Header image

Supply Chain Risk Evaluation with DoD Contractors Pushed

Senator says digital escorts often do not have the technical training or expertise needed to catch malicious code or suspicious behaviour.

The U.S. Department of Defense has been urged to launch a probe into its contractors' use of Chinese personnel.

Following a ProPublica report, which detailed Microsoft's enlistment of Chinese engineers to aid in maintaining the Pentagon's computer systems, Cybersecurity Dive reports that Senators are calling for a list - not only of all military contractors that have sought the services of Chinese personnel for DoD systems maintenance - but also of all subcontractors that hired the Chinese digital escorts.

Senate Intelligence Committee Chairman Tom Cotton wrote in a letter to Defense Secretary Pete Hegseth that “while this arrangement technically meets the requirement that U.S. citizens handle sensitive data, digital escorts often do not have the technical training or expertise needed to catch malicious code or suspicious behaviour.”

Cotton called on the Defense Department to ensure defences against supply chain threats. However Microsoft has allayed Cotton's concerns, stating that none of the Defense Department's systems are being managed by Chinese engineering teams.


Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Upcoming Events

No events found.