Insights

Perspectives on medical device cybersecurity

Practitioner perspectives on regulatory cybersecurity, device safety, and the engineering practices behind submission-ready evidence.

Latest

Recent writing and appearances

Article

Which FDA cybersecurity guidance applies to my submission?

Four FDA premarket cybersecurity guidances share almost the same name. Which one is current, what each superseded, and how to tell which applies to your submission.

Read the article
Press

Quoted in Wired: Why safety-critical security research matters

Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics features Beau's perspective: research done in the open and taken seriously by industry makes safety-critical systems safer.

Read the story in Wired
Article

CISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New

CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from.

Read the article
LinkedIn

Reintroduction: Beau Woods on medical device cybersecurity

After years of quietly building Stratigos Security, Beau shares what the team has been working on and why medical device cybersecurity demands a different kind of testing partner.

Read on LinkedIn
Article

FDA is asking for known vulnerabilities alongside your SBOM

Reviewers are asking for a list of known vulnerabilities with the software component inventory, in machine-readable VEX form. What that means in practice and what to do now.

Read the article
Article

What the February 2026 FDA premarket update changes

FDA's February 2026 revision is a minor update that aligns the premarket cybersecurity guidance with the QMSR. What FDA expects in a submission is unchanged. Two things to change in your procedures.

Read the article
Article

The 2025 FDA premarket cybersecurity guidance: an evolution, not a revolution

FDA's June 2025 update to the premarket cybersecurity guidance is an evolution, not a revolution. Five expectations and clarifications to fold into your cybersecurity program.

Read the article
Next step

Have a question we should write about?