In the critical applications market, trust is the cornerstone.
This means that products must not only be reliable but also fully secure.
Barco has made a clear commitment to security, which translates into a comprehensive security organization that ensures it remains a trusted company capable of delivering secure solutions to the market. This article describes the different aspects of security at Barco.
Companies are becoming increasingly aware of and concerned about cybersecurity, and with good reason. The cost of downtime is enormous, making investment in security a true necessity. According to a BlackBerry report, in the third quarter of 2024 (June to September) alone, no fewer than 600,000 attacks were reported against critical infrastructure, 45% of which targeted the financial sector.
As a company, Barco has security embedded in its DNA. It has been active in the control room market for more than 30 years, having deployed numerous critical installations across government, energy, and security sectors. In addition, it operates in the healthcare market, where security requirements are high and heavily regulated.
The company’s security organization operates on three lines of defense: the first line consists of all employees in their daily operational roles; the second line is the Security Office, led by David Martens, Head of Product Security, focusing on both corporate security and product security strategy; and the third line of defense is cybersecurity auditing.
All employees: security in their DNA
Every employee plays a vital role as the first line of defense, embedding security into every aspect of their daily work. From development to deployment, they actively implement, maintain, and refine the safeguards that protect the company’s infrastructure, products, and data. This collective vigilance helps prevent accidental leaks, unauthorized transfers, and cyber threats, ensuring resilience across the organization.
To foster a security-first mindset within the company, regular training sessions and anti-phishing campaigns are conducted for all employees. Within the R&D teams, additional targeted training ensures engineers are equipped to design and build secure products from the ground up.
Within the R&D departments, specialized profiles such as Product Security Engineers and Security Architects guide and support secure development practices. The Security Champion model is also applied across teams, ensuring that security is considered at every stage of the product lifecycle, from concept to deployment.
This layered approach enables every team to contribute to a secure and resilient ecosystem.
Security Office: strategy for trust and compliance
The Security Office, the second line of defense, leads the company’s cybersecurity program, focusing on both corporate security and product security. Barco ensures compliance with cybersecurity regulations and standards, implementing an ISO 27001:2022 certified ISMS to continuously improve its security posture.
At the heart of Barco’s innovation philosophy lies an unwavering commitment to security, which David Martens, Head of Product Security, has championed throughout his tenure. Every day, the company’s customers recognize that robust security is fundamental to modern digital solutions.
The digital landscape presents fascinating challenges for the Barco team: protecting the intellectual property embedded in its technologies, preventing products from becoming gateways into customer networks, and safeguarding the personal and patient data processed by its systems.
Product security roadmap
Barco’s product security roadmap serves as a compass, guiding an ambitious plan across four key areas:
- Security from the start (shift-left), integrating protection measures in the earliest phases of development.
- Adaptation to complex and constantly evolving regulations affecting the industry.
- Rigorous certifications that validate the company’s security commitments.
- A culture of transparency to drive continuous improvement across the entire product portfolio.
Certification and standardization
Certification and standardization are essential to maximize security levels and comply with various legislations. Although regulations vary by region and sector, there is considerable overlap and common best practices that facilitate compliance. Nevertheless, beyond best practices, a specialized approach is required to obtain certifications and ensure compliance with standards.
Barco’s goal is to build trust through excellence. Each security enhancement represents the company’s commitment to protecting the customers who rely daily on its innovations and product quality.
Cybersecurity auditing: independent evaluation
Barco’s third line of defense is external auditing. Annual ISO 9001 and ISO 27001 audits provide the highest level of independence and objectivity, driving internal teams to focus on continuous improvement.
The company operates with well-defined processes and a constant intention to refine its practices. Without settling, Barco continually challenges itself to evolve and optimize its working methods to achieve better results.
In addition to strengthening internal processes, Barco integrates external security validation into the product development lifecycle itself. To this end, it engages ethical hackers to perform penetration tests aimed at identifying vulnerabilities. These tests are extremely valuable for both developers and customers, keeping teams alert and ensuring that the latest cybersecurity advances are rigorously applied. For customers, this provides an additional guarantee of peace of mind regarding product security.
Furthermore, the company encourages the reporting of vulnerabilities through a responsible disclosure policy. Its global Product Security Incident Response Team (PSIRT) manages all reported vulnerabilities, coordinating swift resolution and the deployment of necessary patches.
In this way, Barco maintains complete transparency in the security of its products, ensuring that its solutions are always safe for deployment.
