Most cybersecurity conversations focus on protecting networks and software from attack, and treat the physical hardware underneath as a solved problem. It rarely is. Hardware-level security is easy to overlook precisely because it does not show up in a dashboard.
Who controls the production line
The first question worth asking a supplier is where manufacturing actually happens, and who controls that process. A vertically integrated manufacturer, with full control over its own board production, can make guarantees about tampering that a manufacturer several supply-chain layers removed from its own factory cannot.
Jurisdiction matters alongside vertical integration. Manufacturers based in countries with high security standards and stable export-control regimes are a materially different risk profile than supply chains that pass through jurisdictions where tampering with firmware, or embedding tracking hardware, is a documented concern for defence and municipal operators alike.
Fujitsu, and why component-level customisation matters
kHouse works closely with Fujitsu, a NATO-friendly manufacturer with its own factories in Japan and the EU building its own motherboards, running at 99.997% availability. Their laptops and desktops can be specified down to component level — cameras, USB ports, and other attack surfaces removed outright rather than merely disabled in software, where they could in principle be re-enabled.
A policy that trusts every request still has to trust the board the request runs on.
None of this replaces the software-level Zero Trust work. It is the layer underneath it — the one that makes "verify everything" a claim you can actually stand behind, instead of a policy document describing a network you are still trusting on faith.