# Extra Security > Medical device security experts. We perform penetration testing and threat modeling for medical device manufacturers preparing for FDA submission. ## What We Do Extra Security is a cybersecurity firm specializing in medical device penetration testing. We test physical medical devices in our dedicated hardware lab — including network protocols, firmware, hardware interfaces, cloud components, and companion mobile apps — and deliver FDA-compliant reports suitable for 510(k) and PMA submissions. We are not a generic penetration testing firm. We focus exclusively on medical devices. An insulin pump, a cardiac monitor, and a diagnostic imaging system all face different risks — our methodology adapts to each device's architecture, clinical context, and intended use environment. ## Our Approach Every engagement is powered by Prognosis — our proprietary AI testing engine that pairs automated exploit workflows with hands-on researchers in a dedicated hardware lab. Prognosis orchestrates the attack — generating signals, analyzing responses, and guiding the researcher through exploit chains in real time. The researcher provides what AI can't: physical access to the device. They open enclosures, connect probes, desolder flash chips, test thermal conditions, and manipulate hardware interfaces. Prognosis drives the methodology. The researcher drives the soldering iron. ## What Makes Us Different - **Code-level remediation**: Every finding includes suggested code fixes and patches your engineering team can apply directly, not generic advice. - **Patient impact analysis**: Findings are assessed for clinical impact, not just CVSS scores. A vulnerability in an infusion pump is a patient safety issue, not just a data breach. - **Flat-rate pricing**: No hourly billing, no surprise invoices, no scope creep fees. You know exactly what you're paying before testing begins. - **Differential testing**: For post-market updates, we can test only the parts of the device and software that changed since the last test, or perform a full reassessment. - **4-week turnaround**: From device receipt to final report. - **Free re-testing**: One re-test included within 60 days. Software-only fixes can often be re-tested without re-shipping the device. ## Standards & Methodologies - IEC 62443 (industrial/medical device cybersecurity) - NIST Cybersecurity Framework - STRIDE and TARA for threat modeling - CVSS for vulnerability scoring - FDA premarket cybersecurity guidance (Section 524B of FD&C Act) - Attack tree mapping ## Our Platform: Thrombus Thrombus (https://thrombus.io) is our online pentest management platform where manufacturers create engagements, upload documentation and source code, track testing progress in real-time, review findings, download FDA-compliant reports, and pay — all in one place. ## Services - **Penetration Testing**: Hands-on security testing in our hardware lab — network, firmware, physical, cloud, and companion apps. $45,000 flat rate. - **Threat Modeling**: Structured risk analysis of device architecture and attack surfaces using STRIDE and TARA methodologies. $15,000 flat rate. - **Threat Model + Pentest**: Combined engagement. $55,000 flat rate. - **FDA ANIN Response**: Help manufacturers who received Additional Information (ANIN) cybersecurity letters from the FDA. We address the identified deficiencies, conduct required testing, and prepare documentation for resubmission. - **Equivalency Validation**: Cybersecurity testing for substantial equivalence claims. We validate that a device meets the same security posture as the predicate device referenced in a 510(k) submission. - **Post-Market Testing**: Ongoing differential testing focused on changes since the last assessment. Discounts for bundled tests. - **Custom Engagements**: Tailored scope and pricing for unique devices. All engagements include FDA-compliant reports and one free re-test within 60 days. ## Ideal For Medical device manufacturers who need: - Premarket cybersecurity testing for FDA submission (510(k), PMA) - Post-market cybersecurity testing and differential assessments - Third-party penetration testing of connected medical devices - Threat modeling for new device architectures (STRIDE, TARA) - Help responding to FDA ANIN cybersecurity letters - Cybersecurity testing for equivalency validation (substantial equivalence claims) - Code-level remediation guidance, not just a list of problems ## Device Types We Test Infusion pumps, patient monitors, imaging systems, implantable devices (pacemakers, insulin pumps), wearables, connected diagnostics, drug delivery systems, surgical robots, remote monitoring devices, and other FDA-regulated medical devices. ## Testing Scope - Network protocols: Wi-Fi, Bluetooth, BLE, Zigbee, cellular, wired - Firmware: extraction, reverse engineering, binary analysis, secure boot validation - Physical: JTAG, UART, debug ports, tamper resistance, side-channel analysis - Cloud/backend: API security, authentication, data handling, update mechanisms - Companion apps: mobile and desktop applications that interface with the device - Source code review when provided ## Report Deliverables - Executive summary with key findings - Detailed testing methodology - Findings with proof-of-concept evidence - Risk assessment prioritized by clinical/patient impact - Remediation roadmap with code-level fix suggestions - Patient impact analysis - Letter of remediation after successful re-test ## Contact - Website: https://extrasecurity.io - Platform: https://thrombus.io - Email: info@extrasecurity.io - Book a call: https://cal.com/team/extra-security/scoping-call