Manufacturers and distributors have become ransomware's favorite targets, and the reason is uncomfortable: attackers know an idle plant bleeds measurable money every hour, which makes operations companies far more likely to pay than an office that can limp along on laptops. This article covers the defenses that actually matter for an operations-heavy business, in the order we implement them for our own clients.
Why Attackers Pick on Operations Companies
The common objection we hear is "we're too small and too boring to hack." The data says otherwise. Manufacturing has ranked among the most-attacked industries for several years running, and mid-size companies are the sweet spot: valuable enough to pay a six-figure ransom, small enough to lack a security team.
Three things make you attractive. Downtime pressure: when the ERP is encrypted, you cannot pick, ship, invoice, or run production, and every hour has a dollar figure attached. Aging systems: shop floors run machines controlled by PCs that cannot be patched without breaking vendor support. Thin IT: one or two people covering everything, with security as a side duty.
The Attack That Actually Happens
Forget movie hacking. The attack that takes down a distributor looks like this: an AP clerk opens an invoice attachment that is not an invoice, malware sits quietly for days mapping the network, then one weekend it encrypts the file server, the ERP database, and every backup it can reach. Monday morning, nothing works, and there is a note asking for payment in Bitcoin.
A close second, and rising fast in distribution: payment fraud. An email arrives that looks exactly like a known vendor announcing new bank details for remittance. AP updates the record, and the next three payments go to a criminal's account. No malware involved, just a convincing email and a missing verification step. If your AP team does not have a callback rule for bank-change requests today, that is a bigger hole than any firewall setting.
Multi-Factor Authentication, Everywhere That Matters
If you do one thing after reading this, turn on MFA. Microsoft's research puts the reduction in account-compromise risk at over 99%. Priority order for an operations company: email (especially anyone in AP or with admin rights), VPN and remote access, the ERP if it is reachable from outside, and banking. Use app-based authenticators rather than SMS where you can. The whole rollout is measured in days, not months, and it closes the door most attacks walk through.
Segment the Network: the Shop Floor Rule
Here is the manufacturing-specific problem: that CNC controller running Windows 7 cannot be patched without voiding vendor support, and replacing the machine is a capital project, not an IT ticket. The answer is not to pretend the machine is secure. It is to make sure the machine cannot reach anything that matters.
Network segmentation puts production equipment, business systems, and guest WiFi on separate networks with a firewall between them. The unpatched controller keeps running the machine, but a compromise there cannot spread to the ERP, and a phished laptop in the office cannot reach the production line. For most mid-size operations this is a few days of firewall work, and it is the single highest-value project on this list after MFA.
Patch What Can Be Patched
Unpatched software remains a top entry point. Keep Windows, browsers, and business applications current, and configure automatic updates for security patches with scheduled windows for the bigger ones. For the systems that genuinely cannot be updated, segmentation (above) is the compensating control. Write down which machines those are; your insurer will ask.
Backups That Assume Ransomware
Modern ransomware hunts backups first, because a company that can restore does not pay. That changes the requirements. Follow 3-2-1 (three copies, two media types, one offsite), make at least one copy immutable so it cannot be encrypted or deleted even with stolen admin credentials, and test restores monthly.
One distinction matters more for you than for most businesses: a backup of the ERP's files is not the same as a restorable ERP. Test the actual scenario. How long from a dead server to entering orders again? If the honest answer is "we are not sure," that is the finding. For companies running on-premise systems such as Sage, P21, or Dynamics, we have seen restore tests turn up backup jobs that had been silently failing for months.
Train the People Who Get the Emails
Human error opens the door in the overwhelming majority of incidents. Short monthly briefings beat annual marathons, real phishing examples from your own inbox beat stock ones, and quarterly simulated phishing keeps everyone honest. Give AP extra attention: invoice-themed phishing and vendor bank-change fraud are aimed squarely at them, and a two-minute callback rule (verify any payment change by phone, using the number you already have on file, never the one in the email) stops the fraud cold.
Have a Plan for the Bad Week
Write down, before you need it: who declares an incident and who they call (IT, legal, insurer, and the FBI's IC3 for fraud), how you communicate when email may be compromised, which systems get restored first, and how long you can run on paper. That last one is not rhetorical. Distributors that survived ransomware well had answered it in advance: they could take orders by phone and ship from printed pick lists for a few days while systems came back.
Check your cyber insurance policy against reality while you are at it. Underwriters now require MFA, tested backups, and endpoint protection as conditions of coverage. A claim can be denied over a control you attested to but never actually enabled.
Customer and Compliance Pressure Is Coming Either Way
Even if you never get attacked, security questionnaires are becoming part of doing business. Large customers increasingly require vendors to attest to controls before awarding contracts, defense-adjacent suppliers face CMMC requirements, and payment processing brings PCI DSS. Companies that build the basics now answer those questionnaires in an afternoon. Companies that have not lose deals over them.
Where to Start
Weeks one and two: MFA on email, VPN, and banking; change default passwords on network gear; verify backups are actually running. Month one: segment guest WiFi and shop floor from business systems, deploy a password manager, run the first short training. Months two and three: test an ERP restore end to end, write the incident plan, run a phishing simulation, and review your insurance requirements against what is actually enabled. None of this requires an enterprise budget. It requires deciding it is operations work, not an IT afterthought.
Uptimize Solutions runs security assessments for manufacturers and distributors: we check the controls above against your actual environment, including the ERP and the shop floor, and hand you a prioritized fix list. See our IT support services, grab the free IT Security Checklist, or schedule a security consultation.
