Home Newsletter Honored Guests Blog About Us Work With Us Sponsor & Advertise Be a Guest The Production Suite Get the Briefing
Skip to main content

Open Door Salon

Christian Espinosa

Christian Espinosa

Founder & CEO, Blue Goat Cyber

Christian Espinosa is the founder and CEO of Blue Goat Cyber, a medical-device cybersecurity firm he started in 2022 after a health scare put him on the other side of the technology he now works to secure. A U.S. Air Force veteran and a cybersecurity practitioner of roughly three decades, he built and sold his previous company, Alpine Security, before turning his focus entirely to medtech. Under his leadership, Blue Goat has supported more than 250 FDA submissions across the 510(k), De Novo, and PMA pathways, for clients including Intuitive Surgical, bioMerieux, and Natera.

His practice sits at the point where software security meets patient safety. He works with manufacturers and their engineering, QA, and regulatory teams to meet the FDA’s premarket cybersecurity expectations, including the requirements introduced under Section 524B of the FD&C Act, without stalling innovation. He is a proponent of building security into a device from the start, treating cybersecurity as part of the quality management system rather than a box checked at the end, and he is the author of The Smartest Person in the Room.

Espinosa appeared on Open Door Salon alongside Edwin Lindsay, principal consultant and managing director at CS Lifesciences, for a conversation with host Lori Ellis on the three forces that make or break a medtech launch: FDA cybersecurity, payers, and hackers. He walked through the surge in FDA cybersecurity deficiency letters, why vibe coding has no place in a regulated device, why country of origin is a signal and not a control, and why any device with a way to connect to it is a cyber device.

Frequently Asked Questions About Christian Espinosa

Who is Christian Espinosa?

Christian Espinosa is the founder and CEO of Blue Goat Cyber, a medical-device cybersecurity firm he started in 2022. He is a U.S. Air Force veteran and has worked in cybersecurity for roughly three decades. Before Blue Goat, he built and sold his previous company, Alpine Security, then turned his focus entirely to medical technology. He is also the author of The Smartest Person in the Room.

What does Christian Espinosa’s company Blue Goat Cyber do?

Christian Espinosa founded Blue Goat Cyber in 2022 as a cybersecurity firm built for medical devices. The company has supported more than 250 FDA submissions across the 510(k), De Novo, and PMA pathways, for clients including Intuitive Surgical, bioMerieux, and Natera. His practice sits where software security meets patient safety.

What does Christian Espinosa do for device manufacturers?

Christian Espinosa works with device manufacturers and their engineering, QA, and regulatory teams on the FDA’s premarket cybersecurity expectations, including the requirements introduced under Section 524B of the FD&C Act. His stated aim is to help those teams meet the bar without stalling innovation.

What does Christian Espinosa argue about cybersecurity and quality?

Christian Espinosa treats device security as a quality problem. On Open Door Salon he said: “Cybersecurity equals quality, because without the quality in cybersecurity a patient can be harmed.” He argues for building security into a device from the start and for carrying cybersecurity inside the quality management system.

What does Christian Espinosa count as a cyber device?

Christian Espinosa holds that any device with a way to connect to it is a cyber device. On Open Door Salon he said: “We can no longer pretend our device is not a cyber device.” He set out that threshold in a conversation on the three forces that make or break a medtech launch.

On Open Door Salon

“FDA, Payers & Hackers: The Three Forces That Make or Break a Launch”
Christian Espinosa & Edwin Lindsay · July 8, 2026

Episode page & show notes on Open Door Salon

“Cybersecurity equals quality, because without the quality in cybersecurity a patient can be harmed.”Christian Espinosa, on Open Door Salon (on what FDA readiness means in 2026)
“If a Chinese device went through super detailed firmware analysis and pen testing, I would trust that more than an American device that nobody even looked at.”Christian Espinosa, on Open Door Salon (on why country of origin is a signal, not a control)
“We can no longer pretend our device is not a cyber device.”Christian Espinosa, on Open Door Salon (on the rising FDA cybersecurity bar)

In this episode

  • Where a medtech launch actually breaks first
  • 37 pages of FDA cybersecurity deficiencies
  • The 180-day clock and the 20% who miss it
  • Why vibe coding fails FDA scrutiny
  • Patient safety, not data protection
  • China, supply chains, and the Contec CMS8000 backdoor
  • What FDA readiness actually means in 2026
  • Why any way to connect makes it a cyber device

Topics

Medical Device CybersecurityFDA Premarket CybersecurityPenetration TestingSoftware Bill of Materials (SBOM)IEC 62304Threat ModelingMedtech RegulatoryPatient SafetySupply Chain SecurityVulnerability Management

Watch on Open Door Salon

FDA, Payers & Hackers | Christian Espinosa & Edwin Lindsay

Open Door Salon brings life-sciences leaders into candid conversation. Every Monday, the week's takeaways land in your inbox.

Subscribe on Substack →
The Briefing

Need the life-sciences signal but short on time?

Get the free quarterly briefing: every guest from the quarter, in one sitting. What decides whether a therapy reaches a patient, gets funded, and can be trusted.