logo
How the semiconductor industry is grappling with cybersecurity threats

How the semiconductor industry is grappling with cybersecurity threats

Yahoo25-07-2025
This story was originally published on Manufacturing Dive. To receive daily news and insights, subscribe to our free daily Manufacturing Dive newsletter.
Cybersecurity has become imperative for chipmakers looking to protect their facilities and operations from rising threats. Otherwise, they are at risk of losing tens of millions of dollars from security incidents.
A single 12-inch wafer used in high-end applications — such as artificial intelligence, high performance computing, or automotive chips — can be worth upwards of $20,000. If production is interrupted during critical stages, like photolithography or plasma etching, thousands of wafers may be damaged. This can result in significant losses from wasted materials, extended downtime, delayed shipments and diminished customer confidence.
On Aug. 3, 2018, a WannaCry variant affected Taiwan Semiconductor Manufacturing Co., disrupting both computer systems and manufacturing tools at multiple facilities in Taiwan. Several fabrication plants were forced to halt production and it took three days to recover approximately 80% of the affected equipment. In a 2018 report, TSMC says the virus led to nearly $84 million in losses for the third quarter.
While some in the industry have disputed his views, TSMC's CEO C.C. Wei said at the time he didn't expect any hacking and 'this was purely our negligence.' At the time, a company spokesperson told Bank Info Security 'this tool arrived at our facility with a virus already on it.'
The key lesson from this incident extended well beyond strengthening cybersecurity through technologies and processes. It underscored how critical security guidelines and successful implementation are across the chipmaking ecosystem.
In the years that followed, semiconductor fabs systematically enhanced their cybersecurity posture through a three-stage, inside-out approach: securing operational environments, inspecting inbound devices and reinforcing supply chain cybersecurity. Further incidents have happened in the years since and the industry has made a coordinated effort, led by a consortium, to bolster its work through initiatives such as a new security standard.
A growing issue
Terence Liu, CEO of Taiwan-based cybersecurity firm TXOne Networks, has had a tough job over the past decade. As a key provider for TSMC, TXOne purpose-built its software and hardware to protect critical infrastructure in more than a dozen countries.
Initial efforts focused on safeguarding internal operations. This included protecting critical production systems through network segmentation, endpoint protection and virtual patching to reduce exposure to known vulnerabilities.
Liu said that as these internal measures matured, 'the focus expanded to securing what enters the fab environment,' adding that 'strict inspection and validation processes were established for incoming equipment and devices, particularly those introduced by employees, contractors, or integration partners.' This step helped reduce the risk of inadvertently introducing threats into highly sensitive production areas.
Sources say companies came to recognize that effective cybersecurity must extend to the broader supply chain. Suppliers are now expected to demonstrate stronger security practices. This often involves completing structured questionnaires and undergoing external vulnerability scans to validate the maturity of their internal cybersecurity controls.
At the same time, there is growing awareness that securing the semiconductor industry requires collective action across the entire value chain, including manufacturers, equipment vendors and software providers.
Several major semiconductor firms have taken the lead in forming communities under the influential organization SEMI, formerly known as the Semiconductor Equipment and Materials International. A notable example of this collaboration is the Taiwan Semiconductor Cybersecurity Committee, chaired by TSMC.
One notable outcome is the development of the SEMI E187 fab equipment cybersecurity specification. This landmark standard is tailored to the unique characteristics of semiconductor manufacturing environments, where equipment lifecycles often span decades and operational continuity is critical.
