Food and agriculture tends to be an overlooked corner of the cybersecurity conversation despite being critical infrastructure where a cyber incident isn’t just a business problem, but can quickly escalate into a food-safety and public-health crisis. The sector operates on unforgiving timelines. Products spoil. Supply chains depend on perfect handoffs. Margins are already razor-thin. A week of downtime doesn’t just mean lost revenue – it means products rotting in storage, broken promises to grocery chains that were counting on that supply, empty shelves.
Regulators don’t see this as a business setback. They see it as a food-safety failure, period. A ransomware attack that forces a facility to go dark for two weeks doesn’t get a grace period, since it gets a product-disposition review that may end in recalls and destroyed goods.
When a processing plant goes offline for a week, it doesn’t just lose revenue; it also spoils inventory, breaks commitments to retail customers, and creates supply-chain gaps that ripple across the sector. That’s where cybersecurity becomes a food-safety problem.
The Food and Agriculture Information Sharing and Analysis Center found that ransomware incidents targeting the food and agriculture sector increased 62% through July 2026 compared with the same period last year. This came as ClickFix social engineering attacks surged 108% during the first half of 2026. When automated refrigeration systems fail, or process-control data integrity is compromised, regulatory traceability records become unreliable. Regulators and retailers won’t clear product to ship.
Food production’s distinct OT environments, made up of continuous-process control in dairy and beverage, discrete packaging automation, and cold chain monitoring, operate where cyber failure becomes a safety event. Qilin, Akira, CL0P, Play, and Lynx led attacks in 2025, with Russian-linked groups accounting for 59.3% of observed activity and Chinese-linked groups 25.4%. However, real pressure comes from retail customers who now set cybersecurity as a shipping condition. Cold-chain monitoring systems are explicit targets because their failure is indistinguishable from spoilage.
Food and agriculture cybersecurity isn’t just about OT resilience. It’s about operationalizing security when the business case is measured in public health.
Protecting food production from cyber threats

Industrial Cyber reached out to experts across the food and agriculture sector to understand how cyber events can affect production, supply continuity, and food safety based on incidents they have experienced or observed.
Oscar Calderon, OT cybersecurity GRC leader at IBM, told Industrial Cyber that in the food and agriculture sector, cyber incidents quickly become operational and food-safety issues.
“I’ve seen production stop not because equipment failed, but because teams could no longer trust control systems, batch records, or quality data,” Calderon added. “Even short outages can create waste, missed deliveries, and broader supply-chain disruption If monitoring or traceability systems are compromised, companies may hold or dispose of product simply because safe conditions can no longer be verified with confidence. In this sector, trusted operational data is often as critical as the production process itself.”
Cyber events disrupt food supply chains by targeting digital and physical manufacturing. Ransomware can freeze IT and OT (operational technology) systems simultaneously, halting just-in-time production, Jonathan Braley, director at Food and Ag-ISAC, assessed. “The Food and Ag-ISAC tracks 330+ adversaries. As of August, we have recorded 247 sector ransomware incidents this year (out of 5,152 across all sectors). None resulted in food supply contamination or safety issues, demonstrating strong safeguards.”


However, Braley mentioned to Industrial Cyber that recent attacks targeting PLCs (programmable logic controllers) can disrupt production, such as altering displays. “While failsafes prevent unsafe goods from reaching consumers, tampering with equipment sensors can force production halts and costly recalls.”
“Early in my manufacturing career, a production manager at a baked goods factory explained what malware in the ERP system would mean for his line. I learned there is no such thing as a short outage,” Stuart King, co-founder and CTO at AnzenOT, told Industrial Cyber. “Any unplanned stop meant hours of lost production, product stuck mid-line and spoiling, systems reset, trucks waiting at the docks, and orders rebuilt around the lost units. Fairlife and United Natural Foods showed the same pattern at supply chain scale.”
He added that continuity suffers at both ends because inputs are perishable; raw milk, livestock, and crops keep arriving, so lost days become destroyed raw material. “Food safety is potentially the most serious consequence, though no confirmed incident has yet put adulterated product into the supply chain.”
