions

    Bring this work to your device

    Need help with fda premarket cybersecurity?

    Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.

    FDA Premarket Cybersecurity Services

    More on FDA Premarket Cybersecurity

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.