Tariffs get the headlines this year. The effective US tariff rate is now near 10%, the highest since 1946. Mid-sized businesses have watched their tariff bills nearly triple since early 2025. That story is real, and it deserves the attention it’s getting. But cost was never the only thing missing from a sourcing decision. Control was the other blind spot, and it’s the supply chain risk nobody priced in.
The Cost Story Everyone’s Telling
For decades, sourcing overseas was the easy call. Tariffs were historically low. Freight was cheap, sometimes absurdly so — ask any owner who’s shipped a defective part back for warranty service, where the return freight alone can cost more than the part did to begin with. Nobody built a line item for what that arbitrage was actually covering up.
That gap is closing now, and tariffs are the visible part of it. Small manufacturers in some sectors have seen margins cut in half over the past year. A business that built its cost structure around a decade of cheap landed costs is feeling that shift directly.
The Supply Chain Risk Nobody Priced In
Cost wasn’t the only thing that arbitrage bought. In mid-2025, US investigators found undisclosed cellular radios inside Chinese-made solar power inverters already connected to American utility grids. Senators have since called for a formal investigation into what amounts to a potential remote kill switch on US energy infrastructure.
Networking equipment has the same problem in a different form. The Commerce Department is moving to ban TP-Link routers outright, over concerns that the company’s ties to China expose its equipment, and the networks running on it, to foreign jurisdiction. TP-Link holds roughly half the US home and small-business router market. A company that standardized on the most common router brand in the country could be forced to replace it on short notice, through no decision of its own.
Software carries the same risk in a quieter form. A popular robot vacuum maker recently updated its privacy policy to admit that user data — including home maps built from onboard cameras and sensors — may be processed in China. None of this required a tariff, a trade dispute, or even a hardware defect. It only required a product built around software the buyer never actually controlled.
The same pattern shows up outside consumer hardware. Salt Typhoon, the state-linked group that breached major US telecom carriers through 2024 and 2025, got in partly through infrastructure providers are legally required to build for law enforcement wiretaps. The lesson isn’t about any one vendor. A backdoor built for one purpose eventually gets used for another, once someone with the wrong intentions finds it.

Why This Keeps Happening
None of this means the businesses affected were careless. Most cost models were never built to price in a risk like this. A purchasing decision weighs unit price, freight, lead time, and tariff exposure. It rarely asks what happens if a vendor’s government asserts jurisdiction over that vendor’s product, or if a supplier’s software quietly reports home.
For most of the last three decades, that kind of risk was real but easy to discount. It rarely showed up, and when it did, nobody had budgeted for it. That’s changing. Regulatory bans, state-linked breaches, and undisclosed hardware features aren’t rare anymore. A cost structure built on a single low-diversity supply chain is exposed to more than a tariff bill now. It’s exposed to a vendor disappearing overnight, a security incident with real liability, or a customer who finds out where their data actually goes.
What Actually Insulates a Business
None of this argues for reshoring everything or refusing to do business overseas. It argues for pricing risk the same way a good cost model already prices tariffs and freight. A few places to start:
- Build a real landed-cost model. Include a risk premium for single-source or foreign-controlled dependencies, not just unit price and duty.
- Know what you couldn’t quickly replace. Treat that list of vendors and components as a risk register, not a footnote.
- Price the alternative deliberately. Where a component touches critical infrastructure, data, or safety, price a domestic or diversified option even at a premium, and choose on purpose instead of by default.
- Revisit vendor risk on a schedule. A supplier’s regulatory status can change faster than most purchasing cycles do.
A Few Questions Worth Asking
Three questions tend to surface the real exposure. Which vendors would you have to replace on 90 days’ notice if regulators acted tomorrow, and do you actually know? Does anything you sell depend on software, firmware, or connectivity you don’t control? If a key supplier disappeared next quarter, would your margin plan survive, or does it quietly assume that supplier is permanent?
Sourcing decisions made for cost reasons years ago are now showing up as risk decisions nobody remembers making. That’s not a failure of judgment. It’s a gap in how most businesses have priced supply chains for the last three decades. Closing it looks less like a security audit and more like the kind of financial leadership that takes risk as seriously as it takes margin.
Robert Idzi, CMA, CSCA
