{
  "generated": "2026-09-05T00:38:36.859Z",
  "site": {
    "name": "Stratigos Security",
    "url": "https://stratigossecurity.com/",
    "tagline": "High-assurance cybersecurity for regulated and safety-critical industries. Founded by Beau Woods, former FDA Entrepreneur in Residence.",
    "summary": "Stratigos Security provides penetration testing, threat modeling, security advisory, and vCISO services for medical device manufacturers and high-tech companies. The team helped write the FDA's premarket and postmarket cybersecurity guidance and has been engaged with the agency since 2013."
  },
  "roles": [
    "regulatory",
    "engineering",
    "quality",
    "clinical",
    "executive",
    "security",
    "research",
    "press",
    "other"
  ],
  "pages": [
    {
      "id": "home",
      "url": "https://stratigossecurity.com/",
      "path": "/",
      "external": false,
      "title": "Home",
      "description": "Overview of Stratigos Security services and positioning",
      "summary": "The front page: penetration testing, threat modeling, and submission-ready documentation for medical device manufacturers, plus testing and advisory for other high-tech companies.",
      "type": "overview",
      "audience": [],
      "answers": [
        "What does Stratigos Security do?",
        "Who is Stratigos Security?",
        "What services does Stratigos offer?"
      ],
      "keywords": [
        "Stratigos Security",
        "overview",
        "services",
        "medical device cybersecurity"
      ],
      "headings": [],
      "text": "Medical device cybersecurity Cybersecurity testing designed by people who helped write the FDA cybersecurity guidance. From penetration testing and threat modeling to submission-ready documentation – we handle the cybersecurity so you can focus on the device. Cybersecurity testing Web, mobile, cloud, and network penetration testing to uncover weaknesses before adversaries do. Our experts simulate real-world threats with findings prioritized by your organization's defined risks. Cybersecurity advisory & vCISO Strategic guidance to build and manage a security program that works. From virtual CISO services to compliance alignment and risk management, we help you integrate security into the way your business already operates. We helped write the rules Our founder helped shape regulatory expectations for cybersecurity, in medical devices, automotive, home IoT, and other areas, working with US and international regulatory bodies through I Am The Cavalry since 2013. For instance, he built a medical device cybersecurity test lab recognized by a sitting FDA commissioner as a model for what good testing looks like, wrote A Hippocratic Oath for Connected Medical Devices , and served as Entrepreneur in Residence there helping to define safe and secure pathways to market. Our team brings the same depth: collectively, hundreds of cybersecurity assessments across safety-critical systems, like medical devices, the electrical grid, and water facilities. Our testing methodology, report structure, and regulatory support are calibrated for real-world hazards, written in language that engineering and quality professionals can understand, and that meet regulatory expectations – because we helped define what that looks like. A track record you can rely on We have supported medical device regulatory submissions from Class I through Class III, through 510(k), PMA, De Novo, and IDE pathways, including novel devices and first-to-market submissions where regulatory scrutiny is highest. Across automated insulin delivery, surgical robotics, bioelectronic medicine, and diagnostics, our testing holds up under the level of review your device will face. Your full cybersecurity testing partner From scoping and threat modeling through testing, reporting, and remediation support, a single Stratigos team carries your engagement from first scope to final report and through your regulatory submission. We produce the testing evidence and documentation your submission needs and we stay with you through review. Expert guidance throughout the process From our first conversation until your product hits the market, Stratigos provides guidance and support to demystify cybersecurity concepts (without trying to make you an expert), tell you what we've seen work (without prescribing your path), and support you when questions arise (rather than drop a report and run). Experience tailored to your device Expert-driven testing within your unique context that goes beyond what automated scanners produce or standards can anticipate. Stratigos covers what others can't, like touch interfaces, physical tamper resilience, and custom wireless protocols. Every finding is contextualized for clinical and regulatory relevance, producing reports that engineers, regulatory teams, and reviewers can work with directly. Why Stratigos Five reasons manufacturers choose us for consequential submissions",
      "priority": 3
    },
    {
      "id": "medical-devices",
      "url": "https://stratigossecurity.com/medical-devices/",
      "path": "/medical-devices/",
      "external": false,
      "title": "Medical Devices",
      "description": "FDA-ready cybersecurity testing for medical device manufacturers",
      "summary": "The medical device practice in one page: penetration testing, threat modeling, the readiness quickstart, and submission documentation, and how they fit together from scoping through FDA review.",
      "type": "overview",
      "audience": [
        "regulatory",
        "engineering",
        "quality",
        "executive",
        "clinical"
      ],
      "answers": [
        "What medical device cybersecurity services does Stratigos offer?",
        "How does Stratigos support an FDA premarket submission?",
        "What does a medical device cybersecurity engagement include?",
        "Do you support postmarket monitoring and periodic retesting?",
        "Which device classes and submission pathways have you supported?",
        "How should a hospital or health system assess a device maker's cybersecurity?",
        "Can you help a healthcare delivery organization evaluate a medical device vendor?"
