Insights Article: Cybersecurity for B2B Industry – Identity Security

For Business Owners, Executives, CIOs & CISOs [6-minute read]
Your Commerce Platform May Be Secure. But Are the Identities Behind It?
Cybersecurity is business-critical for every B2B company, regardless of size, product or location.
What was once largely a relationship-driven business managed through salespeople, phone calls, purchase orders and warehouses has become increasingly digital. Customers can search products, access pricing, request quotes, place orders and manage accounts online. Employees can work remotely, suppliers and service providers can connect to company systems, and applications routinely exchange information without any human involvement.
For distributors and manufacturers, these capabilities improve customer service and make the business more efficient. They also introduce a growing number of digital identities that need to be managed and protected.
Every customer and employee account represents an identity, as does every administrator, contractor and technology vendor with access to company systems. Applications, databases, APIs and automated processes may have credentials of their own.
The access attached to those identities varies considerably. A customer account may have a narrow set of permissions, while an administrator or service account could reach critical systems and sensitive information.
Cybercriminals know this. Rather than trying to defeat a firewall or exploit a sophisticated technical vulnerability, an attacker who obtains legitimate credentials may be able to enter the environment using access the company already trusts.
What happens from there depends on the privileges attached to that identity and the additional access available once inside.
Cyberattacks Are Already Disrupting B2B Companies
Cybersecurity has become a business-critical issue for manufacturers and distributors, regardless of what they make, what they sell or where they operate. Verizon’s 2026 Data Breach Investigations Report examined 3,627 security incidents in the manufacturing sector, including 2,713 with confirmed data disclosure. External threat actors were involved in 95% of manufacturing breaches.
A few examples:
CommScope, a major U.S. manufacturer of communications and connectivity infrastructure, disclosed a cyberattack and resulting data breach in 2023. Employee information was among the data compromised, and the attack was subsequently attributed by cybersecurity researchers to the Vice Society ransomware group.
In January 2024, Schneider Electric, one of the world’s largest industrial technology and electrical equipment manufacturers, experienced a ransomware attack affecting its Sustainability Business division. Systems were taken offline as the company investigated, and Schneider later confirmed that the attackers had obtained company data.
For distributors, the 2025 attack on Ingram Micro provides an especially relevant example of how quickly a cyber incident can affect normal business. The global technology distributor confirmed that ransomware had been detected on certain internal systems and took systems offline as part of its response. The resulting disruption affected its website and ordering capabilities, temporarily preventing some customers from placing online orders.
These incidents aren’t evidence that the affected companies had inadequate security. They demonstrate how cyber incidents can move beyond IT and affect the systems manufacturers and distributors depend on to operate. Ordering, customer service, production, fulfillment, financial systems and access to business information can all be affected when critical digital systems become unavailable or compromised.
For companies increasingly dependent on digital commerce and interconnected business systems, cybersecurity is no longer only about protecting data. It’s also about protecting the ability to do business.

The Website Is Only One Part of a Much Larger Environment
A modern commerce website doesn’t operate in isolation. Behind the customer experience can sit product and pricing information, customer records, order processing, email, cloud services, databases, APIs, inventory systems, financial applications, shipping platforms and, in some environments, an ERP.
The architecture will differ from one company to another. Some businesses tightly integrate these systems while others deliberately keep parts of the environment separate. In either case, people and applications require access to keep everything working.
Salespeople need customer and quoting systems. Finance needs accounting and banking applications. Warehouse employees rely on inventory and fulfillment systems. Developers and technology providers may support the commerce platform, while IT administrators can have privileges extending across servers, Microsoft 365, cloud environments, backups and security tools.
As more of the business becomes connected, a compromised identity can potentially expose far more than the website. The extent of that exposure comes down to the permissions associated with the account and how well access is controlled throughout the organization.

An Attack Can Begin with a Very Ordinary Account
An employee receives what appears to be a legitimate Microsoft 365 notification and enters their credentials. Nothing unusual seems to happen, but the login page was fraudulent and an attacker now has a valid username and password.
At first, that account may provide little more than access to email. That can still reveal a remarkable amount about the company: who works in finance, who approves payments, which vendors provide support, what applications employees use and how internal processes work. Email can also contain invoices, customer information, password-reset messages, shared documents and links to other systems.
