STAAR Surgical makes things that go inside people's eyes. Specifically, the company designs and manufactures implantable Collamer® lenses - EVO ICL™ and Visian ICL™ - used in refractive surgery across 75+ countries. Over 4 million patients have received these devices, which means the threat surface isn't hypothetical: it's a global fleet of surgical products where a compromised system doesn't just leak data, it could jeopardize patient outcomes or regulatory standing in dozens of jurisdictions simultaneously.
The company operates in a heavily regulated medical device environment - FDA, CE marking, and equivalent frameworks in every market it serves. That means cybersecurity work here sits at the intersection of product security, manufacturing floor integrity, and clinical data protection. The attack surface spans proprietary lens design systems, production environments with embedded firmware, and the supply chain infrastructure that moves physical implants across continents. Rigorous quality and continuous improvement are embedded in the culture, which translates to security teams having real leverage to enforce standards rather than just recommend them.
With over 900 employees collaborating globally, STAAR's security posture has to account for distributed operations, cross-border data flows, and the specific regulatory obligations that come with being a Class III medical device manufacturer. The work is concrete: protecting IP around Collamer® material science, securing manufacturing execution systems, and ensuring compliance across a patchwork of international standards. No red-team war stories here - just the hard, unglamorous work of keeping a regulated device company locked down.





