Wednesday, July 22, 2026 / News, Supply Chain Your Weakest Link Is a System You Don't Own A distributor's controller approves a routine software update from the ERP vendor. It is the same vendor that has held remote access for years to clear support tickets and help close the month. Nothing looks wrong. Three weeks later every branch's order entry locks up, and the ransom note names the vendor's own support tool as the way in. Nobody at the distributor clicked anything. The door was already open, and it had a trusted name on it. Some of the worst cyber incidents at distributors do not come through the front door at all. They come through the connections the business built on purpose. The EDI link to a top manufacturer. The remote-support account the ERP provider uses. The punchout tie into a customer's procurement system. The nightly data feed from a content or PIM provider. Every one of those was set up to make the company faster. Everyone is also a way in. The pattern is measurable. In Verizon's 2025 Data Breach Investigations Report, the share of breaches that involved a third party doubled in a single year, to 30 percent, and stolen credentials and unpatched software were the two most common ways in. PHCP/PVF distribution runs on connection. A mid-size distributor might have live EDI with a dozen manufacturers, a hosted or vendor-managed ERP, an eCommerce platform, a rebate portal from a buying group, a tax engine, a freight system, and a couple of feeds keeping product records current. Ask the IT lead to name every system with a standing connection into the ERP, and most cannot finish the list from memory. For fifteen years, the whole channel got the same advice: integrate. Connect to your suppliers. Automate the PO, the ASN, the invoice. Sync your product data instead of rekeying it off a spreadsheet. Turn on punchout so your largest customers can buy without calling the counter. That was the right advice, and the distributors who took it are faster and harder to leave. The same connections are the attack surface. The efficiency and the exposure are the same wire. It does not take a breach of your own systems. A rep agency's email gets taken over, and the attacker uses it to send corrected remit-to instructions to every distributor the agency serves, from an address those distributors have trusted for years. Or a content provider that pushes product data to dozens of distributors gets compromised, and the feed itself becomes the delivery method. You did nothing wrong. Someone you connected to did. The FBI's Internet Crime Complaint Center counted $2.77 billion in reported business email compromise losses in 2024, most of it money that moved on instructions that looked legitimate. Distributors are exposed here because the connections are old, useful, and nobody's job to review. The EDI map to a manufacturer was set up years ago by someone who has since retired. The ERP vendor's remote access is how support has always worked and shutting it off means slower fixes when a branch is down. The punchout credential for a big house account has not rotated since the customer went live. None of these are oversights exactly. They are the residue of a business that kept integrating and never went back to prune. Firewalls, multifactor login, and password discipline still matter. They are table stakes, and a distributor without them is exposed for simpler reasons. But you can do all of that well and still get hit, because the part most distributors never account for is the integration list: every standing connection into your systems, and whether the company on the other end is as careful as you are. A distributor with tight internal security and one sloppy vendor is one compromised vendor away from a bad month. Few distributors have ever asked a trading partner what their security actually looks like. This is where the shape of the channel works against everyone. No single company owns the risk, because the risk lives in the space between companies. The manufacturer assumes the distributor has it handled. The distributor assumes the ERP vendor has it handled. The ERP vendor is secured for itself, not for what happens downstream when its access is misused. Everyone is covered on their own page. The gap is in the seams. This is not just anecdote. In ASA's April 2026 member survey, cybersecurity and data privacy were the two most-cited concerns about adopting new AI tools, ranked ahead of cost, staffing, and integration headaches. Members are wiring in tools and connections faster than ever, and they already sense the exposure. The incidents rarely start inside the building. They start with a trusted connection: a partner's mailbox, a vendor's access, a feed everyone had stopped thinking about. The distributors who come through them in decent shape share one habit. They know what is connected to them, and they treat a partner's security as their own problem, not the partner's. For fifteen years distributors connected everything they could and treated security as each company's private business. Those two instincts are now in direct conflict, and the bill comes due one trusted partner at a time. The distributors who see that are already changing what they expect from the vendors and partners they connect to. They ask the question the channel has mostly avoided: prove you are not my weakest link. The rest are one bad week away from learning which connection it was, and by then the money has already moved or the branch is already dark. The incident scenes in this article are illustrative composites reflecting patterns common across PHCP/PVF distribution, not specific companies. Figures are drawn from the sources below. Sources: Verizon, 2025 Data Breach Investigations Report (third-party involvement in breaches doubled to 30 percent). FBI Internet Crime Complaint Center, 2024 Internet Crime Report ($2.77 billion in reported business email compromise losses). ASA Applied AI Task Group Member Survey, April 2026 (data privacy and cybersecurity ranked as members' top two concerns about adopting AI). By Nils Swenson Print