Transcript
Lightly edited for punctuation. Timestamps mark the start of each paragraph.
[0:00]Did you know that if your medical device has software, FDA requires a bunch of cybersecurity documentation and testing? The last thing you want to do is try to hack it together a week before you're submitting to FDA. And it takes a lot of experience to know how to do this right. Not just technical and cybersecurity, but also regulatory. Understanding exactly what FDA wants to see and how they want to see it. And by the way, it's not just documentation. They want to see independent cybersecurity testing.
[0:25]Things like penetration testing, fuzz testing, and vulnerability analysis. Preparing these documents can take your team months if they've never done it before. And worse, if they make mistakes, it can lead to huge delays with FDA, as they respond with information requests and deficiencies. And oftentimes companies have to pull their submission, which can delay them by six to nine months. At CyberMed, our whole mission is to help medical device companies with all of that cybersecurity documentation and testing that FDA requires.
[0:54]Our goal is to help ensure that your medical device is secure and that you can show FDA the evidence of that. We help companies in five different ways. First of all, if your team already put together a package, we can review it for you and provide a gap analysis. Secondly, and more commonly, companies come to us to just prepare it for them. That way, we don't waste a lot of time, we get it done in less than 30 days, and you know that it's done right the first time. And it doesn't bog down your team for weeks or months trying to do something that they're not experts at.
[1:24]The third way we help is by performing the independent cybersecurity testing that FDA demands. Things like penetration testing, fuzz testing, vulnerability analysis, and we can do this on embedded devices, mobile apps, web apps, and cloud software. Beyond the specific device, FDA expects your company to have standard operating procedures in place to help ensure that your team is properly trained and knows how to keep your device secure. So we can provide those standard operating procedures and the training your team needs to be compliant.
[1:53]And finally, your cybersecurity responsibilities don't finish when your device is cleared and on the market. In fact, that's where the bulk of your responsibilities come in, and we can provide the post-market support your company needs to stay secure and compliant. So things like SBOM (software bill of materials) management, periodic cybersecurity testing, coordinated disclosure, et cetera. One last thing. A couple of years ago, we found that clients were coming to us for cybersecurity help.
[2:21]And when we asked for their software documentation, it was either non-existent or a total mess. Given that our background is in developing medical devices, and we're experts in things like IEC 62304, we now offer that as a service. So if your team is struggling with the software documentation, things like software requirements specifications or test protocols, we can help there as well. So if your team has any questions on cybersecurity or even software documentation, give us a holler.
[2:48]We're happy to jump on a call. We're very fast, we're very responsive, we're reasonably priced, and our goal is to make this as easy as possible for your team so you can focus on innovating and bringing exciting medical devices to market instead of trying to figure out how to do cybersecurity for a medical device.