In short
Start with the four places a distribution business stops: order intake, the ERP, warehouse connectivity and dispatch. Put an honest recovery time against each. Then work in this order: a phone-based verification rule for supplier bank changes, multi-factor authentication on email, a surveyed and segmented warehouse network, and image-based backup you have tested by restoring. The first step costs nothing.
A wholesale business runs on two things arriving on time: orders in, goods out. Break the link between them and the loss is counted in hours, not days. Almost every IT decision worth making in a distribution firm is a decision about protecting that link.
This is the order I would work in for a firm of 20 to 60 staff, and why.
Where the money stops
Before any conversation about firewalls or backup, map the points where a day's revenue can halt. In most distribution businesses there are four.
- Order intake. Email, a web portal, EDI, or a phone line into the sales desk. If order email stops, nothing downstream has anything to work on.
- The order management or ERP system. On a server in the office or hosted by the vendor, this is the record of what was promised to whom, at what price.
- Warehouse connectivity. Handheld scanners, label printers, and the wireless network they depend on. A pick list that cannot reach a handheld becomes a pick done on paper.
- Dispatch. Carrier integrations, proof of delivery, and the printers at the pack bench.
Write those four down and put an honest number beside each: how long can this be down before customers notice, and before the order goes elsewhere? That one page is worth more than a technical audit, because it tells you where the money should go first.
Invoice redirection is the fraud aimed at your trade
Distribution firms pay a lot of suppliers, often on terms, usually by bank transfer. That makes the supplier payment run a target. The fraud is straightforward: an email arrives that looks like it comes from a supplier you deal with every week, saying their bank details have changed. The next payment run sends real money to a criminal's account.
It works because it does not look like an attack. There is no malware, and often no compromised account on your side at all. Sometimes the supplier's own mailbox has been broken into, and the criminal has read months of your correspondence before writing in the right tone about the right invoice numbers.
Technology helps at the edges. Multi-factor authentication on every mailbox, so your own accounts cannot be turned against your customers. Mail rules that flag external senders and lookalike domains. But the control that stops the loss is a process rule, and it costs nothing:
Any change to supplier bank details is verified by phone, on a number already held in the finance system, before a payment is released. Never on a number taken from the email requesting the change.
Write it down, tell the finance team it is a rule rather than a preference, and back them when they hold up a payment to make the call. Ireland's National Cyber Security Centre publishes guidance on business email compromise that is worth circulating internally.
Warehouse Wi-Fi is not office Wi-Fi
Office wireless has to cover desks with people sitting still. Warehouse wireless has to cover racking that blocks signal, a yard, sometimes a cold store, with devices moving between access points while a picker walks. These are different engineering problems, and the second one is rarely solved by adding another access point in the corner.
The failures are recognisable. Scanners that drop mid-pick and have to be logged in again. A dead zone in one aisle that everyone has learned to walk around. A network that behaves until eight people are picking at once.
What fixes it is unglamorous: a site survey done with the racking full rather than empty, access points placed for coverage and roaming rather than convenience, and cabling to each one instead of mesh hops. Then segmentation, so scanners, cameras, guest devices and office PCs sit on separate networks. Segmentation limits how far a compromised device can travel, and it stops a camera firmware update interfering with picking. We use UniFi hardware on most sites, and this is the part of our networking work that changes how a warehouse feels day to day.
Decide how long you can go without taking orders
Most firms have backup. Far fewer can say how long a recovery takes, and that is the number that matters. Backup is a copy of your data. Recovery is your business running again. The gap between them is measured in hours you are not selling.
Set a recovery time objective for each of the four points above. For order intake and the ERP it is usually short, because staff are idle and customers are waiting. Then check whether your current arrangement can meet it. A nightly copy to cloud storage may be fine for archives and hopeless for an ERP server that 30 people depend on, because restoring it means rebuilding a machine before the data is any use.
Image-based backup, with local and cloud copies and the ability to run a failed server temporarily from the backup appliance, is what closes that gap. Two further points, both of which we see missed:
- Test the restore, not the backup job. A green tick means the job ran. It does not mean the data comes back. Restore something real, on a schedule, and write down how long it took.
- Back up Microsoft 365 separately. Microsoft replicates your mail, which protects you against their hardware failing. It does not protect you against a deleted mailbox, a retention gap, or a compromised account clearing a folder.
A sensible order of work
For a distributor of 20 to 60 staff, this is the sequence I would follow.
- The verification rule for supplier bank changes. Free, immediate, and it addresses the loss most likely to happen this quarter.
- Email and identity. Multi-factor authentication everywhere, admin accounts kept separate from daily accounts, and starters and leavers handled the same way every time.
- The warehouse network. Survey, coverage, segmentation. This is capital spend, so plan it rather than reacting to it after a bad week.
- Recovery. Image-based backup with a tested restore, and a written recovery time for order intake and the ERP.
- Review. Half an hour once a quarter on what broke and what is due. That is what our Technology Success Program exists to do.
The first two are mostly discipline. Three and four cost money, and they are the ones worth a proper conversation before the invoice lands.
Where to start
Take the four failure points, write your honest recovery times beside them, and see which one you would not survive on a busy Thursday. That is your first project.
If you want a second opinion on the answer, we work with wholesale and distribution firms from our offices in Kilkenny and Cork, and our managed IT service covers the monitoring, patching and support underneath all of it. Get in touch and we will go through it with you.
Does NIS2 apply to a wholesale distributor in Ireland?
It depends on what you distribute and how large you are, so check rather than assume. NIS2, Directive (EU) 2022/2555, lists the sectors it covers in its annexes, and some distribution activity sits inside them, including food distribution and the wholesale distribution of medicinal products. General trade wholesale usually sits outside. Size thresholds apply as well. Confirm your position against the NCSC guidance or with your legal adviser.
How do we stop an invoice redirection email from costing us money?
Make verification a rule. Any change to a supplier's bank details is confirmed by phone, using a number already held in your finance system, before a payment is released. Never use a number or address taken from the email asking for the change. Support that with multi-factor authentication on all mailboxes and flagging of external senders. The phone call is what prevents the loss.
Should warehouse scanners be on the same Wi-Fi as office staff?
No. Put scanners, cameras, guest devices and office computers on separate network segments. Segmentation limits how far a compromised device can travel, and it keeps traffic from one group interfering with another. It also makes troubleshooting faster, because you can see which group is affected. On most sites this is a configuration change on managed switches and access points rather than new cabling.
How quickly should our order system be back after a ransomware attack?
Set the target yourself rather than accepting whatever your current backup happens to deliver. Ask how many hours of not taking orders the business can absorb before customers go elsewhere, then check whether your arrangement can meet that number. Image-based backup that can run a failed server temporarily usually measures recovery in hours. A file-level copy to cloud storage often measures it in days, because the server has to be rebuilt first.
What does a wholesaler need beyond antivirus and backup?
Three things in particular. A verification process for supplier payment changes, because that is the fraud aimed at this trade. Identity controls on email, including multi-factor authentication and a consistent starters and leavers process. And a warehouse network designed for scanners and racking rather than desks. Antivirus and backup are the floor. These are the controls that keep orders moving on a busy day.