Free Agentic AI Workshop Map your footprint, identify your highest-risk gaps, and leave with a leadership-ready summary. Book a Workshop→
Start assessment

Let’s Talk about Hardware Supply Chain Risks

December 9, 2025 · Jason Garbis

Ok, I admit that this topic is not going to make you the life of the party this holiday season (or if it is, please invite me to THAT party), but it is an important topic. I was prompted to write about this based on some recent research published by a security researcher, Matej Kovačič.

He discovered that a popular remote access device, an inexpensive Chinese-manufactured hardware device, the NanoKVM was terribly insecure, included an undocumented microphone, and included unnecessary network monitoring and cracking tools. His summary:

“The device is riddled with security flaws, originally shipped with default passwords, communicates with servers in China, comes preinstalled with hacking tools, and even includes a built-in microphone – fully equipped for recording audio – without clear mention of it in the documentation…I am pretty sure these issues stem from extreme negligence and rushed development rather than malicious intent. However, that doesn’t make them any less concerning.”

Let’s zoom out for a minute, and first of all, respect the effort and skill that this researcher applied to uncover this. We should be troubled by this discovery, even if we don’t have this specific device on our network. Because, it forces us to ask ourselves: How much confidence do we have that devices running on our networks are well-behaved, and don’t have similar vulnerabilities or malicious content? The answer for the vast majority of enterprises is that our confidence is Low

We’ve put together a simple chart below, showing four levels of Enterprise Supply Chain Security. Hopefully, few enterprises are at level 1, with minimal controls and monitoring. But even those at level 2 and 3 have some degree of risk. It’s not until an organization is at level 4, which very very few are, that they have minimized the risk.

But let’s return to the real world: the vast majority of organizations do not have the time, skills, or need, to perform the activities or enforce the rigor associated with level 4. Enterprises have business goals and business users, and security teams need to establish programs and processes that keep them productive while balancing the effort and risk. So, first look at the attributes of level 2 and 3, and determine which you could and should apply to your organization. You can and should also reduce your risk by only purchasing hardware and software from reputable vendors. Deploying Dell servers purchased via the manufacturer? Pretty safe and reliable choice. Deploying a remote access widget from an unknown Chinese manufacturer? Not a good choice, even if it’s inexpensive.

Second, invest in and prioritize detection and monitoring tools, controls, and processes. You can and should have a known set of allowed activity on your network, and detect and respond to any (attempted) deviations. You need to get yourself into the position where you know enough about expected network activity that you can enforce “default deny”. This is a big part of Zero Trust, and must be something you aim for. Yes, this requires a clear picture of the devices on your network and their allowed set of inbound and outbound network activity. And yes, this therefore requires a higher level of discipline for your device lifecycle and governance processes. This is simply a necessity for a successful security program in the real world. So don’t fight it – embrace it. Your information security program will be in a better place.

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading