Start your day with intelligence. Get The OODA Daily Pulse.
By Trent R. Teyema, DSc and David Bray, PhD
The cybersecurity landscape is undergoing a fundamental transformation. How can organizations verify the integrity of the technology infrastructure they depend on when adversaries have moved beyond software exploits to compromise the silicon itself?
We are witnessing a shift from software-focused defenses to the recognition that hardware itself has become a primary attack vector. The threat environment is transitioning from a domain once dominated by network intrusions and malware to one increasingly characterized by chip-level compromises embedded before devices ever reach their intended users.
Just a decade ago, cybersecurity professionals focused primarily on firewalls, intrusion detection systems, endpoint protection, and network monitoring. The assumption was straightforward: if organizations could secure the software layer and monitor network traffic, they could protect their systems. Today, that assumption is no longer sufficient. Field deployments of chip-level Independent Verification and Validation (IV&V) technology have identified substantial hardware-level anomalies in 53% of the tested equipment to include counterfeit components, unauthorized firmware modifications, and embedded backdoors invisible to traditional security tools.
In this context, chip-level IV&V refers to independent inspection and analytic comparison of physical components, firmware, and device-level characteristics against expected baselines to identify counterfeit parts, unexplained modifications, or anomalous behavior before systems are deployed. This paradigm shift demands a complete rethink of cybersecurity, procurement practices, and supply chain risk management.
U.S. military and civilian activities increasingly depend on technology infrastructure, including critical operations in defense, intelligence, emergency services, financial systems, healthcare, and energy distribution. Cybersecurity frameworks such as NIST guidance and Zero Trust architectures remain important tools for establishing software and network security practices, but they are not sufficient by themselves to verify component-level hardware integrity at scale.
Software security measures can only detect and respond to attacks that occur after deployment, but they generally cannot identify threats embedded in physical components before those systems are powered on. Traditional security approaches are not designed to independently verify hardware integrity.
There is also persistent tension between procurement efficiency and security verification. Organizations have often treated speed to deployment, vendor consolidation, and cost optimization as dominant technology acquisition priorities. Security professionals may disagree with this emphasis, yet neither traditional procurement frameworks nor existing cybersecurity standards fully answer what organizations should do when hardware itself arrives pre-compromised.
Software security paradigms struggle to detect physical-layer compromises, where adversaries embed malicious components during manufacturing or distribution. Hardware’s unique characteristics require verification frameworks designed for the physical layer, rather than borrowed software security analogies.
Consequently, organizations may need scalable solutions that can verify chip-level hardware integrity before deployment and throughout operational lifecycles. Most organizations currently do not do this, relying instead on bills of materials, vendor attestations, and documentation that may be incomplete, inaccurate, or incapable of revealing component-level compromise.
This becomes even more important given the increasing complexity of global supply chains, where components pass through multiple countries and numerous hands before reaching their final destination. Each handoff creates opportunities for compromise that could result in catastrophic failures or data exfiltration affecting critical systems for years.
The globalization of technology supply chains presents a paradox for organizational security. Supply chains now span dozens of countries, with individual devices containing components from multiple manufacturers across different continents. These global networks enable cost efficiency and rapid innovation, but they also create unprecedented vulnerabilities.
Unlike closed, vertically integrated manufacturing systems where a single entity-controlled production from raw materials to finished product, modern supply chains involve countless intermediaries, subcontractors, and distribution channels. Adversaries can and do target any point in this chain to introduce compromised components without directly confronting the end user organization.
As supply chains become more complex, the number of potential compromise points also increases. These compromise points are especially attractive to state and non-state actors with adversarial relationships relative to the United States and its allies. Compared to software attacks that leave digital traces, hardware compromises present a fundamentally different attribution challenge. A server experiencing unexpected behavior could be suffering from a manufacturing defect, component degradation, or a deliberate hardware-level backdoor.
Physical forensics of chip-level modifications would be extremely difficult to conduct given the microscopic scale of modern semiconductor manufacturing and the proprietary nature of chip designs. Most organizations therefore operate under the assumption that hardware from reputable vendors is trustworthy. Yet recent assessments using chip-level IV&V technology have identified substantial device-level anomalies in more than half the tested equipment, raising a critical question: how many critical systems currently in operation contain similar compromises that have simply never been detected?
This verification gap creates a blind spot that adversaries can exploit, introducing compromises that persist undetected throughout a device’s operational lifetime, especially if the compromised hardware appears to function normally under routine conditions. Imagine a data center with five hundred servers suddenly experiencing coordinated failures during a crisis. Is it a sophisticated cyberattack, a remotely triggered supply chain compromise, or a coincidental hardware failure? Identifying the cause in a timely manner, let alone implementing an effective response, would be difficult.