      ],
      "keywords": [
        "FDA",
        "premarket",
        "postmarket",
        "submission",
        "Class II",
        "Class III",
        "510(k)",
        "PMA",
        "De Novo",
        "IDE",
        "cyber device",
        "section 524B",
        "retest",
        "monitoring",
        "insulin pump",
        "surgical robot",
        "diagnostics",
        "hospital",
        "health system",
        "HDO",
        "procurement",
        "MDS2",
        "vendor security"
      ],
      "headings": [],
      "text": "Medical device penetration testing Regulatory-aligned cybersecurity and penetration testing covering firmware, hardware, wireless protocols, cloud APIs, and application layers. Every finding contextualized for clinical and regulatory relevance. Reports built so engineering, quality, and regulatory professionals can use them. Threat modeling & security architecture review Scoping, threat modeling, and security architecture review aligned to your device's intended use, risk profile, and regulatory pathway. The foundation that ensures testing coverage matches what reviewers expect to see. Medical device cybersecurity quickstart Get feedback on your device's readiness to withstand scrutiny of a threat model, penetration test, and regulatory review, as well as understand what needs to be done to match regulatory expectations and why it matters to safety and effectiveness. Regulatory documentation quality Typical cybersecurity outputs are often at odds with quality management system and regulatory submission artifacts. Reviewers expect findings contextualized against your other documentation and traceable to hazard analysis and threat model. And quality processes frequently require sound evidence and methodological support to substantiate findings. Unfortunately most off-the-shelf penetration testing reports do not satisfy these. How we deliver cyber certainty Clinical contextualization A cardiac rhythm management device has a fundamentally different risk profile than a glucose monitor. Understanding this clinical context is vital in scoping, performing testing, and creating a report appropriately prioritized for your specific device and its intended use. Otherwise, you may experience excess cost, delay, and risk to your submission. Evidence standards, expertise, and independence Regulatory guidance requires test reports to document both the technical findings and the independence and expertise of the testers. Stratigos' experience and expertise drives us to a rigorous standard: each finding documents a set of techniques that produced a specific condition, with methodology and evidence sufficient for an independent party to reproduce it. That discipline makes our reports defensible under any level of scrutiny, including reviewers, legal counsel, and independent experts. How we deliver cyber certainty Remediation and retest rigor Regulators expect to see a documented remediation and retesting cycle. Our post-remediation testing addendum documents each original finding's status in an updated device version, including what was retested, what was observed, and how the evidence supports closure. The addendum passes the same independent review process as the original report, giving you a clean, regulator-ready record of the test-remediate-test cycle. Medical device penetration testing demands a specialized toolkit: firmware reverse engineering, wireless protocol fuzzing, hardware interface analysis, and vulnerability chaining in a safety-critical context. Each member of our team has spent years or decades in these specialties and our methodology reflects that focus. When you engage Stratigos, you get a team that does this work every day for manufacturers for whom safety and effectiveness is a top priority. Timeline is the real economics For most device programs, development and regulatory timelines influence total cost far more than testing fees. A six-month delay that burns $30K per day in overhead and lost sales is a huge financial burden. Cybersecurity testing that's designed for submission success from the start buys down the greatest risk and cost. Our team directly informed the cybersecurity guidance that reviewers use today. That perspective allows us to anticipate what reviewers expect and provide output that survives regulatory scrutiny. We speak the language of firmware, cloud, and clinical workflows, and we frame results in ways your quality team can immediately use in submissions and medical device files. We deliver reports yo…",
      "priority": 1
    },
    {
      "id": "medical-device-penetration-testing",
      "url": "https://stratigossecurity.com/medical-devices/penetration-testing/",
      "path": "/medical-devices/penetration-testing/",
      "external": false,
      "title": "Medical Device Penetration Testing",
      "description": "FDA-aligned penetration testing methodology for medical devices",
      "summary": "Regulatory-aligned penetration testing for medical devices across firmware, hardware interfaces, wireless, cloud back-ends, and applications, with evidence-grade findings written for clinical and regulatory review.",
      "type": "service",
      "audience": [
        "engineering",
        "regulatory",
        "quality"
      ],
      "answers": [
        "How is medical device penetration testing different from a web or network pentest?",
        "What does FDA expect from penetration testing in a premarket submission?",
        "What does a medical device penetration test cover?",
        "How are penetration test findings documented for FDA reviewers?",
        "Do you test firmware, wireless protocols, and hardware interfaces?"
      ],
      "keywords": [
        "penetration testing",
        "pentest",
        "firmware",
        "wireless",
        "RF",
        "Bluetooth",
        "BLE",
        "hardware interfaces",
        "JTAG",
        "UART",
        "embedded",
        "companion app",
        "mobile app",
        "cloud API",
        "DICOM",
        "fuzzing",
        "exploit",
        "adversary",
        "evidence",
        "test report",
        "reproduction steps",
        "clinical hazard",
        "retest",
        "retest addendum"
      ],
      "headings": [],
      "text": "Scope is developed from the manufacturer's hazard analysis and threat model, prioritizing the clinical effects the manufacturer most needs to investigate. Penetration testing is modeled on adversary behavior, which is standards-defiant by nature. Until adversaries are constrained by checklists, penetration testing shouldn't be either. It IS NOT a compliance audit Measuring against NIST, OWASP, or IEC produces a record of steps taken. Penetration testing produces evidence about what effects can be demonstrated. It IS NOT a pass or fail Findings are inputs to the manufacturer's risk management process. Whether a finding represents acceptable or unacceptable risk is a clinical and business determination that belongs with the manufacturer. Firmware and embedded systems Reverse engineering, binary analysis, and identification of hardcoded credentials, cryptographic weaknesses, and authentication bypasses in embedded components. Fuzz testing and protocol analysis across BLE, Wi-Fi, proprietary RF, Zigbee, and TCP/IP communication layers. Cloud and API infrastructure Assessment of cloud