97% of identity attacks observed by Microsoft were password spray attacks. Microsoft Digital Defense Report 2025 also reported a 32% increase in identity-based attacks during the first half of 2025.
With that information, the attacker can begin looking for ways to expand their access. A reused password might open another application. A shared folder could contain credentials. An old administrative account might still be active. A service account may have more privileges than it needs, or a technology vendor may have permanent remote access that isn’t closely monitored.
An incident that started with one employee’s email account can gradually reach administrator credentials, cloud infrastructure, databases, backups and other critical systems. The attacker may have been inside for days or weeks before ransomware, data theft or another visible event finally reveals the intrusion.

Digital Commerce Creates More Identities to Manage
Customer accounts can contain contact information, order history, account details, addresses, pricing and other commercially sensitive information. Beyond protecting individual customer accounts, companies also need to consider the people who administer the systems behind them.
Employees may be able to manage customer accounts, modify product information, access orders or change configuration settings. Developers may have access to production environments, while outside technology providers may require administrative access for support and maintenance.
Those permissions tend to accumulate over time. Someone changes roles and receives new access without surrendering everything associated with the old position. A contractor finishes a project but the account remains active. Temporary administrator access granted to a vendor quietly becomes permanent. A shared administrative password becomes known to several people because changing it would be inconvenient.
None of these situations necessarily causes an incident on its own. Over time, these leftover permissions give a compromised account more opportunities to reach systems it was never intended to access.
Some of the Most Powerful Identities Aren’t People
Applications constantly communicate with other applications. Websites connect to APIs and databases, backup systems connect to servers, integration platforms exchange information between business systems, and automated processes move data without anyone manually logging in.
Those connections rely on service accounts, application credentials, API keys and other non-human identities. Many require elevated access to do their jobs, making them particularly useful if an attacker manages to compromise one.
These accounts can operate quietly for years. Passwords may rarely change because of concerns about disrupting an application. Credentials can end up embedded in scripts or configuration files. Some accounts have more access than they require, while others no longer have a clear owner.
As companies add cloud services, applications, APIs and automation, the number of non-human identities continues to grow. In some environments, they already outnumber the people using the systems.
Third-Party Vendors Add Another Layer
Manufacturers and distributors depend on technology providers, parts providers, logistics companies, consultants and contractors. Some of them need access to internal systems to do their jobs.
A software company may need administrative access to troubleshoot an application. An IT provider may remotely maintain infrastructure. A developer might require production access during a project. All of that can be perfectly legitimate. Problems develop when temporary access isn’t temporary.
61% of manufacturing breaches involved a third-party vendor.
Vendor accounts can remain active long after projects end. Administrative credentials may be shared among technicians, and remote access can remain available around the clock even when it’s rarely required.
If the vendor itself is compromised, credentials used to connect to customer environments can give an attacker another route in. Third-party access deserves the same visibility and control as access provided to employees.
How Confident Are You About Your Own Access?
For many organizations, the difficult part isn’t knowing whether security controls exist. It’s knowing whether access across the business still reflects what was originally intended.
Consider a few practical examples:
- Could you quickly identify every account with administrative access to your commerce platform?
- Do you know which vendors can remotely access company systems today?
- Are there service accounts running applications or integrations that nobody routinely reviews?
- When an employee changes roles, are old permissions removed or simply added to?
- If a privileged credential were used unexpectedly tonight, would someone know?
Identity Security Is About Understanding Access
Managing this environment requires more than passwords and multifactor authentication. Companies need visibility into who and what has access, why that access exists and how much authority comes with it.
Three areas of identity security address different parts of that challenge:
Identity and Access Management (IAM)
Controls how users authenticate and gain access to applications, systems, and business resources. Ensures the right people can securely sign in and use the tools they need.
Identity Governance & Administration (IGA)
Provides visibility into who has access, why they have it, and whether it remains appropriate. Helps organizations review, certify, and remove access as roles and responsibilities change.
Privileged Access Management (PAM)
Protects high-risk accounts, including administrators, service accounts, and third parties. Reduces the risk of misuse by controlling and monitoring privileged access.
Before deciding which technologies or controls need to change, it helps to understand the access that already exists.
