The risk is not theoretical: four cases where technological dependence became a crisis
Kaspersky in the US and Lithuania, Huawei in the UK, TikTok in the US. Four cases where depending on foreign technology stopped being hypothetical and became a geopolitical decision.
Dependence has already come due
The risk of depending on foreign technology is usually treated as a distant hypothesis. It is not. In recent years, several countries have watched widely used security and infrastructure products become unavailable, banned, or forced to change owners, by political decision. Four cases show what is at stake.
Kaspersky: from market standard to banned product
Kaspersky was one of the most widely used antivirus products in the world. In 2017, the United States barred its products from federal networks, citing the risk of Russian government access. In 2024, the Commerce Department went further and banned the sale of the software in the country; updates for US customers were cut off months later. A security product that millions relied on simply stopped being available.
Lithuania had reached the same conclusion earlier: in 2017 it labeled the software a threat and ordered its removal from computers managing critical infrastructure. The company denied the accusations. The point is not guilt: it is that the continuity of a defensive tool came to depend on a geopolitical decision, not on the contract.
Huawei: 5G dismantled in the United Kingdom
In 2020, the United Kingdom reversed course and banned Huawei 5G equipment. Operators were barred from buying new gear from the end of that year and required to remove all installed Huawei 5G equipment by 2027. The decision followed a reassessment by the British cyber security authority, driven in part by sanctions affecting the company's chip supply chain.
The result is the concrete cost of dependence: ripping out and replacing critical infrastructure already in operation, with delay and a billion-pound bill. When the vendor of an essential component leaves the equation, the migration cost is yours.
TikTok: data, jurisdiction and a few hours of blackout
The TikTok case shifted the discussion from attack to data jurisdiction. Concerned about ByteDance's control and where American data was processed, the US Congress passed a law in 2024 requiring the sale of the US operation or a ban. The Supreme Court upheld the law in early 2025, and the app briefly went dark for US users for a few hours before being restored.
With no vulnerability exploited at all, a service used by tens of millions stopped, because jurisdiction over the data and control of the company sat outside the country.
The pattern behind the cases
Different sectors and technologies, but the same mechanism:
- Availability is not guaranteed: an essential product can be cut off by a government's decision, not the vendor's.
- Jurisdiction matters: where data is processed and who controls the company decide who governs your risk.
- Geopolitics overrides the contract: no SLA protects against a sanction, a law or a diplomatic crisis.
- Replacement is expensive: ripping out and swapping infrastructure in production costs time and money no one budgeted.
- Someone else decides: in every case, whoever set the fate of the technology was not the one depending on it.
What this teaches Brazil
None of these countries acted out of rejection of foreign technology. They acted because they could not accept a critical capability sitting outside their control. The United States, the United Kingdom and Lithuania had the resources and alternatives to react. The uncomfortable question is: would Brazil, which imports most of the technology that sustains its cyber defense, react in time?
The risk is not a vendor's malice. It is depending on a decision you do not control.
The lesson is not to ban anyone. It is to know, clearly, which dependencies are acceptable and which represent strategic risk, and to build national capability before you need it. Because, as these four cases show, when the bill arrives, it arrives fast.


