The Typhoon of Silicon: Why Your Risk Committee Is Still Fighting the Last War
A Destroyer That Sailed and Computed at the Same Time
On the morning of August 18, 2020, the guided-missile destroyer USS Mustin pushed into the northern mouth of the Taiwan Strait, its five-inch gun angled southward in the old grammar of naval sovereignty. To a strategist trained in the nineteenth century, the ship’s meaning could be read straight off a table of displacement, armor thickness and gun caliber — the arithmetic of industrial attrition that decided the great conflicts of the last century. But the most consequential thing aboard the Mustin was nowhere near the deck. It sat in a windowless compartment below the bridge, where sailors in rows faced glowing displays, drinking in feeds from drones, satellites and radar arrays. The ship did not merely sail through contested water. It computed its way through.
A few dozen miles off the starboard bow stood the most expensive factory in human history: TSMC’s Fab 18. In that single building on a tectonically restless island, the computational destiny of the planet is carved a few atoms at a time. Most boards have never put those two facts in the same sentence, and that omission is not a gap in technical literacy. It is a governance failure with a measurable price tag, and it is compounding quietly while committees review phishing statistics and patch cadence.
Why the Cloud Is a Very Specific Place on a Map
There is a comfortable fiction in executive suites that cyber risk is intangible — a threat vibe that lives somewhere in “the cloud.” The cloud is not a metaphor. It is a set of buildings, and every one of them runs on slabs of ultra-pure silicon that had to be physically manufactured, packaged, tested and shipped. Every encrypted message, every automated procurement decision, every fraud model and every real-time pricing engine is, at bottom, electrical current moving through switches carved into crystalline rock. When you say “our platform is in the cloud,” you are making an implicit geographic claim about where the switches are.
The scale of that dependency is hard to feel. During the iPhone 12 production run in 2020, a single Taiwanese facility fabricated well over one quintillion transistors in a matter of months. A transistor is nothing more than a tiny electric switch that flips between on and off — the one and the zero — and those flips are the entire vocabulary of digital computing. In a single recent year, the chip industry produced more transistors than the combined output of every other industry in human history, measured in units of anything. There is no second place in that comparison. There is barely a first place and a rounding error.
So the useful mental model is not “software with a supply chain attached.” It is the reverse. Software is the polite surface; the supply chain is the substance. A board that reviews cyber posture without reviewing the geographic concentration of its silicon has examined the paint and skipped the foundation.
From Vacuum Tubes to Solid-State Switches: How We Got Here
To understand why the concentration is so dangerous, it helps to understand how recently all of this was fragile, hand-built and unreliable. In 1945, a computer like ENIAC required roughly eighteen thousand vacuum tubes, each about the size of a fist. It was a moth-ridden monster that failed on a two-day rhythm because the tubes — glowing like lightbulbs — burned out or attracted insects. The machine that was supposed to compute artillery tables spent most of its life being repaired by people with flashlights.
The escape route began with William Shockley, a brilliant and famously difficult physicist at Bell Labs. Long before Palo Alto stood for technology, Shockley had grown up in it, convinced of both his own superiority and the peculiar potential of a class of materials called semiconductors. Most materials are blunt instruments: copper conducts, glass blocks. Semiconductors are negotiable — their conductivity can be manipulated, which means they can be told to switch. In a 1945 notebook, Shockley sketched a “solid state valve,” a piece of silicon whose current could be turned on and off by an electric field.
Shockley’s colleagues Walter Brattain and John Bardeen demonstrated the first working transistor in December 1947, but it was Shockley’s mental picture of a layered sandwich of semiconductor material that made switching possible at industrial scale. That single idea moved the world out of the Atomic Age and into the Silicon Age. It also introduced a new problem that will sound depressingly familiar to anyone who has ever managed legacy integration: the tyranny of numbers. As machines demanded more transistors, the hand-soldered wiring became an impenetrable jungle, and every added connection multiplied the chance of failure.
The fix came from Jean Hoerni, a Swiss physicist and one of the “traitorous eight” who walked out of Shockley’s lab to found Fairchild Semiconductor. Early transistors were built in a “mesa” structure, protruding from the silicon surface like flat-topped desert hills. Mesas were exposed. A single grain of dust or a stray impurity could land on the surface, react with the material, and kill the circuit. In 1959, Hoerni realized the mesa was unnecessary: he could build the transistor into the silicon instead, sealing it beneath a protective layer of silicon dioxide. That was the planar process. It let Robert Noyce see that many transistors could be fabricated on one chip and wired together with deposited metal — the integrated circuit as we know it.
The mesa is a better metaphor for modern risk management than most risk frameworks deserve. Mesa-era organizations leave critical dependencies protruding, unshielded, exposed to whatever dust the environment happens to be carrying. Planar-era organizations integrate the dependency into the structure of the business and shield it deliberately. The interesting question for a risk committee is not whether it has a cyber policy. It is which shape its exposure currently has.