back-ends, companion apps, and API endpoints that connect to or control the device. Physical attack surface evaluation including debug ports, JTAG, UART, and removable storage. Mobile and companion applications Static and dynamic analysis of iOS and Android apps that interface with the device, including runtime manipulation and local data storage review. Vulnerability chaining Mapping the pathways, techniques, and conditions required to produce each finding, ensuring context is accurately described for regulatory review. Scoping and threat modeling We identify exposure surfaces aligned to your device architecture, intended use, foreseeable misuse, and existing risk controls. The resulting test plan translates the scoping conversation into a documented agreement on what will be tested, why, and under what conditions. Your team reviews it for scope accuracy before testing begins. Exposure surface mapping We identify the device's input vectors: open ports, active protocols, radio frequencies, API endpoints, physical interfaces, and any other path through which external input reaches the device or its supporting systems. Manual expert testing Testers work through the interfaces, protocols, and components defined in the test plan using targeted manual techniques informed by the priority objectives. The test plan is a starting point, it does not constrain which techniques are applied or in what sequence. When a condition in one area opens a promising path in an adjacent area, the team follows it. Reporting, remediation, and retest We share preliminary results with your technical team to confirm factual accuracy before delivering the final report. The final report passes an independent review for evidentiary sufficiency: is the cause-to-effect chain documented, is it relevant to a genuine hazard or threat, and can each finding be reproduced from the steps as written? When findings require remediation, we provide a post-remediation testing addendum that documents whether each finding has been addressed, with evidence – giving regulators the test-remediate-test cycle they expect. After delivery, we support your team through the regulatory review process. That can include joining calls with reviewers to explain methodology, clarifying findings in written responses, or providing additional documentation to supplement the submission. We represent the testing performed, while your team can speak precisely to risk assessment, remediation decisions, and clinical significance. Documented agreement on scope, objectives, and testing conditions. Referenced in the final report and suitable for inclusion in your quality documentation. Regular testing updates Routine updates during the engagement (such as via email, Slack, or Teams): where we are, what we've found, what we're doing next. Preliminary technical briefing Results shared within a week of testing completion for …",
      "priority": 1
    },
    {
      "id": "threat-modeling",
      "url": "https://stratigossecurity.com/medical-devices/threat-modeling/",
      "path": "/medical-devices/threat-modeling/",
      "external": false,
      "title": "Medical Device Threat Modeling",
      "description": "Threat modeling aligned to AAMI TIR57, ISO 14971, IEC 81001-5-1",
      "summary": "Threat modeling for medical devices aligned to AAMI TIR57, ISO 14971, and IEC 81001-5-1, as a standalone engagement or the foundation of a security risk management file.",
      "type": "service",
      "audience": [
        "engineering",
        "quality",
        "regulatory"
      ],
      "answers": [
        "How do I threat model a medical device?",
        "Which standards apply to medical device threat modeling?",
        "How does threat modeling connect to ISO 14971 risk management?",
        "Is a threat model required for an FDA cybersecurity submission?",
        "What is the MDIC threat modeling playbook?"
      ],
      "keywords": [
        "threat modeling",
        "threat model",
        "AAMI TIR57",
        "ISO 14971",
        "IEC 81001-5-1",
        "STRIDE",
        "attack tree",
        "security risk management",
        "hazard analysis",
        "MDIC playbook",
        "MITRE",
        "security architecture review"
      ],
      "headings": [],
      "text": "Device architecture review We map your device's components, interfaces, data flows, and communication pathways to identify the full exposure surface. This includes the device itself, companion applications, cloud infrastructure, wireless protocols, and any third-party components or libraries. Threat identification We identify potential threats aligned to your device's clinical context. This goes beyond generic threat libraries: we evaluate threats specific to your device category and its intended use, drawing on real-world examples. Risk characterization Threats are characterized by potential impact on patient safety and clinical effectiveness. This characterization maps directly to your hazard analysis and supports the risk management documentation regulators expect. Testing scope definition The threat model directly defines what penetration testing should cover and why. This ensures testing coverage is focused on high-relevance attack surfaces and produces the traceability that reviewers look for between threat identification and testing evidence. Our threat modeling methodology aligns with AAMI TIR57, ISO 14971, IEC 81001-5-1, and FDA premarket guidance. The output integrates with your broader risk management and quality system documentation. What we deliver How you get value from our threat modeling help Two paths in Standalone or integrated with full penetration testing Threat modeling can be engaged as a standalone service, which can reduce timeline and costs for manufacturers early in development who want to build security in from the design phase, or as the first step of a full penetration testing engagement. Many clients start here and move into testing once the scope is defined. If you've already completed a threat model with another firm or internally, we can review it before testing begins.",
      "priority": 1
    },
    {
      "id": "cyber-certainty",
      "url": "https://stratigossecurity.com/medical-devices/cyber-certainty/",
      "path": "/medical-devices/cyber-certainty/",
      "external": false,
      "title": "Cyber Certainty",
      "description": "Submission-ready cybersecurity documentation, eSTAR-ready reports, deficiency response",
      "summary": "Submission-ready cybersecurity documentation for medical devices: eSTAR-ready reports, traceability from threat model to test evidence, and responses to FDA cybersecurity deficiencies.",
      "type": "service",
      "audience": [
        "regulatory",
        "quality",
        "executive"
      ],
      "answers": [
        "What cybersecurity documentation does an FDA premarket submission need?",
        "How do I respond to an FDA cybersecurity deficiency letter?",
        "What goes in the eSTAR cybersecurity section of a 510(k), De Novo, or PMA?",
        "What does section 524B require for cyber devices?",
        "What do FDA reviewers expect in the cybersecurity section of a submission?",
        "Do you provide an SBOM and a cybersecurity management plan for the submission?",
        "How do I prepare the cybersecurity part of a premarket submission?"
