<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BATO Consulting Insights</title>
    <link>https://bato.com/insights/</link>
    <description>Practical writing on security and engineering in regulated industries.</description>
    <language>en-us</language>
    <atom:link href="https://bato.com/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Tue, 01 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>Is Your Product a &quot;Cyber Device&quot; Under Section 524B?</title>
      <link>https://bato.com/insights/is-our-product-a-cyber-device/</link>
      <guid isPermaLink="true">https://bato.com/insights/is-our-product-a-cyber-device/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>Section 524B's cyber device test has three prongs and all must be met. The connectivity prong is read far more broadly than most self-assessments assume.</description>
    </item>
    <item>
      <title>The Four Security Architecture Views, and What Actually Goes in Them</title>
      <link>https://bato.com/insights/fda-security-architecture-views/</link>
      <guid isPermaLink="true">https://bato.com/insights/fda-security-architecture-views/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>FDA recommends four security architecture views. Everyone lists the names. Here is what belongs in each diagram and which question each one has to answer.</description>
    </item>
    <item>
      <title>What Does FDA Actually Want in a Threat Model?</title>
      <link>https://bato.com/insights/threat-modeling-medical-device-fda/</link>
      <guid isPermaLink="true">https://bato.com/insights/threat-modeling-medical-device-fda/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>FDA expects a structured threat model that the rest of the submission derives from. Start with trust boundaries, and rank the results by patient harm.</description>
    </item>
    <item>
      <title>Why Your Security Risk Assessment Cannot Live in Your 14971 File</title>
      <link>https://bato.com/insights/security-risk-vs-safety-risk-medical-device/</link>
      <guid isPermaLink="true">https://bato.com/insights/security-risk-vs-safety-risk-medical-device/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>FDA treats security risk management as a process distinct from safety risk management. They score differently, and they converge at exactly one place.</description>
    </item>
    <item>
      <title>Your Security Controls Are Not Requirements Yet</title>
      <link>https://bato.com/insights/security-requirements-testable-medical-device/</link>
      <guid isPermaLink="true">https://bato.com/insights/security-requirements-testable-medical-device/</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>FDA expects security controls written as uniquely identified, testable requirements traced to threats and tests. Most submissions contain principles instead.</description>
    </item>
    <item>
      <title>Does a Security Patch Require a New 510(k)?</title>
      <link>https://bato.com/insights/security-patch-new-510k-required/</link>
      <guid isPermaLink="true">https://bato.com/insights/security-patch-new-510k-required/</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>A change made solely to strengthen cybersecurity rarely needs a new 510(k). The word doing the work is solely, and most real patches are not solely anything.</description>
    </item>
    <item>
      <title>FDA Changed Its Cybersecurity Guidance Again. What Actually Moved?</title>
      <link>https://bato.com/insights/fda-cybersecurity-guidance-2026-what-changed/</link>
      <guid isPermaLink="true">https://bato.com/insights/fda-cybersecurity-guidance-2026-what-changed/</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>FDA reissued its premarket cybersecurity guidance to align with the QMSR. The requirements did not change. Your citations did, and so did where security lives.</description>
    </item>
    <item>
      <title>One Credential, Every Device: Reading a CISA Advisory as a Design Failure</title>
      <link>https://bato.com/insights/hard-coded-credential-medical-device-advisory-teardown/</link>
      <guid isPermaLink="true">https://bato.com/insights/hard-coded-credential-medical-device-advisory-teardown/</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>A CISA advisory describes one hard-coded credential shared across every unit of a connected therapy device. Five ordinary controls would each have caught it.</description>
    </item>
    <item>
      <title>Standing Up a Coordinated Vulnerability Disclosure Program</title>
      <link>https://bato.com/insights/coordinated-vulnerability-disclosure-program-setup/</link>
      <guid isPermaLink="true">https://bato.com/insights/coordinated-vulnerability-disclosure-program-setup/</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>Section 524B requires a coordinated disclosure process. The mechanics take a week. What makes it real is naming who owns the hop from inbox to the fix.</description>
    </item>
    <item>
      <title>There Is Finally a Common Standard for Medical Device Penetration Testing</title>
      <link>https://bato.com/insights/mdic-penetration-testing-framework-medical-devices/</link>
      <guid isPermaLink="true">https://bato.com/insights/mdic-penetration-testing-framework-medical-devices/</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <description>MDIC published a consensus penetration testing framework for medical devices. Four of its five stages sit outside the test, and that is where programs fail.</description>
    </item>
    <item>
      <title>Cloud Cost Audits: Where the Money Actually Goes</title>
      <link>https://bato.com/insights/cloud-cost-audit-where-the-money-goes/</link>
      <guid isPermaLink="true">https://bato.com/insights/cloud-cost-audit-where-the-money-goes/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>Cloud spend rises because nobody owns the bill. Where the money actually goes: dead resources, launch-day sizing nobody revisited, and outgrown architecture.</description>
    </item>
    <item>
      <title>Deploying AI in Regulated Environments Without Breaking Compliance</title>
