Sep03
Most cybersecurity conversations start with software and networks: firewalls, intrusion detection, patch cycles, or endpoint protection. On a recent special edition of The Business of Government Hour, I sat down with Dr. David Bray and Dr. Trent Teyemato ask a harder question.
What happens when the compromise sits deeper than software, inside the chip itself, before a system is ever plugged in?
Bray started working with the U.S. federal government at 15 and had a security clearance with the Ballistic Missile Defense Organization by 17. His career then moved through the Bioterrorism Preparedness Response Program, where he helped the government respond to 9/11 and the original SARS outbreak, a tour in Afghanistan, and a senior National Intelligence Service post, before landing at the FCC and now he is leading research at the intersection of data, technology, and geopolitics. Teyema built his career inside the FBI's cybercrime program, served twice on the White House National Security Council for Cyber, and later ran the Bureau's cyber policy section. Between them, they've spent decades watching threats evolve from software exploits into something far more foundational. Their message to government leaders is direct: hardware trust isn't a peripheral concern.
Every cybersecurity safeguard government puts in place ultimately depends on the integrity of the hardware beneath it.
Bray opened with a story reframing the entire conversation. Roughly four years ago, a commercial non-destructive verification technology was tested against two routers pulled from underwater nuclear environments operated by the U.S. government. Those routers had already passed two prior vendor inspections. The new technology flagged them anyway. When the box came open, investigators found Huawei daughterboards, each the size of a thumbnail, soldered onto the router. Government experts who reviewed the finding called it, in Bray's words, “one of the most sophisticated compromises we’ve seen.”
The story doesn't end there. The same verification effort gained access to a U.S. military warehouse holding roughly 500 pieces of kit, and the failure rate came in above 53 percent. Not every failure signals a nation-state compromise, but as Bray put it, “it does mean the hardware is not what you’re expecting.” His estimate for the share reflecting something genuinely sophisticated runs between 20 and 25 percent, a striking figure for equipment already in service inside government facilities.
Teyema's own history reaches back further, to counterfeit Pentium chips overclocked and relabeled by organized crime groups in the 1990s, and to the slow migration of manufacturing overseas, which turned “gold CDs” and “gold code” into artifacts nobody fully traced. His framing matters here: “It’s not just a supply chain issue,” he said, “but now how do you trust that you’re actually getting” what was ordered. The forensic challenge compounds when vendors themselves are unable to confirm authorship of the code running inside their own products. Teyema recounted asking vendors directly whether a piece of equipment belonged to them, only to hear, “it says it’s theirs on the outside… but it’s not ours.”
Part of what makes this conversation difficult is definitional. When Bray talks about hardware, he means the full stack beneath the operating system: BIOS, CMOS, microprocessors, graphics cards, memory, and the system boards themselves. Government has spent the last five or six years building out software bills of materials, tracking what code runs where and whether it carries known vulnerabilities. A parallel effort toward hardware bills of materials is underway, but Bray was blunt about its limits. It remains voluntary, and nothing verifies whether a vendor's claims match what ships.
“We may, in some respects,” he said, “we may be building castles on sand. In this case, you can’t even trust the chips themselves.”
This distinction between software and hardware compromise carries real operational weight. A compromised router or switch sits at the exact point where an organization deploys its cybersecurity software, the tools meant to flag anything unusual entering or leaving the network. If the device itself is compromised at boot, Bray explained, it opens a back door and masks its own traffic from the systems built to catch it. He offered an analogy every executive will recognize. Spending heavily on security cameras for a building, only to have someone hack the video feed itself, so the cameras show nothing wrong even as the building empties out.
I asked both guests how seriously they rate this threat, and whether it touches government uniquely or reaches further. Their answer surprised me. Bray and Teyema described compromises turning up in gaming mice, smart refrigerators pulling gigabytes of data to unknown destinations, laptops and phones tampered with during overseas travel, and traffic cameras installed across an American city with hard-coded root access passwords. When I asked whether, across their combined field experience, they'd ever run an engagement without finding compromise, Bray answered plainly:
“I don’t think there’s been any setting where we have not found things compromised.”
Teyema agreed, adding the pervasiveness now spans “all sectors,” from law firms and bakeries to critical infrastructure operators, wherever compromised components find their way into the supply chain.
The motives split roughly into two camps, according to Teyema. State actors position compromised hardware for intelligence collection, or in his words, for “preparing the field or battlefield,” positioning themselves to disrupt water systems, power grids, or communications during a future confrontation. Criminal actors pursue financial gain through the same access points, sometimes working independently and sometimes, as Teyema noted, when state actors “make them an offer they can’t refuse.” The two groups aren't always separate.
Bray distilled the risk into three scenarios keeping him awake at night: quiet exfiltration of intellectual property and pre-decisional information, subtle manipulation of data eroding trust in the underlying decisions organizations make, and outright extortion, where compromised infrastructure becomes leverage during a real-world confrontation. Teyema grounded this in recent history, pointing to adversarial attacks on Ukrainian power and banking systems and reported attacks on American water systems. “If you can’t get on the internet, you can’t get to your money,” he said. “If your phone doesn’t work, how many people would be lost right now?”
Bray offered an example illustrating how narrow the window for compromise turns out to be. A foreign government had ordered 100 storage devices tied to cloud infrastructure, and its own law required continuous visual monitoring of any equipment destined for sensitive use, from the moment it left the vendor until installation. This monitoring lapsed for roughly two days. Out of caution, officials ran a scan on the first ten devices before installing the rest. Every one of the ten accepted any password entered. Officials halted the rollout and assumed the remaining ninety carried the same flaw. The equipment left the vendor clean. Somewhere in a 48-hour transit window, it didn't.