Cyber threats to cold chain, refrigeration systems
The executives detail where cold-chain and refrigeration systems sit within the OT environment. They further look into what a compromise would mean operationally and from a food-safety perspective.
“From what I’ve seen, refrigeration and cold-chain systems are tightly integrated into OT environments through sensors, controllers, alarms, and remote monitoring platforms,” according to Calderon.
He added that a compromise can quickly affect storage validation, logistics, controllers, alarms, and remote monitoring platforms. “A compromise can quickly affect storage validation, logistics, and production continuity. In food operations, refrigeration issues are not just operational problems; they can become food-safety events very quickly. Even if equipment keeps running, loss of confidence in temperature or environmental data can force product holds, delayed shipments, or disposal decisions.”


Braley said that cold-chain and industrial refrigeration systems operate within the process-control layer of OT environments. They connect physical equipment like chillers, freezers, and building management systems directly to PLCs, human-machine interfaces (HMIs), and sensors linked to broader plant controls.
“An OT compromise allows adversaries to disable alarms, alter setpoints, or manipulate data, risking equipment damage and storage disruptions,” he added. “From a food safety standpoint, sustained temperature deviations promote pathogen growth. If live monitoring or historical logs are tampered with, operators cannot verify that food stayed within FDA-required safety margins, making it impossible to guarantee product integrity.”
King pointed out that in many plants, refrigeration does not sit in the OT asset inventory. It belongs to the facilities organization, runs within the context of the building management systems and is probably monitored by a third party over a connection.
“Operationally, a compromise means losing visibility and control of temperature in storage and in the cold chain out the door,” he observed. “The food safety consequence does not require anything to actually spoil because if temperature monitoring fails then you’ve lost the ability to prove that product stayed in range. Which means it gets disposed of regardless of its actual condition. That is why refrigeration telemetry and its records deserve the same integrity and availability treatment as the production control systems.”
When data integrity threatens food safety
The executives zero in on what point a compromise of production, quality, or traceability records forces a product hold, disposal, or recall decision.
Calderon said that in my experience, product hold or disposal decisions begin when teams can no longer trust the integrity of production, quality, or traceability data. “Decisions begin when teams can no longer trust the integrity of production, quality, or traceability data. Even if operations continue physically, uncertainty around batch records, temperatures, sanitation logs, or critical control points can stop shipments immediately.”
He noted that in food manufacturing, digital records help prove safety and regulatory compliance. “I’ve seen situations where the process remained stable, but loss of confidence in the supporting data still created major operational, regulatory, and financial impact.”
A compromise becomes operationally significant when an organization can no longer verify the integrity or reliability of records and data required to confirm that a product was safely produced, handled, stored, or distributed within mandated controls, Braley said. “If production or quality logs are tampered with or rendered unavailable, a company may immediately place affected inventory on hold while it determines what can be validated.”
He added that if traceability records cannot reliably establish the affected lots, scope, or distribution path, the organization may need to expand the hold or disposal decision because it cannot confidently distinguish between compromised and uncompromised products.
“The moment the records for a production window can no longer be trusted! Food safety systems built on HACCP run on documented checks at critical control points, and those records exist to demonstrate, batch by batch, that the process stayed within validated limits,” King said. “If a cyber incident leaves the records for a window missing, altered, or unverifiable, then that’s a compliance issue. Everything produced in that window is presumptively suspect, and it’s up to the operator to make a decision based on what can still be demonstrated rather than on what probably happened.”
Securing cybersecurity under peak production pressure
The executives look into how cyber risk changes during seasonal production peaks, when facilities operate at maximum capacity with little room for maintenance, recovery, or security work.
“I think the cyber risks themselves do not change much during peak seasons; your attack surfaces remain fairly flat, but the impact becomes far greater,” Calderon said. “Food and agriculture facilities often run at maximum utilization during harvests or high-demand periods, leaving very little room for downtime or recovery. Even small incidents can affect production volumes, deliveries, shelf life, and supply continuity.”
He added that security maintenance is also harder to schedule because uptime becomes the overriding priority when production windows are tight.