While cybersecurity frameworks represent major steps toward establishing security standards, these frameworks primarily focus on software vulnerabilities, identity controls, and network defenses rather than independent hardware integrity verification. Supply chain risk management programs often rely on vendor certifications and country-of-origin documentation. Counterfeit detection efforts focus on obvious physical indicators. None of these approaches can reliably identify chip-level modifications or firmware inconsistencies embedded in otherwise legitimate-appearing components.
Here is a reality that security leaders rarely discuss openly: CIOs and CISOs are already underwater. They face an expanding threat landscape where AI-empowered bad actors have supercharged traditional attack methods, automated vulnerability discovery, and accelerated the pace of exploitation. Ransomware attacks have become more sophisticated. Phishing campaigns now use AI-generated content that bypasses traditional detection. Supply chain attacks through software dependencies multiply faster than security teams can assess them. Zero-day vulnerabilities emerge with alarming frequency. The security operations center never sleeps, and the alert queue never empties.
Into this already overwhelming environment comes a new imperative: verify whether hardware itself might be compromised from the moment it arrives. For many security leaders, this represents a cognitive bridge too far. The psychological burden of accepting that the physical devices deployed throughout an organization might contain embedded compromises before they are ever powered on creates a form of cognitive dissonance that many leaders struggle to process while managing daily operational demands.
Several security leaders, when confronted with chip-level verification findings, exhibit what can only be described as denial. Not because they necessarily doubt the technical validity of the findings, but because accepting the implications would require acknowledging that their current security posture includes weaknesses they may lack the resources to address. The mental model that hardware from reputable vendors is trustworthy provides psychological comfort in an otherwise chaotic threat environment. Challenging that assumption feels, to a CISO, like removing the last stable foundation.
This cognitive dissonance becomes even more acute when considering targeted attacks on organizational VIPs. The possibility that adversaries might compromise hardware specifically deployed to executives, board members, or key technical personnel to exfiltrate intellectual property, strategic plans, or sensitive communications represents a threat model that many organizations have never seriously considered. Yet the targeting of specific individuals through compromised devices they use daily is not theoretical. It is happening. The intellectual property and insights that senior leaders possess make them high-value targets for sophisticated adversaries willing to invest in supply chain manipulation.
For critical infrastructure operators, this leadership denial problem presents a particular challenge. The systems controlling essential services cannot fail. The pressure to maintain operational continuity creates powerful incentives to avoid confronting uncomfortable truths about hardware integrity. Yet the risk of compromised hardware in systems controlling power generation, water treatment, transportation networks, or emergency services is too significant to ignore based on psychological comfort.
This suggests that critical infrastructure sectors may need external requirements mandating independent hardware verification to overcome the cognitive dissonance that prevents voluntary adoption. Just as safety regulations require physical inspection of critical equipment regardless of a manufacturer’s reputation, hardware security may require chip-level verification to ensure that systems communities depend on rest on a foundation of verified integrity.
Even as technical solutions for hardware verification exist and have been proven in operational deployments, a more fundamental challenge persists: a collective action problem that leaves critical vulnerabilities unaddressed while each sector waits for the other to act.
Yet when engaging with government agencies about hardware security, a common response emerges: business will take care of it. Commercial entities, driven by competitive pressures and liability concerns, are expected to adopt security measures to protect their operations and customers. Market forces, the argument goes, will drive chip-level hardware IV&V without government intervention.
Meanwhile, when engaging with private sector organizations, particularly boards and C-suites, a parallel problematic response emerges: government will take care of it. National security agencies are expected to identify supply chain threats, regulatory frameworks are expected to establish requirements, and government procurement standards are expected to drive industry practices. Business leaders, already managing countless operational challenges, often assume that hardware security falls within the government’s responsibility to protect critical infrastructure and national security interests.
These mutual expectations create a dangerous gap in which neither sector acts with sufficient urgency. Meanwhile, the chip-level imperative for critical infrastructure persists and is being exploited to gain access to important data, intellectual property, and intelligence. Adversaries do not wait for sectors to resolve their coordination challenges. They continue to exploit the gap.
Breaking this collective action problem requires explicit recognition that hardware verification is a shared responsibility requiring coordinated action across government and the private sector. Neither can wait for the other to act first. What remains is the will to act despite the coordination challenges and the cognitive dissonance that makes accepting hardware-level threats psychologically difficult.
The governance gap is especially consequential because the United States is building massive numbers of data centers without routine IV&V processes for the hardware being deployed. These facilities are designed to support cloud computing, artificial intelligence development, and digital services that underpin the modern economy and society. Yet they are being constructed and populated with hardware that may never have been independently verified at the component level. Each unverified server, switch, accelerator, and storage system represents a potential compromise point that could persist for years of operational lifetime.
