A water company hires from the retail front line
Primo Brands, the branded-water company behind Poland Spring, Pure Life, and Deer Park, named Ravi Thatavarthy its chief information security officer, effective in early July. The pedigree behind the hire is the interesting part. Thatavarthy comes from the retail and connected-product world, having led security at BJ's Wholesale Club, at the pharmacy chain Rite Aid, and at the robot maker iRobot. That is a security leader shaped by high-volume consumer environments, payment data, and internet-connected hardware, now moving into a manufacturer and distributor of physical goods. The choice says Primo wants a CISO fluent in the messy intersection of consumer data, retail operations, and industrial systems.
In his own words, posted to LinkedIn and shared by the company, Thatavarthy framed the job around foundations, saying he joined to strengthen the security and technology base that supports an iconic portfolio of brands. The phrasing is modest, and the timing is not accidental. Consumer-goods companies have spent the past two years absorbing the same ransomware and supply-chain pressure that hit retailers and manufacturers, without always having the security maturity those sectors were forced to build. Hiring a leader who cut his teeth in more targeted industries is a way to import that hard-won maturity rather than acquire it painfully during an incident.
A resume built in high-stakes consumer environments
Thatavarthy brings more than two decades of security leadership, most of it in places where a breach has immediate consumer consequences. At Rite Aid he served as group vice president for security and enterprise architecture, at BJ's Wholesale Club he was vice president and chief information security officer, and at iRobot he owned security across both product and corporate IT. Each of those roles carries a distinct threat model: pharmacy data and health privacy at Rite Aid, payment and membership data at a warehouse-club retailer, and connected-device security at a maker of home robots. Few backgrounds combine consumer data protection and product security as directly as this one does.
That breadth is precisely what a modern manufacturer needs. A company like Primo runs plants, fleets, and distribution alongside consumer-facing digital channels, which means its attack surface spans operational technology, corporate IT, and customer data at once. A CISO who has defended payment systems, regulated health data, and networked hardware has seen most of those problems in isolation and now has to defend them together. The appointment reads as a deliberate attempt to consolidate that experience under one leader, rather than to hire a specialist in any single domain. For a consumer-goods firm scaling its security program quickly, generalist depth beats narrow expertise.
Why a beverage manufacturer needs this now
Bottled-water production is a physical, plant-heavy business, and that is exactly what makes it a target. Manufacturing operations run on operational technology, the industrial control systems that keep bottling lines, treatment, and logistics moving, and those systems have become a favored entry point for ransomware crews that know a halted line costs real money by the hour. The food and beverage sector has already seen production-halting attacks that turned an IT compromise into a supply shortage. Bringing in a CISO with manufacturing-adjacent and retail-supply-chain experience is a way to treat that OT exposure as a board-level operational risk rather than a purely technical one.
The supply chain compounds the exposure. A branded-water company depends on suppliers, co-packers, distributors, and retail partners, each a potential path into its systems and each a dependency that can be disrupted. Securing that web requires the same third-party risk discipline that big retailers were forced to develop after a decade of partner-driven breaches. Thatavarthy's time inside large retail organizations is directly relevant here, because those companies learned to map and monitor sprawling vendor ecosystems the hard way. For any manufacturer, the lesson is that the perimeter now includes every partner that touches your operations, and someone senior has to own that reality.
The consumer-goods maturity gap
Consumer-goods companies have historically trailed banks, retailers, and tech firms in security investment, in part because their risk felt more physical than digital. That gap is closing fast under pressure from ransomware operators who have discovered that manufacturers pay to keep lines running. The result is a wave of senior security hires across the sector as companies try to catch up before an incident forces the issue. Primo naming a chief information security officer with a heavyweight retail resume fits that pattern precisely. It is a company buying maturity from industries that were attacked earlier and learned to defend themselves under real fire.
For technology leaders in any less-targeted sector, the trajectory is a warning worth heeding. Security maturity tends to arrive either through foresight or through crisis, and crisis is far more expensive. The consumer-goods firms hiring experienced CISOs now are choosing the cheaper path, building capability before an attacker sets the timeline. The pattern also raises the going rate for proven security leaders, since demand is spreading into sectors that did not compete for this talent a few years ago. Companies still treating security as an IT subfunction should expect both the threat and the cost of talent to keep climbing toward them.
The connected-product lesson from iRobot
The iRobot chapter of Thatavarthy's career deserves attention, because it points at where consumer-goods security is heading. A maker of home robots has to secure its corporate systems, the devices in customers' homes, and the data those devices collect, a discipline most packaged-goods companies have avoided until recently. As beverage and consumer brands add connected packaging, smart dispensers, loyalty apps, and direct-to-consumer channels, they inherit exactly this product-security problem. Hiring a leader who has already defended networked consumer hardware gives Primo a head start on threats that its category is only beginning to encounter at scale.
This is the quiet strategic logic of the appointment. A water company today is mostly plants and distribution, yet consumer brands are steadily digitizing the product itself and the relationship with the buyer. Each smart feature and each app is a new data flow and a new attack surface. A CISO who has owned product security understands that a security team has to be involved in product design from the outset, well before launch. For technology leaders watching their own companies add connected features, the message is to bring security into the product roadmap early, because retrofitting it onto shipped devices is slow, costly, and often incomplete.
The roadmap implication
Primo's hire is a small data point in a large shift: security leadership is spreading out of its traditional strongholds and into every sector that touches consumer data, physical operations, or connected products, which by now is nearly all of them. The specific profile Primo chose, a retail-and-hardware-hardened CISO moving into manufacturing, is a template other consumer-goods companies will follow as they confront OT risk, supply-chain exposure, and the early stages of product digitization together. Expect a steady run of similar appointments across food, beverage, and packaged goods, and expect the winners to hire before an incident rather than during one.
For CIOs and boards, the practical prompt is to assess honestly where their own security maturity sits relative to their threat exposure. If a company runs plants, depends on a wide partner network, holds consumer data, or is adding connected features, its risk profile may already exceed the security function it has staffed for. Primo answered that question by importing experience from industries that were attacked earlier and learned to defend under pressure. The move is affordable insurance compared with the cost of a halted production line. The organizations that read it as a prompt to close their own gap will avoid learning these lessons the expensive way.



