The Financial Times reported on September 6, 2026 that Huawei's long-running U.S. criminal case is poised for trial in Brooklyn. The case centers on allegations from U.S. prosecutors that Huawei and related entities engaged in racketeering, trade-secret theft, sanctions-related deception, and misleading conduct involving banking relationships. Huawei denies the charges and has argued that the prosecution is politically motivated.
That legal question belongs in court. The business lesson is narrower and more practical: technology vendor trust cannot rest on a familiar logo, a persuasive proposal, or a reseller's confidence. When a product touches communications, networking, cloud services, surveillance, payments, regulated data, or customer records, owners need a procurement risk review that goes beyond the quote.
Vendor Risk Is Not Just a Security Problem
Many smaller organizations treat vendor due diligence as something only banks, hospitals, or large companies do. That view is outdated. A New Jersey business may rely on a managed service provider, a cloud platform, a phone system, a firewall, a camera vendor, a payroll app, a backup service, and several software subscriptions before lunch. Each vendor can affect uptime, privacy, compliance, billing, support, and the company's ability to change providers later.
The Huawei trial is unusually large and politically sensitive, but the underlying decision pattern is familiar. A business is asked to approve technology based on capability, cost, urgency, or availability. The harder questions arrive later: who built it, who supports it, where the data goes, what contractual promises exist, what happens if the vendor becomes restricted, and how difficult replacement would be.
The Owner Decision Behind the Headline
The practical decision is not whether a small business should have an opinion on a federal criminal case. It is whether leadership requires written answers before approving sensitive technology vendors. That matters because supply chain technology risk often appears after the system is already installed, integrated, and operationally hard to unwind.
For networking and communications gear, the risk may be support availability, firmware provenance, remote access, monitoring, or replacement cost. For cloud and SaaS vendors, it may be data residency, subcontractors, account recovery, API access, export controls, or termination rights. For an MSP-managed environment, it may be whether the provider has documented why a vendor was selected and what alternatives were considered.
None of this requires panic. It requires evidence. A vendor trust conversation that produces only verbal assurances is thin. A vendor trust conversation that produces documentation, ownership, contract terms, and an exit plan gives the business something it can manage.
Questions to Ask Before the Purchase Order
- What role will this vendor play? Identify whether the product touches core operations, regulated data, remote access, network traffic, customer records, or financial workflows.
- Who has remote or administrative access? Ask whether the vendor, reseller, MSP, or subcontractor can access the system and how that access is logged, approved, and removed.
- Where are data and support operations located? Get a written answer about data storage, support teams, subcontractors, and any cross-border handling that matters for contracts or compliance.
- What happens if the vendor becomes unavailable or restricted? Ask for a substitution plan, export-control impact review, support continuity plan, and replacement estimate before the system becomes critical.
- What proof supports the recommendation? Request security documentation, certifications where relevant, patch history, end-of-life dates, references, and a written reason this vendor fits the business need.
- Who owns the decision after installation? Make sure someone inside the company owns renewals, contract changes, access reviews, and vendor performance checks.
A Practical Next Step
Before approving the next sensitive technology purchase or renewal, ask your IT provider or internal team for a one-page vendor due-diligence summary. It does not need to be a legal brief. It should explain the business purpose, the data or systems involved, the access model, the main vendor risks, the alternatives considered, and the exit path if the vendor no longer fits.
That kind of written summary changes the conversation. It moves the decision from "this looks like a good deal" to "this is the risk we are accepting, and here is why." For owners, office managers, healthcare practices, schools, nonprofits, and professional services firms, that is the difference between buying technology and governing it.
The Huawei case may be decided in a federal courtroom, but the procurement lesson belongs in every conference room where technology gets approved. Vendor trust deserves more than a handshake and a spec sheet.
Sources and further reading
- Was Huawei's rise built on crime? A Brooklyn jury will decide
- Chinese Telecommunications Conglomerate Huawei and Subsidiaries Charged in Racketeering Conspiracy and Conspiracy to Steal Trade Secrets
- Chinese Telecommunications Conglomerate Huawei and Huawei CFO Wanzhou Meng Charged With Financial Fraud
- Two Chinese Intelligence Officers Charged with Obstruction of Justice in Scheme to Bribe U.S. Government Employee and Steal Documents Related to the Federal Prosecution of a PRC-Ba