      ],
      "keywords": [
        "eSTAR",
        "deficiency response",
        "additional information request",
        "hold letter",
        "SBOM",
        "software bill of materials",
        "cybersecurity management plan",
        "traceability",
        "labeling",
        "section 524B",
        "cyber device",
        "premarket guidance",
        "510(k)",
        "PMA",
        "De Novo",
        "reviewer",
        "documentation",
        "evidence",
        "report",
        "test report",
        "attestation",
        "letter of attestation",
        "retest addendum",
        "submission package"
      ],
      "headings": [],
      "text": "Submission-ready penetration test reports Our reports are formatted for inclusion in regulatory submissions, eSTAR packages, and medical device files. Every finding documents the specific methodology used, the observed cause and conditions, and the resulting effect, with evidence sufficient for an independent party to reproduce it. Your regulatory team uses our output directly. Remediation and retest reports When penetration testing identifies findings, regulators expect a documented remediation and retesting cycle. Our post-remediation testing addendum references original finding IDs, documents the updated device version, applies the original technique (or notes why it no longer applies), and records the result. It passes the same independent review process as the original report. Cybersecurity deficiency response If you've received a cybersecurity deficiency letter or information request, we help you understand what the reviewer is asking for, prepare the response documentation, and conduct additional testing to address the specific concerns raised, if needed. We can join calls with reviewers to explain methodology or clarify findings. What we deliver Outputs and assistance to support your submission Independent review Every deliverable passes a separate evidentiary check Every Stratigos deliverable passes an independent review before delivery. A qualified reviewer who was not the primary tester examines all findings for evidentiary sufficiency: is the cause-to-effect chain documented, is it relevant to a real hazard or threat, and can the finding be reproduced from the steps as written? The independence and completeness of the test report as a standalone document is a reviewable characteristic of any submission. Why it matters Three sentences in 60 pages – one of the highest-scrutiny areas in the submission Penetration testing is only three sentences in the 60-page premarket cybersecurity guidance, yet it's consistently one of the highest-scrutiny areas of a submission. Reviewers look for a complete, independent test report with findings that connect cleanly to the device's hazard analysis and align with the product's version history. Our documentation is designed to meet that expectation on the first read, designed by people who understand the review process from the inside, structured to give reviewers what they need, and timed to keep your submission moving.",
      "priority": 1
    },
    {
      "id": "quickstart",
      "url": "https://stratigossecurity.com/medical-devices/quickstart/",
      "path": "/medical-devices/quickstart/",
      "external": false,
      "title": "Medical Device Cybersecurity Quickstart",
      "description": "Rapid readiness review of a device's cybersecurity posture ahead of threat modeling, testing, and regulatory review",
      "summary": "A short readiness review that tells you where a device stands before threat modeling, penetration testing, or regulatory review, with a prioritized plan for what to do next.",
      "type": "service",
      "audience": [
        "executive",
        "engineering",
        "regulatory"
      ],
      "answers": [
        "Where should we start with medical device cybersecurity?",
        "How ready is our device for FDA cybersecurity review?",
        "What is the first step before a penetration test or threat model?",
        "Is there a quick gap assessment for a startup or an early-stage device?"
      ],
      "keywords": [
        "readiness",
        "gap assessment",
        "quickstart",
        "getting started",
        "first step",
        "roadmap",
        "early stage",
        "startup",
        "checklist"
      ],
      "headings": [],
      "text": "An expert read on the device's cybersecurity posture, resilience against adversaries (penetration test readiness), and how it compares against regulatory guidance. A prioritized gap list What needs to change to address safety and effectiveness concerns from cybersecurity sources, as well as meet regulatory expectations. A plan for what comes next A recommended path through threat modeling, testing, and documentation that fits your device and your timeline. What you get What you walk away with Who it's for Early enough to change the outcome The quickstart fits teams early in the process, while there is still time to change course cheaply. Most clients engage ahead of a submission, a redesign, or their first penetration test. Nothing is wasted if deeper work follows: the quickstart output becomes the starting point for scoping and testing. Often information learned in the quickstart reduces cost and delay from cybersecurity issues just before submission.",
      "priority": 2
    },
    {
      "id": "penetration-testing",
      "url": "https://stratigossecurity.com/penetration-testing/",
      "path": "/penetration-testing/",
      "external": false,
      "title": "Penetration Testing",
      "description": "General penetration testing services for high-tech companies",
      "summary": "Manual penetration testing for high-tech companies outside the medical device practice: web applications and APIs, networks, cloud, mobile, and connected devices, with findings prioritized by real exploitability.",
      "type": "service",
      "audience": [
        "engineering",
        "security",
        "executive"
      ],
      "answers": [
        "Do you do web application, API, or network penetration testing outside medical devices?",
        "What does a penetration test include and what is delivered?",
        "Do you test cloud environments and mobile apps?",
        "Do you test IoT and connected devices that are not medical devices?"
      ],
      "keywords": [
        "penetration testing",
        "web application",
        "API",
        "network",
        "cloud",
        "AWS",
        "Azure",
        "GCP",
        "mobile",
        "iOS",
        "Android",
        "IoT",
        "connected devices",
        "OWASP",
        "retest",
        "red team"
      ],
      "headings": [],
      "text": "Web application testing Manual testing of web apps and APIs for injection vulnerabilities, authentication weaknesses, session flaws, and logic errors. Covers OWASP Top 10 and beyond, with manual verification of all findings. Network penetration testing Internal and external network testing to identify exposed services, misconfigurations, privilege escalation paths, and lateral movement opportunities. Delivered with clear remediation guidance prioritized by actual business impact. Cloud security testing Assessment of cloud environments (such as AWS, Azure, and GCP) for misconfigured resources, overprivileged access, and exposed data. Includes identity and access management review and container/serverless configuration analysis. IoT and connected device testing Security testing for connected devices across firmware, hardware interfaces, wireless protocols, and cloud back-ends. Particularly relevant for manufacturers whose devices operate in high-stakes environments outside the medical device regulatory pathway. Mobile application testing Static and dynamic analysis of iOS and Android applications, including reverse engineering, runtime manipulation testing, and API security review. Manual, expert-driven testing combined with targeted automated tooling Findings contextualized by business impact and actual exploitability Clear remediation guidance that engineering teams can act on immediately Retest included to confirm fixes are effective Reports formatted for executive, technical, and compliance audiences Medical devices Testing a medical device? Our medical device practice pairs penetration testing with clinical context and evidence-grade reporting built for regulatory submission. See medical device penetration testing → Service areas Five disciplines under one engagement model What sets our testing apart Manual depth, business context, and reports your team can use {apart.map((item) => )}",
      "priority": 2
    },
    {
      "id": "advisory",
      "url": "https://stratigossecurity.com/advisory/",
      "path": "/advisory/",
      "external": false,
      "title": "Advisory",
      "description": "Security advisory and vCISO services",
      "summary": "Virtual CISO and security advisory: program development, risk assessment, compliance alignment with HIPAA, SOC 2, ISO 27001, NIST, IEC 62443, and FDA expectations, and supply chain risk.",
      "type": "service",
      "audience": [
        "executive",
        "security",
        "quality"
      ],
      "answers": [
        "Do you offer virtual CISO or fractional CISO services?",
        "Can you help build a security program or roadmap?",
        "Can you help with SOC 2, ISO 27001, HIPAA, or NIST alignment?",
        "Do you assess third-party or supply chain cybersecurity risk?",
        "Can you present cybersecurity risk to a board or investors?",
        "Do you offer vCISO services for a startup or a small medical device company?"
