top of page
EXPLORE OUR

Resources

Cybersecurity Doesn't Stop at IT or OT: Taking Security Down to the Silicon

Writer: Mark Sangster
Mark Sangster
1 day ago
6 min read

Cybersecurity has progressed in lockstep with information technology as it expanded from on-premises devices and networks to hybrid or full cloud infrastructure. Organizations built firewalls around networks, deployed endpoint protection, strengthened identity and access management, encrypted sensitive information, patched software vulnerabilities, and monitored networks for suspicious activity.


The mantras change over the years, as the themes of major cybersecurity conferences shift from one short-shelf-life trope to the next. Technology, people, artificial intelligence, and so on. The only constant through this change is that cybersecurity has focused primarily on protecting information technology.


Some might argue that’s a cynical view, given that internet-connected devices have escaped their front-office cubicles for the factory floors of operational technology (OT), moved into the wilds of Industrial control systems that run our utilities and infrastructure, and even wormed their way into our flesh, implanted in medical devices.


While IT technology, or the Internet of Things (IoT), is now within the cybersecurity perimeter, we still consider cybersecurity as the protection of IT technology, regardless of its current abode. We “trust but verify” users, data, and processes, but turn a blind eye to the silicon foundation of information technology. Worse, every server, firewall, industrial controller, drone, communications system, and manufacturing machine ultimately depends on printed circuit boards, semiconductors, processors, memory, firmware, and thousands of electronic components.


In other words, we remain blind to the electronics themselves. The silicon we literally trust with our lives is the ultimate self-gifted Trojan horse. It’s time we admit that we are exposed to the next wave of technological failures or cyberattacks that lurk in the silicon, below the applications, below the data in memory, below electrons flying about in our electronics.


The Cybersecurity Stack Is Deeper Than We Think

True organizational resilience demands we expand cybersecurity beyond the alphabet soup of technology and compliance standards to reach the silicon. And this is why it matters: IT-focused cybersecurity assumes an adversary’s presence creates at least minute waves in the system that one of our many layers of defense will detect.


As I would lecture on the regular, criminals are not James Bond with a laser watch. They don't teleport into your environment like a juggernaut Jason Bourne and instantly carry out their nefarious mischief. They make waves. If not explicit, like detectable malware, then inferential: concurrent log-ins, failed authentication attempts, new accounts appearing in Active Directory, escalated credential authority, data bursts, etc.


In silicon-level attacks, there are no users. No malware for our endpoint antivirus to find. Your Security Operations Center (SOC) has no perceptible indicators of compromise until it’s too late. Perhaps a radio signal broadcasts, or a firmware command executes, and the lights go out. No warning.


The defense industry is petrified of the potential of Silicon-initiated attacks (that’s my term, not theirs). In June 2026, a rogue wave ripped through the United Kingdom’s Royal Navy when the Telegraph reported that camera components on the K3 Scout unmanned surface vehicles (USVs), built by the Kraken Technology Group, were sending heartbeat status signals to an IP address in China. The U.K. Ministry of Defence later denied any data breach, as reported by the BBC.


Regardless, the complex, multi-layered, and often obscured supply chain required to build sophisticated devices like USVs is exposed to cyber vulnerabilities that could do more than call home. Next time, the device could be easily disabled.


That’s defense. What about infrastructure? Multiple incidents have seen water reservoirs in Texas lose much-needed reserves through cyberattacks.


Cybersecurity stratifies data, applications, operating systems, networks, and firmware, but stops at the “metal”. In reality, it’s a combination of chemicals, compounds, and silicon.


At the top of the stack, security technologies routinely monitor network traffic, scan software for vulnerabilities, control user access, detect malware, and maintain security logs. But visibility becomes progressively more difficult as we move deeper into the silicon (SI):


What firmware is actually running inside a device?


Did a supplier make an undocumented change?


Is the semiconductor inside a product actually the device specified in the approved design?


Was a component substituted?


Was something changed between manufacturing and delivery?


Does today's production unit actually match the system that was originally qualified?


These questions expose a fundamental challenge in modern cybersecurity: How can you secure what you cannot verify?


The Supply Chain Has Become Part of the Attack Surface

A defense contractor, aerospace manufacturer, drone company, or critical infrastructure operator may rely on hundreds or thousands of suppliers. Components can pass through semiconductor manufacturers, distributors, brokers, contract manufacturers, logistics providers, integration facilities, and repair organizations before reaching their final destination.


Each stage creates another potential point where defects, substitutions, counterfeits, or malicious modifications could enter the product. Add to this melee the ever-changing political alliances and crumbling long-standing allies that shift the trusted line in the sand weekly.


