Key Takeaways

  • Chain-of-custody breaks down when ICT assets move beyond visible, documented control. 
  • The biggest risks are poor component provenance, custody gaps, configuration drift and fragmented sustainment ownership. 
  • For Defence and regulated buyers, assurance depends on evidence, not supplier trust alone. 
  • A verifiable chain-of-custody record helps protect system integrity, accountability and operational confidence. 

In Defence and other high-consequence environments, trust is often treated as a proxy for control. A supplier is approved, a contract is signed, and assurance is assumed to follow. But in practice, trust is not the same as traceability. Once hardware, software, components, subcontractors, logistics providers, integration teams and sustainment partners enter the picture, risk does not disappear. It moves into the spaces where visibility becomes fragmented. 

That is where chain-of-custody breaks down. 

In ICT, chain-of-custody refers to the documented, verifiable record of who has handled, modified, transported, stored, integrated, maintained or disposed of a system or component across its lifecycle. It is not only about physical possession. It is about proving integrity, accountability and control from source to sustainment to retirement. 

Secure procurement does not end at vendor selection. It extends across the entire system lifecycle. When visibility breaks down, organisations face: 

  • Loss of traceability across suppliers and handlers 
  • Increased ICT supply chain risk and compliance exposure 
  • Delayed incident response and uncertain accountability 
  • Reduced confidence in system integrity lifecycle 

The following six breakdown points are where that risk most often emerges. 

1. Multi-tier supllier opacity

Most supply chains extend far beyond the contracted vendor. Beneath any approved supplier sits a network of: 

  • Manufacturers and sub-assemblers 
  • Distributors and regional fulfilment partners 
  • Firmware providers and component suppliers 
  • Logistics and handling intermediaries 
  • This opacity is structural. Procurement typically governs tier-one suppliers, while deeper layers remain commercially obscured. 

 

Why it happens 

  • Global, multi-layered supply chains 
  • Commercial segmentation between parties 
  • Limited obligation to disclose sub-tier relationships 

What risk it creates 

  • Undetected component substitution 
  • Exposure to unauthorised intermediaries 
  • Incomplete chain-of-custody ICT records 

Why attribution fails  

Responsibility fragments across organisations. When issues occur, accountability becomes contested rather than provable

2. Unverified Component Governance

Even where supply pathways appear legitimate, underlying components may not be fully verified. This is especially common when: 

  • Lead times force alternative sourcing 
  • Stock is constrained or redirected 
  • Assumptions are made about authorised channels

Why it happens 

  • Availability pressures outweigh assurance discipline 
  • Procurement checks focus on supplier, not component lineage 
  • Limited independent verification processes 

What risk it creates 

  • Introduction of altered or non-conforming components 
  • Undocumented firmware or configuration variations 
  • Compliance exposure during audit or accreditation 

Why attribution fails  

By the time provenance issues surface, components are often integrated, redistributed or in production use. The evidentiary trail is incomplete. 

3. Configuration drift during integration

Systems rarely remain unchanged between procurement and deployment. Integration introduces variance through: 

  • Imaging and software loading 
  • Network configuration and environment alignment 
  • Mission-specific adjustments 

Why it happens 

  • Multiple teams operating across environments 
  • Time pressure and project dependencies 
  • Inconsistent documentation of changes 

What risk it creates 

  • Misalignment between approved and deployed configuration 
  • Weakened system integrity lifecycle assurance 
  • Increased difficulty in troubleshooting or accreditation 

 

Why attribution fails  

Ownership is distributed: 

  • Procurement confirms delivery 
  • Engineers manage configuration 
  • Security assesses final state 

 

Without unified control, no single party can evidence the full picture. 

4. Custody gaps during logistics and storage

Physical handling introduces risk even when sourcing is sound. ICT assets often move through: 

  • Third-party couriers 
  • Warehousing and staging environments 
  • Temporary storage and redistribution points 

 

Why it happens 

  • Variability in custody controls between locations 
  • Inconsistent tamper evidence and tracking 
  • Limited visibility between dispatch and receipt 

What risk it creates 

  • Potential tampering or unauthorised access 
  • Loss of assurance even without confirmed compromise 
  • Breaks in secure supply chain defence 

Why attribution fails  

Each party controls only part of the journey. If integrity is questioned later, the intervening record may not exist. 

5. Fragmented responsibility during sustainment

Chain-of-custody erosion often accelerates after deployment. Sustainment introduces repeated handling across: 

  • Service desks and OEM support 
  • Field engineers and subcontractors 
  • Managed service providers and internal teams 

 

Why it happens 

  • Disparate systems for recording activity 
  • Split ownership across operational functions 
  • Focus on resolution rather than traceability 

What risk it creates 

  • Loss of sustained visibility over system changes 
  • Weak audit and compliance posture 
  • Reduced operational readiness confidence 

Why attribution fails  

Historical activity fragments over time: 

  • Multiple interventions 
  • Incomplete logs 
  • Inconsistent ownership 

 What remains is partial history rather than defensible evidence. 

6. End-of-life disposal and data exposure

Disposal is frequently treated as administrative, yet still carries significant risk. Assets pass through: 

  • Decommissioning workflows 
  • Third-party disposal vendors 
  • Storage prior to destruction or redistribution 

 

Why it happens 

  • Lower perceived operational importance 
  • Separation from core ICT governance 
  • Inconsistent documentation standards 

What risk it creates 

  • Residual data exposure 
  • Reintroduction of devices into secondary markets 
  • Breakdown of final chain-of-custody assurance 

Why attribution fails  

Disposal chains often lack: 

  • Detailed handling records 
  • Verified sanitisation evidence 
  • Clear accountability frameworks 

Once an asset leaves controlled oversight, traceability degrades rapidly. 

The attribution problem is the real risk multiplier

Chain-of-custody failures are not just about control gaps. They are about the inability to prove what has happened. 

When attribution breaks down, organisations face: 

  • Delayed response 
    Time is spent reconstructing history instead of resolving incidents 
  • Increased exposure 
    Responsibility becomes ambiguous across technical, commercial and operational stakeholders 
  • Weakened accountability 
    Assurance becomes assumed rather than evidenced 

In Defence and regulated environments, this is not acceptable. Decisions must be defensible under scrutiny. If an organisation cannot prove system integrity, confidence in the system erodes regardless of actual compromise. 

What this means for buyers

Evaluating vendors alone is no longer sufficient. Buyers must assess system-wide supply chain integrity and lifecycle accountability. 

That means moving beyond capability and asking: 

  • Can component provenance be evidenced, not assumed? 
  • Is there a continuous, verifiable chain-of-custody ICT record? 
  • Who owns system integrity after delivery? 
  • How are integration and configuration changes controlled? 
  • What governance exists across sustainment and disposal? 
  • Can attribution be established quickly if something fails? 
     

Traditional procurement processes do not fully address these questions. Yet they sit at the centre of Defence procurement risk.