This was known to be compromised, though. People using it anyway weren't being fooled because they couldn't audit the code. They were forced by federal standards or they'd lose the ability to sell to the government and go out of business.
Your best bet is multiple layers of defense. It may sound ridiculous, but don't use just one VPN/firewall. Make your adversaries compromise multiple vendors. Encrypt several times. That's what the actual DoD does and why the NSA probably doesn't even care. And, of course, the really important information is classified and never hits a publicly reachable network at all, so compromising the supply chain doesn't even help. As a private organization, you probably don't have the option to build an entirely separate network that doesn't touch the Internet and then protect the ingress/egress nodes with your own private military, so I don't know what to tell you there.