Keywords: Bill of Materials, Operations Cybersecurity, OT, Product Security, SBOM
Overview
The 2025 ARC Industry Forum in Orlando included a comprehensive program addressing various aspects of Operations Cybersecurity. It included a series of workshops addressing several specific topics in this area. Attendees included owner-operators, security professionals, suppliers, and other stakeholders in industrial cybersecurity who had the opportunity to participate in the discussion with their perspectives and concerns.
Many cybersecurity events are focused on security practitioners and offer sessions with pundits debating the effectiveness of different technologies and suppliers describing new features in their security offerings. ARC’s cybersecurity program is targeted toward the people responsible for the safety and availability of industrial operations. These operational concerns drive cybersecurity investments, and the people who control the budgets attend ARC cybersecurity sessions to understand their risks and what peers are doing to manage them.
All the workshops and case study sessions at the 2025 ARC Forum received high ratings for content and relevance, and this workshop was no exception.
Workshop Highlights
One such workshop took the form of a panel of experts discussing the need for improvements in hardware and software product security. Specifically, for OT systems, how to ensure the security of both installed (i.e., legacy) components and those available for purchase and installation.
ARC Contributing Consultant Eric Cosman provided a brief overview of research done by ARC on this subject. This was followed by a discussion between the following panelists.
- Nathan Faith (Global Sr. Manager, Cybersecurity Governance, Risk, and Compliance, Olin Corp.)
- Rob Putman (Global Manager Cyber Security Services, ABB)
- Brad Nash (IIT Perimeter Security, ExxonMobil)
- Matthew Bohne (VP & Chief Product Security Officer, Honeywell)
The panelists shared their observations, experiences, and thoughts on the challenges faced. This Insight summarizes some key takeaways from the 90-minute workshop.
ARC Research
Eric Cosman opened the workshop by summarizing his research on this subject, which centered around several broad questions:
- What is the current status of hardware and software product security?How effective are standards in defining what is required?
- Can CISA's Secure-by-Design efforts really make a major impact?
- What is the role of regulations?
- What is the value of conformance testing and certification?
- Are there implications arising from the use of artificial intelligence (AI)?
- Are software bills of materials of value to end users?
- Is there a hardware analog to SBOMs?
- What steps should end users or asset owners be taking?
- What steps should product suppliers be taking?
Addressing these questions led to several general observations.
ARC Advisory Group clients can view the complete report at the ARC Client Portal.
Contact Us if you would like to speak with the author.
Obtain more ARC In-depth Research Market Analysis.