Choke Points That Make OPEC Look Fragmented
A half-century of obsession with efficiency has produced an industrial structure with almost no redundancy at the decisive layers. For comparison, OPEC supplies roughly forty percent of the world’s oil — a figure that governments treat as a strategic threat serious enough to justify wars, treaties and strategic petroleum reserves. Now consider that about thirty-seven percent of the world’s new computing power comes from a single company on a single island. Then consider the layer above it: the Dutch firm ASML holds a one hundred percent monopoly on extreme ultraviolet lithography machines, the only tools capable of etching patterns for leading-edge chips — shapes smaller than half the width of a coronavirus. Without ASML’s machines, no one anywhere builds a cutting-edge processor. Without TSMC’s fabs, no one builds one at volume.
Risk committees routinely spend their time interrogating firewall rules and reviewing penetration test reports while their entire digital stack depends on a building that sits near a fault line which produced a magnitude 7.3 earthquake in 1999. That is not a hypothetical fragility. It is a documented one, with a date attached and a century of seismic activity behind it. The probability was never the issue. The exposure is.
What makes the current moment different from earlier eras of concentration is that the pressure is no longer purely commercial. The most dangerous variable now sits in Washington and Beijing, and it is measured in export licenses, entity listings and technology transfer rules. Efficiency created the choke points; politics is now deciding who gets to squeeze them, and when.
When a Regulatory Pen Stroke Becomes a Weapon
Geopolitics used to be the background noise of international commerce. It is now a primary instrument, used by states to achieve a condition that deserves its own vocabulary: technological asphyxiation. The clearest demonstration is Huawei. For two decades Huawei was the crown jewel of Chinese technology — a global leader in 5G infrastructure and smartphones, founded by Ren Zhengfei, expanding with the apparent inevitability of subsidies, scale and aggressive pricing. Its momentum was not broken by a competitor’s superior product. It was not broken by a hack. It was broken by a list.
The U.S. Department of Commerce used the Entity List to bar Huawei from buying advanced chips built with American technology. Because the global network of chip designers, such as Arm, and toolmakers, such as ASML and the great Californian equipment firms, is so deeply entangled with U.S. intellectual property, the restriction reached far beyond American borders. Huawei found itself, in the words of its own leadership, fatally dependent on foreigners. Revenue slumped. Entire product lines became unbuildable. A government effectively shuttered a multi-billion-dollar enterprise not by bombing a factory but by turning off the flow of semiconductors — a blockade measured in bytes rather than in nautical miles.
Understanding how such a lever became available requires understanding Morris Chang, whose biography is essentially the biography of the integrated circuit. Born in mainland China, he fled the typhoon of steel as a refugee, was educated at Harvard, MIT and Stanford, and spent his career at Texas Instruments, where he held a top-secret U.S. security clearance to develop military electronics. He then moved to Taiwan and founded TSMC. The model he pioneered — the pure-play foundry, in which one company manufactures chips that everyone else designs — is precisely what created the extraordinary efficiency of the modern world. It is also what created the fragility. When every fabless designer on earth depends on the same handful of fabs, the fabs become the single point of failure for the entire global economy, and whoever can influence those fabs can influence everyone downstream.
That is the structure a risk committee is actually exposed to. Not malware in isolation. Not a phishing campaign. A sovereign decision, announced in a press release, that removes a supplier, a tool or a market from your plan for the next three to five years.
The 2021 Shortage Was a Contagion, Not an Accident
The business consequences of this fragility are no longer theoretical, because we already ran the experiment. The 2021 chip shortage was a textbook case of supply chain contagion. A single fire at a Japanese facility. Ice storms that knocked out power in Texas, idling chip plants that could not simply be restarted. COVID lockdowns in Malaysia that closed packaging and test operations. Individually, each event was survivable. Together, they converged on a supply chain with no slack anywhere.
The result was that auto factories for Toyota and General Motors went dark. Executives who had spent careers managing thousands of moving parts discovered that the absence of a microcontroller costing a few cents could halt the assembly of a forty-thousand-dollar vehicle. Production lines sat idle not because the cars lacked engines or steel, but because they lacked a commodity so cheap that no one had bothered to build redundancy into its supply. The lesson generalizes brutally: the cheaper and more commoditized a dependency is, the less attention it receives, and the more leverage it quietly accumulates over your operations.
None of this was a cyberattack in the conventional sense. It was geopolitical and geophysical cyber risk expressing itself as empty assembly lines and billions in lost revenue — which is exactly the point. The classification matters less than the consequence. If your continuity plan treats “cyber” as one risk register line and “supplier disruption” as another, you will misread the actual event when it arrives.
Decoupling Without a Map
Both Washington and Beijing now speak openly about decoupling their technology sectors. The rhetoric is easy; the engineering is not. The ultra-efficient international network of chemical suppliers, machine-tool makers, photoresist specialists, designers and packaging houses cannot be unwound like a corporate reorg. Each layer is the output of decades of accumulated tacit knowledge, and much of it exists in only one or two places on earth. You cannot decree a second ASML into existence, and you cannot schedule a second ecosystem into being by a fiscal quarter.