This digital infrastructure construction boom without verification directly threatens the notion of Silicon Sovereignty in an age of global supply chains. Silicon sovereignty, the concept that nations should maintain control over the integrity of the semiconductor technology powering critical systems, becomes meaningless if we cannot verify that the silicon we deploy actually matches what we believe we purchased.
Building data centers at scale without verification processes is akin to constructing critical infrastructure on an unexamined foundation. We assume it is solid because we cannot see beneath the surface, but we have not actually verified its integrity.
The collective action problem also extends beyond domestic coordination. International supply chains mean that hardware verification requires cooperation across allied nations. Yet each nation may assume others will establish verification standards and share threat intelligence. The result is a fragmented approach that leaves gaps adversaries can exploit.
How then could organizations integrate hardware verification into existing security operations in a way that overcomes the psychological challenges of CISOs already under siege from threats while also avoiding unsustainable costs or operational disruptions?
The answer lies in treating hardware integrity as a foundational security requirement rather than an optional enhancement. Just as organizations now routinely scan software for vulnerabilities and monitor networks for intrusions, hardware verification must become a standard practice. Technology exists today to perform chip-level IV&V at scale using AI-driven analysis of billions of component data points.
Organizations do not need to verify every device in the same way on day one. A practical implementation model can begin with risk-tiered adoption:
We think incorporating hardware verification into security operations is necessary to address the realities of 21st-century supply chain threats juxtaposed with the increasing sophistication of adversaries. Extending security practices to include physical-layer verification recognizes that hardware integrity underpins all other security measures. More importantly, it enables organizations to detect and respond to compromises that are currently invisible to conventional security tools.
Organizations stand at a critical juncture in the evolution of cybersecurity. The shift from software-only defenses to comprehensive hardware verification presents both challenges and opportunities. The technology to verify hardware integrity exists and has been proven in operational deployments. The question is whether organizations will adopt these capabilities proactively or wait until a major incident forces reactive implementation.
We cannot afford to apply old assumptions about hardware trustworthiness to new realities of global supply chain vulnerability. The time for decisive action is now, before we witness the infrastructure equivalent of a catastrophic failure caused by undetected hardware compromises. By incorporating hardware verification into security operations, organizations can ensure that their critical systems rest on a foundation of verified integrity rather than assumed trustworthiness.
The future of hardware security, and by extension the security of everything built on that hardware foundation, depends on our willingness to confront uncomfortable truths and overcome coordination challenges. The work begins now with verification of the systems we deploy today and tomorrow.
Dr. David A. Bray is a Distinguished Fellow and Chair of the Accelerator with the Alfred Lee Loomis Innovation Council at the non-partisan Henry L. Stimson Center. He is also a CEO and transformation leader for different “under the radar” tech and data ventures seeking to get started in novel situations. He is Principal at LeadDoAdapt Ventures, Inc. and has served in a variety of leadership roles in turbulent environments. He previously served as a non-partisan Senior National Intelligence Service Executive, as Chief Information Officer of the Federal Communications Commission, and IT Chief for the Bioterrorism Preparedness and Response Program. Business Insider named him one of the top “24 Americans Changing the World” and he has received both the Joint Civilian Service Commendation Award and the National Intelligence Exceptional Achievement Medal. David accepted a leadership role in December 2019 to direct the successful bipartisan Commission on the Geopolitical Impacts of New Technologies and Data that included Senator Mark Warner, Senator Rob Portman, Rep. Suzan DelBene, and Rep. Michael McCaul. From 2017 to the start of 2020, David also served as Executive Director for the People-Centered Internet coalition Chaired by Internet co-originator Vint Cerf. Business Insider named him one of the top “24 Americans Who Are Changing the World” and he was named a Young Global Leader by the World Economic Forum. For twelve different startups, he has served as President, CEO, Chief Strategy Officer, and Strategic Advisor roles. The U.S. Congress invited him to serve as an expert witness on AI in September 2025.
Dr. Trent Teyema (FBI Special Agent – SES ret.), advises governments and companies on cybersecurity, blockchain, infrastructures, national security, and space. He has served in numerous senior leadership positions, to include the Director of Cybersecurity Policy for the White House’s National Security Council, the SAC of the Cyber and Counterintelligence Division for FBI Los Angeles, the FBI Cyber Division’s COO / Chief of Cyber Readiness. Mr. Teyema founded and led the National Cyber Investigative Joint Task Force (NCIJTF) which is one of the seven US cybersecurity centers. Dr. Teyema recently defended his dissertation on the cybersecurity of space-based assets successfully at Marymount University.