• Home
  • Latest
  • Coins2Day 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

After SolarWinds, the U.S. can trust no one

By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
January 29, 2021, 1:45 PM ET
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.Bronte Wittpenn/Bloomberg via Getty Images

The recent cyberattack against SolarWinds, a Texas-based IT firm, has shaken up the U.S. National security establishment. Fortunately, it is also serving as a wake-up call that has inspired the new Biden administration to strengthen the defense of its communications networks and systems.

Attackers thought to be working for Russian intelligence infected the company’s software, which was then downloaded by a still-unknown number of its 18,000 customers. These included the U.S. Departments of Treasury, Defense, Justice, State, Commerce, and Energy, plus governments and companies in at least seven other countries.

Some experts say such attacks are “child’s play” for the best nation-state hackers, including those of Russia, China, the U.S., and a few others. They can break into almost any system, sometimes by compromising otherwise trusted supply chains through a third-party vendor. Their formidable capabilities are quickly being augmented by artificial intelligence.

To ward off these skilled, motivated, and well-resourced cyber miscreants, the U.S. Needs a comprehensive national approach. It must start by reexamining traditional notions of trust.

Earlier this month, William Evanina, former director of the U.S. National Counterintelligence and Security Center, said America should adopt a position of “zero trust” in order to start properly managing supply chain risk. Zero trust is the idea that no untested technology should be ever be trusted—or barred—without verification. The fallacy of the “trusted vendor” underpins last year’s Clean Network Initiative, which “fails as a serious effort at cybersecurity,” according to Jason Healey, a former security expert with the U.S. Air Force and the White House.

Instead, we must deploy national-security–level defenses and risk-management protocols for critical technologies. We must abandon the apparent presumption that if you only deploy products and components from “trusted” vendors, you’ll have a “clean network.” After all, SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty, which it apparently did long before anyone spotted the problem. We must assume all networks are dirty, and act accordingly.

Last year, two colleagues and I wrote an article called “Don’t Trust Anyone” that was published in a journal funded by the U.S. Department of Defense. We noted that blacklisting some technology vendors, while de facto trusting others, is a recipe for disaster—as the SolarWinds hack subsequently made clear.

Instead, we should follow the advice of the bipartisan Cyberspace Solarium Commission and other experts, and start assessing the risk from all suppliers. We should then monitor for any risks that may arise after network gear is deployed.

To make such assessments, it will be crucial to build a consensus around global standards for telecom and mobile operators, and for the security of network equipment. Currently, operators and vendors lack clear, consistent standards-based guidance about what technologies they can deploy in various countries, and how those technologies will be operated and maintained. Standardized guidelines can be built into procurement requirements and contractual provisions, and possibly included in regulatory or statutory frameworks.

Equally important are mechanisms to verify and test key components of network technology. Verification helps ensure that all vendors’ technology conforms to well-defined requirements that fit the risk environment. Security testing provides an objective basis for judging networks and systems to be secure and resilient, even under difficult conditions. Testing criteria can be adjusted—and strengthened, if need be—for critical infrastructure, such as the banking system or the power grid.

The telecom industry’s leading standards-setting ­­organizations have devised a framework called NESAS that could serve as the foundation for higher-assurance standards and testing programs. NESAS lets mobile equipment sellers voluntarily subject both their gear and their tech processes to a comprehensive cybersecurity audit. This provides a baseline for strong telecom equipment requirements, and points to a path forward that envisions rigorous third-party testing—with results to be shared with customers.

In addition, some countries are enacting laws to make networks more secure. Last October, Germany unveiled legislation that raises security requirements for all telecom operators, equipment suppliers, and data processors, and makes them accountable for the security of the technology supply chain. Operators must disclose all of the critical components they will deploy in their networks, while equipment sellers must spell out in detail how they will ensure that their products cannot be used for sabotage, espionage, or terrorism. Players that fail to meet legally mandated thresholds could be fined, banned, or shut down. 

As a society, we need to support those who are working to make critical technology more secure, while at the same time demanding greater accountability from organizations and leaders. The incoming Biden administration has an opportunity to build on the important work that has already been done to help achieve greater security. As SolarWinds made clear, this should be one of its highest priorities.

Andy Purdy is the chief security officer for Huawei Technologies USA.

More opinion from Coins2Day:

  • I’m a McDonald’s worker who was homeless due to low pay. It’s time for a $15 minimum wage
  • Adults should listen to children to understand the severity of the climate crisis
  • We’re Columbia students going on a tuition strike. Here’s why
  • How to accelerate the far-too-slow COVID vaccine rollout
  • Clean-energy startups are key to “building back better” after COVID
About the Author
By Andy Purdy
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

sharma
CommentaryTraining
AI will infiltrate the industrial workforce in 2026—let’s apply it to training the next generation, not replacing them
By Kriti SharmaJanuary 15, 2026
22 hours ago
CommentaryBusiness
Using AI just to reduce costs is a woeful misuse of a transformative technology
By Nigel VazJanuary 15, 2026
24 hours ago
powell
CommentaryMiddle class
Forget the K-Shape: We have a barbell economy—and the middle class is buckling under the weight
By Katica RoyJanuary 14, 2026
2 days ago
engineer
Commentaryengineering
China graduates 1.3 million engineers per year, versus just 130,000 in the U.S. We need AI to bridge the gap
By Paul Eremenko and Ashish SrivastavaJanuary 14, 2026
2 days ago
powell/trump
CommentaryFederal Reserve
Is Powell’s Fed head independence dead? Trump outfoxes himself this time
By Jeffrey SonnenfeldJanuary 13, 2026
3 days ago
paramount
CommentaryM&A
A cautionary Hollywood tale: the Ellisons’ lose-lose Paramount positioning
By Jeffrey Sonnenfeld and Stephen HenriquesJanuary 12, 2026
4 days ago

Most Popular

placeholder alt text
Personal Finance
Peter Thiel makes his biggest donation in years to help defeat California’s billionaire wealth tax
By Nick LichtenbergJanuary 14, 2026
2 days ago
placeholder alt text
Europe
Americans have been quietly plundering Greenland for over 100 years, since a Navy officer chipped fragments off the Cape York iron meteorite
By Paul Bierman and The ConversationJanuary 14, 2026
1 day ago
placeholder alt text
Health
The head of marketing at Slate posted on LinkedIn requesting cleaning services as a benefit at her company. The next day, HR answered her call
By Sydney LakeJanuary 15, 2026
23 hours ago
placeholder alt text
Success
Despite a $45 million net worth, Big Bang Theory star still works tough, 16-hour days—he repeats one mantra when overwhelmed
By Orianna Rosa RoyleJanuary 15, 2026
22 hours ago
placeholder alt text
Economy
California's wealth tax doesn't fix the real problem: Cash-poor billionaires who borrow money, tax-free, to live on
By Nick LichtenbergJanuary 14, 2026
2 days ago
placeholder alt text
Politics
One year after Bill Gates surprised with the choice to close his foundation by 2045, he's cutting staff jobs
By Stephanie Beasley and The Associated PressJanuary 14, 2026
1 day ago

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.