This is where the Malacca Dilemma has migrated. For decades, Chinese strategists worried about the chokepoint through which most of their imported oil must pass. Today the chokepoint is inside a wafer: the ability to solve arithmetic — adding, multiplying, extracting square roots — at a quintillion-operation scale. Military and economic power in this century is a function of that arithmetic, which is why Beijing is spending enormous sums to escape the chip choke and why export controls have become the preferred instrument of statecraft on both sides. Boards are now operating inside that contest whether they have an opinion about it or not.
A Governance Model Built for Bytes and Chips
The traditional governance arrangement — cyber as a silo delegated to the CISO, with an annual briefing to the audit committee — is functionally obsolete. This is not a criticism of CISOs. It is a description of a scope mismatch. A CISO is equipped to protect the integrity of data and harden the network, and that work remains essential. What a CISO cannot do alone is manage the strategic survival of the firm across silicon choke points, because that problem does not respect the boundaries of the IT function. It touches treasury, procurement, manufacturing, product roadmap and geopolitics simultaneously.
The work therefore has to be distributed. The CFO owns the financial exposure to hardware disruption and the modeling of multi-quarter revenue loss when a line stops. The COO owns physical supply chain mapping — not tier-one suppliers, but the tier-three and tier-four layers where the actual single points of failure hide. The board owns strategic resilience: the deliberate acceptance that some efficiency must be traded for survivability. And someone, ideally a standing committee rather than a heroic individual, has to hold the combined picture.
The governing instinct here is not new. It is the one Andy Grove articulated in Only the Paranoid Survive, written from the experience of a company that nearly died of complacency. In the 1980s, Grove and Gordon Moore had to rescue Intel by pivoting out of memory chips and into microprocessors, under ferocious Japanese competitive pressure and the loud derision of rivals like Jerry Sanders at AMD. That era of paranoid competition produced the relentless cost reduction and consolidation that built the world we now depend on — and it left us with a system that has essentially zero margin for error. The paranoia that saved Intel is now a governance requirement for everyone else.
A risk committee adopting that posture stops asking whether the cyber program is adequately funded and starts asking structural questions about the firm’s position in a bifurcated world:
- Where is our computing power actually fabricated, and which jurisdictions, fault lines and shipping lanes does that imply?
- What share of our technology stack could be neutralized by a single update to an export control list or an entity designation?
- Which of the two emerging technology ecosystems are we building for, and what does that choice cost us in market access, tooling and talent?
- If a leading-edge fab goes offline for six months, what is our specific, costed plan — and has anyone rehearsed it?
- Are our resilience assumptions written down anywhere auditable, or do they exist only as confidence in a meeting room?
None of those questions can be answered by a vendor questionnaire. All of them can be answered, at least approximately, with disciplined mapping and honest modeling. The uncomfortable part is that the answers frequently imply spending money on redundancy that will look, in a calm year, like waste.
Reading the Filings, the Insurance and the Roadmap
There are practical places to start that do not require a geopolitical research team. Read your own risk disclosures and compare them against what your engineers actually know about where components originate; the gap between the two is usually the most informative document in the company. Examine your insurance program: what, precisely, is excluded, and would a state-directed export restriction even be a covered peril? Most policies were drafted for an era in which the dominant threats were fires, floods and lawsuits, not a foreign ministry’s licensing decision. Then look at the research and development roadmap and ask which ecosystem each product line assumes it will be able to buy from in five years. If the answer is “the same one as today, but cheaper,” that is an assumption, not a plan.
Sovereignty-induced supply chain attrition is likely to be the defining operating condition of the next decade: not a dramatic rupture, but a slow, cumulative narrowing of options. Resilience planning has to assume that the international network underwriting your margins could be interrupted by a missile strike, a natural disaster, a public health crisis or a change in export controls — and that you may get very little warning. The organizations that handle this well will not be the ones with the most elaborate scenario documents. They will be the ones that made a small number of expensive, unglamorous decisions early, when those decisions still looked optional.
Where the Next Decade Is Actually Decided
The transition from the Atomic Age to the Silicon Age is finished; there is no version of the future in which computing power stops determining the balance of military and economic strength. The pioneers of this industry — Shockley, Kilby, Noyce, Moore, Chang and the manufacturing and marketing managers who drove costs down with religious persistence — built a world of staggering efficiency. That efficiency is real, and it is also the source of the fragility. Pat Haggerty of Texas Instruments once preached that the integrated circuit would end up inside every piece of electronics the military used. The prophecy overshot in the least dramatic way imaginable: semiconductors are now embedded in everything from automobiles to refrigerators, and none of those devices cares which ministry signs the export license.
Leaders can no longer file cyber risk under IT expense, nor treat it as an insurance line item that transfers responsibility to an underwriter. It is the substrate of modern sovereignty, and the firms that treat it as such will make different capital allocation decisions than the firms that do not. If a risk committee is still focused on patch compliance while ignoring the physical geography of its silicon, it is not managing risk — it is waiting for the tectonic plates to shift and hoping the fault line runs under somebody else’s factory. The typhoon of steel has been replaced by a typhoon of silicon, and in that weather, only the paranoid survive.