Why This Matters to Distributors: Manufacturers and distributors reported declines in several cybersecurity practices in 2026, including employee training, penetration testing, and cyber monitoring. The declines come as companies rely more heavily on cloud providers and other outside technology partners, increasing the importance of knowing which security controls remain the distributor’s responsibility.
Manufacturers and distributors cut back on several cybersecurity measures in 2026, even as companies increased their scrutiny of security controls at cloud providers, according to new research from Citrin Cooperman.
Regular cybersecurity awareness training fell to 44% of respondents from 55% in 2025, while penetration testing declined to 37% from 43%, according to the firm’s 2026 Manufacturing and Distribution Pulse Survey Report.
The share of companies with someone internally or externally monitoring cybersecurity activity and assets fell to 34% from 47%, the largest decline among the measures tracked in the survey. Cyber insurance coverage slipped to 28% from 30%.

Two other cybersecurity measures were unchanged. Forty-two percent of respondents said they conduct annual risk assessments, while 34% said they have a formal incident response plan.
The declines come as manufacturers and distributors continue to rely on cloud applications and outside technology providers for core business systems.
Citrin Cooperman said the results could indicate that companies increasingly view cybersecurity as a risk to manage rather than an area requiring increased spending each year. Cost pressures, cybersecurity fatigue, or confidence that existing controls are sufficient also could be factors, according to the report.
While several internal cybersecurity measures declined, companies reported more scrutiny of controls maintained by their cloud providers.
73% of respondents said they obtain and annually evaluate System and Organization Controls reports and address the complementary user entity controls identified in those reports.
Another 23% obtain SOC reports but do not evaluate the complementary controls. Four percent said they do not obtain SOC reports from their cloud application providers.
SOC reports assess controls maintained by service providers, but they do not transfer all cybersecurity responsibility to those vendors. Complementary user entity controls identify measures that customers are expected to maintain for the service provider’s controls to work as intended.
That distinction is particularly relevant for distributors using cloud-based enterprise resource planning, warehouse management, customer relationship management, and other operating systems. Security responsibilities can be divided between the distributor and its technology providers.
The survey also found uneven compliance with the federal government’s Cybersecurity Maturity Model Certification requirements.
11% of respondents said they were fully compliant with CMMC 2.0. Another 39% said they were not yet compliant but had a plan to achieve compliance.
28% said they do not do business with the Department of Defense, while 21% said they are not subject to CMMC requirements.
CMMC establishes cybersecurity requirements for companies handling certain information in the Defense Department supply chain, including manufacturers, distributors and other contractors and suppliers.
FINN Partners conducted a survey for Citrin Cooperman from Feb. 26 through March 5. It included 590 finance and accounting professionals at the vice president level or higher at U.S. manufacturing and distribution companies with at least $10 million in annual revenue.
The year-over-year comparison shows declines in four of the six cybersecurity measures tracked.
Cyber activity monitoring recorded the largest drop, falling 13 percentage points. Awareness training declined 11 points, penetration testing fell 6 points, and cyber insurance coverage declined 2 points. Annual risk assessments and incident response plans were unchanged.
The results show a divergence in how manufacturers and distributors are addressing cyber risk: Companies are putting more scrutiny on controls maintained by outside providers while several cybersecurity practices within their own organizations are becoming less common.
For distributors, that makes the division of responsibility with technology providers increasingly important. A vendor’s security controls do not eliminate the need for distributors to monitor their own systems, train employees, or maintain plans for responding when an attack occurs.
Do not miss any content from Distribution Strategy Group. Join our list.
Share this article:



