
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Christian Espinosa is the founder and CEO of Blue Goat Cyber, a medical-device cybersecurity firm he started in 2022 after a health scare put him on the other side of the technology he now works to secure. A U.S. Air Force veteran and a cybersecurity practitioner of roughly three decades, he built and sold his previous company, Alpine Security, before turning his focus entirely to medtech. Under his leadership, Blue Goat has supported more than 250 FDA submissions across the 510(k), De Novo, and PMA pathways, for clients including Intuitive Surgical, bioMerieux, and Natera.
His practice sits at the point where software security meets patient safety. He works with manufacturers and their engineering, QA, and regulatory teams to meet the FDA’s premarket cybersecurity expectations, including the requirements introduced under Section 524B of the FD&C Act, without stalling innovation. He is a proponent of building security into a device from the start, treating cybersecurity as part of the quality management system rather than a box checked at the end, and he is the author of The Smartest Person in the Room.
Espinosa appeared on Open Door Salon alongside Edwin Lindsay, principal consultant and managing director at CS Lifesciences, for a conversation with host Lori Ellis on the three forces that make or break a medtech launch: FDA cybersecurity, payers, and hackers. He walked through the surge in FDA cybersecurity deficiency letters, why vibe coding has no place in a regulated device, why country of origin is a signal and not a control, and why any device with a way to connect to it is a cyber device.
On Open Door Salon
“FDA, Payers & Hackers: The Three Forces That Make or Break a Launch”
Christian Espinosa & Edwin Lindsay · July 8, 2026
Episode page & show notes on Open Door Salon
In this episode
- Where a medtech launch actually breaks first
- 37 pages of FDA cybersecurity deficiencies
- The 180-day clock and the 20% who miss it
- Why vibe coding fails FDA scrutiny
- Patient safety, not data protection
- China, supply chains, and the Contec CMS8000 backdoor
- What FDA readiness actually means in 2026
- Why any way to connect makes it a cyber device
Topics
Watch on Open Door Salon
Open Door Salon brings life-sciences leaders into candid conversation. Every Monday, the week's takeaways land in your inbox.
Subscribe on Substack →