The standard has evolved into a key purchasing requirement for many leading manufacturers and is now enforced throughout their supply chains. The supply chain enforcement is real and growing, with E187 certification now a baseline expectation for OEMs supplying to global fabs.
TSMC's contract now mandates it, and official reference guides firmly embed it into procurement criteria. Certification bodies, such as Bureau Veritas and Intertek, offer formal assessment services and structured paths toward compliance. Companies such as Gallant, Control, and Delta have already qualified, signaling the existence of structured, scalable compliance paths, not just voluntary guidance.
Looking ahead
What began as a regional initiative has quickly grown into a global movement.
James Tu, TSMC's head of corporate information security, outlined a vision to extend this cybersecurity uplift across the entire global semiconductor ecosystem during a talk at Semicon West in 2023. Tu plays a key role at Semi's Taiwan Cybersecurity Committee.
'Let us work together to enhance global supply chain security by influencing our own suppliers and partnering with SEMI,' he said. Tu stressed the need to influence TSMC's suppliers, collaborate with SEMI, and support the committee's members to create a ripple effect that boosts supply chain security broadly.
This vision ultimately led to the formation of the Semiconductor Manufacturing Cybersecurity Consortium, a global group dedicated to advancing cyber resilience across the semiconductor supply chain.
SMCC aims to unite chipmakers, equipment firms, cybersecurity vendors and nonprofits to safeguard semiconductor production from rising cyber threats. Its working groups focus on building implementation frameworks, aligning with global regulations and strengthening supply chain resilience. SMCC also monitors regulations such as the European Union's Cyber Resilience Act.
In the past, each semiconductor fab required suppliers to complete its own cybersecurity questionnaire, which placed a heavy burden on suppliers who had to respond to numerous, varying assessments. SMCC consolidated expert input and developed a unified cybersecurity assessment questionnaire, serving as a standardized baseline for self-assessment and continuous improvement. This reduced the time and effort required from suppliers. SMCC also published the NIST Cybersecurity Framework 2.0 Semiconductor Profile.
During a February 2023 NIST workshop, then-Cybersecurity and Infrastructure Security Agency Director Jen Easterly applauded NIST's work to update the framework. She and CISA had been pushing for the technology community to focus on 'product safety' and 'the idea that software and hardware must be secure by design and secure by default'. She said the framework had been useful to companies seeking out a clear and actionable foundation for implementation — especially one that aligns with globally recognized best practices.
This comes as the sector still faces a wave of cyber threats, with attackers targeting critical infrastructure, intellectual property, and production systems. Advanced persistent threats, ransomware and firmware-level attacks are becoming more sophisticated, often backed by nation-state actors.
Experts say that what distinguishes the semiconductor industry in its cybersecurity transformation is the ability to combine deep technical expertise with a collaborative, long-term plan that involves shared responsibility.
While not every industry operates with the semiconductor industry's high level of complexity or automation, the principles are broadly applicable: Cybersecurity is no longer optional. It's a foundational element of operational resilience and business trust.
As TXOne Networks' Liu likes to emphasize, 'strong [operational technology] security not only protects production but also safeguards long-term competitiveness.'
Recommended Reading
Cyberattacks in manufacturing: What's driving the trend?
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Watchung, NJ Pool Construction Service Announced By Sage Landscape Contractors
Watchung, NJ Pool Construction Service Announced By Sage Landscape Contractors

