3S Market 探討報導
《從台積電 2 奈米洩密到 NVIDIA GPU 遭非法轉運:高科技公司的安控,必須守住「五道信任關」》
從門禁、手機與文件管制,到資料防洩、晶片追蹤與終端客戶驗證,半導體安全已從「守住廠房」走向「守住人、空間、資料、產品與流向」。
高科技公司的安全,最危險的情境可能不是陌生人翻牆進廠。
真正棘手的,反而可能是一個原本就有合法門禁權限、合法電腦帳號,甚至合法接觸機密資料的人,做了一件他不應該做的事;另一種情況則更複雜:產品合法製造、合法出貨,第一手客戶也看似合法,但是經過轉售商、物流商、第三國公司幾次轉手後,最後卻到了原本禁止銷售的對象手上。
這兩種風險,台積電、NVIDIA 以及全球半導體供應鏈都已經碰過。
因此,高科技公司的安控如果仍然停留在「圍牆+攝影機+門禁+警衛」,防得住外面的人,卻未必防得住裡面的人;守得住工廠的大門,也未必守得住一顆晶片離開工廠之後的去向。
這也重新定義了所謂的高科技廠房安控:它必須從 Physical Security 延伸到 Information Security、Insider Risk、Supply Chain Security 與 Export Compliance,最後形成一套可以追溯的 Security Orchestration。
台積電的案例告訴我們:有門禁權限,不代表有資料使用權
這不是假設情境。
2017、2018 年台積電就陸續發生,員工涉嫌重製 28 奈米製程機密資料、準備攜往中國半導體公司使用的案件。2018 年案件中,檢方指控一名吳姓工程師在任職期間,非法重製 28 奈米重要製程文件,準備離職後前往中國無錫華潤上華科技任職。
到了先進製程世代,問題沒有消失,反而更加敏感。
2025 年台灣高檢署智慧財產檢察分署,偵辦台積電國家核心關鍵技術營業秘密案件。檢方指出,一名前台積電員工離職後,任職於半導體設備供應商,利用與台積電在職員工的關係,取得先進製程相關資料,再以拍攝方式重製技術內容。案件之所以曝光,是台積電主動發現「在職員工檔案接觸異常」,經內部調查後報請司法機關偵辦。
這裡其實出現一個非常值得安控產業思考的現象:
門沒有被破壞,帳號也沒有被駭。
有權限的人走進有權限的地方,開啟他原本可能可以接觸的資料,再利用另外一項設備 —— 例如手機 —— 把資料帶了出去。
到了 2026 年又出現另一宗案件。台灣高檢署指出,一名前台積電副理涉嫌與他人籌畫,在中國成立半導體材料分析公司,並擅自重製台積電國家核心及一般營業秘密共 21 件,甚至將資料攜回家中研讀。台積電察覺異常後進行內部調查並取回資料。
所以第一個結論非常明確:
高科技公司的安全邊界,不能畫在廠房圍牆,而要畫在「資料真正被使用的那一刻」。
NVIDIA 的案例則告訴我們:資料不一定從廠房出去
2022 年 NVIDIA 發生網路安全事件。NVIDIA 官方確認,攻擊者取得部分員工密碼及公司專有資訊,並開始把部分資料放到網路上。公司隨後要求所有員工更換密碼並強化網路安全措施。
這是另一種完全不同的入口。
台積電的部分案例屬於 Insider Risk;NVIDIA 2022 年事件則屬於外部攻擊取得內部憑證與資料。
更值得注意的是第三方供應商。
2023 年台積電 IT 硬體供應商 Kinmax 遭到網路攻擊,導致與伺服器初始設定、組態有關的資訊外洩。台積電表示事件沒有影響營運或客戶資訊,並立即停止與該供應商的資料交換。
因此,一家公司的安全程度,已經不能只看「自己公司的資安做得多好」。
供應商所持有的帳號、設定檔、系統權限、維護工具與遠端連線,同樣是你的攻擊面。
更麻煩的是:晶片出了廠,安全問題可能才剛開始
2024 年又出現另一種完全不同的半導體安全事件。
TechInsights 拆解華為 Ascend 910B AI 處理器後,發現其中存在台積電製造的晶片。由於華為當時已受到美國出口限制,台積電隨即向美國主管機關通報,並停止向中國晶片設計公司 Sophgo 出貨。Reuters 報導指出,Sophgo 曾向台積電下單與該晶片相符的產品,但晶片究竟如何進入華為產品,當時並沒有被確認;Sophgo也否認與華為存在業務關係。
這個案例不能簡化成「誰偷偷賣給誰」。
真正值得產業研究的是:
當一顆晶片合法離開晶圓廠後,原製造商究竟還掌握多少 downstream visibility?