An identity review can uncover privileged accounts that aren’t closely monitored, former employees with residual access, service accounts without clear ownership, vendor credentials that rarely change and employees who have accumulated permissions as their responsibilities changed.
Any one of these issues might seem minor. Several of them connected together can create an access path nobody intended to build.
Then Follow the Access
A useful way to understand identity risk is to assume that an attacker has already obtained one legitimate credential. It could belong to an employee, administrator, vendor or service account. Then follow the access.
Look at the applications and information available to that identity and the privileges attached to it. Determine whether the account can reach other credentials or move into another part of the environment. From there, see whether a path exists to administrative systems, cloud infrastructure, customer information, backups or other critical resources.
Detection matters too. Unusual use of a legitimate account needs to be recognized quickly, and the organization needs to be able to shut down that access before the attacker can move further.
The objective is to contain the damage one compromised identity can cause. As businesses become more dependent on digital commerce, cloud applications, third-party access, automation and interconnected systems, controlling that movement becomes part of protecting the operation itself.
Following those access paths before an attacker does is one of the most valuable exercises an organization can undertake. It shows where legitimate access could become an unintended route to something more sensitive and where additional controls would have the greatest impact.
Start by Understanding Where You Stand
Firewalls, endpoint protection, multifactor authentication, backups and monitoring all have important roles to play. They don’t provide a complete picture of how identities and privileges have accumulated across an organization.
Access that was perfectly legitimate when it was granted can become a risk when it is no longer needed, has grown beyond someone’s responsibilities or isn’t being monitored.
The starting point doesn’t have to be another security product. It can simply be gaining a clear understanding of the identities that exist today, the access attached to them and where that access could lead.
How Exposed Is Your Company?
Falcon’s Identity Security Gap Assessment provides a quick first look at privileged accounts, credentials, employee and vendor access, MFA, service accounts, monitoring and identity governance.
It’s free, requires no signup and takes only a few minutes to complete. Your results can help identify areas of your identity environment that may warrant a closer look.
Need a Deeper Look?
An Identity Security Discovery goes beyond the assessment and examines your current environment: who and what has access, where privileged access exists, how third-party and service accounts are managed, and where unnecessary or excessive permissions may create risk.
The outcome is a clearer picture of your current identity exposure, the gaps that matter most and a prioritized path for addressing them.
/*
Bootstrap's carousel only lays out the .active slide (the rest sit
at display:none), so CSS alone can't size the card to "the tallest
slide" — nothing to measure until it's shown. This briefly forces
each slide to lay out off-screen (visibility:hidden, so nothing
flashes), records its height, then locks every .post-case-example
card to the tallest one via min-height. Runs on load and on resize
(debounced), since text reflows at different widths.
*/
(function () {
function equalizeCaseHeights(root) {
var cards = Array.prototype.slice.call(root.querySelectorAll('.post-case-example'));
if (cards.length < 2) return;
cards.forEach(function (card) { card.style.minHeight = ''; });
var max = 0;
cards.forEach(function (card) {
var item = card.closest('.carousel-item');
var isActive = item.classList.contains('active');
if (!isActive) {
item.style.display = 'block';
item.style.position = 'absolute';
item.style.visibility = 'hidden';
item.style.zIndex = '-1';
}
max = Math.max(max, card.offsetHeight);
if (!isActive) {
item.style.display = '';
item.style.position = '';
item.style.visibility = '';
item.style.zIndex = '';
}
});
cards.forEach(function (card) { card.style.minHeight = max + 'px'; });
}
function runAll() {
document.querySelectorAll('.post-case-carousel').forEach(equalizeCaseHeights);
}
window.addEventListener('load', runAll);
var resizeTimer;
window.addEventListener('resize', function () {
clearTimeout(resizeTimer);
resizeTimer = setTimeout(runAll, 150);
});
})();
Sources: Verizon 2026 Data Breach Investigations Report, Manufacturing Snapshot; Microsoft Digital Defense Report 2025; CommScope 2024 Sustainability Report; Schneider Electric cybersecurity incident disclosures; Ingram Micro cybersecurity incident disclosures and SEC filings; public breach notifications and cybersecurity incident reporting cited throughout the article.