Associated Press

time33 minutes ago

  • Associated Press

Watchung, NJ Pool Construction Service Announced By Sage Landscape Contractors

Sage Landscape Contractors and Tree Experts expands pool construction services to Watchung, NJ, offering custom concrete pools with integrated landscaping and hardscaping from their Watchung-based team with 40+ years of experience. Plainfield, United States, August 1, 2025 -- Sage Landscape Contractors and Tree Experts has announced the availability of their pool and spa construction services in Watchung, New Jersey, and surrounding areas. The company, which has served Central New Jersey for over 40 years, focuses on custom pool installations that integrate with the surrounding landscape. For more information about their pool construction services, visit The Watchung-based company provides services that address both the pool itself and the surrounding area. Their team handles landscaping and hardscaping to create unified outdoor spaces. Founded in the 1980s by Ed Sage III, a Rutgers-trained landscape architect, the company applies decades of regional experience to each project. Sage Landscape Contractors works exclusively in concrete, a material which offers significant advantages in terms of both durability and customization options. Unlike pre-fabricated fiberglass options, concrete pools can be configured to suit the existing landscaping, integrating natural features into their design and blending aesthetics with functionality. The company begins each project with planning and design phases. Their process accounts for practical considerations including drainage, grading issues, property setbacks, easements, and environmental factors such as shadows from structures and trees. This preparatory work determines optimal pool placement and ensures functional integration of all elements. For pool surrounds, Sage offers four decking material options: exotic hardwoods like ipe; natural stone in various colors and textures; concrete in multiple styles; and pavers that can be removed and replaced if pool repairs become necessary. Each material presents different advantages depending on the property conditions and homeowner preferences. The company's comprehensive approach transforms properties into functional outdoor living spaces that add value to homes. Their portfolio demonstrates experience with various pool styles, from traditional rectangular designs to free-form shapes that complement natural landscapes. Beyond pool construction, Sage provides tree and plant care services, including pruning, removal, deep root fertilization, insect and disease control, and seasonal plant management. Additional services include stormwater management and property grading solutions. This full-service capability allows homeowners to work with a single contractor for their complete outdoor environment. For additional information about Sage Landscape Contractors and Tree Experts' pool and spa construction services, visit Contact Info: Name: Ed Sage Email: Send Email Organization: Sage Landscape Contractors and Tree Experts Address: 16 Driftway Ln, Plainfield, NJ 07060, United States Website: Release ID: 89166247 In case of identifying any problems, concerns, or inaccuracies in the content shared in this press release, or if a press release needs to be taken down, we urge you to notify us immediately by contacting [email protected] (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). Our dedicated team will be readily accessible to address your concerns and take swift action within 8 hours to rectify any issues identified or assist with the removal process. We are committed to delivering high-quality content and ensuring accuracy for our valued readers.

AWG Crypto Launches XRP Cloud Mining Contracts, Bringing Daily Rewards to the Ripple Ecosystem
AWG Crypto Launches XRP Cloud Mining Contracts, Bringing Daily Rewards to the Ripple Ecosystem

Associated Press

time33 minutes ago

  • Associated Press

AWG Crypto Launches XRP Cloud Mining Contracts, Bringing Daily Rewards to the Ripple Ecosystem

As Ripple's XRP ecosystem expands globally, AWG Crypto has announced a major advancement in cryptocurrency mining: the launch of XRP-focused cloud mining contracts. These flexible, short-term contracts are now available on both web and mobile platforms, allowing users to mine XRP remotely and receive daily XRP rewards — no mining hardware, setup or prior experience required. For the first time, retail participants can join the XRP economy through a streamlined, fully integrated platform. Key Features of AWG Crypto's XRP Cloud Mining Contracts Mining Contracts for Every Budget and Strategy AWG Crypto offers a variety of XRP-based mining contracts designed for flexibility, predictable income and low risk. Contracts include: Whether testing the waters or building a long-term portfolio, users can choose from low-risk, high-transparency contracts that generate stable daily XRP income. Click here to explore more XRP cloud contracts. What Sets AWG Crypto Apart? Get Started in 3 Easy Steps Mining XRP for a Digital Future Since 2018, AWG Crypto has helped millions of users worldwide earn passive crypto income through secure and intelligent cloud mining. With the launch of XRP mining, the platform bridges institutional-grade infrastructure with retail accessibility. Users can now choose to earn yield directly in XRP or diversify into other digital assets — all in a secure, remote-first environment. 'XRP has always been fast, efficient and scalable. Now, it can also be mined securely, remotely and profitably. We've removed all barriers so anyone can participate in the future growth of XRP,' said an AWG Crypto spokesperson. About AWG Crypto AWG Crypto is a leading compliant cloud mining service platform, relying on self-built mining farms and joint mining pool computing power to provide users with safe and efficient digital currency mining solutions. The platform adheres to the concept of 'user first' and is committed to lowering the industry participation threshold through technological innovation and promoting the development of inclusive finance. For more information, visit Disclaimer The information provided in this press release is not a solicitation for investment, nor is it intended as investment advice, financial advice, or trading advice. Cryptocurrency mining and staking involve risk. There is potential for loss of funds. It is strongly recommended you practice due diligence, including consultation with a professional financial advisor, before investing in or trading cryptocurrency and securities. Media Contact Bertha Tom [email protected] ### SOURCE: AWG Crypto Copyright 2025 EZ Newswire