到了 NVIDIA GPU,這個問題更加直接。
美國司法部 2025 年公布的 Operation Gatekeeper 案件顯示,相關人員承認在 2024 年 10 月至 2025 年 5 月間,非法出口或企圖出口,至少 1.6 億美元受出口管制的 NVIDIA H100、H200 GPU。司法文件所描述的手法,包括利用中間商與稻草買家、虛假申報最終客戶、修改運輸文件,甚至拆除 NVIDIA 標籤,並重新貼上虛構品牌,再把貨品偽報成普通電腦零組件。
NVIDIA 並不是該案被指控從事走私的一方。
但是這個案件非常清楚地證明:
產品是真的、訂單是真的、物流也是真的,假的可能只是「買家是誰、貨要到哪裡」。
這就已經不再是傳統廠區安控能單獨解決的問題了。
因此,高科技公司真正需要守的是「五道信任關」
如果把上述案件放在一起看,可以發現半導體高科技公司的安全,其實可以重新整理成五道信任關:
信任關 | 要回答的問題 | 核心控制 |
人的信任 | 你是誰?現在還應不應該有權限? | 身分、門禁、MFA、生物辨識、人員生命週期 |
空間的信任 | 你現在可以進哪裡? | 分區門禁、防尾隨、訪客與供應商管理 |
資料的信任 | 你可以看什麼、複製什麼、帶走什麼? | DLP、權限、手機/USB/列印管制、稽核 |
產品的信任 | 這顆晶片、板卡、設備現在在哪裡? | Serial、RFID、WMS、電子封條、Chain of Custody |
流向的信任 | 最後究竟賣給誰、用在哪裡? | KYB/KYC、End User、物流、出口管制、持續驗證 |
也就是說,真正的問題已經由過去的:「這個人能不能進這扇門?」
變成:「這個人現在為什麼進這扇門?進去後碰了什麼?下載了什麼?帶出了什麼?最後又交給了誰?」
這才是高安全場域下一階段真正需要建立的能力。
第一層部署:門禁不只認人,更要認「現在的任務」
傳統企業門禁最大的問題,是把 Access Right 當成長期靜態權限。
工程師屬於 A 部門,因此可以進 A 區;設備商工程師獲得承包商資格,因此一年都可以進入某些設備區。
但高機密場域更適合改成 Role+Project+Time+Location。
同一名工程師今天參與 2 奈米專案,可以進入相關區域;專案結束後權限自動收回。供應商工程師今天下午 2 點到 5 點進場維修某一台設備,他取得的是這三小時、這一條路徑、這一個設備區的授權,而不是整座廠房通行證。
因此,高安全區應搭配企業級門禁、多重驗證、防尾隨、Anti-passback、門位感測器,必要時加入互鎖門或 Mantrap。
真正重要的不是再多裝一道門,而是:權限要會過期。
第二層部署:手機可能比 USB 更值得管
台積電近期案件值得安控業特別注意的一點,就是「拍攝」。
很多企業已經防 USB、限制 Email、管制雲端硬碟,但只要一支高解析度手機能進入機密區域,螢幕上的資料仍可能瞬間變成另一份完全不受 DLP 管控的影像檔案。
因此極高機密區可以設置智慧型手機與電子設備置物櫃,員工或訪客在進入安全區前存放手機、智慧手錶、相機、可攜式儲存裝置。
門禁甚至可以和置物櫃系統聯動:手機沒有完成寄存 → 高安全門禁不開放。
而高風險研發區的文件、工作站畫面也可以加入動態浮水印,例如使用者、時間、設備編號,讓「拍照」本身產生可追溯性。
這比單純寫一句「禁止拍照」實際得多。
第三層部署:把「刷卡紀錄」與「資料存取紀錄」接起來
這可能是整套系統最值得發展的一步。
假設某工程師凌晨 1 點沒有進入研發中心,帳號卻突然大量開啟機密資料;或者他當天只被授權進入設備維修區,卻讀取與工作內容完全無關的先進製程文件。
單獨看門禁紀錄,沒有異常。
單獨看 IT Log,也不一定馬上異常。
但是兩份資料疊在一起,異常就出現了。
因此高科技企業未來的 GSOC 或 Security Operation Center,應該把:
Access Control+Identity+DLP+SIEM+UEBA+PAM+HR+Visitor Management
進行事件關聯。
這也是所謂 Security Orchestration 真正有價值的地方 —— 不是把所有設備放在一個螢幕,而是讓不同系統互相驗證。
