The supplier and the customer: a manufacturer's guide to ransomware and third-party risk · Global Digital
Global Digital
Let's talk
Whitepaper · September 2026

The supplier and the customer: a manufacturer's guide to ransomware and third-party risk

Manufacturers are the most-targeted mid-market sector for ransomware, and every one of them is a supplier to someone. This guide treats those two facts as a single problem and lays out a 90-day plan that does not begin with a purchase.

12-minute read·For owners, CFOs and operations leaders of mid-market manufacturers·Download the PDF
Executive summary

Manufacturing accounts for more mid-market ransomware victims than the next two sectors combined. Between January 2023 and June 2026, manufacturers made up 2,521 of the 9,781 disclosed mid-market incidents that Black Kite catalogued in North America and Europe, and the sector's share rose from 20.7 percent in 2023 to a peak of 28 percent in 2025.1

The reasons are structural rather than technical. Manufacturers run long, opaque supplier chains, tolerate very little downtime, and increasingly serve customers who audit them. A mid-market manufacturer is therefore exposed in two directions at once: through the suppliers it depends on, and through the customers who depend on it. Most companies manage those directions with separate people, separate budgets, and separate spreadsheets, if they manage them at all.

This paper argues for treating them as one problem, owned by one person, with one short list of controls. It closes with a 90-day plan, a board reporting format, and an honest statement of what can wait.

2,521
of 9,781 disclosed mid-market incidents were manufacturers
28%
peak sector share in 2025, up from 20.7% in 2023
22 sec
median handoff from vendor access to ransomware operator

Source: Black Kite, 2023 – H1 2026 · refs 1, 3

Why manufacturers, specifically

Three characteristics make manufacturing the preferred target.

Low tolerance for outage. A distributor can reroute. A professional-services firm can work from laptops. A plant that cannot see its production schedule, ship orders, or invoice cannot substitute. Attackers price their demands against that pressure.

Long, layered supply chains. The typical manufacturer buys from hundreds of suppliers and sells to a smaller number of customers who are themselves larger and better defended. Every one of those relationships is a network connection, an EDI feed, a shared portal, or a remote-access agreement. Black Kite describes a typical vendor-risk team as two people responsible for more than 300 suppliers, with some software and services sitting outside any formal inventory.2

Operational technology that cannot be patched on a Tuesday. Production systems run on schedules set by output, not by vendor release notes. Where the boundary between the office network and the plant floor is soft, an email compromise becomes a production incident.

None of this is news to plant leadership. What is new is the speed. A related Black Kite study found that once an attacker gains initial access to a vendor environment, the handoff to a ransomware operator takes a median of 22 seconds, down from eight hours in 2022.3 The window between a supplier's compromise and your own has effectively closed.

The two directions

As a customer of your suppliers. The question is not are our suppliers secure but which suppliers can stop us, and how would we know they were compromised. Most manufacturers can name their top ten suppliers by spend. Far fewer can name the ones whose failure stops shipping within a week, and those lists overlap less than people expect. The logistics provider, the label printer, the managed-service provider with remote access to every workstation, and the small software vendor whose module runs the shop floor are rarely top-ten by spend.

As a supplier to your customers. Larger customers now send security questionnaires as a condition of doing business, and the trend is regulatory as well as commercial. Rules such as the EU's NIS2 Directive and, in the United States, requirements including NYCRR 500 and HIPAA can oblige covered organizations to address risk in their supply chains.2 When your customer is covered, the obligation flows down to you whether or not you are.

The commercial consequence is rarely immediate. A weak questionnaire answer does not lose the account this quarter. It loses the account at renewal, to a competitor who answered well, and the reason is never stated.

The questionnaire your largest customer sends is the questionnaire you should send upstream.

Seen this way, the two directions are the same work. The controls that make you a defensible supplier are the controls you should require of your own suppliers.

The exposure that matters

The volume of published vulnerabilities is not a useful measure of risk. More than 48,000 CVEs — Common Vulnerabilities and Exposures, the catalog numbers assigned to publicly disclosed software flaws — were published in 2025; roughly 800, about 1.6 percent, were ever exploited in the wild.1 Black Kite's supply-chain analysis narrows that further to a much smaller set that is both discoverable from the outside and carries a high probability of exploitation.3

01

Known exploited vulnerabilities

The useful list is short, and it is public. The CISA Known Exploited Vulnerabilities catalog is maintained for exactly this purpose.4 Nearly 30 percent of the mid-market organizations Black Kite scanned had at least one known exploited vulnerability exposed to the internet.5 That single finding explains a large share of the incidents in the dataset.

02

Email authentication

DMARC was missing or insufficiently configured at 46.8 percent of companies scanned, and DKIM at 24.2 percent.1 These are configuration settings, not products. A manufacturer whose domain can be spoofed is a manufacturer whose suppliers can be tricked into wiring money to the wrong account, and whose customers will receive convincing fraud in its name.

03

Remote access

Managed-service providers are high-value targets precisely because their tools reach every client at once; the pattern of one compromised remote-management platform cascading into dozens of downstream businesses has repeated across several tools and years.6 If a third party can reach your environment, the question of how that access is authenticated, logged, and revoked is not a technical detail. It is the front door.

04

Unsupported software

A platform past its vendor's end of support will not receive fixes for the next entry on the exploited list. Underwriters ask about this. Customers' questionnaires ask about this. The EOL Radar tracks the dates for the business systems mid-market manufacturers most commonly run.

