The zenith of techno-politics has created a shift in global supply chains – from operational marvels to geopolitical flashpoints – making weaponised interdependence a quintessential feature of the contemporary era.
The “weaponisation of supply chains” is narrowly defined here as “intentional exploitation of supply chains to disable, manipulate, and compromise critical technologies through cyber-physical attacks, tampering, and manoeuvring the embedded vulnerabilities.” Critical technologies are defined as the amalgamation of present and emerging technologies deemed vital for strategic interests, including national security, economic prosperity, and development. Their peculiar characteristics include indispensability – dominance or access to such technologies is critical for; and maturity – it includes both well-established and emerging technologies.
But the most notable aspect of critical technologies is their associated supply chain vulnerability. Disruption, sabotage, and supply chain scarcity, along with their critical components, can lead to multifaceted vulnerabilities and amplify threat vectors. Critical technologies include, but are not limited to, advanced communication and information technologies, Artificial Intelligence (AI), quantum computing, biotechnology, PNT sensing technologies, advanced materials and manufacturing, cyber and encryption technologies, advanced energy technologies, logistics and sensors, machine learning, semiconductors and microelectronics. State and non-state actors, through various means, exploit the various structural vulnerabilities in the supply chain, such as logistics, digitisation, opacity, and concentration, to cause disruption and sabotage.
Techno-Politics & Weaponised Technological Interdependence
Techno-politics manifests as a deeply embedded reciprocal nexus between technological advancements and geopolitical dynamics, in which technology itself has become a cardinal indicator of national security. At its core, tools and techniques shape the global stage by altering the balance of power and diplomatic clout and by reconfiguring the matrix of international cooperation and competition. The traditional concept of geopolitics is the state’s ability to exercise superiority and mobilise national resources by occupying a specific physical space. This space is not limited to four domains of warfare, i.e., land, oceans, air, and outer space, but has expanded to encompass environments involving the exchange of data, knowledge, and information in the digital age.
Technological innovation, comprised of technological breakthroughs, novel inventions, and advancements across various fields, is now considered a catalyst for geopolitical power with profound potential to upend existing power structures.
Two key trends are metamorphosing this techno-politics landscape:
- Ascendancy of critical and emerging technologies, notably advanced telecommunication, quantum computing, Artificial Intelligence (AI), and biotechnology, is begetting structural shifts in global economic, security, and power dynamics;
- The geopolitical flux is amplifying the strategic quest for technologies and resources, shifting global and regional alliances, and reengineering supply chains.
The convergence of these two trends has led technology to assert its monopoly on inter-state tensions and battlefields. Consequently, it has prompted governments to seek technological prowess, exercise policy autonomy and industrial policies, adopt protectionist measures, and impose investment and export controls to strategically reorient global supply chains and data flows. As a result, the fierce technological competition, evident in the US-China race for AI supremacy and chips, has unmasked the non-neutrality of technology. The most tangible entanglement between geopolitical realities and technological innovation can be understood by the multifaceted forms of interdependence technology has created. Amongst these, the global supply chain of critical technologies remains the primary example that orchestrates economic ties, but concurrently engenders geopolitical vulnerabilities and risks.
Vulnerabilities and Threat Vectors Regarding Critical Technologies Supply Chain
The era of techno-politics, marked by technological disruption and geopolitical flux, has rendered supply chains high-value targets, enabling actors to execute calculated attacks to erode trust, sabotage markets, and wield enormous influence beyond traditional battlefields. Cost efficiency, scale, and speed, once hailed as quintessential attributes of supply chains, have now become liabilities. The inherent vulnerabilities in the supply chains of intricate, large-scale critical technologies make them easy targets for exploitation. Defence sectors of states are also dependent on such complex, long international supply chains to acquire critical infrastructure, communications, and other technologies, which makes them vulnerable to supply chain infiltration. This undermines supply chain security, which encompasses the security of technologies, techniques, and processes intertwined with supply chains.
The digitisation of supply chains has given birth to multitudinous technological vulnerabilities alongside existing geography-centric threats. These threats can be either accidental or targeted attempts to corrupt and infiltrate supply chains, which, in turn, compromise predictability (forecastable, stable flow despite disruption risks) and reliability (quality or quantity of a particular product).
Supply chain threats can arise from four key sources:
- Foreign or concentrated dependency – upstream supply dependency on a single foreign firm or supplier susceptible to geopolitical risks;
- Counterfeiting – imitation of an original product design to manufacture counterfeit ones;
- Inadequate security infrastructure – lack of necessary security measures and potent technology systems; and
- Fragile contingency planning – unpreparedness for possible disruption in the supply chain.
Moreover, digital supply chains remain highly vulnerable to sabotage, in which attackers can damage or disrupt the process, product, or entire supply chain for malicious purposes. Interdependence in digital supply chains also creates conduits for tampering that can allow an attacker to contaminate or alter the product in the supply chain. Such unauthorised modifications can later be used to carry out information leakage attacks or to induce faulty behaviour in the hardware system at the chosen stage of the supply chain. Information leakage attacks can provide attackers with various types of data, including logistics data, confidential supplier information, design information, and data stored on digital devices. By employing machine learning and reverse engineering, attackers may model the Physically Unclonable Function (PUF) of chips to make a challenge-response pair and thereby fabricate chips. Besides, attackers can target system memory to acquire critical information through either a buffer overflow or a direct-access memory attack.
Cyber supply chain attacks have become the most lethal and recurrent threat vectors, exploiting software and hardware systems at various stages of the supply chain. In terms of hardware supply chain attacks, attackers may inject malicious code during manufacturing, alter hardware or insert harmful firmware into a device during shipping, or activate embedded backdoors post-product deployment. Whereas software supply chain cyber-attacks mostly occur as initial breaches, in which insider threats, unpatched software vulnerabilities, and phishing tactics are used to subvert third-party vendor systems. Besides, malicious actors can carry out code manipulation by lacing software destined for distribution with a backdoor or malware. Rudimentary recognition of risks associated with poor supply chain security, limited safety measures against these risks, and elusive supply chain visibility remain key factors increasing the vulnerability of critical technologies’ supply chains. The Lebanon Pager attack is a real-life manifestation of how attackers carry out cyber-kinetic attacks by targeting Cyber-Physical Systems (CPS) in a supply chain. Pager attacks reveal supply chain vulnerabilities and the fragmented nature of global supply chains, marked by geographical dispersion across raw material extraction, production, assembly, and distribution stages.
These developments necessitate states to adopt a multi-layered techno-security architecture to ensure integrity at four levels – software, hardware, supply chain monitoring, and cross-verification. This mechanism could serve as a control mechanism across the critical technologies supply chain to curb their weaponisation and concurrently enable technological interdependence to function smoothly.
Safia Mansoor is a PhD Scholar of International Relations at the School of Integrated Social Sciences, University of Lahore. She has also served as Research Associate at the Maritime Centre of Excellence, Pakistan Navy War College Lahore. Her research areas include arms control and disarmament, emerging military technologies, and nuclear deterrence and strategic stability in South Asia.
This article is published under a Creative Commons License and may be republished with attribution.