The concept of corporate cybersecurity used to begin at the so-called perimeter, with firewalls guarding network entry points, email gateways filtering out suspicious messages, and antivirus software blocking malware. This wall-building mindset at the perimeter worked reasonably well when corporate information systems were relatively closed.
However, the rise of generative AI, AI agents, cloud services, and APIs has fundamentally altered corporate perimeters. Since corporations nowadays may rely simultaneously on external AI models, cloud service platforms, SaaS, open source software, third-party packages, and data exchanges across different organizations, the focus has now shifted from who is allowed access to corporate networks to which technologies, data, and trust relationships corporations can rely on.
This shift deserves to be reconsidered in terms of supply chain resilience, a concept that used to center on raw materials, logistics, and production capacity, but now must also take into account models, computing power, APIs, open source packages, and data flows, given the significance of digital technologies in modern-day corporate operations. If any single link is compromised, infiltrated, or interrupted, risks could proliferate rapidly along these digital dependencies.
AI has expanded attack paths into tech supply chains
The first change that AI has brought is faster and more persistent attacks. According to information disclosed publicly in 2026 about attacks involving Hermes Agent, an open-source AI agent framework, attackers can use AI agents to perform reconnaissance, vulnerability searches, and internal resource mapping with minimal intervention, turning attacks from one-off operations into automated, continuous processes. This means that the risk corporations now face is no longer limited to whether an individual endpoint has been breached, but also includes whether attackers can formulate continuous attack pathways by exploiting corporations' links to third-party technologies.
The second change is that trusted sources no longer imply trusted content. In the April 2026 attack on the CPUID project, attackers managed to compromise the website's download mechanism, causing legitimate download links for CPU-Z and HWMonitor to be temporarily redirected to malware. What was once a trusted software source thus became an entry point for attacks. Such incidents show that enterprises can no longer judge if a tool is secure based solely on its source, file name, or any single detection tool; instead, they must also scrutinize their trust relationships in software, services, and data exchange processes.
Diversity, alternatives, autonomy key to resilience
Since dependence on technology will only continue to increase, the first step for corporations is to reduce reliance on any single point that could potentially fail. If a company relies on just a single cloud service, AI model, or API, any service outage, steep price change, or security issue can hit operations directly. Companies should therefore inventory critical technology dependencies and seek out heterogeneous suppliers, alternative options, and backup mechanisms for highly concentrated areas.
The second step is to establish substitute capabilities. To achieve true resilience, corporations must have the ability to continue working under protected conditions when risks arise, instead of simply shutting things down. As an example, for files that must be received but cannot be fully verified as safe, content disarm and reconstruction (CDR) technology can be used to remove potential threats and regenerate usable content, allowing companies to continue using material after secure processing, instead of being forced into either accepting files as-is or blocking them completely.
The third step is to achieve technological autonomy. This does not necessarily mean that all technologies must be developed in-house, but that critical capabilities must not be entirely beyond a corporation's own control. For core industries, critical data, software, and risk-validation capabilities should remain sufficiently manageable and replaceable, so that corporations do not lose all response capacity if external services are disrupted or contaminated.
From zero trust to technology supply chain governance
Turning to the issue of zero trust in the AI era, one should not simply conclude that no device or person is to be trusted, but instead ask the following questions: Which files can be trusted? What data can be exchanged? Which APIs can I connect to? Which third-party technologies can I depend on?
This implies that cybersecurity governance must be part of procurement, research and development, information technology, legal compliance, and overall operations and management. Governance in the software supply chain should encompass code repositories, open source packages, and development tools by stressing the visibility and traceability of each component, while regular reviews of critical third-party services should cover the degree of dependency on these services, the risk of outages, and options for alternatives.
More importantly, corporations must establish mechanisms to continuously re-identify risk, since the rapid evolution of AI technology and attack methods means that currently effective defense mechanisms may be rendered obsolete by newer attack techniques. Thus, resilience governance should not follow a permanent, unchanging set of rules, but instead form a dynamic cycle of identifying risks, adjusting defenses, verifying the effectiveness of these defenses, and re-identifying risks.
Taiwan's network defenses must go beyond its perimeter
This is a particularly pertinent issue for Taiwan, due to its high dependence on the global technology supply chain. While the focus of supply chain resilience used to be concentrated on semiconductors, critical raw materials, energy, and manufacturing equipment, digital technology must become part of the discussion going forward, since AI models, cloud services, APIs, open source software, and data flows could all become new critical dependencies. Governments and corporations should establish mechanisms to map their dependencies and identify where risks are highly concentrated in critical digital technologies, and build alternatives and backup plans for critical AI models, APIs, and cloud services. Moreover, they should also cultivate multifaceted talent with expertise in AI, cybersecurity, and industrial operations.
The issue goes beyond information security, with far-reaching implications for industrial resilience and economic security. For corporations in the AI era, the challenge now is not how to build ever-higher walls, but how to keep the entire technology supply chain operating when one link fails. As companies move from securing their perimeters to governing their dependencies, concerns regarding supply chain resilience must also extend from physical goods into digital technologies. In addition to improving cybersecurity governance, this shift also marks a new stage in the governance of supply chain resilience.
Article translated by Kevin Wang and edited by Ysi Chen