OEMs must invest in supply chain cybersecurity best practices
2026-08-07
Almost all industries around the world have become targets of cybercriminals. Potential benefits include money, computing power, and enterprise and customer data. The supply chain of electronic products is particularly fragile, so network security should be one of our top priorities.
For example, in February 2025, Taiwanese printed circuit board (PC board) manufacturer Unimicron was attacked by Sarcoma ransomware. Sarcoma is a ransomware organization that launched a total of 83 cyber attacks between July 2024 and March 2025 (Figure 1). As part of the Unimicro intrusion operation, cybercriminals have released file samples allegedly stolen from the company's systems during the intrusion and threatened to leak all 377GB of SQL files and company data documents if the company does not pay the ransom.
Figure 1: Sarcoma has launched ransomware attacks on organizations around the world, including manufacturing and technology companies. At present, attacks are mainly concentrated in North America and Europe. (Image source: Ransomware. live)
The problem is becoming increasingly serious A 2025 report by Cybersecurity Ventures predicts that by 2025, the annual losses caused by cybercrime will reach $10.5 trillion, far higher than the $3 trillion in 2015. According to a source from Gartner, the losses caused by attacks targeting the software supply chain alone will increase from $46 billion in 2023 to $138 billion in 2031.
The invasion losses are also increasing. IBM research estimates that the average loss of network security intrusions has reached $4.88 million. This only includes hard losses, without considering potential soft losses such as brand erosion.
Analysts and experts have pointed out several reasons for the rapid increase in cybercrime:
Organizations are increasingly reliant on software: In the electronics industry, companies used to rely on various independently developed applications, which formed protective islands. Nowadays, most organizations are turning to third-party software and open source applications, which provide opportunities for criminals to inject malicious code and create disasters (Figure 2). More and more employees are working remotely or in a hybrid environment: With more and more employees working from home or different locations, the increase in potential attack surfaces has also brought vulnerabilities. The use of the Internet of Things (IoT) and cloud is on the rise: while IoT devices and cloud infrastructure are useful, they also provide more entry points for potential attackers. Attackers are becoming increasingly sophisticated: State backed groups and ransomware attackers are using increasingly sophisticated techniques to attack various organizations.
Figure 2: The diagram provides an overview of the increasing number of malicious components discovered in open-source dependencies. (Image source: Gartner)
Four methods to implement safety first Attackers are becoming increasingly intelligent, so organizations need to remain vigilant at all times. Cybersecurity is like a big adventure game: organizations build security measures around data and company systems, while villains search for new ways to infiltrate the system. Companies should regularly evaluate their programs and technologies to stay ahead of attackers, or at least make them challenging enough for them to turn to other targets. Portal websites and networks must provide security protection and backup. Both digital and physical files need to be protected.
Cybersecurity insurance must be included in the budget. Taking a chance may be tempting, but compared to invasion losses, insurance costs are negligible. This type of insurance can help organizations recover legal fees and costs associated with dealing with intrusions. It may even compensate for losses caused by the loss of customer or worker productivity. According to data from Embroker, by 2024, businesses will spend an average of $1200 to $7000 annually on online insurance, with a median cost of approximately $2000 per year. As expected, the price of online insurance has been fluctuating and reached a high point in 2022. Since then, these costs have been continuously decreasing.
Another important strategy is to organize security audits. Moral hackers or 'white hat' hackers can perform penetration testing to identify vulnerabilities in the current system and find them before black hat hackers discover them.
Finally, make sure your organization understands the importance of investing in cybersecurity. These efforts should be included in the budget to increase investment year by year.
The reality of modern electronic supply chain is that organizations are spread all over the world, and the threats they face are also spread all over the world. The costs of intrusion, as well as time, money, reputation, and compliance risks, continue to rise and may persist. Organizations must prioritize risk prevention and invest in security. As long as given due attention, OEMs can benefit from supply chain applications, thereby increasing visibility, resilience, and mitigating risks, while avoiding the risk of bad actors provoking them.