The Secure Blog
The Christian Espinosa blog. Page 2
Thought leadership on cybersecurity, leadership, and the human side of high-performing teams.
More posts
Page 2 of 8 · 170 total
-

Speed Is Easy. Control Is Hard.
Three days of Formula 4 with Skip Barber at New Jersey Motorsports Park. Top speed near 185 kph, but the lesson wasn't the number. It was how long you can stay near it without losing control. The same principle runs racing, business, and life.
Read the full post: Speed Is Easy. Control Is Hard. -

Eternal Optimism Is A Curse. Informed Optimism Is A Blessing.
The leader who says 'we've never had an issue, so we're fine' isn't optimistic, they're asleep. The difference between hope and awareness, and why one keeps you ready while the other keeps you comfortable until the bad news hits.
Read the full post: Eternal Optimism Is A Curse. Informed Optimism Is A Blessing. -

Founder-CEO vs Hired CEO: The Difference Is Personal
I've been both, a founder who built and sold a company, and a founder watching a non-founder CEO take the wheel. Why founder-CEO and professional CEO are not the same job, and why Blue Goat Cyber is built the way it is.
Read the full post: Founder-CEO vs Hired CEO: The Difference Is Personal -

Five Seconds On Elbrus And The FDA Submission
Four hours before this summit photo on Mt. Elbrus, I almost died from five seconds of lost focus. Same mistake MedTech teams make on FDA cybersecurity submissions, and the self-arrest that gets you out of it.
Read the full post: Five Seconds On Elbrus And The FDA Submission -

The Ultrasound That Found My Clots: Why Medical Device Cybersecurity Is Personal
In 2022 a Doppler ultrasound found six blood clots in my left leg. That device saved my life. It's also why I treat medical device cybersecurity as a patient safety issue, not a compliance checkbox.
Read the full post: The Ultrasound That Found My Clots: Why Medical Device Cybersecurity Is Personal -

Don't Stop Believing: The Comeback Isn't Dramatic
Six blood clots in 2022. A year later, a finish line at IRONMAN 70.3 Chattanooga and a song I used to think was cheesy. What nobody tells you about coming back from something that almost killed you.
Read the full post: Don't Stop Believing: The Comeback Isn't Dramatic -

The Hard Part Is The Bar, Not The Fall
Hanging off an inverted biplane at the World Free Fall Convention taught me something about leadership: the falling is easy. The bar is what costs you.
Read the full post: The Hard Part Is The Bar, Not The Fall -

Tulum, Prosecco, and the Sign I Almost Missed
I'd just sold Alpine Security and every instinct said grind the next thing. Then I sat still in Tulum long enough to hear what was actually around me, and the next move got obvious.
Read the full post: Tulum, Prosecco, and the Sign I Almost Missed -

Check Your Grip: What Top Gun Still Teaches Me About Leadership
Top Gun sent me to the Air Force Academy and shaped how I think about leading under pressure. Thirty years later, the lesson I keep coming back to is about grip, and when to loosen it.
Read the full post: Check Your Grip: What Top Gun Still Teaches Me About Leadership -

Through Immersion Comes Clarity
Sixteen-hour days on AI and the business aren't balanced or sustainable, but they're the fastest way to see the gaps you've been stepping over for years.
Read the full post: Through Immersion Comes Clarity -

What Ozzy and Zakk Taught Me About Not Getting Sanded Down
Ozzy Osbourne and Zakk Wylde got me through the dark stretches and shaped who I am. The lesson, in music and in leadership, is to stop sanding down the edges that make you you.
Read the full post: What Ozzy and Zakk Taught Me About Not Getting Sanded Down -

What a 'Good' SBOM Actually Looks Like, And What Reviewers Reject
FDA reviewers see thousands of SBOMs. Most are wrong in the same handful of ways. Here's what a defensible Software Bill of Materials looks like for a medical device submission, and the patterns that trigger a deficiency.
Read the full post: What a 'Good' SBOM Actually Looks Like, And What Reviewers Reject -

If Your Reviewer Can't See the System, You Don't Have an Architecture
Security Architecture Views are where most medical device submissions either earn trust or lose it. Here's what a clear, defensible architecture view looks like, and why most teams over-engineer the diagrams and under-engineer the boundaries.
Read the full post: If Your Reviewer Can't See the System, You Don't Have an Architecture -

The Accident That Taught Me to Live in the In-Between
I spent decades chasing the next summit, the next exit, the next certification. Then a crash in an Illinois intersection taught me the micro-moment is the whole game.
Read the full post: The Accident That Taught Me to Live in the In-Between -

Why Postmarket Cybersecurity Is Where MedTech Actually Fails
FDA clearance is the floor, not the finish line. A look at why most medical device cybersecurity programs collapse after launch, and what the working postmarket programs do differently.
Read the full post: Why Postmarket Cybersecurity Is Where MedTech Actually Fails -

The Smartest Person in the Room Is Usually Wrong
The smartest person in the room is usually the one losing the war. After 25 years in cybersecurity, here is why ego, not technology, is the real breach.
Read the full post: The Smartest Person in the Room Is Usually Wrong -

FDA Premarket Cybersecurity: What the 2026 Guidance Actually Requires
A plain-English breakdown of FDA's final 2026 premarket cybersecurity guidance, what the threat model, SBOM, labeling, and cybersecurity management plan actually have to look like for clearance.
Read the full post: FDA Premarket Cybersecurity: What the 2026 Guidance Actually Requires -

Total Product Lifecycle: The Framing That Fixes Most MedTech Submissions
Most medical device cybersecurity programs fail because they treat security as a premarket activity. The Total Product Lifecycle framing is what the FDA expects, and what makes the work durable.
Read the full post: Total Product Lifecycle: The Framing That Fixes Most MedTech Submissions -

Threat Modeling Is the Work. Everything Else Is the Receipt.
Most medical device cybersecurity submissions fail at the threat model, not because reviewers are picky, but because teams treat threat modeling as documentation. It's the engineering discipline that produces everything else.
Read the full post: Threat Modeling Is the Work. Everything Else Is the Receipt. -

Acting With Intention: What It Means and How to Make It a Habit
Are we always acting with intention? Sometimes, we are aware of it; other times, it seems like it’s just a reaction. Intention can also be a double-edged
Read the full post: Acting With Intention: What It Means and How to Make It a Habit -

Reflection Is Part of the Messy and Uncomfortable Growth Process
If you want to grow and evolve as a human, it can be uncomfortable. If it weren’t, we’d all be a bit more aware and enlightened. What I’ve learned is that
Read the full post: Reflection Is Part of the Messy and Uncomfortable Growth Process -

No One Wants to Feel Alone in Times of Need
There are many variations of the concept of the loneliness of humanness. They say we are born and die alone. In between those two moments, we create
Read the full post: No One Wants to Feel Alone in Times of Need -

Trying to Do the Right Thing and Getting It All Wrong
Most of us are always trying to do the right thing. Except, we often get it all wrong. I came to this realization while I was recuperating from a health
Read the full post: Trying to Do the Right Thing and Getting It All Wrong -

Shedding Your Defense Modes
Everybody has the capacity to shift into defense mode. It’s a normal reaction to go into self-preservation behaviors. Sometimes, they occur when others
Read the full post: Shedding Your Defense Modes