
Episode #49
MedTech Vulnerability Response w. Ken Hoyme
Vulnerability disclosures are speeding up, and the tools built to defend medical devices haven't caught up to that pace. Ken Hoyme spent his career building the safety-critical systems behind the Boeing 777 and Boston Scientific's cardiac devices, then wrote the paper that became the industry's playbook for streamlining post-market security patching. He joins Shannon Lantzy to break down why the gap between finding a vulnerability and fixing it matters more than ever, what code signing has to do with who controls a patch, and why automated insulin delivery could become the proving ground for how medical devices get updated in the future. Timestamps: [00:00] Introduction to Ken Hoyme and his paper on post-market security [01:00] Ken's path from Honeywell to Guidant to Boston Scientific [04:00] What draws Ken to life-critical systems [06:00] Ken's high school years and family background [07:00] What AAMI is and how Ken got pulled into committee work [09:00] The origin of AAMI TIR57 and its purpose [10:00] Why cybersecurity risk doesn't behave like historical safety risk [12:00] The CIA triad and why medical devices need to think beyond confidentiality [14:00] Real-world cases: MRI outages and stroke misdiagnosis risk [16:00] Why patching everything immediately isn't as simple as it sounds [17:00] The "sneaker net" era of deploying software updates [19:00] Ken's core thesis for vertically integrated devices like CGMs and insulin pumps [20:00] The parallel between hardware sustaining engineering and software patching [23:00] Why platform and application testing get tangled together [25:00] Making the case for separating verification from validation [26:00] Why it's hard to predict how a patch changes system behavior [27:00] The case for a dedicated, separately funded post-market patch team [30:00] AI as a red teamer and the coming vulnerability flood [32:00] The Linux bug that sat undetected for 27 years [33:00] Could open-source patches be trusted for medical devices [36:00] What it would take to "validate the validation" [58:00] The worst advice Ken's heard about post-market security [1:00:00] What Ken would fix about how FDA regulates devices [1:03:00] Ken's heroes and where to find him online Connect with Shannon: LinkedIn: https://www.linkedin.com/in/shannonlantzy/ Website: https://www.shannonlantzy.com/ Connect with Ken: LinkedIn: https://www.linkedin.com/in/kenhoyme/






