The internet is a supply chain. A supply chain is any system in which components produced or controlled by one party become inputs to another, creating a chain of dependencies through which value, function, and risk all travel together. By that definition the internet is not merely served by supply chains. It is one: the largest, the most consequential, and the least examined ever built.
That is not a figure of speech, and everything here follows from taking it at face value. A supply chain has to be understood before it can be protected, which means knowing what the components are, where they come from, who controls them, and which of them actually matter.
The Comparison

Two chains, one inspected

A traditional supply chain of four stages with an inspection gate at each of its three handoffs, marked documented, certified and retained; below it a digital supply chain of four equivalent stages with the same three handoff positions drawn as empty dashed outlines, nothing required at any of them.
The Premise

Dependency creates leverage

Every point at which one component depends on another is a point at which the integrity of everything downstream rests on the integrity of that input. A compromised input does not announce itself. It travels forward, incorporated into outputs that carry no visible sign of the change at their source.
A page is an assembly
A page loaded in a browser is not one artifact from one source. It is an assembly of components sourced from dozens of providers, delivered across infrastructure operated by parties the user has never heard of. Every one of those components was assembled from components of its own.
Trust is cheaper than verification
Supply chains are built for efficiency, not for continuous checking of every input against an authoritative reference. Verification at scale is expensive and trust is free, which is why trust is extended by default. That default is the condition every supply chain compromise relies on.
The chain has no natural edge
Each dependency carries its own, backward through code, services, infrastructure, firmware, and hardware to origins no single organization has mapped. The chain runs to the nth party rather than the third, and there is no tier at which it becomes safe to stop looking. There is only the tier at which the looking stopped.
Nobody designed it this way
This is what results from building a system of this scale through thousands of organizations over half a century, with no central architect, no authority with enforcement power over the whole, and no requirement that any participant document its dependencies in a form anyone else can read.
The Gap

The most important supply chain is the least protected

Consider what is demanded of the supply chains the world treats as critical. A pharmaceutical manufacturer documents the provenance, composition, and testing history of every ingredient it sells. An aircraft manufacturer traces the certification history of every component it installs and holds those records for the life of the airframe. A food producer must show where an ingredient was grown, processed, and transported, and must produce that record within hours of a contamination event. Regulators audit the records, inspect the facilities, and impose consequences when the documentation does not hold up.
Now consider what is demanded of the organizations building on the digital supply chain. A team integrating a third-party script is generally not required to document where it came from, who wrote it, or what it carries with it. A company adding a content delivery integration is not required to demonstrate that what that provider delivers has been verified against anything. An operator putting a browser-based interface in front of a control system is not required to map what that interface loads before connecting it. For most organizations, in most jurisdictions, across most of this supply chain, there is no obligation to document, audit, verify, or monitor what is being integrated and executed.
This is not carelessness on anyone's part. The frameworks that would make systematic protection possible were written for components, and this is a problem of assemblies. Sophisticated tools exist for protecting individual parts. Very little exists for seeing the chain as a whole.
Direction of Travel

The gap is widening

More of what matters now runs on this chain than did five years ago. The chain itself is longer. And the money to examine it follows incidents that have already happened rather than exposure that has not yet produced one.
More systems depend on it
Power, water, transport, and manufacturing platforms have moved to web-based interfaces and cloud-connected architectures. Government, healthcare, and financial systems have followed. Each migration brings a domain that was insulated from this supply chain into direct contact with it, usually without a matching investment in understanding the new exposure.
Complexity outpaces comprehension
Dependency trees, third-party integrations, and the number of distinct providers whose code executes on any given page have all grown sharply. Each addition is a new trust decision, made once at integration and rarely revisited as the dependency evolves, changes hands, or becomes interesting to somebody for reasons that have nothing to do with you.
Investment follows what is visible
Security spending is calibrated to the incidents that have already happened and the requirements that carry enforcement consequences. Exposure that has not yet produced a public, attributed failure does not compete well for budget, so the attack surface grows on one curve and the attention on another.
Physical supply chains are inspectable. This one is not.
Components in a physical chain are tangible, and their provenance can be checked at each handoff, at least in principle. The digital supply chain operates at a speed and scale that makes handoff inspection impossible: hundreds of billions of requests are made every day, and each one is a supply chain transaction: a request for a component, a response delivering it, and the execution of whatever arrived. No workforce could review a meaningful fraction of them, and almost nothing observes them for integrity at scale. They pass through the chain trusted by default and recorded by no one. That is the condition this section is about, and the reason the work starts with observation rather than paperwork.
01 · Structure

The layers

The digital supply chain is not one chain. It is eight layers operating at once: networks and infrastructure, software and firmware, hardware and devices, services and development kits, code and libraries, data and models, resources and files, and the interface where all of them converge into what a person actually sees.
The write-up covers what each layer contributes, what evidence exists for it, and why the exposure is not the sum of the vulnerabilities in each layer but the set of pathways between them.
02 · Control

When control changes hands

A component can change owner without changing a line of code. The domain resolves the same way, the script has the same hash, and the traffic is identical because it is identical. What changed is who decides what that component does next, and none of that is visible in a capture.
The write-up covers the four ways control actually moves, the interval between a transfer and anyone noticing it, six documented cases with the dates, and why the monitoring that would have caught them sits in registries, filings and repository records rather than on the network.
03 · Coverage

The existing tools stop short of ownership

Bills of materials, build attestations, exploitability statements, control reports, browser policies, posture scores, attack surface discovery, and beneficial ownership screening. Nine categories, what each one establishes, and the precise point at which each stops.
The write-up states plainly what this method adds: the step between where external discovery ends and where ownership resolution begins. It also defines the four terms the work depends on, and explains why an undisclosed provider is usually not a concealed one.
04 · Method

Digital Supply Chain Mapping

Capture, resolution, attribution, and reconciliation, applied to every provider the evidence surfaces and repeated against the tiers beneath them. A vendor list records decisions; an application records behavior, and the two drift apart from the day the contract is signed.
The write-up covers the full cycle, the observation and attribution axes it runs along, how a host is resolved to a company and what happens when it cannot be, and what the work product contains.

The other half of the question is who owns them

Mapping the chain establishes what you depend on. Resolving who owns and controls those providers is what decides whether a dependency is a sourcing problem or a material risk to the business. That is Equity Chain Mapping, run against the parties this work surfaces.