Perspectives on medical device cybersecurity
Practitioner perspectives on regulatory cybersecurity, device safety, and the engineering practices behind submission-ready evidence.
Recent writing and appearances
Which FDA cybersecurity guidance applies to my submission?
Four FDA premarket cybersecurity guidances share almost the same name. Which one is current, what each superseded, and how to tell which applies to your submission.
Read the article PressQuoted in Wired: Why safety-critical security research matters
Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics features Beau's perspective: research done in the open and taken seriously by industry makes safety-critical systems safer.
Read the story in Wired ArticleCISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New
CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from.
Read the article LinkedInReintroduction: Beau Woods on medical device cybersecurity
After years of quietly building Stratigos Security, Beau shares what the team has been working on and why medical device cybersecurity demands a different kind of testing partner.
Read on LinkedIn ArticleFDA is asking for known vulnerabilities alongside your SBOM
Reviewers are asking for a list of known vulnerabilities with the software component inventory, in machine-readable VEX form. What that means in practice and what to do now.
Read the article ArticleWhat the February 2026 FDA premarket update changes
FDA's February 2026 revision is a minor update that aligns the premarket cybersecurity guidance with the QMSR. What FDA expects in a submission is unchanged. Two things to change in your procedures.
Read the article ArticleThe 2025 FDA premarket cybersecurity guidance: an evolution, not a revolution
FDA's June 2025 update to the premarket cybersecurity guidance is an evolution, not a revolution. Five expectations and clarifications to fold into your cybersecurity program.
Read the article