Listen now
Key takeaways
- Total Product Lifecycle (TPLC) security covers a product from initial concept to final decommissioning, integrating security throughout its entire lifespan.
- The Secure Product Development Framework (SPDF) and Secure Software Development Lifecycle (SSDLC) are critical components of TPLC, embedding security into the iterative development process.
- Neglecting a full-lifecycle security approach, particularly the often-overlooked decommissioning phase, is a primary reason for product vulnerabilities and potential data breaches.
- Security considerations must extend beyond the product's code to include the development environment, update mechanisms, supply chain integrity, and physical security of developer equipment.
- Startups and smaller companies face significant challenges in implementing comprehensive secure development practices due to cost, time constraints, and a focus on rapid market entry.
- Even with robust processes, human error remains a significant vulnerability, necessitating continuous checks, multiple reviews, and strict adherence to security protocols.
- Regulatory compliance and market access, including forthcoming FDA requirements, increasingly demand a demonstrable, end-to-end security posture throughout the TPLC.
- Threat modeling should encompass the entire TPLC, including the device, associated systems, development, manufacturing processes, and potential environmental factors like natural disasters or geographic data hosting.
How well does your security strategy cover the entire product lifespan - from concept to decommissioning?
This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks.
Key points:
(1:50) Intro to TPLC and SPDF
- The importance of TPLC and SPDF in secure development.
(7:00) Update Vulnerabilities and OTA Risks
-
An example of compromised keys in an otherwise secure over-the-air (OTA) process.
-
Trade-offs between update convenience and security.
(12:16) Threat Modeling
-
Threat modeling’s application to development environments.
-
The overlooked risks of data storage locations and natural disasters.
(17:24) Infrastructure Challenges
-
How clients struggled with infrastructure across hospital environments.
-
How scripts and hardcoded passwords can introduce risk.
(19:56) Building a SPDF That Works
-
Best practices: coding standards, multi-layer review, and automated testing.
-
Secure development is like planning for your own death - it’s hard, but necessary.
Notable quotes
“The SPDF, which is closely related to the Secure Software Development Lifecycle (SSDLC), is presented as an essential component of the TPLC. It provides a structured approach to ensure security is integrated into every stage of the product's ongoing development, rather than being treated as an afterthought.”
“I think it is extremely important to think about from concept to decommissioning, the security in that entire process because it is often forgot about once the product is sold.”
“Everything needs to be considered start to finish here. I think a really important part of it that is also often overlooked is what is the development environment like?”
“It does not matter how great the encryption is if the key is very simple and you can break it. And so we were able to just guess the key and then we pushed out we could push out our own updates across all of the fielded devices with whatever we wanted on it by tampering with what is going on in that update server.”
Frequently asked questions
Bring this work to your device
Need help with fda premarket cybersecurity?
Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.
FDA Premarket Cybersecurity ServicesMore on FDA Premarket Cybersecurity
Keep listening
-
Episode 70
Why MedTech Needs Specialists with Zoltan Kevei and Saby Toth of Bishop & Co
With Zoltan Kevei
-
Episode 69
Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital
With Varun Turlapati
-
Episode 67
De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners
With Brent Lavin
-
Episode 65
Who Owns Patient Data Security in Trials with Rob Bedford, CEO of Franklyn Health
With Rob Bedford