This is not merely theoretical. NIST SP 800-171 Rev. 3 explicitly identifies supply-chain threats including counterfeits, tampering, poor manufacturing practices, and insertion of malicious software, firmware, and hardware. Real-world cybersecurity incidents show that organizations must think beyond conventional perimeter security.


Every day, manufacturers and OEMs trust their suppliers but cannot verify the thousands (or more) of electronic components and assemblies they receive from a wide range of suppliers. These components or assemblies look identical, carry the correct part numbers, pass visual inspection and functional testing, and arrive with the appropriate supplier documentation.


But internally, something has changed. Perhaps a semiconductor was substituted, or the PCB manufacturing process changed. Due to supply chain issues, a component was substituted with one from an unauthorized source. Perhaps counterfeit components were introduced somewhere along the supply chain. Or worse, an adversarial party modified the electronics or firmware.


Conventional in-circuit testing can verify predetermined electrical characteristics, but it provides limited visibility into internal construction and variation. Palitronica identifies hidden defects, undocumented substitutions, and supplier process drift as examples of differences that can escape conventional inspection and functional testing.


Cybersecurity therefore needs another layer: Hardware assurance.


From IT Security to OT Security to Electronics Assurance

The evolution of cybersecurity can be understood in three broad stages.


IT SECURITY

Question: Is our information environment secure?


Organizations protect:

Networks • endpoints • applications • identities • cloud environments • data


OT SECURITY

Question: Are our physical operations secure?


Organizations protect:

Industrial controls • manufacturing systems • PLCs • sensors • robotics • connected equipment


ELECTRONICS ASSURANCE

Question: Can we trust the electronics underneath those systems?


Organizations need visibility into:

Hardware • firmware • components • assemblies • configuration • authenticity • physical integrity


That last layer is where Palitronica extends the cybersecurity model


Taking Cybersecurity Down to the Silicon

Palitronica's Anvil platform applies physics-based electronics verification to help organizations determine whether the hardware they build, buy, and deploy remains consistent with trusted electronics.


Anvil Checkpoint uses radio-frequency reflectometry and machine learning to characterize electronic devices. Rather than looking only for a predefined defect, Anvil establishes a known-good profile and compares subsequent electronics against that reference.


The system can evaluate microcircuits, components, assemblies, and complete modules. Palitronica's technology detects physical differences down to the silicon level without requiring access to schematics, firmware, BOMs, or detailed prior knowledge of the target.


Anvil Inspector firmware assurance provides agentic AI-powered fuzzing with side-channel analysis. At the core of Anvil Inspector Firmware Assurance is PowerFuzzer, Palitronica’s proprietary black-box firmware-analysis technology, which assesses power usage during command and process testing to determine whether the process runs as designed or whether power usage indicates additional activities beyond design or authorized functions.


The Anvil agentic-AI framework coordinates PowerFuzzer and other Inspector Tools with protocol, vulnerability, standards, and threat-analysis agents. These agents verify firmware functions and operations, confirm software changes, and expose unauthorized activities and vulnerabilities that commonly become cybersecurity exposures and risks.


Assume Nothing. Test Everything.

This approach matters because hardware security presents a different challenge than conventional cybersecurity. Traditional security tools generally need some understanding of what they are looking for. Malware scanners search for malicious behaviors or code; vulnerability scanners look for known vulnerabilities and configurations; and functional manufacturing tests confirm whether predetermined functions behave correctly.


Anvil Electronics Assurance platform takes a different approach. Anvil does not need to know precisely what is wrong. It identifies whether a device's physical characteristics differ from the trusted population it is being compared against. We describe this as moving organizations from trust-based assurance to evidence-based validation.


Zero Trust Should Apply to Hardware Too

Zero Trust transformed cybersecurity by challenging a long-standing assumption:


Do not automatically trust something simply because it is inside the network.


The same principle extends to electronics.


  • Don't automatically trust a component because it came from an approved distributor.


  • Don't automatically trust an assembly because the supplier provided a certificate.


  • Don't automatically trust a device because it passed a functional test.


  • Don't automatically trust a replacement component because it carries the correct markings.


For hardware, that means establishing trusted baselines and independently determining whether delivered electronics remain consistent with those baselines. Palitronica is helping organizations make that transition—extending cybersecurity and supply-chain assurance into the physical electronics underneath modern digital systems.

You can download and read more about how to strengthen NIST SP 800.5(PDF) as well as NIST SP 800-171(PDF).

bottom of page