Engineering Insights

What the Sierra Wireless Ransomware Attack Taught Me About Choosing Technology Vendors

I've worked in quality control for about eight years, doing the same job in a few different settings: incoming inspection, vendor audits, final acceptance testing. At my current company, I review every cellular module and gateway before it reaches a customer—roughly 240 unique line items a year. In Q1 2024 alone, I rejected 6% of first deliveries for spec deviations. That's the lens I see the world through.

So when I talk about choosing a technology vendor, I'm not coming at it from marketing or sales. I'm coming from the side that has to say "no" before something ships. Which might be why the Sierra Wireless ransomware attack in 2021 changed how I think about vendor evaluation more than any product failure I've seen.

The Surface Problem: Spreadsheet Confidence

In early 2024, our engineering team picked a wireless module for a new product line the way most teams do: they built a spreadsheet with roughly thirty criteria. LTE bands, certifications, carrier approvals, power draw, temperature range, physical size. Clean columns. Weighted scores. It looked like a mature decision process.

Nobody sets out to let a spreadsheet make the decision for them. But that's what happens when the project is behind schedule and the commercial team wants an answer by Friday. The spreadsheet becomes the justification for the easiest choice—the vendor we already know, the module we've already used. It's comfortable. It works. It also misses the important question.

Somewhere in that process, I asked a question nobody on the team had an answer for: what's our plan if this vendor stops shipping? Not because the product fails, but because the company fails? I got blank looks. That's a normal reaction—most of us don't think of the vendor as a moving part in the design. But they are.

I'm not a cybersecurity specialist, so I can't speak to the technical details of how ransomware works or which safeguards would have stopped the 2021 attack. What I can speak to is what happened to the supply chain after the news came out. That's where the real lesson sits.

The Deeper Issue: You're Buying a Company's Future, Not a Component

For context, a quick overview of Sierra Wireless for anyone who hasn't tracked the industry: it's a Canadian communications brand—now part of Semtech—that has been building cellular modules, routers, and gateways for over two decades. Their products sit inside industrial gear, fleet telematics, and public safety networks. A good example is the AirLink VSRX, a vehicle-mounted router designed to keep first responders connected. We've tested it for deployment, and the hardware is solid.

Now here's what I want to say plainly: when you compare two cellular modules, you're comparing hardware capabilities. But when you choose a supplier, you're choosing an organization's future. That future includes its security practices, its incident response, its communication style under pressure. None of that shows up on a datasheet.

A multimeter measures voltage, resistance, continuity. Real values, honestly captured. You can trust it. But a datasheet is like a multimeter that only works in perfect lab conditions—it doesn't tell you what happens when the circuit is hit with a surge. The ransomware event was a surge. It showed us exactly what spec sheets don't show.

Before 2021, I don't think many buyers asked "what's your incident response plan?" during a supplier evaluation. I know I didn't. After a major supplier gets hit publicly, that question moves from nice-to-have to essential. (Note to self: never let the spreadsheet decide alone.)

The Cost: When Their Emergency Becomes Yours

In late March 2021, Sierra Wireless disclosed that it had been hit by ransomware. According to its public statements, the attack forced the company to shut down systems, and production at some facilities was suspended to contain it. Products stopped shipping for a period. Customer deliveries were delayed.

From the outside, that looks like one company's bad news. From inside the supply chain, it ripples. At the time, we weren't a direct buyer for the affected product lines, but we watched the fallout with partners and integrators who were. Everyone felt the ripple: delayed schedules, shifted priorities, unanswered emails.

The costs aren't dramatic, but they're real. Three things happened to companies waiting on modules:

  • First, orders stuck in the pipeline stop moving. Lead times stretch from two weeks to "we'll let you know."
  • Second, the re-engineering cost starts. When a vendor is unstable, you begin qualifying alternatives. That means test bench time, re-certifications, additional inventory buffers.
  • Third—and this is the expensive one—confidence drops. After you watch a supplier work through a crisis, even normal lead times feel fragile. You start planning for failures you used to ignore.

In the forums and working groups I follow, the question wasn't whether Sierra Wireless would make it. It was: how long will this last, and what do we do in the meantime? Honestly, the company's communication during that period was better than most. They put out updates. They didn't go silent. That consistency matters when you're trying to make plans of your own.

The Small-Customer Test

Here's where I should disclose my bias. We're not one of those customers that gets a dedicated account team. Our order quantities are modest, and I've had vendors who didn't bother calling back. I've learned to read that as a signal.

A supplier that treats a small order with the same seriousness as a large one understands that revenue isn't the only measure of a relationship. Small doesn't mean unimportant—it means potential. In my experience, the vendors who took our small orders seriously when we were starting out are the ones we still work with now that the orders are bigger.

The ransomware event reinforced that for me. Even during a genuinely hard year, Sierra Wireless kept talking to its customers—including smaller ones. That's not a small thing. It's exactly the thing I look for now.

I'll say it plainly: if you're a small company making technology decisions, don't let anyone convince you that your requirements deserve less rigor because your order is smaller. The module you buy has to work the same way whether you buy ten or ten thousand. The real question is whether the vendor treats it that way.

What We Changed in Our Evaluation Process

The attack didn't change our product choices. We still specify Sierra Wireless modules, and we're still testing the AirLink VSRX for vehicle deployments. What it changed is how we qualify any vendor, including them.

Three things changed in our process:

First, we evaluate the actual hardware before we believe anything. Not just the datasheet. We put a sample on the bench, run it through our own acceptance tests, load our own firmware. If it passes, we trust the part. If it fails, no spreadsheet score can save it.

Second, we ask about security maturity. I'm not asking for anyone's incident response plan—that's sensitive material. I'm asking whether they've tested one. Whether they carry cyber insurance. What lessons from a past event changed how they operate now. A vendor who can answer those questions concretely is a vendor who has thought about them.

Third, we build in redundancy. For every critical component, we pre-qualify a second source. We don't split orders during normal times; we just keep the option open. When a disruption hits, that option turns a crisis into a cost analysis.

None of this is glamorous. It's the unglamorous work that quality is: checking, rechecking, asking uncomfortable questions, keeping honest notes. But it's the thing that keeps production lines moving when other lines have stopped.

The Bottom Line

Buying wireless technology is ultimately a bet on an organization's future—its security, its resilience, its willingness to tell you the truth when things are going badly. Spec sheets measure capabilities. They don't measure that.

The multimeter analogy still fits: the values you can measure are important. But the behaviors you can't easily measure—honesty, consistency, follow-through—often turn out to be what saves you in the end.

As of early 2025, the IoT technology landscape is still moving quickly. Carrier certifications change, module families expand, new products appear. Verify current specifications before you design anything in. The principles for choosing a vendor, though? Those haven't changed since 2021. I don't expect them to.

Leave a Comment

Your email address will not be published. Required fields are marked