• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

After SolarWinds, the U.S. can trust no one

By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
January 29, 2021, 1:45 PM ET
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.Bronte Wittpenn/Bloomberg via Getty Images

The recent cyberattack against SolarWinds, a Texas-based IT firm, has shaken up the U.S. national security establishment. Fortunately, it is also serving as a wake-up call that has inspired the new Biden administration to strengthen the defense of its communications networks and systems.

Attackers thought to be working for Russian intelligence infected the company’s software, which was then downloaded by a still-unknown number of its 18,000 customers. These included the U.S. Departments of Treasury, Defense, Justice, State, Commerce, and Energy, plus governments and companies in at least seven other countries.

Some experts say such attacks are “child’s play” for the best nation-state hackers, including those of Russia, China, the U.S., and a few others. They can break into almost any system, sometimes by compromising otherwise trusted supply chains through a third-party vendor. Their formidable capabilities are quickly being augmented by artificial intelligence.

To ward off these skilled, motivated, and well-resourced cyber miscreants, the U.S. needs a comprehensive national approach. It must start by reexamining traditional notions of trust.

Earlier this month, William Evanina, former director of the U.S. National Counterintelligence and Security Center, said America should adopt a position of “zero trust” in order to start properly managing supply chain risk. Zero trust is the idea that no untested technology should be ever be trusted—or barred—without verification. The fallacy of the “trusted vendor” underpins last year’s Clean Network Initiative, which “fails as a serious effort at cybersecurity,” according to Jason Healey, a former security expert with the U.S. Air Force and the White House.

Instead, we must deploy national-security–level defenses and risk-management protocols for critical technologies. We must abandon the apparent presumption that if you only deploy products and components from “trusted” vendors, you’ll have a “clean network.” After all, SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty, which it apparently did long before anyone spotted the problem. We must assume all networks are dirty, and act accordingly.

Last year, two colleagues and I wrote an article called “Don’t Trust Anyone” that was published in a journal funded by the U.S. Department of Defense. We noted that blacklisting some technology vendors, while de facto trusting others, is a recipe for disaster—as the SolarWinds hack subsequently made clear.

Instead, we should follow the advice of the bipartisan Cyberspace Solarium Commission and other experts, and start assessing the risk from all suppliers. We should then monitor for any risks that may arise after network gear is deployed.

To make such assessments, it will be crucial to build a consensus around global standards for telecom and mobile operators, and for the security of network equipment. Currently, operators and vendors lack clear, consistent standards-based guidance about what technologies they can deploy in various countries, and how those technologies will be operated and maintained. Standardized guidelines can be built into procurement requirements and contractual provisions, and possibly included in regulatory or statutory frameworks.

Equally important are mechanisms to verify and test key components of network technology. Verification helps ensure that all vendors’ technology conforms to well-defined requirements that fit the risk environment. Security testing provides an objective basis for judging networks and systems to be secure and resilient, even under difficult conditions. Testing criteria can be adjusted—and strengthened, if need be—for critical infrastructure, such as the banking system or the power grid.

The telecom industry’s leading standards-setting ­­organizations have devised a framework called NESAS that could serve as the foundation for higher-assurance standards and testing programs. NESAS lets mobile equipment sellers voluntarily subject both their gear and their tech processes to a comprehensive cybersecurity audit. This provides a baseline for strong telecom equipment requirements, and points to a path forward that envisions rigorous third-party testing—with results to be shared with customers.

In addition, some countries are enacting laws to make networks more secure. Last October, Germany unveiled legislation that raises security requirements for all telecom operators, equipment suppliers, and data processors, and makes them accountable for the security of the technology supply chain. Operators must disclose all of the critical components they will deploy in their networks, while equipment sellers must spell out in detail how they will ensure that their products cannot be used for sabotage, espionage, or terrorism. Players that fail to meet legally mandated thresholds could be fined, banned, or shut down. 

As a society, we need to support those who are working to make critical technology more secure, while at the same time demanding greater accountability from organizations and leaders. The incoming Biden administration has an opportunity to build on the important work that has already been done to help achieve greater security. As SolarWinds made clear, this should be one of its highest priorities.

Andy Purdy is the chief security officer for Huawei Technologies USA.

More opinion from Fortune:

  • I’m a McDonald’s worker who was homeless due to low pay. It’s time for a $15 minimum wage
  • Adults should listen to children to understand the severity of the climate crisis
  • We’re Columbia students going on a tuition strike. Here’s why
  • How to accelerate the far-too-slow COVID vaccine rollout
  • Clean-energy startups are key to “building back better” after COVID
About the Author
By Andy Purdy
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

gary
Commentaryregulation
The biggest mistake CEOs make with AI has nothing to do with the technology
By Gary ShapiroApril 1, 2026
9 hours ago
trump
CommentaryEPA
The EPA just valued a human life at $0. That’s not just a moral crisis — it’s a market crisis
By Andrew BeharApril 1, 2026
10 hours ago
dressel
Commentaryhistory
AI can’t remember what your company learned the hard way 
By Jason DresselApril 1, 2026
11 hours ago
pelosi
CommentaryElections
Congress has a lower approval rating than Hitler in some polls. And we just keep voting for the same 2 parties
By Stu StrumwasserApril 1, 2026
13 hours ago
gen z
CommentaryGen Z
Gen Z is engineering an analog future — and it’s at least a $5 billion opportunity
By Luba KassovaApril 1, 2026
14 hours ago
brian
CommentaryCulture
The real engine of innovation is trust
By Brian DoublesMarch 31, 2026
1 day ago

Most Popular

Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
Economy
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
By Fortune EditorsMarch 30, 2026
2 days ago
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
Success
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
By Fortune EditorsMarch 31, 2026
1 day ago
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
Personal Finance
Kevin O'Leary says if you earn $68,000 a year and follow this rule, you'll retire a millionaire
By Fortune EditorsMarch 31, 2026
1 day ago
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
AI
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
By Fortune EditorsMarch 30, 2026
2 days ago
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
Economy
Hiring just hit a level not seen since the economy was ‘closed down literally’ during COVID, top economist says
By Fortune EditorsMarch 31, 2026
1 day ago
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
Energy
Markets cheer as Trump threatens to abandon Iran war, but Jamie Dimon sides with allies: ‘Win this thing and clean up the straits’
By Fortune EditorsMarch 31, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.