National Security Isn’t a Convenience Feature

This morning I read a report that the Federal Communications Commission (FCC) is moving to restrict U.S. approval of new foreign-produced robots and network-connected power inverters due to concerns they could be remotely shut down, hijacked, or used for surveillance. Previously approved models can still be sold and used.

My first reaction was simple: This shouldn’t be controversial. It should be common sense.

For nearly 25 years I’ve worked in cybersecurity, and one lesson has remained constant: if you connect a device to your network, you are trusting the people who built it. You’re trusting the software they installed, the firmware they update, the cloud services they control, and the supply chain that produced every component inside it.

When those devices come from countries that are strategic competitors, or outright adversaries, that trust should never be assumed.

The discussion often centers around whether there is a “backdoor.” The reality is that we may never know. A sophisticated manufacturer doesn’t need an obvious backdoor. They simply need the capability to update firmware, collect telemetry, or maintain remote management features that can be activated when the time is right. Modern devices are incredibly complex. Verifying every line of code and every hardware component is practically impossible.

Now consider network-connected power inverters.

These aren’t just consumer gadgets. They are devices directly connected to our electrical infrastructure. They influence how energy flows through our grid, interact with utility equipment, and in many cases can receive software updates remotely. If enough of these devices were manipulated simultaneously, the consequences could extend far beyond a single homeowner losing power.

This isn’t science fiction. It’s exactly the type of scenario cybersecurity professionals, like myself and my business partner, Will, have been discussing for years.

What frustrates me most isn’t the technology per say, t’s everyone’s mindset, the instant gratification crowd.  The Tik Tok folks who don’t’ understand it’s the largest “connect the dots” society game.  Who’s connected to who….where are weak points, where are blackmail points.  Network access data but more importantly, patterns of life.  Then again, they are much more concerned with how many likes they get than any thing else so why bother explaining it more.

Far too often, we willingly create our own vulnerabilities because we prioritize convenience, lower prices, or the newest gadget over long-term security. We spend billions defending our networks from foreign hackers while simultaneously purchasing equipment that may provide those same adversaries an opportunity to establish a foothold inside our critical infrastructure.

We worry about sophisticated cyberattacks, then we voluntarily install the devices.

It’s like locking every door in your house while handing someone a spare key because it came with free shipping. Unfortunately, whenever restrictions like these are proposed, there is always a group of people who complain because they want their inexpensive electronics, smart devices, or the latest “toy.” The conversation quickly becomes about personal inconvenience rather than national resilience.

The question shouldn’t be, “Can I still buy it?”.  The question should be, “Should this device ever have been connected to critical infrastructure in the first place?”

The average person rarely thinks about the bigger picture because everything seems to work fine, until it doesn’t.

Cybersecurity is unique because success is invisible. When systems remain online, people assume the threats never existed. When preventative measures stop an attack before it happens, no one notices. That can make security investments feel unnecessary.

But when the lights go out…When substations begin behaving unexpectedly…When communications fail…When hospitals, water systems, manufacturing facilities, or emergency services are affected…Suddenly everyone understands why those warnings mattered.

The unfortunate reality is that by the time the public fully appreciates the risk, it’s often because the damage has already been done.

As a nation, we need to stop thinking about cybersecurity as an IT problem. It is an economic issue, an energy issue, a public safety issue, and ultimately a national security issue. Critical infrastructure should be built on trusted technology, trusted supply chains, and secure-by-design principles—not simply on whichever product is the cheapest or most convenient.

However, here in the United States (and actually in all of the Western world), we don’t need to wait for an adversary to find a way into our infrastructure, we continue opening the front door ourselves and not just invite them in.  We give them a room, key to the front door, and make them stay.

The good news is that awareness is growing, and actions like the FCC’s are a step in the right direction. They acknowledge what cybersecurity professionals have been saying for years: protecting our nation starts long before an attack occurs. It starts with making smarter decisions about what we allow onto our networks and into the systems that keep our country running.

The goal isn’t to create fear. It’s to recognize that resilience begins with common sense. Every device we connect becomes part of our security posture. Every purchasing decision becomes a national security decision when it touches critical infrastructure.

The question is no longer whether these risks exist. The question is whether we’ll act before we’re forced to learn the lesson the hard way.