Summary
The core message of the available transcript is that high-tech product security now needs to move from an internal engineering sign-off activity to a shared ecosystem capability that connects product design with customers, regulators, markets, and supply chains. Francesco Pizzocolo opens by framing this shift through a bridge metaphor: product design once acted like a bridge between engineering effort and internal approval, but the “river” has moved. Market actors such as content owners, platforms, OEMs, and enterprise buyers began demanding product security even before regulations such as the CRA and NIS2 reinforced security-by-design expectations. The Brabant House Cyber innovation pillar is presented as an attempt to build the “last piece of bridges” between product security and these new stakeholders.
The speakers emphasize that this work must be co-created with the ecosystem rather than designed in isolation. The squirrel bridge example is used to make that point: building infrastructure is not enough unless the intended users know about it and actually need it. Audience interaction through Mentimeter asks participants about barriers to product security, definitions of product security, and their organizations’ current maturity. The discussion surfaces funding, prioritization, ownership, lifecycle management, customer trust, availability, reliability, and security by design as recurring concerns. Hidde-Jan Jongsma notes that many people in the room appear to come from relatively mature organizations with structured programs, but the initiative is intended to support a wider ecosystem, including smaller and less mature players.
Francesco then explains the Brabant House Cyber partnership as a triple-helix collaboration among research institutes, universities, industry, and government, initiated by the province of North Brabant, TNO, BOM, High Tech NL, and Brainport Development. The session focuses on the innovation pillar, while also acknowledging the talent pillar, led by Avans, and a resilience pillar focused more on SMEs in the Brabant region. The innovation pillar aims to build shared product security capability for the high-tech ecosystem by strengthening trust, product continuity, and market position. Its timeline began in January with launch and partner engagement, moved into an early adopter program in June, targets an official launch of the radar and handbook in December, and plans to start the innovation engine in 2027.
In the final available section, Hidde-Jan introduces the transition handbook for more advanced and mature product security. He explains that while many resources already exist for information security, vulnerability management, and secure build processes, the problem is often that there is too much material for organizations starting out. The handbook is intended as a practical signpost for less mature organizations and as a roadmap for suppliers that need to meet regulatory requirements or customer expectations. Rather than trying to serve every large organization in detail, it aims to help raise the maturity of the wider supply chain by pointing companies toward useful starting points for cybersecurity by design, certification, SBOMs, and related initiatives.
Key Topics
5 key topics from Francesco Pizzocolo, Peter van Liesdonk and Hidde-Jan Jongsma at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Co-create product security capabilities with the ecosystem that must use them.
- Prioritize funding and ownership before expanding product security programs.
- Define product security consistently across teams and suppliers.
- Use handbooks as signposts for less mature supply-chain partners.
- Align security by design with customer and regulatory expectations.
“nobody can solve it alone because of the complexity of the supply chain.”
Up Next



Next in agenda
International Perspectives on NCSC-NL’s CCB Program



Also on supply chain security
TaHiTI, threat hunting methodology.

Also on supply chain security
From awareness to action: SME Cyber Security
Emiel Kerpershoek