# Stratigos Security > High-assurance cybersecurity for regulated and safety-critical industries. Founded by Beau Woods, former FDA Entrepreneur in Residence. Stratigos Security provides penetration testing, threat modeling, security advisory, and vCISO services for medical device manufacturers and high-tech companies. The team helped write the FDA's premarket and postmarket cybersecurity guidance and has been engaged with the agency since 2013. ## Pages - [Home](https://stratigossecurity.com/): Overview of Stratigos Security services and positioning - [Medical Devices](https://stratigossecurity.com/medical-devices/): FDA-ready cybersecurity testing for medical device manufacturers - [Medical Device Penetration Testing](https://stratigossecurity.com/medical-devices/penetration-testing/): FDA-aligned penetration testing methodology for medical devices - [Medical Device Threat Modeling](https://stratigossecurity.com/medical-devices/threat-modeling/): Threat modeling aligned to AAMI TIR57, ISO 14971, IEC 81001-5-1 - [Cyber Certainty](https://stratigossecurity.com/medical-devices/cyber-certainty/): Submission-ready cybersecurity documentation, eSTAR-ready reports, deficiency response - [Medical Device Cybersecurity Quickstart](https://stratigossecurity.com/medical-devices/quickstart/): Rapid readiness review of a device's cybersecurity posture ahead of threat modeling, testing, and regulatory review - [Penetration Testing](https://stratigossecurity.com/penetration-testing/): General penetration testing services for high-tech companies - [Advisory](https://stratigossecurity.com/advisory/): Security advisory and vCISO services - [Why Us](https://stratigossecurity.com/why-us/): Differentiators and five questions to ask any medical device penetration testing firm - [About](https://stratigossecurity.com/about/): Beau Woods bio, team credentials, company history - [Contact](https://stratigossecurity.com/contact/?via=agents-pointer): Schedule a call with Stratigos Security - [Insights](https://stratigossecurity.com/insights/): Thought leadership on medical device cybersecurity - [Coordinated Vulnerability Disclosure](https://stratigossecurity.com/coordinated-vulnerability-disclosure/): How Stratigos discloses vulnerabilities it finds and how to report one to Stratigos - [Privacy & Security](https://stratigossecurity.com/privacy/): Privacy practices and data handling - [Sustainability](https://stratigossecurity.com/sustainability/): Commitment to a lower-impact business model ## Insights - [Which FDA cybersecurity guidance applies to my submission?](https://stratigossecurity.com/insights/which-fda-cybersecurity-guidance-applies/): Four FDA premarket cybersecurity guidances share almost the same name. Which one is current, what each superseded, and how to tell which applies to your submission. (article, 2026-09-10) - [Quoted in Wired: Why safety-critical security research matters](https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/): Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics features Beau's perspective: research done in the open and taken seriously by industry makes safety-critical systems safer. (appearance, 2026-08-12) - [CISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New](https://stratigossecurity.com/insights/cisa-cvd-guidance/): CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from. (article, 2026-07-23) - [Reintroduction: Beau Woods on medical device cybersecurity](https://www.linkedin.com/posts/beauwoods_im-getting-more-active-here-for-dayjob-share-7482465952652013568-Bsb5/): After years of quietly building Stratigos Security, Beau shares what the team has been working on and why medical device cybersecurity demands a different kind of testing partner. (appearance, 2026-07-13) - [FDA is asking for known vulnerabilities alongside your SBOM](https://stratigossecurity.com/insights/known-vulnerabilities-vex-premarket-submissions/): Reviewers are asking for a list of known vulnerabilities with the software component inventory, in machine-readable VEX form. What that means in practice and what to do now. (article, 2026-03-16) - [What the February 2026 FDA premarket update changes](https://stratigossecurity.com/insights/fda-premarket-cybersecurity-guidance-2026-update/): FDA's February 2026 revision is a minor update that aligns the premarket cybersecurity guidance with the QMSR. What FDA expects in a submission is unchanged. Two things to change in your procedures. (article, 2026-02-03) - [The 2025 FDA premarket cybersecurity guidance: an evolution, not a revolution](https://stratigossecurity.com/insights/fda-premarket-cybersecurity-guidance-2025-update/): FDA's June 2025 update to the premarket cybersecurity guidance is an evolution, not a revolution. Five expectations and clarifications to fold into your cybersecurity program. (article, 2025-06-27) - [Stratigos CEO presents at Digital Biomarkers & Digital Measurements Summit](https://stratigossecurity.com/insights/stratigos-ceo-presents-at-digital-biomarkers-digital-measurements-summit/): Stratigos