Devices are becoming a primary target for cyberattacks, reinforcing the need to ensure that supply chain risk management must apply to hardware as much as software.
By: Dave Dimlich
President of SD3IT
Today’s cyber threat landscape gives security teams plenty of high-risk areas to think about. Supply chains are one of them. Once primarily a concern of logistics and shipping efficiency, supply chains have become a major focus of cybersecurity efforts because of the frequency of disruptions and the potential damage attacks can do. Most notably, organizations are pouring resources into securing the software supply chain, which has been targeted in highly damaging attacks from SolarWinds in 2020 to this year’s LiteLLM-Trivy scanner attack.
But while addressing issues like software integrity, vendor compliance with security standards and artificial intelligence vulnerabilities, there is another fundamental question organizations need to ask early in the process: Is the hardware itself trustworthy?
That question is becoming harder to answer as IT environments become more distributed and the technology supporting them becomes more complex. Whether it’s embedded operational technology (OT), edge devices, servers or other components of the infrastructure, hardware weaknesses can leave the entire enterprise vulnerable.
If organizations haven’t noticed how vulnerable their hardware is, cyberattackers certainly have. Verizon’s 2026 Data Breach Investigations Report (DBIR) points out that vulnerability exploitation, which can involve software as well as hardware, is now the No. 1 attack vector, occurring in 31% of breaches, speedily overtaking credential abuse, now at 13%, for the top spot. Edge devices and VPNs, which increased from 3% to 22% of the breaches involving device vulnerabilities, contributed significantly to the increase. Hardware doesn’t make up all of that increase, but it is, all of a sudden, a major contributor to it.
Organizations aren’t always prepared. The DBIR reports that only 26% of critical vulnerabilities identified in the Cybersecurity Infrastructure and Security Agency’s Known Exploited Vulnerabilities (CISA KEV) catalog were fully remediated by organizations in 2025, down from 38% in 2024.
Enterprises are now faced with the urgent need to focus on securing hardware devices. That involves multiple steps from discovery to monitoring, but it starts with having full knowledge of a hardware component’s provenance.
The Importance of Hardware’s Pedigree
As I discussed in an earlier Inside the Mission post on supply chain disruptions, modern enterprises depend on hardware, software, cloud providers, IoT devices and third-party services that can originate from dozens of suppliers across multiple countries. Hardware can pass through multiple manufacturers, suppliers, distributors and logistics providers before reaching an organization’s facility.
Each of those steps creates another opportunity for tampering, counterfeiting or some other act that can compromise a device before it’s even added to the enterprise. A weakness anywhere in the ecosystem can become a risk to the organization.
The goal of hardware provenance is to establish a verifiable record of where a physical component came from, how it was handled and whether it remained trustworthy throughout that journey.
A compromised piece of hardware can look innocent enough, but there are a host of ways that it can be surreptitiously added to the network. As hardware travels through the supply chain, counterfeit components, often designed to resemble legitimate devices, can be substituted without authorization. Firmware can be compromised before delivery, or a shipment can be intercepted or tampered with during transit. Some threats can originate even earlier, such as during manufacturing or assembly.
That makes hardware supply chain security different from many traditional cybersecurity problems. A compromised component can potentially bypass controls that normally protect an operating system or application environment, giving the security controls in place a much shakier foundation.
The breadth of IT enterprises and the connectedness of systems underscore why supply chain risk management (SCRM) cannot stop at the primary vendor. Organizations increasingly need visibility into the broader ecosystem that produces and delivers their technology. The same principles that are (ideally) applied to software should also apply to the physical technology entering the environment.
Hardware Needs a Bill of Materials Too
Organizations are increasingly familiar with the software bill of materials, or SBOM, which supplies a thorough inventory of the components, libraries and dependencies that go into software applications. SBOMs have become essential elements of both software security and software supply chain security. Hardware needs a comparable level of visibility.
A hardware bill of materials (HBOM) is emerging as a way to identify the physical components that make up a device and trace those components back through the supply chain. The Cybersecurity and Infrastructure Security Agency (CISA) has developed an HBOM Framework specifically to give government and industry a consistent way for hardware vendors to communicate information about the components contained in products. That can include identifying sub-tier suppliers, understanding where components originate and recognizing dependencies that might otherwise remain hidden.
Procurement decisions increasingly have security consequences long after the purchase order has been issued; HBOMs and other practices help apply security practices early in the process.
Establishing a Hardware Root of Trust
Establishing a chain of custody for devices is one part of the equation, but you also need ways to determine whether the hardware and its firmware are authentic. This is where hardware-based roots of trust (RoTs) come into play.
RoTs, which are also used with software, provide a foundation for establishing device identity and validating the integrity of components and firmware. A RoT will assign a secure, unique digital signature to a device using cryptographic mechanisms to verify what’s running on it, and can check the authenticity of all components again at any point in the future.
Microsoft provides a useful example of this approach in its Azure infrastructure. Its hardware security architecture uses hardware RoTs, including technologies such as Project Cerberus and Trusted Platform Modules, to establish trust in hardware components and firmware. It also uses RoTs to provide traceability through the entire hardware lifecycle.
At SD3IT, that is where we see the practical value of bringing procurement, cybersecurity and infrastructure planning together. Supply chain security cannot be a checklist that someone completes when equipment is ordered. It has to become part of the architecture and operational processes.
Building Supply Chain Security Into the Architecture
Protecting the supply chain is a critical area where SD3IT has a proven record of excellence. We see the practical value of bringing procurement, cybersecurity and infrastructure planning together to gain full lifecycle visibility and security.
Hardware security doesn’t exist independently from the rest of the environment. A secure server still needs protected identity controls. A trusted edge device needs appropriate access policies. A ruggedized system operating in a disconnected environment needs a security architecture that accounts for what happens when it’s no longer connected to the enterprise.
A common thread in securing both physical and digital assets is with a zero trust approach that continuously evaluates users, devices, systems and data, rather than assuming something is trustworthy simply because it’s already inside the environment. That approach applies to hardware too.
For federal and defense organizations in particular, that means incorporating provenance and SCRM considerations into procurement, deployment and lifecycle management. It also means understanding how hardware security connects to identity, encryption, monitoring and policy enforcement. Along with our team of partners, SD3IT integrates secure architectures and solutions for military, civilian federal and commercial organizations.
The Box Is Part of the Security Architecture
In today’s multi-faceted threat environment, hardware can be as big a target as user credentials or applications, so a robust security posture must include hardware supply chain protections.
That requires provenance. An HBOM can provide visibility; a hardware RoT can act as an anchor for identity and integrity; and cryptographic verification can help detect unauthorized changes. SCRM can bring those capabilities together with procurement, vendor management and operational oversight.
The result is a more complete approach to infrastructure security, and one organizations can no longer afford to treat as optional. Because if you can’t trust the box, you can’t trust what runs on it.
About SD3IT
At SD3IT, we help federal agencies, defense organizations and commercial enterprises build secure, resilient technology environments that accelerate mission success. From AI-ready infrastructure and zero trust architectures to edge computing, data center modernization and systems integration, we design, drive and deliver solutions that help customers operate with confidence across today’s increasingly complex mission environments.