      ],
      "keywords": [
        "vCISO",
        "virtual CISO",
        "fractional CISO",
        "security program",
        "governance",
        "board",
        "risk assessment",
        "compliance",
        "HIPAA",
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "IEC 62443",
        "supply chain",
        "vendor risk",
        "due diligence",
        "AI vendors",
        "startup",
        "small company",
        "security leadership"
      ],
      "headings": [],
      "text": "Virtual CISO (vCISO) Ongoing strategic cybersecurity leadership for organizations that need a senior-level voice without a full-time executive. Covers strategy, board and investor communication, vendor oversight, incident response planning, and team development. Security program development Build or strengthen a cybersecurity program from the ground up. We assess your current state, identify gaps against relevant frameworks (NIST, ISO 27001, HIPAA, SOC 2), and create a practical roadmap your team can execute. Risk assessment and management Identify, prioritize, and communicate cybersecurity risk in business terms. Useful for board presentations, investor due diligence, and regulatory submissions where risk management documentation is required. Compliance alignment Guidance on aligning your cybersecurity posture with the frameworks and regulations that matter to your business: HIPAA, SOC 2, ISO 27001, NIST CSF, IEC 62443, FDA cybersecurity guidance, and others. Cyber supply chain risk Third-party and supply chain cybersecurity assessments to identify and manage risk. This may include vendor diligence, product supply chain cybersecurity, or managing third-party technology platforms (such as AI models or SaaS providers). Service areas Five engagements, scoped to where you are",
      "priority": 2
    },
    {
      "id": "why-us",
      "url": "https://stratigossecurity.com/why-us/",
      "path": "/why-us/",
      "external": false,
      "title": "Why Us",
      "description": "Differentiators and five questions to ask any medical device penetration testing firm",
      "summary": "Why manufacturers choose Stratigos for consequential submissions, and five questions to ask any medical device penetration testing firm you are evaluating.",
      "type": "company",
      "audience": [
        "executive",
        "regulatory",
        "quality"
      ],
      "answers": [
        "Why choose Stratigos over another penetration testing firm?",
        "What questions should I ask a medical device penetration testing firm?",
        "How do I compare or evaluate medical device cybersecurity vendors?",
        "What is Stratigos's track record with FDA submissions?",
        "What makes your reports hold up under regulatory review?"
      ],
      "keywords": [
        "differentiators",
        "compare",
        "evaluate",
        "vendor selection",
        "questions to ask",
        "track record",
        "evidence-grade",
        "startup speed",
        "intersectional expertise",
        "shortlist"
      ],
      "headings": [],
      "text": "We helped write the rules Our founder, Beau Woods , has been evaluating medical device cybersecurity for over 20 years and served as an Entrepreneur in Residence at the FDA. Beau is one of a handful of cybersecurity professionals to inform medical device regulatory guidance. That perspective shapes our testing methodology, report structure, and ongoing support, calibrated to what engineering, quality, and regulatory teams can use. Intersectional expertise Medical device cybersecurity requires fluency across three domains: cybersecurity research, medical device safety, and regulatory process. Our team operates across all three in a single engagement, which means scoping decisions, testing choices, and report language all reflect what each discipline needs. That intersection is where Stratigos was built to work. A track record you can rely on We have supported medical device regulatory submissions from Class I through Class III, through 510(k), PMA, De Novo, and IDE pathways, including novel devices and first-to-market submissions where regulatory scrutiny is highest. Across automated insulin delivery, surgical robotics, bioelectronic medicine, and diagnostics, our testing holds up under the level of review your device will face. Evidence-grade documentation Our reports are designed to withstand scrutiny from regulatory reviewers, legal counsel, and independent experts. Every finding documents a specific, directly observable condition with evidence sufficient for an independent party to reproduce it. The deliverable is suitable for engineering teams, medical device files, eSTAR packages, and submissions for regulatory review, as appropriate. We work with you, not around you We share preliminary results, provide regular updates during testing, and work alongside your team from scoping through submission support. We view this dialog as integral to ensuring device safety and effectiveness, as well as producing better outputs. When reviewers have questions after submission, we're available to join calls and explain methodology directly. We deliver results your team can act on in days to weeks, not months. For many of our clients, that retesting can begin even as the final report is reaching them. For manufacturers working against a submission deadline, that efficiency saves effort and cost. How has your team worked with regulatory agencies directly to understand their intent and expectations? Can you show me a sample report format your clients include in a submission package? How do you ensure your results reflect real world threats, not just theoretical ones? How much of your work is focused specifically on medical device penetration testing? How do you capture the conditions and methodology of a finding so that we can assess its risk within a clinical context? Differentiators Six attributes that show up in every engagement How to choose a partner Five questions to ask any medical device penetration testing firm Every medical device program deserves a testing partner with genuine fluency across cybersecurity, device safety, and regulatory process. If you're evaluating firms, these questions help surface what matters most. {questions.map((q) => )} We're happy to answer all of these questions for Stratigos. Ask any firm you're considering to do the same.",
      "priority": 2
    },
    {
      "id": "about",
      "url": "https://stratigossecurity.com/about/",
      "path": "/about/",
      "external": false,
      "title": "About",
      "description": "Beau Woods bio, team credentials, company history",
      "summary": "Who we are: founder Beau Woods's work with the FDA on cybersecurity guidance, the team's standards and testing background, and press appearances.",
      "type": "company",
      "audience": [
        "executive",
        "press",
        "research"
      ],
      "answers": [
        "Who is Beau Woods?",
        "Who founded Stratigos Security and when?",
        "What is Stratigos's experience with the FDA?",
        "Has Stratigos been in the press or on television?",
        "What is the background of the Stratigos team?"
