Hardware businesses tend to invest where the risk feels tangible. The correspondence layer holding all of it together attracts far less attention, despite carrying the drawings, quotes and payment instructions that the whole project depends on.
That imbalance has become a problem. Manufacturing and electronics firms are now routinely targeted precisely because their supply chains involve frequent, high-value transfers between parties who rarely meet. Attackers don’t need to breach a factory network when a convincing message about updated bank details will do the same job. Email is where the money actually moves, and it deserves treating accordingly.
How supplier fraud actually works
The typical case is unglamorous — someone compromises a mailbox somewhere in the chain, watches for a few weeks to learn the rhythm of orders and invoices, then intervenes at the right moment with revised payment details. Nothing looks wrong because nothing is technically forged.
The message arrives in an existing thread from a real address, and the first anyone knows is when the genuine supplier chases a payment that has already gone elsewhere.
Protecting the technical material
Design files carry their own exposure. Board layouts, tooling specifications and assembly documentation represent years of development, and they travel by email constantly. Most providers store that material readable on their servers, which is a meaningful risk for firms whose competitive position rests on the details of how something is made.
CAD files and full assembly packs regularly exceed attachment limits, so people fall back on whichever consumer file-transfer service appears first in a search. That routes your intellectual property through a third party nobody has assessed, usually behind a public download link that stays live long after the recipient has finished with it. Providers that handle large attachments securely remove the reason to improvise.
Choosing an email service built on end-to-end encryption keeps those files unreadable to everyone except the intended recipient, including the provider itself.
The controls that make a difference
Two-factor authentication on every account remains the single highest-value change, and it is free. Beyond that, publish proper authentication records for your domain so that nobody can spoof it convincingly, and establish a rule that changes to payment details are verified by phone using a number you already hold rather than one supplied in the message. The National Cyber Security Centre’s small organisations guide sets out the rest in plain language, and it assumes no in-house expertise.
Why it belongs in the quality conversation
Manufacturers already understand process discipline. Nobody in electronics would accept an unverified component from an unknown source into a production run, yet plenty accept unverified payment instructions from an unverified sender without a second look.
The same reasoning that drives investment in advanced PCB services and tighter manufacturing control applies to the channel carrying the specifications in the first place.
Where to begin
Start by working out who currently has access to the shared inboxes, which is usually more people than anyone expects.
Turn on two-factor authentication for all of them this week. Then set the verification rule for payment changes in writing and tell your suppliers you have done it, because they will almost certainly welcome the same discipline in return. None of it requires a budget line, and all of it is considerably cheaper than the alternative.