Security Founder and CEO, Beau Woods, delivered a presentation and joined a panel discussion at the Digital Biomarkers & Digital Measurements Summit today. (article, 2020-11-17) - [Stratigos CEO keynotes H-ISAC Medical Device Security Workshop](https://stratigossecurity.com/insights/stratigos-ceo-keynotes-h-isac-medical-device-security-workshop/): Stratigos Security Founder and CEO, Beau Woods, was invited to keynote the Health Information Sharing and Analysis Center (H-ISAC) Medical Device Security Workshop, on October 29, 2020. (article, 2020-11-01) - [Stratigos CEO interviewed for IntoSecurity Podcast](https://stratigossecurity.com/insights/stratigos-ceo-interviewed-for-intosecurity-podcast/): Stratigos Security Founder and CEO, Beau Woods, was interviewed by Dan Raywood of InfoSecurity Magazine on a special Cybersecurity Awareness Month episode of the IntoSecurity Podcast. (article, 2020-10-16) - [Stratigos CEO quoted in Wall Street Journal on Future of Hacking](https://stratigossecurity.com/insights/stratigos-ceo-quoted-in-wall-street-journal-on-future-of-hacking/): Stratigos Security Founder and CEO, Beau Woods, was quoted in a Wall Street Journal story, Hackers Eye their Next Targets, from Schools to Cars. (article, 2020-10-08) - [Stratigos CEO quoted in Washington Post on Cybersecurity Awareness Month](https://stratigossecurity.com/insights/stratigos-ceo-quoted-in-washington-post-on-cybersecurity-awareness-month/): Stratigos Security Founder and CEO, Beau Woods, was mentioned in a Washington Post story, Americans are as insecure as ever on the 17th annual Cybersecurity Awareness month. (article, 2020-10-02) - [Stratigos CEO quoted in Vox](https://stratigossecurity.com/insights/stratigos-ceo-quoted-in-vox/): Stratigos Security Founder and CEO, Beau Woods, was quoted in a Washington Post story, The US killed Soleimani. What will Iran do next? (article, 2020-01-10) - [Stratigos CEO Mentioned in Washington Post](https://stratigossecurity.com/insights/stratigos-ceo-mentioned-in-washington-post/): Stratigos Security Founder and CEO, Beau Woods, was mentioned in a Washington Post story, Hackers are going after medical devices — and manufacturers are helping them. (article, 2019-08-08) - [Stratigos CEO quoted in The Verge](https://stratigossecurity.com/insights/stratigos-ceo-quoted-in-the-verge/): Stratigos Security Founder and CEO, Beau Woods, was quoted in a Verge story, Health Care's Huge Cybersecurity Problem. (article, 2019-04-04) - [Stratigos CEO joins Council on Foreign Relations panel](https://stratigossecurity.com/insights/stratigos-ceo-joins-council-on-foreign-relations-panel/): Stratigos Security Founder and CEO, Beau Woods, joined a panel discussion at the Council on Foreign Relations, titled Hacking and the Internet of Things. (article, 2019-01-17) - [Stratigos CEO featured in Council on Foreign Relations podcast](https://stratigossecurity.com/insights/stratigos-ceo-featured-in-council-on-foreign-relations-podcast/): Stratigos Security Founder and CEO, Beau Woods, sat down for a podcast with Micah Zenko, from the Council on Foreign Relations. (article, 2017-06-02) ## For AI agents - [Page finder](https://stratigossecurity.com/agents/?via=llms-txt): Ask in the reader's own words and get the one page most likely to answer, with the short answer where the site has one. The question alone gets the general answer. Include who it is for and what changes it, and you get the specific one: the role (regulatory, engineering, quality, clinical, executive, security, research, press) gets the version written for that reader; the kind of organization (device maker, hospital, consultancy, ...) gets the answer for who has to act; the situation (device type, pathway such as 510(k) or PMA, stage, the decision at hand) gets the page for that case. Each detail narrows the result and the reply shows which it used; one call with them beats two without. Kinds and situations only, never names: nothing that identifies the reader is asked, and anything resembling contact details is removed before storage. What is sent is kept so the site can be improved around what visitors come for. - [Finder API](https://stratigossecurity.com/api/agent/find?q={question}): The same as JSON, one GET, with role, organization, and situation parameters; each list also accepts a few words of your own when nothing on it fits. Put the reader's question where {question} stands; it is a placeholder, not a question to ask. If your fetcher drops query strings, put the question in the path instead: https://stratigossecurity.com/api/agent/find/{question}. For a detailed description, POST the same fields as JSON so the words stay out of the URL. Description: https://stratigossecurity.com/api/agent/openapi.json - [Site index](https://stratigossecurity.com/site-index.json): The machine-readable index behind the finder: every page with its summary, the questions it answers, and who it is written for.