      ],
      "keywords": [
        "founder",
        "CEO",
        "biography",
        "bio",
        "credentials",
        "Entrepreneur in Residence",
        "FDA EIR",
        "I Am The Cavalry",
        "DEF CON",
        "CISA",
        "Atlantic Council",
        "team",
        "company history",
        "2012",
        "press",
        "leadership",
        "DICOM",
        "IHE",
        "RSNA"
      ],
      "headings": [],
      "text": "Founding story Built for a gap nobody else was filling Medical device cybersecurity sits at the intersection of three disciplines that rarely reside together in a single team: cybersecurity research, medical device safety, and regulatory process. That gap used to show up at the worst possible time: late-stage submission, with questions about cybersecurity that no single advisor could fully answer. Stratigos closes that gap. Our team brings together cybersecurity practitioners, regulatory advisors with direct FDA experience, and medical device safety experts who operate fluently across all three disciplines. We help teams understand what to do, how to do it, and how to demonstrate to regulators that they've done it. Our founder's work has focused on medical device cybersecurity for most of the last 25 years, including launching Stratigos in 2012. Manufacturers bring us their most consequential submissions because our methodology has been refined through dozens of engagements with life-sustaining devices, and because we remain actively involved in shaping the cybersafety principles our work supports. Leadership Team Beau Woods Founder CEO Beau Woods is the founder and CEO of Stratigos Security. He has over 20 years of experience advising organizations on cybersecurity and risk management, with particular focus on the intersection of cybersecurity and safety for connected technology. Beau served as an Entrepreneur in Residence at the U.S. Food and Drug Administration, where he directly informed the premarket and postmarket cybersecurity guidance that reviewers use today, and he continues to advise the agency on cybersecurity matters. He helped shape the FDA's Software as a Medical Device (SaMD) Precertification Program. He has also served as a Senior Advisor with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and is a Cyber Safety Innovation Fellow with the Atlantic Council. Beau is a leader of the I Am The Cavalry grassroots initiative, leads the public policy space at DEF CON, and helped found the Biohacking Village Device Lab, the ICS Village, the Aerospace Village, and Hack the Sea. He has advised Congress and the White House on cybersecurity matters and has consulted across energy, healthcare, automotive, aviation, rail, and IoT industries. Beau founded Stratigos Security in 2012. Prior to that, he was Managing Principal Consultant at Dell SecureWorks. He holds a BS in Psychology from the Georgia Institute of Technology. Beau has built a team with deep, specialized experience in medical device security, including expertise testing and refining interoperability and security standards with organizations like IHE and RSNA, and years of hands-on security testing on DICOM imaging protocols and embedded device firmware. Together, the team combines regulatory fluency with the kind of technical depth that most cybersecurity firms cannot match. ABC News Live Prime brought Beau on as its cybersecurity expert during the July 2024 global technology outage.",
      "priority": 3
    },
    {
      "id": "contact",
      "url": "https://stratigossecurity.com/contact/?via=agents-pointer",
      "path": "/contact/?via=agents-pointer",
      "external": false,
      "title": "Contact",
      "description": "Schedule a call with Stratigos Security",
      "summary": "The contact form is the fastest way to reach a person at Stratigos. Replies within one business day.",
      "type": "contact",
      "audience": [],
      "answers": [
        "How do I contact Stratigos?",
        "How much does a medical device penetration test cost?",
        "How do I get a quote or a proposal?",
        "How quickly can an engagement start?",
        "Can I schedule a call with a Stratigos expert?"
      ],
      "keywords": [
        "contact",
        "quote",
        "pricing",
        "cost",
        "budget",
        "proposal",
        "scope",
        "timeline",
        "availability",
        "schedule a call",
        "hire",
        "engage",
        "talk to us"
      ],
      "headings": [],
      "text": "Send us a note Tell us about your project First name Last name Work email Company Service interested in Medical device cybersecurity testing Penetration testing Security advisory vCISO Not sure yet Tell us about your project (optional) Get in touch Direct contact Email info@stratigossecurity.com LinkedIn linkedin.com/company/stratigos-security",
      "priority": 3
    },
    {
      "id": "insights",
      "url": "https://stratigossecurity.com/insights/",
      "path": "/insights/",
      "external": false,
      "title": "Insights",
      "description": "Thought leadership on medical device cybersecurity",
      "summary": "Articles, talks, and press on medical device cybersecurity from the Stratigos team.",
      "type": "company",
      "audience": [
        "research",
        "press",
        "regulatory"
      ],
      "answers": [
        "What has Stratigos written or said publicly?",
        "Where can I read Stratigos's analysis of new guidance?"
      ],
      "keywords": [
        "articles",
        "blog",
        "insights",
        "talks",
        "podcast",
        "webinar",
        "press",
        "writing"
      ],
      "headings": [],
      "text": "Latest Recent writing and appearances {posts.map((post) => ( ))}",
      "priority": 3
    },
    {
      "id": "coordinated-vulnerability-disclosure",
      "url": "https://stratigossecurity.com/coordinated-vulnerability-disclosure/",
      "path": "/coordinated-vulnerability-disclosure/",
      "external": false,
      "title": "Coordinated Vulnerability Disclosure",
      "description": "How Stratigos discloses vulnerabilities it finds and how to report one to Stratigos",
      "summary": "How to report a vulnerability to Stratigos and how we disclose vulnerabilities we find in others’ products, including safe harbor and timelines.",
      "type": "policy",
      "audience": [
        "security",
        "research",
        "engineering"
      ],
      "answers": [
        "How do I report a vulnerability to Stratigos?",
        "What is Stratigos's coordinated vulnerability disclosure policy?",
        "How does Stratigos disclose vulnerabilities it finds?",
        "Is there safe harbor for security researchers?"