ThreeD Capital Inc. Completes Private Placement Financing
ThreeD Capital Inc. Completes Private Placement Financing

Hamilton Spectator

time35 minutes ago

  • Hamilton Spectator

ThreeD Capital Inc. Completes Private Placement Financing

TORONTO, Aug. 01, 2025 (GLOBE NEWSWIRE) — ThreeD Capital Inc. ('ThreeD' or the 'Company') (CSE:IDK / OTCQX:IDKFF) a Canadian-based venture capital firm focused on opportunistic investments in companies in the junior resources and disruptive technologies sectors, is pleased to announce that it has closed its previously announced private placement financing (the 'Private Placement') pursuant to which it has issued an aggregate of 11,600,000 units ('Units') of the Company in exchange for total gross proceeds of $696,000, or $0.06 per Unit. Each Unit issued as part of the Private Placement is comprised of one common share and one common share purchase warrant (a 'Warrant'). Each whole Warrant entitles the holder thereof to acquire one common share of the Company at an exercise price of $0.15 per common share for a period of 60 months. No commission or finders' fees were paid as part of the Private Placement. All securities issued and issuable in connection with the Private Placement will be subject to a four-month and a day hold period expiring on December 2, 2025. In connection with the Private Placement, management and directors of the Company (collectively the 'Insiders'), purchased a total of 11,600,000 Units. Insiders' participation in the Private Placement constitutes a 'related party transaction' pursuant to Multilateral Instrument 61-101 – Protection of Minority Security Holders in Special Transactions ('MI 61-101'). The Company is relying on the exemption from the valuation and minority shareholder approval requirements under MI 61-101, as the fair market value of the Insiders' participation in the Private Placement does not exceed 25% of the market capitalization of the Company. About ThreeD Capital Inc. ThreeD is a publicly-traded Canadian-based venture capital firm focused on opportunistic investments in companies in the junior resources and disruptive technologies sectors. ThreeD's investment strategy is to invest in multiple private and public companies across a variety of sectors globally. ThreeD seeks to invest in early stage, promising companies where it may be the lead investor and can additionally provide investees with advisory services and access to the Company's ecosystem. For further information: Matthew Davis, CPA Chief Financial Officer and Corporate Secretary info@ Phone: 416-941-8900 The Canadian Securities Exchange has neither approved nor disapproved the contents of this news release and accepts no responsibility for the adequacy or accuracy hereof. Forward-Looking Statements This news release contains certain forward-looking statements and forward-looking information (collectively referred to herein as 'forward-looking statements') within the meaning of Canadian securities laws including, without limitation, statements with respect to the future investments by the Company. All statements other than statements of historical fact are forward-looking statements. Undue reliance should not be placed on forward-looking statements, which are inherently uncertain, are based on estimates and assumptions, and are subject to known and unknown risks and uncertainties (both general and specific) that contribute to the possibility that the future events or circumstances contemplated by the forward-looking statements will not occur. Although the Company believes that the expectations reflected in the forward looking statements contained in this press release, and the assumptions on which such forward-looking statements are made, are reasonable, there can be no assurance that such expectations will prove to be correct. Readers are cautioned not to place undue reliance on forward-looking statements included in this document, as there can be no assurance that the plans, intentions or expectations upon which the forward-looking statements are based will occur. By their nature, forward-looking statements involve numerous assumptions, known and unknown risks and uncertainties that contribute to the possibility that the predictions, forecasts, projections and other forward-looking statements will not occur, which may cause the Company's actual performance and results in future periods to differ materially from any estimates or projections of future performance or results expressed or implied by such forward-looking statements. The forward-looking statements contained in this news release are made as of the date hereof and the Company does not undertake any obligation to update publicly or to revise any of the included forward-looking statements, except as required by applicable law. The forward-looking statements contained herein are expressly qualified by this cautionary statement.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store