Insights

Notes from the work

Practical writing on security and engineering in regulated industries — what the requirements actually say, and what closing them involves.

Premarket cybersecurity for connected devices and software-only products alike, FDA submissions, and the engineering behind a defensible security claim.

Is Your Product a "Cyber Device" Under Section 524B?

Section 524B's cyber device test has three prongs and all must be met. The connectivity prong is read far more broadly than most self-assessments assume.

The Four Security Architecture Views, and What Actually Goes in Them

FDA recommends four security architecture views. Everyone lists the names. Here is what belongs in each diagram and which question each one has to answer.

What Does FDA Actually Want in a Threat Model?

FDA expects a structured threat model that the rest of the submission derives from. Start with trust boundaries, and rank the results by patient harm.

Why Your Security Risk Assessment Cannot Live in Your 14971 File

FDA treats security risk management as a process distinct from safety risk management. They score differently, and they converge at exactly one place.

Your Security Controls Are Not Requirements Yet

FDA expects security controls written as uniquely identified, testable requirements traced to threats and tests. Most submissions contain principles instead.

Does a Security Patch Require a New 510(k)?

A change made solely to strengthen cybersecurity rarely needs a new 510(k). The word doing the work is solely, and most real patches are not solely anything.

FDA Changed Its Cybersecurity Guidance Again. What Actually Moved?

FDA reissued its premarket cybersecurity guidance to align with the QMSR. The requirements did not change. Your citations did, and so did where security lives.

One Credential, Every Device: Reading a CISA Advisory as a Design Failure

A CISA advisory describes one hard-coded credential shared across every unit of a connected therapy device. Five ordinary controls would each have caught it.

Standing Up a Coordinated Vulnerability Disclosure Program

Section 524B requires a coordinated disclosure process. The mechanics take a week. What makes it real is naming who owns the hop from inbox to the fix.

There Is Finally a Common Standard for Medical Device Penetration Testing

MDIC published a consensus penetration testing framework for medical devices. Four of its five stages sit outside the test, and that is where programs fail.

Your SBOM Lists the Framework, Not the 1,000 Packages Underneath

Most first-draft SBOMs name the framework and the major libraries and stop. The vulnerabilities are in everything those pulled in, which is where the work is.

Responding to an FDA Cybersecurity Deficiency Letter

What an FDA cybersecurity deficiency letter asks for, why the 180-day clock is shorter than it looks, and what changes when your product is software-only.

FDA Section 524B: What Premarket Cybersecurity Actually Requires

What Section 524B requires in a premarket submission for cyber devices, why software-only products are covered, and where these submissions fall short.

Running security in a company too small for a full-time CISO and too regulated to go without one.

Modernizing systems that carry real consequences when they break.

Using AI tooling where an auditor, a regulator, or a customer will eventually ask how it works.