Last reviewed: May 1, 2026
Listen now
How well does your security strategy cover the entire product lifespan - from concept to decommissioning?
This episode dives into the importance of the Total Product Lifecycle (TPLC) and Secure Product Development Framework (SPDF) in medical device cybersecurity. Christian and Trevor share stories, best practices, and pitfalls from real-world cases involving update security, insecure development environments, and overlooked decommissioning risks.
Key points:
(1:50) Intro to TPLC and SPDF
- The importance of TPLC and SPDF in secure development.
(7:00) Update Vulnerabilities and OTA Risks
-
An example of compromised keys in an otherwise secure over-the-air (OTA) process.
-
Trade-offs between update convenience and security.
(12:16) Threat Modeling
-
Threat modeling’s application to development environments.
-
The overlooked risks of data storage locations and natural disasters.
(17:24) Infrastructure Challenges
-
How clients struggled with infrastructure across hospital environments.
-
How scripts and hardcoded passwords can introduce risk.
(19:56) Building a SPDF That Works
-
Best practices: coding standards, multi-layer review, and automated testing.
-
Secure development is like planning for your own death - it’s hard, but necessary.
Bring this work to your device
Need help with fda premarket cybersecurity?
Blue Goat Cyber delivers fda premarket cybersecurity services for medical device manufacturers - from threat modeling to FDA-ready reports.
FDA Premarket Cybersecurity ServicesMore on FDA Premarket Cybersecurity
Keep listening
-
Episode 69
Science Before Hype in MedTech Investing with Varun Turlapati of Chaanakya Capital
With Varun Turlapati
-
Episode 67
De-Risking Product Decisions in MedTech Startups with Brent Lavin of Ironwood MedTech Partners
With Brent Lavin
-
Episode 65
Why Clinical Trials Are the Most Expensive Capital Outlay for Startups with Rob Bedford, CEO of Franklyn Health
With Rob Bedford
-
Episode 64
Traceability Requirements and Documentation Audit Trails with Dr. Basant Bajpai, CEO of Compliance MedQRA
With Dr. Basant Bajpai