Cybersecurity in Semiconductor Manufacturing
Analysis of cybersecurity risks in semiconductor manufacturing, based on "How Does the Unencrypted SECS/GEM Protocol Cause Wafer Fab Shutdowns?" | Tech Orange.
OPEN SOURCEThe unencrypted SECS/GEM communication protocol significantly heightens risks in semiconductor manufacturing, enabling unauthorized access that can lead to operational shutdowns. A report indicates that 96% of cybersecurity incidents stem from IT systems infiltrating operational technology, underscoring vulnerabilities within production lines.
The semiconductor ecosystem in Taiwan is intricate, involving multiple stages from IC design to manufacturing, with over 12,000 vendors contributing to its complexity. Major suppliers like ASML play a pivotal role, with extensive interdependencies that necessitate effective supply chain security management to mitigate vulnerabilities associated with equipment and identity management.
In semiconductor facilities, the prevalence of unmanaged service accounts—often exceeding 30 per equipment unit—exposes significant vulnerabilities to cyber threats. The reliance on outdated communication protocols exacerbates the risk of system failures and security breaches, as evidenced by past incidents affecting critical infrastructure.
The interconnectedness of energy and semiconductor operations is highlighted by incidents such as a major power outage in Taiwan, which illustrates how a single point of failure can disrupt the entire supply chain. Taiwanese manufacturers are increasingly recognizing the urgency of enhancing security protocols in response to global incidents and regulatory pressures.
The CME187 standard is currently being updated to broaden its control scope in semiconductor manufacturing, reflecting the evolving security landscape. Despite compliance with such standards, concerns persist that adherence alone does not guarantee safety, indicating a need for ongoing security measures tailored to the specific circumstances of each organization.


- The lack of encryption in communication protocols poses significant risks to semiconductor manufacturing, allowing unauthorized access and potential shutdowns of operations
- Mars Cheng highlights that 96% of cybersecurity incidents originate from IT systems infiltrating operational technology (OT), emphasizing the vulnerability of production lines
- A recent report from Inésas cybersecurity agency indicates that threats to OT and supply chains are rapidly increasing, with semiconductor-related risks now categorized as a distinct threat
- Many organizations are forced to coexist with known vulnerabilities due to the critical nature of production lines, which complicates immediate risk mitigation efforts
- The semiconductor industry faces unique challenges in cybersecurity, as downtime for maintenance or security updates is often unacceptable, leading to reliance on compensatory measures
details
details
details
details
Read full analysis
- Highlight the critical need for robust security protocols in semiconductor manufacturing
- Emphasize the vulnerabilities posed by unencrypted communication protocols
- Argue that compliance with standards like CME187 does not ensure safety
- Point out the challenges in implementing comprehensive security measures
- The lack of encryption in communication protocols poses significant risks to semiconductor manufacturing, allowing unauthorized access and potential shutdowns of operations
- The semiconductor ecosystem in Taiwan is complex, involving multiple stages from IC design to manufacturing and packaging, with numerous companies contributing to each phase
- Major suppliers, such as ASML, play a critical role in the supply chain, with ASML having over 1,200 suppliers in Asia alone, highlighting the extensive interdependencies within the industry
- Effective supply chain security management in the semiconductor sector requires collaboration among over 12,000 vendors, driven by the need to address vulnerabilities and risks associated with equipment and identity management
- Frameworks like 31187 and 1188 have been proposed to standardize security measures across the lifecycle of semiconductor equipment, addressing both new installations and existing operational systems
- Risks in the semiconductor industry are compounded by external dependencies and potential vulnerabilities from equipment identity and communication protocols, as evidenced by past incidents in Europe affecting critical infrastructure
- The unencrypted SECS/GEM communication protocol poses significant risks to semiconductor manufacturing, as it allows for unauthorized modifications and can lead to operational disruptions
- In semiconductor facilities, there are often over 30 unmanaged service accounts per equipment unit, highlighting a lack of control over device identities and increasing vulnerability to cyber threats
- The reliance on outdated communication protocols, which are not upgraded over decades, exacerbates the risk of system failures and security breaches in the semiconductor supply chain
- Recent incidents, such as a major power outage in Taiwan caused by a brief disruption in natural gas supply, illustrate the interconnectedness of energy and semiconductor operations, emphasizing the need for robust security measures
- There is a growing awareness among Taiwanese semiconductor manufacturers of the importance of enhancing security protocols, driven by lessons learned from global incidents and regulatory pressures from entities like the EU
- The semiconductor industry is heavily reliant on various essential resources, including electricity, water, and chemicals, which are critical for manufacturing processes
- A single point of failure, such as a disruption in power supply, can lead to systemic failures across the semiconductor supply chain, highlighting the interconnectedness of energy and semiconductor operations
- Taiwanese semiconductor manufacturers are increasingly aware of the need to enhance security protocols, driven by both global incidents and regulatory pressures, particularly from the EU
- Standards like E187 and E188 are being developed to ensure safety in semiconductor manufacturing, focusing on equipment security before and during installation, but challenges remain in achieving comprehensive safety across all systems
- The semiconductor sectors security is not only about internal measures but also involves the safety of external partners and supply chains, emphasizing a collaborative approach to security
- The CME187 standard is undergoing a second version update, which aims to deepen its control scope and content, reflecting the evolving nature of security needs in semiconductor manufacturing
- Despite implementing CME187, clients express concerns that compliance alone does not guarantee safety, indicating a need for ongoing security measures beyond standard adherence
- The TXOne framework integrates various standards and controls, emphasizing the importance of tailored security measures for different roles and sizes of enterprises within the semiconductor supply chain
- Operational security in semiconductor production extends beyond the production line itself to include critical infrastructure, necessitating comprehensive safety strategies that go beyond existing standards
- The integration of different control measures and standards is crucial for enhancing security, allowing organizations to select appropriate measures based on their specific circumstances and capabilities
The discussion highlights significant vulnerabilities in the semiconductor manufacturing sector, particularly due to the reliance on unencrypted communication protocols like SECS/GEM. This lack of encryption not only facilitates unauthorized access but also poses a risk of operational shutdowns, which can have cascading effects across the supply chain.
This analysis is an original interpretation prepared by Art Argentum based on the transcript of the source video. The original video content remains the property of the respective YouTube channel. Art Argentum is not responsible for the accuracy or intent of the original material.