第四層部署:產品也必須建立「身份證」
對高價值 AI GPU、晶片、測試板、Prototype 或關鍵模組,物流管理不能只做到「這一箱已經出貨」。
應該逐步建立:
Serial Number → Lot → Package → Pallet → Warehouse → Forwarder → Distributor → End User
的履歷鏈。
UHF RFID、條碼、電子封條、倉庫門禁、裝卸碼頭影像、WMS、TMS、ERP 可以共同建立 Chain of Custody。
發貨區則應採雙人覆核、高安全儲存籠、出貨批次驗證及電子封條;高風險貨物甚至可對物流路線進行追蹤。
影像監控在這裡仍然重要,但它扮演的不是「一直有人盯著看」。
而是回答:
這一箱貨在 14:32 是誰從哪一個庫位取出?誰批准?從哪一道 Dock 出去?上了哪一台車?
影像變成證據鏈的一部分,而不是安控系統的全部。
第五層部署:真正難防的是「合法客戶變成非法流向」
這正是 NVIDIA GPU 非法轉運案件最值得研究之處。
美國 BIS 對先進運算晶片的防轉運指引,已經把 Due Diligence 拉到非常細,包括確認客戶名稱、地址、營業內容、交易角色、最終使用者、交付及安裝地點、母公司所在地、產品用途以及是否會再出口或轉售;客戶拒絕提供資料、本業與採購品項明顯不符、地址與電話異常等,都可能成為 Red Flag。
這代表半導體公司的「安控中心」概念可能也必須往外延伸。
未來高風險訂單可以形成:
Order → Customer → Beneficial Owner → End User → Shipping Address → Freight Forwarder → Installation Site
的交易安全圖譜。
例如一家成立六個月的小公司突然採購大量高階 GPU;客戶不需要原廠安裝與維護;交貨地點突然從 A 國改到 B 國倉庫;或者採購量與其公司規模明顯不符。
任何一項可能都不是犯罪。
但同時出現三、四項,就應該觸發:Hold Shipment。
不是業務說「客戶很急」就可以出貨,而是進入 Compliance Review。
這其實就是把傳統安控的「異常事件管理」,搬到了交易與供應鏈。
程序安全尤其要盯住三個時間點:進來、改變、離開
高科技公司還有一個很容易忽略的風險,就是員工生命週期。
安全程序不能只做好新人報到。
真正應建立的是:Joiner → Mover → Leaver。
新人加入什麼專案,就取得什麼權限;調職後舊權限立即取消;提出離職之後,機密資料大量下載、異常列印、非正常時段登入、USB 使用與敏感區進出應提高稽核敏感度。
這不是把即將離職的員工當成嫌疑犯,而是因為組織與員工的「Need to Know」已經發生變化。
供應商亦相同。
專案結束,門禁卡不能只是放著等過期;VPN、Remote Maintenance、Shared Account、資料夾權限都必須同步失效。
安控真正要做的,不是保證「永遠不會洩密」
任何安全系統如果宣稱可以百分之百阻止內鬼、駭客或晶片轉運,基本上都不現實。
安全真正可以做到的是五件事:
降低機會、增加難度、提早發現、限制損害、留下證據。
一個工程師真的想偷資料,他可能永遠會尋找新的方法。
但是如果進高安全區必須重新授權,手機不能帶進去;資料開啟留下紀錄,螢幕有個人浮水印;大量資料存取會告警;列印必須二次授權;離職與調職自動重新計算權限 —— 他的成本與被發現機率就完全不同。
產品也是一樣。
如果 GPU 每一次轉移都留有 Serial、物流、買家、最終用戶與出貨紀錄,中間商想把它洗成「不知道從哪裡來的一張板卡」,難度自然提高。
結語:高科技安控下一步,是把「廠房安全」做成「可信任供應鏈」
台積電的 28 奈米與 2 奈米案件、NVIDIA 的 2022 年資料外洩事件、台積電供應商遭駭、台積電晶片出現在受限制對象產品,以及 NVIDIA GPU 遭第三方非法轉運,看似是完全不同的新聞。
但把它們放在同一張安全地圖上,就會發現它們其實在問同一件事:
我們究竟相信誰?而這個信任可以維持多久?
