Nobody in their right mind is updating a bootloader in the field OTA, let alone one inaccessible on a mountain top.
My gut says if you're worried about this in the bootloader, it might be doing too much.
When I actually have these conversations with security guys, it's because they've either missed their window on contributing to part selection (in one case because that team hadn't been hired yet!) or no one consulted them in the first place. In both cases the solution is to write some guidelines and get the EEs to use them during part selection in the future.