This gap between vendor and installation point is where Teyema sees the real vulnerability. Buyers assume they're purchasing directly from a manufacturer, when in practice most hardware moves through a reseller. An insider threat inside a reseller, not necessarily a senior figure, creates an opening nobody at the buying organization ever sees. Some cases prosecutors have pursued as counterfeiting, Bray noted, likely reflect this same dynamic, mislabeled because counterfeiting proves easier than a targeted hardware compromise. The lesson for procurement officers is uncomfortable: a trusted vendor relationship doesn't guarantee a trusted supply chain, because the chain runs through hands the buyer never audits.
One of the most important shifts in this conversation was conceptual rather than technical. Bray argued government needs to move from a cybersecurity mindset to a cyber resiliency mindset, because perfect security is operationally unworkable. “If you want something perfectly cybersecure,” he said, “disconnect it from the internet, make sure no human being touches it, and buried underground. Kind of hard to be operational in that context.”
The real question becomes how much risk is tolerable in a given context, and where zero tolerance is required because the stakes involve critical infrastructure or military operations.
Bray also named two structural obstacles slowing action: a collective action problem, where government points to business and business points back to government, and a shame-and-blame culture in cybersecurity punishing disclosure rather than rewarding it. Thin margins in hardware manufacturing compound the issue, since any price increase tied to verification looks unattractive to buyers who don't yet see the risk. Teyema's response reframes disclosure as a strength rather than a liability. Organizations built around detecting problems after the fact, he said, need to shift toward managing risk before a crisis forces the issue.
I asked the two to walk a layperson through what hardware verification looks like in practice. Bray described a call-and-response process run at boot: an external device interrogates the system's chips, checking power draw, response time, and computational behavior against a known baseline, cross-referenced against a database of roughly 70 billion known good chips. The process returns a composite score between zero and one within seconds for simpler devices, or a few minutes for something as complex as a router. Bray summarized the philosophy behind it as a deliberate inversion of a familiar Cold War maxim.
“It’s almost a reverse of what President Reagan said, which was trust but verify,” he said. “It’s verify and then trust.”
Teyema tied this back to the hardware bill of materials concept. Vendors, he argued, should be able to state exactly what components ship inside a given device, locked to a verifiable standard, so buyers are able to confirm a match on arrival. A mismatch doesn't automatically mean malice. It might reflect a legitimate substitution during a supply shortage. But without verification, buyers have no way to distinguish a benign swap from a hostile one. “It’s like trying to bring this down from kind of this ethereal, it’s so big, how do you defend against it,” Teyema said, “to, yeah, it is very real world, very personal.”
Both guests offered concrete steps for agency leaders. Bray's first recommendation: identify the “crown jewels,” the hardware handling sensitive or internet-facing operations and apply independent verification and validation there first. Second, consider air-gapping the most sensitive systems entirely, disconnecting them from the internet rather than relying on encryption or virtual private networks, since Bray noted hardware-based VPNs have themselves shown up compromised. Third, as agencies procure new hardware, build verification into the acquisition process itself rather than continuing to spend, in his words, “good money after bad things.”
Teyema pushed back gently against heavy-handed regulation, arguing incentives outperform mandates. “It can’t be a regulatory big hammer,” he said, favoring market-driven approaches where verified, trustworthy hardware becomes a competitive differentiator vendors want to offer. Bray extended this thinking to specific procurement moments already embedded in government process, suggesting satellite launches requiring FCC verification add a hardware integrity check before launch, and state and federal regulators overseeing the electric grid or water systems require verification as new devices come online.
Bray also proposed something more unconventional: a policy amnesty period, perhaps 180 days, during which organizations discovering compromised hardware in their own systems face no liability for having operated with it previously. Without this protection, he argued, the incentive runs toward willful ignorance. Pairing amnesty with some form of cost offset for replacing compromised equipment would function as a modest economic stimulus while closing a real security gap.
On the harder question of onshoring chip manufacturing, both were realistic. Bray called for a “yes and” strategy, building certain critical chips domestically while incentivizing trusted allied nations to expand manufacturing capacity elsewhere, given the high cost of full domestic production. Teyema agreed that global manufacturing will persist, and the real objective is validation and verification wherever chips are made, not the elimination of a multinational supply chain.
While serious, this problem isn't paralyzing. Teyema closed with direct advice about hardware integrity for boards and executives uncertain about where to begin. "You're not going to solve everything today or tomorrow," he said, "but appreciate that this is an important effort that we need to work on." It matters because this hardware runs the operations of most organizations and losing its integrity changes how those organizations function.
The point was not that organizations can eliminate every hardware risk. It was that they can begin identifying what matters most, verifying what they depend on, and reducing their exposure before a compromise becomes a crisis.
Bray captured that urgency in a line worth remembering: “An ounce of pain now is worth a pound of care later.” Verification carries a cost, but so does waiting. For government leaders responsible for critical infrastructure, national security systems, and the digital foundations of daily operations, waiting is increasingly becoming the more expensive choice.
Keywords: Cybersecurity, GovTech
Verify, Then Trust: Hardware Integrity and the Hidden Foundation of Cyber Resilience
The Ecosystem Is Yours to Command
Why Enterprise AI Never Gets Past the Pilot Stage
Why High Performers Don't Always Make Great CEOs
Your Supply-Chain AI Pilot Worked. So Why Didn’t It Scale?