      <link>https://bato.com/insights/deploying-ai-in-regulated-environments/</link>
      <guid isPermaLink="true">https://bato.com/insights/deploying-ai-in-regulated-environments/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>The compliance risk is not the AI pilot that stalls in review. It is the AI everyone is already using, on regulated data, with no policy governing any of it.</description>
    </item>
    <item>
      <title>Rescuing a Stalled Platform Migration</title>
      <link>https://bato.com/insights/rescuing-a-stalled-platform-migration/</link>
      <guid isPermaLink="true">https://bato.com/insights/rescuing-a-stalled-platform-migration/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>A stalled EMR, CRM, or core platform migration is almost always a data problem wearing a schedule problem's clothes. What to do first when one is in trouble.</description>
    </item>
    <item>
      <title>Sometimes You Don't Need AI. You Just Need I.</title>
      <link>https://bato.com/insights/you-dont-need-ai-you-just-need-i/</link>
      <guid isPermaLink="true">https://bato.com/insights/you-dont-need-ai-you-just-need-i/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>A lot of what gets specified as an AI feature is a well-understood problem with a direct solution that is faster, cheaper, and easier to defend to a regulator.</description>
    </item>
    <item>
      <title>What Enterprise Security Questionnaires Are Actually Asking For</title>
      <link>https://bato.com/insights/enterprise-security-questionnaires/</link>
      <guid isPermaLink="true">https://bato.com/insights/enterprise-security-questionnaires/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>A security questionnaire is a revenue problem. The answers exist somewhere in your environment, and the deal stalls because nobody there can produce them.</description>
    </item>
    <item>
      <title>Your SBOM Lists the Framework, Not the 1,000 Packages Underneath</title>
      <link>https://bato.com/insights/sbom-lists-the-framework-not-the-packages/</link>
      <guid isPermaLink="true">https://bato.com/insights/sbom-lists-the-framework-not-the-packages/</guid>
      <pubDate>Thu, 20 Aug 2026 12:00:00 GMT</pubDate>
      <description>Most first-draft SBOMs name the framework and the major libraries and stop. The vulnerabilities are in everything those pulled in, which is where the work is.</description>
    </item>
    <item>
      <title>Responding to an FDA Cybersecurity Deficiency Letter</title>
      <link>https://bato.com/insights/responding-to-fda-cybersecurity-deficiency-letter/</link>
      <guid isPermaLink="true">https://bato.com/insights/responding-to-fda-cybersecurity-deficiency-letter/</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <description>What an FDA cybersecurity deficiency letter asks for, why the 180-day clock is shorter than it looks, and what changes when your product is software-only.</description>
    </item>
    <item>
      <title>The Technology Stage Most Growing Companies Skip</title>
      <link>https://bato.com/insights/the-technology-stage-companies-skip/</link>
      <guid isPermaLink="true">https://bato.com/insights/the-technology-stage-companies-skip/</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <description>Growing companies build their technology function in the same order and skip the same step: a named senior technical owner, accountable for the whole estate.</description>
    </item>
    <item>
      <title>You Have a Penetration Test Report. Now What?</title>
      <link>https://bato.com/insights/penetration-test-report-what-to-do-next/</link>
      <guid isPermaLink="true">https://bato.com/insights/penetration-test-report-what-to-do-next/</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <description>A practical first pass at a penetration test report: how to triage findings, how to argue with a severity rating, and why a quarter of them may not be real.</description>
    </item>
    <item>
      <title>Your MSP Is Not Your Security Program</title>
      <link>https://bato.com/insights/your-msp-is-not-your-security-program/</link>
      <guid isPermaLink="true">https://bato.com/insights/your-msp-is-not-your-security-program/</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <description>An MSP closing tickets is not a security program. The gap shows up as tools purchased but never deployed, and logs too short to investigate an incident.</description>
    </item>
    <item>
      <title>FDA Section 524B: What Premarket Cybersecurity Actually Requires</title>
      <link>https://bato.com/insights/fda-524b-premarket-cybersecurity-requirements/</link>
      <guid isPermaLink="true">https://bato.com/insights/fda-524b-premarket-cybersecurity-requirements/</guid>
      <pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate>
      <description>What Section 524B requires in a premarket submission for cyber devices, why software-only products are covered, and where these submissions fall short.</description>
    </item>
    <item>
      <title>Using AI Coding Assistants in a Regulated Codebase</title>
      <link>https://bato.com/insights/ai-coding-assistants-regulated-codebase/</link>
      <guid isPermaLink="true">https://bato.com/insights/ai-coding-assistants-regulated-codebase/</guid>
      <pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate>
      <description>AI coding tools are usable under a quality system, but only if you can answer who reviewed the change, what it was verified against, and where it came from.</description>
    </item>
    <item>
      <title>Who Closes Penetration Test Findings?</title>
      <link>https://bato.com/insights/who-closes-penetration-test-findings/</link>
      <guid isPermaLink="true">https://bato.com/insights/who-closes-penetration-test-findings/</guid>
      <pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate>
      <description>A penetration test report is a list of problems, not a fix. Why a testing firm cannot close its own findings, and what that actually leaves you holding.</description>
    </item>
  </channel>
</rss>