相信一個員工,不代表他可以永遠讀取所有資料。
相信一個供應商,不代表他的帳號可以永遠存在。
相信一個經銷商,不代表產品交給他以後就不需要知道去了哪裡。
甚至相信一張合法訂單,也不能代表最終使用者一定就是訂單上的那家公司。
因此,高科技公司的安控正在從「控制門」走向控制信任。
如果用 3S Market 一直在倡議建立的安全五層次來看,這個架構其實非常清楚:
基礎安全建立門禁、入侵偵測、置物櫃、資產追蹤與必要影像證據;程序安全規定誰在什麼情況可以進入、下載、列印、攜出與出貨;風險管理開始把異常存取、異常交易、異常物流進行關聯;韌性安全處理外洩之後的隔離、停權、停止資料交換、Hold Shipment 與事故應變;到了永續安全,才是持續更新供應商、客戶、出口管制、權限與稽核制度。
所以可以把這篇最後濃縮成一句話:
高科技公司的安全,不能只保證「不讓不該進來的人進來」,還必須保證「進來的人只做該做的事,出去的資料與產品最後也去到該去的地方」。
這才是半導體高科技公司真正的安控解決方案。
3S Market English version
If You Were the Chief Security Officer of a Semiconductor Company, How Would You Handle These Situations?
From TSMC technology leaks and illegal NVIDIA GPU transshipment to people, data, products, and supply-chain destinations — how should security architecture in the semiconductor industry be redesigned?
Security at a high-tech company is no longer just about keeping intruders outside the fence.
In many cases, the greater danger may come from someone who already has a valid badge, a legitimate system account, and authorized access to sensitive information — but then does something that falls outside the original purpose of that authorization.
Another risk is even harder to control. A product may be legally manufactured and legally shipped to what appears to be a legitimate customer, only to be resold, redirected, relabeled, or transshipped through third countries before eventually reaching a prohibited end user.
The semiconductor industry has already encountered both kinds of problems.
That means security can no longer stop at fences, guards, surveillance systems, and access control. A company may successfully protect the entrance to its factory yet still fail to protect its intellectual property, confidential data, high-value products, or downstream supply chain.
For semiconductor and advanced technology companies, security therefore has to expand from Physical Security into Information Security, Insider Risk, Supply Chain Security, Export Compliance, and Security Orchestration.
The real question is no longer simply:
“Can this person enter this area?”
It is increasingly:
“Why is this person entering now? What are they authorized to access? What data did they view or download? What did they take out? Where did the product go after it left the factory? And who ultimately received it?”
TSMC’s Cases Show That Access Permission Is Not the Same as Permission to Use Information
This is not a hypothetical scenario.
TSMC has experienced multiple cases involving employees accused of improperly copying or removing confidential process information.
Earlier cases involved 28-nanometer process technology, where employees were accused of reproducing sensitive manufacturing information and preparing to take that knowledge to semiconductor companies in China.
More recently, cases involving advanced process technologies demonstrated that insider threats have become even more sensitive.
In one investigation, former and current employees were suspected of using their legitimate access relationships to obtain advanced semiconductor process information. In some instances, technical information was allegedly reproduced through photography.
One of the most important details was that the incident was reportedly discovered because TSMC detected abnormal access patterns involving internal files.
