Notes from the work
Practical writing on security and engineering in regulated industries — what the requirements actually say, and what closing them involves.
Premarket cybersecurity for connected devices and software-only products alike, FDA submissions, and the engineering behind a defensible security claim.
Is Your Product a "Cyber Device" Under Section 524B?
Section 524B's cyber device test has three prongs and all must be met. The connectivity prong is read far more broadly than most self-assessments assume.
The Four Security Architecture Views, and What Actually Goes in Them
FDA recommends four security architecture views. Everyone lists the names. Here is what belongs in each diagram and which question each one has to answer.
What Does FDA Actually Want in a Threat Model?
FDA expects a structured threat model that the rest of the submission derives from. Start with trust boundaries, and rank the results by patient harm.
Why Your Security Risk Assessment Cannot Live in Your 14971 File
FDA treats security risk management as a process distinct from safety risk management. They score differently, and they converge at exactly one place.
Your Security Controls Are Not Requirements Yet
FDA expects security controls written as uniquely identified, testable requirements traced to threats and tests. Most submissions contain principles instead.
Does a Security Patch Require a New 510(k)?
A change made solely to strengthen cybersecurity rarely needs a new 510(k). The word doing the work is solely, and most real patches are not solely anything.
FDA Changed Its Cybersecurity Guidance Again. What Actually Moved?
FDA reissued its premarket cybersecurity guidance to align with the QMSR. The requirements did not change. Your citations did, and so did where security lives.
One Credential, Every Device: Reading a CISA Advisory as a Design Failure
A CISA advisory describes one hard-coded credential shared across every unit of a connected therapy device. Five ordinary controls would each have caught it.
Standing Up a Coordinated Vulnerability Disclosure Program
Section 524B requires a coordinated disclosure process. The mechanics take a week. What makes it real is naming who owns the hop from inbox to the fix.
There Is Finally a Common Standard for Medical Device Penetration Testing
MDIC published a consensus penetration testing framework for medical devices. Four of its five stages sit outside the test, and that is where programs fail.
Your SBOM Lists the Framework, Not the 1,000 Packages Underneath
Most first-draft SBOMs name the framework and the major libraries and stop. The vulnerabilities are in everything those pulled in, which is where the work is.
Responding to an FDA Cybersecurity Deficiency Letter
What an FDA cybersecurity deficiency letter asks for, why the 180-day clock is shorter than it looks, and what changes when your product is software-only.
FDA Section 524B: What Premarket Cybersecurity Actually Requires
What Section 524B requires in a premarket submission for cyber devices, why software-only products are covered, and where these submissions fall short.
Running security in a company too small for a full-time CISO and too regulated to go without one.
What Enterprise Security Questionnaires Are Actually Asking For
A security questionnaire is a revenue problem. The answers exist somewhere in your environment, and the deal stalls because nobody there can produce them.
You Have a Penetration Test Report. Now What?
A practical first pass at a penetration test report: how to triage findings, how to argue with a severity rating, and why a quarter of them may not be real.
Your MSP Is Not Your Security Program
An MSP closing tickets is not a security program. The gap shows up as tools purchased but never deployed, and logs too short to investigate an incident.
Who Closes Penetration Test Findings?
A penetration test report is a list of problems, not a fix. Why a testing firm cannot close its own findings, and what that actually leaves you holding.
Modernizing systems that carry real consequences when they break.
Cloud Cost Audits: Where the Money Actually Goes
Cloud spend rises because nobody owns the bill. Where the money actually goes: dead resources, launch-day sizing nobody revisited, and outgrown architecture.
Rescuing a Stalled Platform Migration
A stalled EMR, CRM, or core platform migration is almost always a data problem wearing a schedule problem's clothes. What to do first when one is in trouble.
The Technology Stage Most Growing Companies Skip
Growing companies build their technology function in the same order and skip the same step: a named senior technical owner, accountable for the whole estate.
Using AI tooling where an auditor, a regulator, or a customer will eventually ask how it works.
Deploying AI in Regulated Environments Without Breaking Compliance
The compliance risk is not the AI pilot that stalls in review. It is the AI everyone is already using, on regulated data, with no policy governing any of it.
Sometimes You Don't Need AI. You Just Need I.
A lot of what gets specified as an AI feature is a well-understood problem with a direct solution that is faster, cheaper, and easier to defend to a regulator.
Using AI Coding Assistants in a Regulated Codebase
AI coding tools are usable under a quality system, but only if you can answer who reviewed the change, what it was verified against, and where it came from.