Flagging that the FBI warns that cybercriminals increasingly target food and agricultural cooperatives during high-stakes planting (April–June) and harvest (September–November) seasons, Braley identified that hackers exploit the supply chain’s zero-downtime tolerance, maximizing pressure on vulnerable co-ops to pay extortion demands quickly.
“Food and Ag-ISAC data reflects this seasonal surge,” he said. “In 2025, we recorded 265 ransomware attacks, a 29% increase over 2024 – with Q4 alone accounting for 99 incidents. We also observe elevated cyberattacks during the U.S. holiday season, when threat actors exploit reduced staffing and holiday schedules.”
King stated that there’s little room for maintenance, recovery, or security work irrespective of seasonal demand peaks. “There have been warnings in the past of hackers trying to time ransomware with planting and harvesting seasons so it’s fair to say the threat scores are going to be higher during these periods and the business impacts greater. Downtime costs are not constant.”
Meeting customer cybersecurity expectations
The executives address how major retail, food-service, or institutional customers shape your cybersecurity requirements, and where their expectations differ from the organization’s own priorities.
Calderon explained that major organizations increasingly influence cybersecurity through audits, supplier requirements, and supply-chain risk expectations. “In my experience, large retailers and food-service organizations often treat cybersecurity and traceability as conditions for doing business.”
He added that their focus is usually on standardized controls and compliance maturity, while OT teams remain focused on uptime, safety, and managing legacy systems. The challenge is implementing stronger security without affecting production stability or food-safety operations.
“Customer questionnaires and insurance requirements often diverge from internal operational priorities,” according to Braley. “Built mainly for enterprise IT, these standards fail to fit the OT, PLCs, and legacy equipment driving food and ag operations, but smaller suppliers face the same benchmarks as large firms with dedicated security teams. Meanwhile, internal priorities center on production continuity and food safety, which compete for the same limited budget.”
He mentioned that the Food and Ag-ISAC supports members across all maturity levels. “We offer public resources to help small and medium-sized businesses (SMBs) build their cybersecurity posture, including its recent SMB guide.”
King said that it is not uncommon for customers to require security questionnaires and audits. “Generally, these tend to be IT rather than OT focused, with an emphasis on data protection rather than availability of OT systems. I’ve yet to see a customer assessment ask how long it takes to restore a line to safe production.”
Need to rethink food and agriculture cybersecurity
The executives examine what the broader OT cybersecurity conversation consistently misunderstands or overlooks about food and agriculture.
“I think the OT cybersecurity conversation often overlooks how operationally constrained food and agriculture environments can be,” Calderon said. “Many facilities still rely on older PLCs, unsupported operating systems, and industrial equipment on older PLCs, unsupported operating systems, and industrial equipment designed for reliability and long production life rather than cybersecurity.”
He added that from what he has seen, “the challenge is not awareness; it’s improving security without disrupting production, cold-chain operations, safety, or product quality. In this industry, digital records and operational continuity are directly tied to whether product can safely move through the supply chain.”
Braley said that because foundational controls like PLCs are shared across sectors, threat advisories often focus on energy and water, inadvertently obscuring risks to food and agriculture. Additionally, the belief that small and medium-sized organizations are too insignificant to target is a misconception; opportunistic attackers routinely target smaller entities that lack robust defenses.
Furthermore, he recognized that OT attacks are often mischaracterized as highly specialized intrusions. In practice, many OT compromises originate in corporate IT networks, where weak segmentation allows adversaries to move laterally into production. Strong network separation and monitoring are therefore critical to protecting agricultural operations from disruption.
“The conversation still treats food and agriculture as a lower tier of critical infrastructure than power, water, and pipelines,” King said. “The sector runs on thin margins with small security teams, consolidation has concentrated production in fewer and larger facilities, and the consequence of an outage reaches the consumer faster than in almost any other sector.”
“Second, most published OT security research is focused on adversary sophistication, vulnerability counts, and asset visibility,” he added. “Those variables matter less to the outcome of a food and agriculture incident than recovery time, process complexity, and restart burden. A dairy or a protein plant with a difficult, sequenced restart takes days to come back regardless of how sophisticated the attacker was.”