Adversaries churn; the list does not

Of the 60 ransomware operators active against the mid-market in 2023, only 17 remained active by the first half of 2026, and roughly one in three groups active in any six-month period had never been seen before.1 A defense built around named adversaries will need rebuilding every year. A defense built around the four exposures above will not, because every operator in the dataset used some combination of them.

A 90-day plan

The plan below assumes no new tooling and no new headcount. It assumes one accountable owner, usually the controller or the operations leader rather than IT, because the decisions are commercial.

Days 1 to 30
Know what you have
  • Inventory every internet-facing system and check it against the CISA catalog. Fix anything on the list. Defer anything that is not.
  • Confirm DMARC and DKIM are enforced, not merely published. If nobody can answer in a sentence, they are not.
  • List every third party with remote access to your network, including the managed-service provider, the ERP partner, and the equipment vendors with maintenance portals. For each, record how access is authenticated and who can turn it off.
  • Name the suppliers whose outage stops production or shipping within a week. Rank by time-to-impact, not by spend.
Days 31 to 60
Close the two directions
  • Obtain your largest customer's security questionnaire, or the standard one their industry uses, and answer it internally before they ask. Every honest no is a roadmap item.
  • Send a five-question version of that questionnaire to the suppliers you named in the first thirty days. Ask about known exploited vulnerabilities, email authentication, multi-factor authentication on remote access, backup testing, and end-of-support software. Do not ask fifty questions; they will not answer, and you will not read the answers.
  • Confirm that backups of the ERP, the MES, and the file shares are tested by restoration, not by the existence of a job log, and that at least one copy is offline or immutable.
  • Document the manual runbook: how orders are taken, scheduled, shipped, and invoiced for ten days without the ERP. If that document cannot be written, the recovery time objective is a guess.
Days 61 to 90
Make it durable
  • Assign the supplier list and the customer questionnaire to one owner with a quarterly refresh.
  • Put a decision date on any unsupported platform. The date is not the vendor's end of support; it is the end of support minus a realistic selection and implementation runway.
  • Brief the board using the one-page format below.
  • Run the Business Resiliency Scorecard to benchmark the result against NIST CSF 2.07 and identify the next weakest function.

What the board should see

A board does not need a threat briefing. It needs five lines, updated quarterly:

Measure
Target
Internet-facing systems with a known exploited vulnerability
zero
Email authentication status
enforced / not enforced
Third parties with remote access, and how many use multi-factor authentication
all
Date of last successful restoration test for the ERP
date
Business-critical platforms past end of support, and the decision date for each
count · dates

Five numbers, one page, no adjectives. When a customer's procurement team or an insurance underwriter asks, the same page answers them.

The insurance connection

The controls above are the ones cyber underwriters weight most heavily, and the ones most likely to appear as conditions or exclusions at renewal. A manufacturer that can show enforced email authentication, no exposed known exploited vulnerabilities, tested backups, and a dated plan for unsupported software is negotiating from a different position than one that cannot. Most commercial cyber policies renew on a calendar-year cycle, and underwriters typically begin their review 60 to 90 days ahead of the renewal date.8 A gap fixed in September is a gap the underwriter never sees. The same gap found in a December renewal review is a condition, an exclusion, or a higher premium, negotiated from a weaker position with less time to respond.

The honest case for doing less

We would resist any proposal that begins with a platform purchase and ends with a dashboard. The companies in this dataset were not defeated by sophisticated, novel attacks. They fell to a known vulnerability, a spoofable domain, an unwatched supplier, or a remote-access tool with a shared password. Fixing those does not require a vendor. It requires an owner.

There are things that can wait. A formal third-party risk management program with tiering, scoring, and continuous monitoring is worth building at $200 million in revenue and usually premature at $40 million. A security operations center, in-house or outsourced, is a reasonable investment once the basics are in place and a poor one before. Segmenting the plant floor from the office network is valuable and often disruptive; it belongs in a planned window, not in a panic.

What cannot wait is the first thirty days. The arithmetic is simple: at $40 million in revenue, ten days of disrupted shipping is roughly $1.1 million of revenue deferred or lost before any recovery cost is counted. The first thirty days of the plan above cost a few weeks of one person's attention.

How we help

Our team has led technology and security functions inside manufacturers and distributors, and we have sat on the customer side of the questionnaire. We resell nothing, so the answer to what should we buy is often nothing yet. If your team wants a second opinion on the plan, the supplier list, or a customer's audit, start a conversation.

Sources
  1. Mid-Market Ransomware Report 2026, Black Kite.
  2. Ransomware attackers are zeroing in on mid-market companies, Help Net Security, August 24, 2026.
  3. 2026 Supply Chain Vulnerability Report, Black Kite.
  4. Known Exploited Vulnerabilities Catalog, CISA.
  5. Ransomware disproportionately targets medium-sized firms, straining customer relationships, Cybersecurity Dive, August 19, 2026.
  6. Six Supply Chain Attack Groups to Watch Out for in 2026, Group-IB, July 2026.
  7. Cybersecurity Framework, NIST.
  8. What Insurance Carriers See When Evaluating Cyber Risk, Winter-Dent & Company, July 2026.
Benchmark the result

See where the next weakest function is.

The Business Resiliency Scorecard benchmarks your continuity readiness against NIST CSF 2.0 in ten minutes — free, no signup.

No SDR layer. We sell expertise, not products.