• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

After SolarWinds, the U.S. can trust no one

By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
January 29, 2021, 1:45 PM ET
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.Bronte Wittpenn/Bloomberg via Getty Images

The recent cyberattack against SolarWinds, a Texas-based IT firm, has shaken up the U.S. national security establishment. Fortunately, it is also serving as a wake-up call that has inspired the new Biden administration to strengthen the defense of its communications networks and systems.

Attackers thought to be working for Russian intelligence infected the company’s software, which was then downloaded by a still-unknown number of its 18,000 customers. These included the U.S. Departments of Treasury, Defense, Justice, State, Commerce, and Energy, plus governments and companies in at least seven other countries.

Some experts say such attacks are “child’s play” for the best nation-state hackers, including those of Russia, China, the U.S., and a few others. They can break into almost any system, sometimes by compromising otherwise trusted supply chains through a third-party vendor. Their formidable capabilities are quickly being augmented by artificial intelligence.

To ward off these skilled, motivated, and well-resourced cyber miscreants, the U.S. needs a comprehensive national approach. It must start by reexamining traditional notions of trust.

Earlier this month, William Evanina, former director of the U.S. National Counterintelligence and Security Center, said America should adopt a position of “zero trust” in order to start properly managing supply chain risk. Zero trust is the idea that no untested technology should be ever be trusted—or barred—without verification. The fallacy of the “trusted vendor” underpins last year’s Clean Network Initiative, which “fails as a serious effort at cybersecurity,” according to Jason Healey, a former security expert with the U.S. Air Force and the White House.

Instead, we must deploy national-security–level defenses and risk-management protocols for critical technologies. We must abandon the apparent presumption that if you only deploy products and components from “trusted” vendors, you’ll have a “clean network.” After all, SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty, which it apparently did long before anyone spotted the problem. We must assume all networks are dirty, and act accordingly.

Last year, two colleagues and I wrote an article called “Don’t Trust Anyone” that was published in a journal funded by the U.S. Department of Defense. We noted that blacklisting some technology vendors, while de facto trusting others, is a recipe for disaster—as the SolarWinds hack subsequently made clear.

Instead, we should follow the advice of the bipartisan Cyberspace Solarium Commission and other experts, and start assessing the risk from all suppliers. We should then monitor for any risks that may arise after network gear is deployed.

To make such assessments, it will be crucial to build a consensus around global standards for telecom and mobile operators, and for the security of network equipment. Currently, operators and vendors lack clear, consistent standards-based guidance about what technologies they can deploy in various countries, and how those technologies will be operated and maintained. Standardized guidelines can be built into procurement requirements and contractual provisions, and possibly included in regulatory or statutory frameworks.

Equally important are mechanisms to verify and test key components of network technology. Verification helps ensure that all vendors’ technology conforms to well-defined requirements that fit the risk environment. Security testing provides an objective basis for judging networks and systems to be secure and resilient, even under difficult conditions. Testing criteria can be adjusted—and strengthened, if need be—for critical infrastructure, such as the banking system or the power grid.

The telecom industry’s leading standards-setting ­­organizations have devised a framework called NESAS that could serve as the foundation for higher-assurance standards and testing programs. NESAS lets mobile equipment sellers voluntarily subject both their gear and their tech processes to a comprehensive cybersecurity audit. This provides a baseline for strong telecom equipment requirements, and points to a path forward that envisions rigorous third-party testing—with results to be shared with customers.

In addition, some countries are enacting laws to make networks more secure. Last October, Germany unveiled legislation that raises security requirements for all telecom operators, equipment suppliers, and data processors, and makes them accountable for the security of the technology supply chain. Operators must disclose all of the critical components they will deploy in their networks, while equipment sellers must spell out in detail how they will ensure that their products cannot be used for sabotage, espionage, or terrorism. Players that fail to meet legally mandated thresholds could be fined, banned, or shut down. 

As a society, we need to support those who are working to make critical technology more secure, while at the same time demanding greater accountability from organizations and leaders. The incoming Biden administration has an opportunity to build on the important work that has already been done to help achieve greater security. As SolarWinds made clear, this should be one of its highest priorities.

Andy Purdy is the chief security officer for Huawei Technologies USA.

More opinion from Fortune:

  • I’m a McDonald’s worker who was homeless due to low pay. It’s time for a $15 minimum wage
  • Adults should listen to children to understand the severity of the climate crisis
  • We’re Columbia students going on a tuition strike. Here’s why
  • How to accelerate the far-too-slow COVID vaccine rollout
  • Clean-energy startups are key to “building back better” after COVID
About the Author
By Andy Purdy
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

putin
CommentaryRussia
Exclusive analysis: we looked at the 400 western firms still in Russia. Their paltry size strips Putin’s bluff bare naked
By Jeffrey Sonnenfeld, Stephen Henriques, Jake Waldinger and Giuseppe ScottoFebruary 27, 2026
5 hours ago
roth
CommentaryLeadership
The AI resource reallocation challenge: How can companies capture the value of time?
By Erik RothFebruary 27, 2026
7 hours ago
will
CommentaryAdvertising
I’m one of America’s top pollsters and I’ve got a warning for the AI companies: customers aren’t sold on ads
By Will JohnsonFebruary 27, 2026
10 hours ago
the pitt
CommentaryDEI
‘The Pitt’: a masterclass display of DEI in action 
By Robert RabenFebruary 26, 2026
1 day ago
david booth
CommentaryMarkets
3 lessons from investing’s ‘moneyball’ moment
By David BoothFebruary 25, 2026
2 days ago
CommentaryCulture
Gen Z’s enthusiasm for all things touchable is resurrecting the analog economy—and costing parents
By Luba KassovaFebruary 24, 2026
3 days ago

Most Popular

placeholder alt text
Innovation
An MIT roboticist who cofounded bankrupt robot vacuum maker iRobot says Elon Musk’s vision of humanoid robot assistants is ‘pure fantasy thinking’
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago
placeholder alt text
Success
Jeff Bezos says being lazy, not working hard, is the root of anxiety: ‘The stress goes away the second I take that first step’
By Sydney LakeFebruary 25, 2026
2 days ago
placeholder alt text
Economy
Trump claims America is ‘winning so much.’ The IMF agrees, adding that Trump’s trade policies are the only thing holding it back from even more
By Tristan BoveFebruary 26, 2026
23 hours ago
placeholder alt text
Success
Gen Z Olympic champion Eileen Gu says she rewires her brain daily to be more successful—and multimillionaire founder Arianna Huffington says it really does work
By Orianna Rosa RoyleFebruary 25, 2026
2 days ago
placeholder alt text
AI
Jamie Dimon says society should start preparing for AI job displacement: ‘Now’s the time to start thinking about’ it
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago
placeholder alt text
Economy
It’s more than George Clooney moving to France: America is becoming the ‘uncool’ country that people want to move away from
By Nick LichtenbergFebruary 27, 2026
10 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.