• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

After SolarWinds, the U.S. can trust no one

By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
By
Andy Purdy
Andy Purdy
Down Arrow Button Icon
January 29, 2021, 1:45 PM ET
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.
SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty. We must assume all networks are dirty, and act accordingly.Bronte Wittpenn/Bloomberg via Getty Images

The recent cyberattack against SolarWinds, a Texas-based IT firm, has shaken up the U.S. national security establishment. Fortunately, it is also serving as a wake-up call that has inspired the new Biden administration to strengthen the defense of its communications networks and systems.

Attackers thought to be working for Russian intelligence infected the company’s software, which was then downloaded by a still-unknown number of its 18,000 customers. These included the U.S. Departments of Treasury, Defense, Justice, State, Commerce, and Energy, plus governments and companies in at least seven other countries.

Some experts say such attacks are “child’s play” for the best nation-state hackers, including those of Russia, China, the U.S., and a few others. They can break into almost any system, sometimes by compromising otherwise trusted supply chains through a third-party vendor. Their formidable capabilities are quickly being augmented by artificial intelligence.

To ward off these skilled, motivated, and well-resourced cyber miscreants, the U.S. needs a comprehensive national approach. It must start by reexamining traditional notions of trust.

Earlier this month, William Evanina, former director of the U.S. National Counterintelligence and Security Center, said America should adopt a position of “zero trust” in order to start properly managing supply chain risk. Zero trust is the idea that no untested technology should be ever be trusted—or barred—without verification. The fallacy of the “trusted vendor” underpins last year’s Clean Network Initiative, which “fails as a serious effort at cybersecurity,” according to Jason Healey, a former security expert with the U.S. Air Force and the White House.

Instead, we must deploy national-security–level defenses and risk-management protocols for critical technologies. We must abandon the apparent presumption that if you only deploy products and components from “trusted” vendors, you’ll have a “clean network.” After all, SolarWinds was a trusted vendor until it wasn’t, and its supply chain was clean until it got dirty, which it apparently did long before anyone spotted the problem. We must assume all networks are dirty, and act accordingly.

Last year, two colleagues and I wrote an article called “Don’t Trust Anyone” that was published in a journal funded by the U.S. Department of Defense. We noted that blacklisting some technology vendors, while de facto trusting others, is a recipe for disaster—as the SolarWinds hack subsequently made clear.

Instead, we should follow the advice of the bipartisan Cyberspace Solarium Commission and other experts, and start assessing the risk from all suppliers. We should then monitor for any risks that may arise after network gear is deployed.

To make such assessments, it will be crucial to build a consensus around global standards for telecom and mobile operators, and for the security of network equipment. Currently, operators and vendors lack clear, consistent standards-based guidance about what technologies they can deploy in various countries, and how those technologies will be operated and maintained. Standardized guidelines can be built into procurement requirements and contractual provisions, and possibly included in regulatory or statutory frameworks.

Equally important are mechanisms to verify and test key components of network technology. Verification helps ensure that all vendors’ technology conforms to well-defined requirements that fit the risk environment. Security testing provides an objective basis for judging networks and systems to be secure and resilient, even under difficult conditions. Testing criteria can be adjusted—and strengthened, if need be—for critical infrastructure, such as the banking system or the power grid.

The telecom industry’s leading standards-setting ­­organizations have devised a framework called NESAS that could serve as the foundation for higher-assurance standards and testing programs. NESAS lets mobile equipment sellers voluntarily subject both their gear and their tech processes to a comprehensive cybersecurity audit. This provides a baseline for strong telecom equipment requirements, and points to a path forward that envisions rigorous third-party testing—with results to be shared with customers.

In addition, some countries are enacting laws to make networks more secure. Last October, Germany unveiled legislation that raises security requirements for all telecom operators, equipment suppliers, and data processors, and makes them accountable for the security of the technology supply chain. Operators must disclose all of the critical components they will deploy in their networks, while equipment sellers must spell out in detail how they will ensure that their products cannot be used for sabotage, espionage, or terrorism. Players that fail to meet legally mandated thresholds could be fined, banned, or shut down. 

As a society, we need to support those who are working to make critical technology more secure, while at the same time demanding greater accountability from organizations and leaders. The incoming Biden administration has an opportunity to build on the important work that has already been done to help achieve greater security. As SolarWinds made clear, this should be one of its highest priorities.

Andy Purdy is the chief security officer for Huawei Technologies USA.

More opinion from Fortune:

  • I’m a McDonald’s worker who was homeless due to low pay. It’s time for a $15 minimum wage
  • Adults should listen to children to understand the severity of the climate crisis
  • We’re Columbia students going on a tuition strike. Here’s why
  • How to accelerate the far-too-slow COVID vaccine rollout
  • Clean-energy startups are key to “building back better” after COVID
About the Author
By Andy Purdy
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

hegseth
CommentaryMilitary
America shot its arsenal empty in 2 wars. Now it needs Beijing’s permission to reload
By Steve H. Hanke and Jeffrey WengApril 30, 2026
7 hours ago
Duncan Tait, CEO of Inchcape
Europecar manufacturing
“Competition is good for the industry”. Inchcape CEO’s case for optimism in automotive’s next chapter
By Duncan TaitApril 30, 2026
10 hours ago
agentic
CommentaryAI agents
Why your data infrastructure — not your AI model — will determine whether Agentic AI scales
By Jeffrey Sonnenfeld, Stephen Henriques, Catherine Dai and Zander JeinthanuttkanontApril 30, 2026
12 hours ago
hoskins
Commentaryoffices
Gensler Co-Chair: Hot-desking was supposed to save money. It may be costing you your culture
By Diane HoskinsApril 30, 2026
14 hours ago
tillis
CommentaryCongress
Thom Tillis: Free markets built American prosperity. Government intervention puts it at risk
By Thom Tillis and John StanfordApril 30, 2026
15 hours ago
iran
CommentaryIran
The Strait of Hormuz is a data problem, not just a military one
By Erik Bethel and Ami DanielApril 30, 2026
16 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
3 days ago
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
Big Tech
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
By Alexei OreskovicApril 29, 2026
23 hours ago
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
Banking
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
By Eva RoytburgApril 29, 2026
1 day ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
3 days ago
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
Economy
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
By Eleanor PringleApril 29, 2026
2 days ago
With no end in sight, Trump considers new options in Iran war—including the ‘Dark Eagle’ hypersonic missile
Big Tech
With no end in sight, Trump considers new options in Iran war—including the ‘Dark Eagle’ hypersonic missile
By Jim EdwardsApril 30, 2026
14 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.