INSIGHTS | August 20, 2026

Key Takeaways from the 2026 OCP APAC Summit

IOActive recently attended the 2026 OCP APAC Summit in Taipei. Below are our key takeaways from two days with the Open Compute community, along with a short recap video from the show floor at the end of this post.

Key Takeaways

  • The 2026 OCP APAC Summit (August 11–12) drew hyperscalers, semiconductor companies, device manufacturers, and infrastructure providers under the theme “Leading the Future of AI.”
  • AI security conversations extended beyond compute performance to the full stack: networking, cooling, storage, power, firmware, and the security controls underneath all of it.
  • Openness was a recurring theme, anchored by a dedicated SONiC Workshop on the open-source network operating system.
  • Multiple talks and vendor conversations pointed to growing interest in OCP S.A.F.E., the framework for independent security review of device firmware.
  • IOActive helped develop OCP S.A.F.E. from its early stages and continues to evaluate firmware security for device manufacturers today.

AI in the Agentic Era

AI was naturally at the center of this year’s summit, but the conversation went well past GPUs and raw compute performance.

The future of AI depends as much on trustworthy infrastructure as it does on faster accelerators and larger clusters. That means thinking about security across the whole stack, from applications and operating systems down to the firmware and hardware controlling the physical devices.

Open Data Centers and Open Networking

Openness was the other constant. The Open Compute Project’s philosophy of open hardware specifications, interoperable architectures, open firmware increasingly extends to networking, and the summit’s dedicated SONiC Workshop was a good example. SONiC, the open-source network operating system, brought together developers, users, maintainers, and vendors to compare notes on real-world deployments.

The direction of travel is toward data centers built from a diverse ecosystem of components rather than a single vertically integrated platform. That shift raises a practical question for operators: as devices and firmware arrive from a wider set of suppliers, how do you know they were built securely?

OCP S.A.F.E. and the Case for Independent Security Review

That question was the throughline of many of our conversations at the summit. Multiple technical talks and device-vendor discussions pointed to growing interest in OCP S.A.F.E., which lets vendors have their products evaluated by independent security reviewers against an established methodology.

For manufacturers, that’s more than a compliance checkbox. An independent review can surface vulnerabilities in firmware and other security-critical components before devices ship at scale, and it gives customers a concrete basis for confidence in what they’re deploying. As the supply chain behind any given rack grows more diverse, security assurance needs to travel with it.

IOActive has been involved in developing the OCP S.A.F.E. framework since its early stages, and we continue to work with device manufacturers on firmware and security assessments across the infrastructure being deployed today.

Taipei as a Meeting Point

Taipei was a fitting location for these conversations. Taiwan sits at the center of the global technology supply chain, home to a dense concentration of semiconductor companies, server manufacturers, ODMs, component suppliers, and firmware developers—much of the ecosystem responsible for the infrastructure data centers worldwide run on.

The summit itself made room for those conversations to happen: networking lounges, meeting areas, and coffee stations throughout the venue, lunch on-site, and reception drinks in the Expo Hall on the first evening. Live translation kept the technical sessions accessible to an international audience.

If you’re a device vendor preparing for OCP S.A.F.E. or looking to strengthen your firmware’s security, contact IOActive. Our team supports OCP S.A.F.E. assessments and independent firmware source-code security reviews.

Watch Our OCP APAC Summit Recap

Want to see the event from the show floor? We captured some of the technologies, conversations, and demonstrations from our time at the 2026 OCP APAC Summit in Taipei.

INSIGHTS | June 18, 2024

Recent and Upcoming Security Trends in Cloud Low-Level Hardware Devices: A survey

The rapid evolution of cloud infrastructures has introduced complex security challenges, particularly concerning all of the processing devices and peripheral components that underpin modern data centers.

Recognizing the critical need for robust and consistent cloud security standards, technology firms, developers, and cybersecurity experts established the Open Compute Project Security Appraisal Framework and Enablement (OCP S.A.F.E.) Program.

At the 2024 OCP Regional Summit in Lisbon, I was joined by my colleague Alfredo Pironti, Director of Services at IOActive, to present a deep dive into the security of cloud infrastructures, the threats facing the crucial hardware that supports them, and how organizations can prevent being compromised by adopting new threat modeling techniques and security frameworks.

IOActive has monitored the state and health of hardware security for decades. We are now observing the changes in cybercriminal tactics, threats, and vulnerabilities that could compromise key components in digital supply chains and services.

When attackers target the hardware level, they can potentially exploit the entire stack. Once granted access to the hardware foundation, cybercriminals could potentially compromise physical infrastructure, data storage, applications, developer environments, code bases, and entire systems.

If vulnerable hardware is utilized in cloud services, this could even pose threats to national security as so many CSPs are now the backbone of critical infrastructure.

Hardware and computational components have evolved to meet the needs of increasingly complex cloud infrastructures and services. However, each new, enhanced capability may also create a new avenue for attack.

Take NVMe-based SSD disks and SR-IOV-enabled cards, for example. As we discussed during our presentation, historically, board problems, design flaws, or some implementation errors posed the most risk. Now, logical access bugs, data theft, arbitrary and remote code execution vulnerabilities, side-channel attacks, denial-of-service, and supply chain attacks must also be addressed.

IOActive has uncovered a wide range of risks to today’s cloud infrastructure through hands-on experience. Many hardware-based vulnerabilities stem from incorrect implementation, such as integer flaws, out-of-bounds memory issues, and race conditions.

During testing, we observed various security problems caused by component design and operational processes. A critical insight gleaned from our research is that 25% of vulnerabilities found were introduced in the design stage, showing a need for testing services early in the process.

In our presentation, we proposed an archetypal threat model that addresses the disconnect between developers, hardware manufacturers, and service providers regarding security. A core component of our model explores the divergence between the threats that cloud service providers face, and those faced by cloud hardware providers.

As addressed by the OCP S.A.F.E. framework, achieving robust security standards throughout the entire digital supply chain can assist hardware suppliers and service providers alike in tackling today’s cybersecurity challenges.

You can find a recording of our presentation here to share our knowledge and insights on cloud security and how frameworks, including OCP S.A.F.E., benefit organizations today.

– IOActive Senior Security Consultant and Researcher, Sean Rivera