This creates a very important security lesson.
The door was not broken. The account was not necessarily hacked.
An authorized person may enter an authorized area, open information they are technically able to access, and then use another device — such as a smartphone — to remove the information from the company’s controlled environment.
Therefore, the security boundary of a semiconductor company cannot simply be drawn around the factory perimeter.
It must extend to the moment information is actually accessed, used, copied, photographed, printed, downloaded, or transferred.
NVIDIA Demonstrates Another Problem: Data Does Not Have to Leave Through the Factory Door
NVIDIA also experienced a major cybersecurity incident in 2022.
Attackers obtained employee credentials and proprietary company information, and portions of the stolen data were subsequently released online.
This represents a completely different attack path.
Some TSMC cases were primarily associated with Insider Risk.
The NVIDIA incident demonstrated the risk of an external attacker acquiring legitimate internal credentials and using them to reach confidential information.
Third-party suppliers add another layer of exposure.
A company may have strong internal cybersecurity controls, but vendors, maintenance contractors, equipment suppliers, and IT service providers may still possess remote-access privileges, configuration files, passwords, system documentation, or maintenance tools.
This means a company’s actual security level cannot be measured only by how secure its own internal systems are.
A supplier’s account, laptop, VPN connection, maintenance platform, and technical documentation may all become extensions of the company’s attack surface.
The Harder Problem Begins After the Chip Leaves the Factory
Semiconductor security does not end when a product is shipped.
In 2024, a TSMC-manufactured chip was reportedly discovered inside a Huawei AI processor during a third-party technical teardown.
Because Huawei was subject to U.S. export restrictions, the incident immediately raised questions about how the chip moved through the supply chain and ultimately reached a restricted destination.
The issue should not simply be reduced to the question of “who secretly sold the chip.”
The more important question is:
Once a semiconductor product legally leaves the manufacturer, how much downstream visibility does the original manufacturer still have?
This issue becomes even more obvious with high-end NVIDIA GPUs.
U.S. authorities have prosecuted cases involving the illegal export or attempted export of large volumes of restricted NVIDIA H100 and H200 GPUs.
The alleged methods included the use of intermediaries and straw buyers, false declarations of end customers, manipulation of shipping documentation, removal or replacement of product labels, and the misclassification of high-end computing equipment as ordinary electronic components.
NVIDIA itself was not accused of operating those smuggling networks.
But the cases clearly demonstrate a critical point:
The product may be genuine. The purchase order may be genuine. The logistics network may be genuine. What may be false is the identity of the buyer, the destination, or the final end user.
At that point, traditional facility security alone is no longer enough.
Semiconductor Companies Need Five Gates of Trust
When these incidents are examined together, semiconductor security can be reorganized around five fundamental trust gates.
Trust Gate | Core Question | Primary Controls |
Trust in People | Who are you, and should you still have this level of access? | Identity, access control, MFA, biometrics, personnel lifecycle management |
Trust in Space | Where are you allowed to go right now? | Zoned access, anti-tailgating, visitor and contractor controls |
Trust in Data | What can you view, copy, print, photograph, or remove? | DLP, permissions, phone controls, USB controls, logging, watermarking |
Trust in Product | Where is this chip, GPU, prototype, or module now? | Serial numbers, RFID, WMS, tamper seals, chain of custody |
Trust in Destination | Who ultimately receives and uses the product? | KYC/KYB, end-user verification, export controls, logistics monitoring |
The security question has therefore evolved from:“Can this person open this door?”
to:
“Why is this person opening this door now? What can they access after entering? What information did they touch? What did they remove? And where did the product or data eventually go?”
That is the real direction of next-generation security for high-security technology environments.
First Layer of Deployment: Access Control Must Recognize the Mission, Not Just the Person
One of the biggest limitations of conventional corporate access control is that privileges are often treated as static.
An engineer belongs to Department A, so the person can enter Area A.
A contractor is approved as an equipment vendor, so the contractor may retain access privileges for months or even a year.
In highly confidential environments, access should instead be based on:
Role + Project + Time + Location
An engineer assigned to a two-nanometer project may receive access to specific areas only while participating in that project.
When the project ends, the access rights should automatically expire.
