EPISODE · Sep 14, 2026 · 1H 34M
Beyond Software Supply Chains: NSA ASIC Assurance and the Problem of Trusting Silicon
from Cybersecurity Under Pressure. Real Attacks, Real Lessons · host Antonio Gonzalez
When cybersecurity teams discuss supply-chain risk, the conversation usually starts with software. But some of the most consequential trust decisions are made much deeper in the stack — inside the hardware itself.In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the NSA’s latest guidance for Application Specific Integrated Circuits, or ASICs, and what its Level of Assurance 1 framework tells us about securing custom microelectronics throughout design and manufacturing. An organisation may spend years and billions of dollars engineering a critical chip, yet still depend on external design tools, third-party intellectual property, manufacturing facilities and suppliers that sit outside its direct security boundary.The Technical Breakdown explores why hardware assurance is fundamentally different from conventional vulnerability management. The objective is not simply to find a known flaw after deployment, but to establish evidence-supported confidence that the component has not acquired unexpected characteristics or unintended behaviour somewhere along its lifecycle. That requires looking beyond the finished silicon to the engineering environments, EDA tooling, third-party IP, design data, manufacturing processes and organisations involved in producing it.The Operational Decisions translate that problem into risk, procurement and governance. Not every component requires the same degree of assurance, and maximum assurance is neither practical nor economically sustainable for every product. The challenge is determining how critical a component is to the system, what the consequence of subversion would be, which parts of the supply chain can actually be trusted and what evidence is sufficient to justify that trust.In The Pressure Test, the problem becomes immediate: you are responsible for a high-value hardware design destined for a critical system, but fabrication and parts of the engineering chain depend on external organisations. You must decide what information suppliers genuinely need, which controls reduce exposure without making production impossible, and how much residual uncertainty the programme can accept before the chip becomes part of the final system.The key lesson is that hardware supply-chain security cannot be reduced to choosing a trusted supplier. Assurance must be engineered across the lifecycle and supported by evidence proportional to the consequence of failure or malicious modification. The deeper a component sits inside a critical system, the harder it may be to replace — and the more important it becomes to understand exactly why it deserves to be trusted.Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders.Explore all episodes and resources:https://cybersecurityunderpressure.com/episodes
Embed this episode
Ready to play
Beyond Software Supply Chains: NSA ASIC Assurance and the Problem of Trusting Silicon
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.