      ],
      "keywords": [
        "coordinated vulnerability disclosure",
        "CVD",
        "report a vulnerability",
        "security.txt",
        "safe harbor",
        "researcher",
        "disclosure timeline",
        "bug bounty",
        "security@"
      ],
      "headings": [],
      "text": "We discover, review, and confirm the vulnerability. We draft a notification and send it to the vendor\\'s security contacts. We notify other relevant parties (such as CISA, CERT/CC, and MITRE) where appropriate. We work with the vendor to establish timelines, milestones, and remediation processes. The vendor develops a fix, publishes an update, and notifies customers. We release a brief discovery statement. Internal and external tracking codes CVSS v4.0 severity scores Affected vendor(s), product(s), and versions Discovery and reporting dates Issue summaries and details Proof-of-concept validation procedures Recommendations for affected parties Reporting a vulnerability to us If you believe you've found a security or privacy issue in anything we build or operate, we want to hear from you. Email security@stratigossecurity.com with enough detail for us to reproduce the issue: the affected system or product, the steps you took, and any proof-of-concept material you can share. What you can expect from us: We'll acknowledge your report within seven days. We'll keep you informed as we confirm, remediate, and disclose the issue. We'll credit you for the discovery if you'd like, or keep your involvement confidential if you prefer. We will not pursue or support legal action in response to good-faith security research that avoids harm to people, data, and services. We also help unaffiliated researchers navigate coordinated disclosure with other vendors. If you've found something and aren't sure what to do next, contact us and we'll help you work through it. When we find vulnerabilities We believe security research works best when every party acts on its own judgment. We operate transparently with vendors and document our procedures. We don't substitute our judgment for anyone else's, and we expect the same respect in return. Our policy prioritizes the interests of our clients, our firm, and the general public – which may mean disclosing vulnerability information publicly or privately. Our coordinated disclosure process {processSteps.map((s) => )} If a vendor is unresponsive or acts contrary to the public interest, we reserve the right to disclose the vulnerability publicly or privately without further notice. Disclosure documentation Our standard notifications include: {documentationFields.map((f) => )} Resources Our practice aligns with these standards and community resources: Establishing a CVD Program to Work with Security Researchers – joint guide from CISA and international partners (2026) disclose.io – standardized safe harbor and disclosure policy framework ISO/IEC 29147 – Vulnerability disclosure ISO/IEC 30111 – Vulnerability handling processes",
      "priority": 3
    },
    {
      "id": "privacy",
      "url": "https://stratigossecurity.com/privacy/",
      "path": "/privacy/",
      "external": false,
      "title": "Privacy & Security",
      "description": "Privacy practices and data handling",
      "summary": "Privacy practices and data handling for this website, including the note on the page finder for AI agents.",
      "type": "policy",
      "audience": [],
      "answers": [
        "What is Stratigos's privacy policy?",
        "What data does the website collect?",
        "What does the AI agent research record?"
      ],
      "keywords": [
        "privacy",
        "data handling",
        "cookies",
        "analytics",
        "GDPR",
        "retention",
        "agent research"
      ],
      "headings": [],
      "text": "Data handling practices We do not share or sell your information, except with your explicit approval. We take appropriate precautions to safeguard our systems and client information, and act as careful stewards of customer data. Website analytics This website uses Google Analytics to understand how visitors use the site. IP addresses are anonymized, and we do not use analytics data to identify individuals or for advertising. AI agent research We study how AI agents find and read this site. Every request is logged with its headers, network origin, and a salted hash of its address, and a small script reports whether a page rendered. A page finder for agents at /agents/ records what they look for so we can serve it better; that page explains exactly what is collected, why, and for how long. Nothing is collected about the people behind those agents, and no visitor is blocked or shown different content. Reporting concerns For any potential violations of our privacy policy or related concerns, contact us at privacy@stratigossecurity.com .",
      "priority": 5
    },
    {
      "id": "sustainability",
      "url": "https://stratigossecurity.com/sustainability/",
      "path": "/sustainability/",
      "external": false,
      "title": "Sustainability",
      "description": "Commitment to a lower-impact business model",
      "summary": "Stratigos's commitment to a lower-impact business model: remote work and minimal travel.",
      "type": "policy",
      "audience": [],
      "answers": [
        "What is Stratigos's sustainability commitment?"
      ],
      "keywords": [
        "sustainability",
        "environmental impact",
        "remote work",
        "carbon"
      ],
      "headings": [],
      "text": "Reduced client site visits. The company advocates for limiting on-site visits when appropriate to decrease pollution and lower associated costs for clients. Telecommuting promotion. By encouraging remote work, the organization aims to cut daily carbon emissions from vehicle commutes and decrease office space requirements. Public transportation incentives. Employees are encouraged to use public transit for commuting and business travel to minimize their environmental footprint. Wise resource use. The company promotes practices like using reusable coffee cups and reducing paper consumption to lower waste generation. Healthy snacks. Fresh fruits and vegetables are provided to employees because they have lower environmental production costs and support worker wellness. The company welcomes additional sustainability suggestions from stakeholders. Share your ideas via info@stratigossecurity.com .",
      "priority": 5
    },
    {
      "id": "insights-wired-boeing-737-quote",
      "url": "https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/",
      "path": "https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/",
      "external": true,
      "title": "Quoted in Wired: Why safety-critical security research matters",
      "description": "Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics features Beau's perspective: research done in the open and taken seriously by industry makes safety-critical systems safer.",
      "summary": "Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics, with Beau's perspective on why research done in the open and taken seriously by industry makes safety-critical systems safer.",
      "type": "appearance",
      "audience": [
        "press",
        "research",
        "security"
      ],
      "answers": [
        "Why does open security research on safety-critical systems matter?",
        "What did Beau Woods say about the Boeing 737 hardware implant research?"
      ],
      "keywords": [
        "Wired",
        "Boeing 737",
        "avionics",
        "aviation",
        "hardware implant",
        "security research",
        "Andy Greenberg"
      ],
      "headings": [],
      "text": "",
      "priority": 4,
      "date": "2026-08-12"
    },
    {
      "id": "insights-cisa-cvd-guidance",
      "url": "https://stratigossecurity.com/insights/cisa-cvd-guidance/",
      "path": "/insights/cisa-cvd-guidance/",
      "external": false,
      "title": "CISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New",
      "description": "CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from.",
      "summary": "Our reading of CISA's 2026 joint guidance on coordinated vulnerability disclosure: what it gets right, what it leaves out for safety-critical systems, and what device makers should draw from the earlier NTIA work.",
      "type": "article",
      "audience": [
        "security",
        "regulatory",
        "research",
        "engineering"
      ],
      "answers": [
        "What is new in CISA's coordinated vulnerability disclosure guidance?",
        "How does the CISA CVD guidance compare with the 2016 NTIA work?",
        "What should medical device makers take from the CISA CVD guidance?",
        "How does coordinated vulnerability disclosure apply to safety-critical systems?",
        "Where can I find good resources for building a vulnerability disclosure program?"
      ],
      "keywords": [
        "CISA",
        "CVD",
        "coordinated vulnerability disclosure",
        "NTIA",
        "disclosure program",
        "safe harbor",
        "safety-critical",
        "FDA postmarket",
        "JPCERT",
        "NCSC",
        "disclose.io",
        "CERT Guide"
      ],
      "headings": [
        "What the new guidance gets right",
        "What the earlier work still offers",
        "Building for the future, preserving what we've learned"
      ],
      "text": "CISA has published new guidance on how to build a coordinated vulnerability disclosure (CVD) program: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers . It's a joint publication with the NSA, Japan's JPCERT/CC, the Netherlands' NCSC-NL, and the UK's NCSC. Reading it alongside the 2016 NTIA guidance is a useful exercise: there's a lot to like, some genuinely helpful updates, and a couple of areas where the earlier work still has something to offer. A quick note on that earlier work, since it doesn't come up in the new document. The NTIA multistakeholder process, led by Allan Friedman, PhD, produced resources that remain excellent references — I still turn to them regularly, particularly the early-stage template, which lays out how to stand up a program and mature it over time. A large group of people put real effort into it, including Joshua Corman, Amanda Craig Deckard, Bruce Lowenthal, Tara Hairston, Graham Watson, Jessica Wilkerson, Steve Christey Coley, Penny Chase, Art Manion, Katie Moussouris, Chris Wysopal, Kymberlee Price, Jennings Aske, Jen Ellis, Jim Jacobson, and many others. It's worth knowing that history exists, since it offers additional resources and perspectives that didn't fit into the new document. What the new guidance gets right The core of the CISA document looks solid and familiar. The sections and criteria for what belongs in a program are broadly consistent with the earlier work and remain aligned with the CERT Guide to Coordinated Vulnerability Disclosure and the ISO/IEC playbooks. The safe harbor language carries forward from the NTIA work, as well as the work of those like Casey John Ellis through disclose.io. There are also sensible updates for practices that either didn't exist or weren't well established in 2016: - CVE assignment. Recommending that companies assign CVEs should help strengthen the CVE program overall, which in turn makes efforts like the Known Exploited Vulnerabilities list and SBOM more useful. - . This makes programs clearer and easier for researchers to find. - SSVC prioritization. Pointing to SSVC for prioritization is a good step. What the earlier work still offers Two areas from the earlier NTIA work seem worth revisiting. The first is safety-critical systems. The 2016 effort included a working group focused specifically on safety-critical disclosure, because these systems carry additional and adapted considerations. The FDA, medical device makers, and healthcare providers all participated, and that work helped inform the FDA's premarket and postmarket guidance on medical device cybersecurity. The 6 Differences in IoT and Cyber Safety framework from I Am The Cavalry — a grassroots initiative I help lead — distills why: consequences can include direct physical harm, the adversaries and their motivations differ, device composition and economics constrain what defenders can do, the operational context is unusual, and timescales stretch across decades. Gi…",
      "priority": 4,
      "date": "2026-07-23"
    },
    {
      "id": "insights-reintroduction-beau-woods",
      "url": "https://www.linkedin.com/posts/beauwoods_im-getting-more-active-here-for-dayjob-share-7482465952652013568-Bsb5/",
      "path": "https://www.linkedin.com/posts/beauwoods_im-getting-more-active-here-for-dayjob-share-7482465952652013568-Bsb5/",
      "external": true,
      "title": "Reintroduction: Beau Woods on medical device cybersecurity",
      "description": "After years of quietly building Stratigos Security, Beau shares what the team has been working on and why medical device cybersecurity demands a different kind of testing partner.",
      "summary": "A LinkedIn post from Beau Woods on what the team has been building and why medical device cybersecurity demands a different kind of testing partner.",
      "type": "appearance",
      "audience": [
        "executive",
        "press"
      ],
      "answers": [
        "What has Stratigos Security been working on?",
        "Why does medical device cybersecurity need a different kind of testing partner?"
      ],
      "keywords": [
        "LinkedIn",
        "introduction",
        "Beau Woods",
        "Stratigos Security"
      ],
      "headings": [],
      "text": "",
      "priority": 4,
      "date": "2026-07-13"
    }
  ]
}