The attack surface here is physical. Graham Packaging runs nearly 70 plants across four continents, producing more than 16 billion blow-molded plastic containers a year. That's a massive OT footprint - SCADA systems, programmable logic controllers, and networked manufacturing equipment spanning food, beverage, dairy, automotive, and home care verticals. The cybersecurity threat model extends beyond corporate IT into industrial control systems where downtime means halted production lines and supply chain disruption at scale.
Founded in 1970, the company designs and manufactures custom, value-added plastic packaging with a heavy emphasis on sustainability - 91% of its containers are fully recyclable PET and HDPE. It ranked No. 1 out of 54 companies in the plastic, metal, and glass packaging industry on ESG metrics. Its technical domains center on package design, blow-molding processes, and sustainable packaging innovation, which means the security team needs to protect both intellectual property around proprietary designs and the integrity of manufacturing execution systems.
With operations spanning North America, Asia, Europe, and South America, any security role involves defending a globally distributed infrastructure where plant-floor networks interface with enterprise systems and third-party supply chains. The company operates under a values-based framework it calls "Blue Culture," emphasizing innovation and continuous improvement - context that shapes how security initiatives get prioritized and funded across a legacy-heavy industrial environment.