A supplier engineer entering a facility to repair a specific machine between 2:00 p.m. and 5:00 p.m. should receive authorization for that time window, that route, and that equipment zone — not a general pass to the entire facility.
High-security areas can therefore combine enterprise access control with multi-factor authentication, biometrics, anti-passback, door-position monitoring, anti-tailgating technology, interlocking doors, or mantraps.
The most important point is not simply to add another door.
Privileges must expire.
Second Layer of Deployment: Smartphones May Deserve More Attention Than USB Drives
One of the most important lessons from recent semiconductor leakage cases is the role of photography.
Many organizations already restrict USB devices, external email, cloud drives, and file transfers.
But if a high-resolution smartphone can enter a confidential R&D area, information displayed on a workstation can instantly become an uncontrolled image file outside the company’s DLP environment.
For extremely sensitive areas, companies can deploy secure lockers for smartphones and personal electronic devices before entry.
Employees, visitors, and contractors may be required to store smartphones, smartwatches, cameras, removable storage devices, or other recording devices before entering restricted zones.
The locker system can even be integrated with access control:
Device not deposited → Secure-area access remains locked.
Confidential documents and workstation screens can also use dynamic watermarking that includes the user identity, time, workstation number, or project reference.
That way, even if someone photographs a screen, the content remains traceable.
This is far more effective than simply posting a sign that says “No Photography.”
Third Layer of Deployment: Connect Badge Records With Data-Access Logs
This may be one of the most important developments in high-tech security architecture.
Imagine that an engineer does not physically enter the R&D center at 1:00 a.m., yet the engineer’s account suddenly begins accessing large volumes of confidential process data.
Or the engineer has authorization to enter an equipment-maintenance area but suddenly accesses sensitive files unrelated to the assigned work.
If the security team looks only at physical access logs, there may appear to be no problem.
If the IT team looks only at system logs, the activity may not immediately seem suspicious.
But once the two datasets are correlated, the anomaly becomes much clearer.
Future semiconductor GSOCs and Security Operations Centers should therefore correlate:
Access Control + Identity + DLP + SIEM + UEBA + PAM + HR + Visitor Management
The value of Security Orchestration does not come from putting every system on one giant monitor.
Its value comes from allowing different systems to cross-check one another.
Physical access can verify cyber activity.
Cyber activity can verify employee behavior.
HR status can verify whether a privilege still makes sense.
Visitor records can verify whether a contractor should have been present.
This is where isolated security systems become an integrated risk-detection capability.
Fourth Layer of Deployment: High-Value Products Need Their Own Identity
For high-value AI GPUs, semiconductor chips, test boards, prototypes, and critical modules, logistics management cannot stop at “shipment completed.”
A product history should gradually be built around:
Serial Number → Lot → Package → Pallet → Warehouse → Forwarder → Distributor → End User
Barcode systems, UHF RFID, electronic seals, warehouse access control, loading-dock surveillance, WMS, TMS, and ERP can work together to establish a complete Chain of Custody.
High-security shipping areas can also require:
- Dual-person verification
- Restricted storage cages
- Batch-level shipment validation
- Tamper-evident or electronic seals
- Controlled loading docks
- Secure transport procedures
- Route monitoring for high-risk cargo
Video surveillance still has an important role here.
But it is not about having someone stare at a screen continuously.
Its real purpose is to answer questions such as:
Who removed this shipment from the secure storage area at 14:32? Who approved it? Which loading dock did it pass through? Which vehicle received it?
Video becomes part of the evidence chain rather than the entire security solution.
Fifth Layer of Deployment: The Hardest Risk Is a Legitimate Customer Becoming an Illegitimate Destination
This is the most important lesson from illegal GPU transshipment cases.
The difficult problem is not always stopping the original shipment.
It is determining where the shipment ultimately ends up.
Advanced semiconductor transactions increasingly require deeper due diligence involving:
Order → Customer → Beneficial Owner → End User → Shipping Address → Freight Forwarder → Installation Site
A semiconductor company may need to verify the customer’s business activities, corporate ownership, purchasing volume, destination, product purpose, installation location, re-export plans, and relationship with intermediaries.
