Haleon, spun out in 2022 as a standalone consumer healthcare company, operates one of the largest over-the-counter medicine portfolios on the planet. Brands like Sensodyne, Advil, Centrum, and Panadol aren't just household names - they're regulated product lines spanning 170+ countries, each a potential attack surface for supply chain tampering, counterfeit injection, or IP theft. The threat model here is broad: protecting a global manufacturing and distribution network, securing consumer data at massive scale, and defending the intellectual property behind formulations that move billions in revenue.
For a security team, the terrain is complex. You're dealing with operational technology on factory floors, connected consumer-facing platforms, and a corporate footprint that touches every major regulatory regime. The company runs 100% renewable electricity across its sites and targets net-zero by 2030, which means sustainability infrastructure is also in scope. The work spans identity and access management across a sprawling global workforce, application security for digital health products, and incident response across jurisdictions with very different breach notification laws.
Haleon's security function has to bridge the gap between a legacy pharma heritage and a modern, purpose-driven company that talks openly about health inclusivity and professional trust. That means building security programs that don't just check compliance boxes but genuinely protect consumers who rely on these products daily. The stakes are tangible: compromised data or a supply chain breach here doesn't just mean financial loss - it means eroding the trust of the healthcare professionals and customers the company depends on.