Potential warning signs might include:
- A newly established company suddenly ordering large quantities of high-end GPUs
- A customer whose normal business does not match the technology being purchased
- A buyer refusing to disclose the final installation location
- Shipping instructions changing late in the transaction
- Delivery being redirected to a third-country warehouse
- Unusual freight-forwarder arrangements
- Customer scale being inconsistent with order volume
- A buyer refusing manufacturer installation, service, or technical support
None of these signs alone proves wrongdoing.
But several appearing together should trigger a higher level of review.
At that point, the system should be capable of initiating: Hold Shipment
The order should move into compliance review rather than being released simply because “the customer is in a hurry.”
This is essentially the same logic used in physical security anomaly detection — applied to commercial transactions and supply chains.
Procedural Security Must Focus on Three Moments: Joining, Changing, and Leaving
Another frequently overlooked area is the employee lifecycle.
Security procedures cannot focus only on onboarding.
The real control model should be: Joiner → Mover → Leaver
When a new employee joins a project, the person receives only the required privileges.
When the employee transfers to another role, obsolete privileges should disappear automatically.
When someone resigns or enters a sensitive transition period, the organization may increase monitoring of unusual downloads, printing, USB activity, after-hours logins, or access to confidential areas.
This does not mean treating every departing employee as a suspect.
It means recognizing that the employee’s Need to Know has changed.
The same principle applies to suppliers.
When a project ends, the vendor’s badge should not simply remain active until its expiration date.
VPN access, remote-maintenance accounts, shared credentials, data-folder permissions, and temporary system privileges should all be revoked at the same time.
Security Cannot Promise That Leakage Will Never Happen
No security architecture can realistically guarantee that insider theft, hacking, data leakage, or illegal product diversion will never occur.
What security can do is:
Reduce opportunity, increase difficulty, detect earlier, limit damage, and preserve evidence.
A determined insider may always look for another method.
But the risk changes dramatically if:
- High-security areas require renewed authorization
- Smartphones cannot enter sensitive areas
- Confidential files generate detailed access logs
- Screens include individual dynamic watermarks
- Large downloads trigger alerts
- Printing requires secondary approval
- Employee transfers automatically recalculate access rights
- Contractors lose all privileges when assignments end
The same principle applies to products.
If every high-value GPU or semiconductor module retains a traceable relationship among serial number, shipment, customer, logistics provider, end user, and destination, it becomes much harder for a shipment to disappear into an opaque chain of intermediaries.
Conclusion: The Next Stage of Semiconductor Security Is Turning Facility Security Into a Trusted Supply Chain
TSMC’s technology-leak cases, NVIDIA’s cybersecurity incident, supplier compromises, restricted chips appearing in unexpected products, and high-end GPUs being illegally transshipped may appear to be completely different stories.
But when they are placed on the same security map, they are all asking the same question:
Who do we trust — and for how long?
Trusting an employee does not mean the employee should have permanent access to every file.
Trusting a supplier does not mean the supplier’s account should remain active indefinitely.
Trusting a distributor does not mean the manufacturer should stop caring where the product goes after the first sale.
Even a legitimate purchase order does not necessarily mean that the company named on the order is the true end user.
Semiconductor security is therefore moving from controlling doors to controlling trust.
Viewed through the five-layer security framework, the structure becomes clearer.
Basic Security provides access control, intrusion detection, secure storage, asset tracking, and necessary video evidence.
Procedural Security determines who may enter, download, print, carry out, ship, or approve sensitive assets.
Risk Management correlates abnormal access, unusual transactions, suspicious logistics, and behavioral anomalies.
Resilience Security governs containment after an incident — account suspension, data isolation, vendor disconnection, Hold Shipment, investigation, and recovery.
Sustainable Security continuously updates access models, supplier verification, customer due diligence, export-control requirements, audit practices, and security governance.
The entire argument can therefore be summarized in one sentence:
A semiconductor company’s security cannot merely ensure that unauthorized people stay outside. It must also ensure that authorized people do only what they are supposed to do — and that sensitive data and high-value products ultimately go only where they are supposed to go.
That is what a modern semiconductor security solution should actually protect.
按此 ☞ 回今日3S Market新聞首頁
0 comments:
張貼留言