How vulnerable is Britain’s food system to cyberattack?

When cybercriminals targeted Marks & Spencer earlier this year, the disruption quickly spread.

Deliveries stalled, leaving some smaller suppliers struggling with production and cashflow, while products disappeared from shelves.

It was one of the UK’s most high-profile retail cyberattacks, exposing how problems at a single business can reverberate through the food supply chain.

For the people and businesses responsible for keeping Britain fed, it was a stark reminder that cyber resilience has become a critical part of food security.

See also: Advice on basic cybersecurity steps for farm businesses

Technology sits at the heart of modern agriculture, with farmers dependent on satellite navigation to steer tractors, cloud software to manage businesses, automated machinery to improve precision, and digital platforms to record livestock movements.

Beyond the farmgate, processors, hauliers, cold stores and retailers have also come to rely on sophisticated software to keep food flowing from field to fork.

We have reached the point where farming has become a “cyber-physical system”, according to Rami Riashy, a cybersecurity consultant at NCC Group and former agricultural technology engineer.

“Software isn’t just supporting agriculture anymore,” he says.

“It’s controlling where the tractor is going, how much seed is planted, where fertiliser is applied and how machines operate.”

Consequences

That shift fundamentally changes the potential consequences of a cyberattack.

“In the past, software mainly affected data,” says Mr Riashi.

“Now, digital decisions influence physical operations. You can stop a machine harvesting at a critical time, you can affect how chemicals are applied, you can damage crops or create safety hazards.”

Those risks apply to other sectors of farming too, with connected technologies monitoring livestock health, controlling automated milking systems, and helping machinery detect animals and other obstacles in the field.

If those systems fail or are compromised, the consequences extend beyond lost productivity to operator safety and animal welfare.

Prof Simon Pearson, director of the Lincoln Institute for Agri-food Technology, believes the transformation has happened almost unnoticed.

Modern agriculture, he says, has become dependent on an ecosystem of digital services extending far beyond the farmgate.

Farmers may think of the tractor sitting in the yard as the critical asset, but it relies on positioning systems, software updates, cloud connectivity and a host of external services to perform at its best.

This level of precision farming has enabled farmers to make great strides in reducing fuel use, optimising fertiliser applications, improving animal welfare and making better use of resources.

But, as Mr Riashy points out, the challenge from a cybersecurity perspective is that digital systems have become integral to almost every critical operation.

“Historically, if there was a problem with connectivity, farmers could often carry on manually,” he says.

“I don’t think that’s the case anymore. Modern agriculture really depends on that digital infrastructure working correctly.

“The challenge isn’t rejecting technology, it’s making sure that if those systems fail, farmers can continue operating safely.”

Food distributors equally vulnerable to cyberattack

The same story is playing out across the rest of the food chain.

Most people never think about the refrigerated warehouses that hold food before it reaches supermarket shelves, and fewer still are aware of the software directing thousands of pallets around those warehouses every day.

But according to Tom Southall, deputy chief executive of the Cold Chain Federation, those digital systems have become every bit as important as the refrigeration units themselves.

Warehouse management software tracks every pallet entering and leaving a site, directs forklift movements, allocates storage space and ensures the correct products leave on the right vehicles.

Transport management systems co-ordinate deliveries across national logistics networks, while temperature monitoring systems ensure chilled and frozen products stay cold.

Mr Southall says the sector has seen a marked increase in cyberattacks over the past three to four years.

At the same time, the industry’s reliance on digital systems means reverting to manual processes is unrealistic.

In a small warehouse, staff might be able to work around a systems failure for a few hours, but in an automated distribution centre handling tens of thousands of pallets, that is no longer possible.

Without the digital systems needed to move food efficiently through the supply chain, supermarket shelves can empty surprisingly quickly, and that interdependence concerns cybersecurity specialists.

Ripple effect

Modern farms do not operate in isolation – they rely on machinery manufacturers, GPS providers, software companies, dealerships, feed suppliers, processors, hauliers, cold stores and retailers.

A problem affecting any one part of that chain can quickly ripple far beyond the original target.

As Prof Pearson points out, farmers themselves may never be the intended victim.

“If a milk processor is attacked, farmers can’t move milk into that supply chain. If fertiliser suppliers can’t dispatch product, that’s another problem,” he says.

Mr Riashy believes recent events have already demonstrated the extent to which agriculture can become part of a wider geopolitical conflict.

He points to the war in Ukraine, where food production became strategically important because of the country’s role as one of the world’s largest grain exporters.

During the conflict, agricultural machinery stolen from occupied territory was remotely disabled by its manufacturer using an anti-theft function, preventing the machines being used.

The situation illustrated how connected equipment can create new vulnerabilities if similar capabilities fell into the wrong hands.

“Imagine harvest,” he says. “If you couldn’t use those machines during that narrow harvest window, the consequences could be devastating.”

These risks are not confined to tractors. Mr Riashy recalls hearing of an incident in which the temperature readings on a grain trailer were manipulated.

Operators believed grain was being stored correctly, when in reality temperatures were much higher. By the time the problem was discovered, the grain had spoiled.

“It was something so simple that you would never think would have such a severe consequence,” he says.

That is why Mr Riashy believes the focus should be on cyber resilience as a whole, rather than just preventing attacks.

“The objective isn’t to create alarm. It’s just to recognise that cybersecurity has to become another fundamental pillar of agricultural resilience, alongside biosecurity, food safety and environmental stewardship.”

Blackmail is the modus operandi of choice for cybercriminals

The cyberattacks that have dominated headlines in recent years have largely been the work of organised criminal gangs motivated by money.

Ransomware groups infiltrate computer networks, encrypt data or steal sensitive information, and demand payment in exchange for restoring access or preventing stolen files from being published.

According to cybersecurity firm Sophos, manufacturing remains one of the sectors most frequently targeted.

“In general, threat actors don’t target specific industries,” says Aidan Sinnott, principal threat researcher at Sophos. “They target vulnerabilities.”

As food manufacturers, processors and logistics providers have become more connected, their “digital attack surface” has grown, making them more exposed to cybercrime.

The attacks on Marks & Spencer, Co-op and chilled logistics company Peter Green Chilled brought that reality into sharp focus.

And consumers noticed the consequences because food failed to reach supermarket shelves.

For cybersecurity specialists, however, those incidents illustrate something bigger. Mr Sinnott believes they have demonstrated to cybercriminals just how disruptive – and therefore potentially lucrative – attacks on food supply chains can be.

“When ransomware gangs and criminals see the impact it’s having in the headlines, it obviously creates an interest for them because it’s something they can leverage to get bigger ransoms and put pressure on victims,” he says.

Tom Southall of the Cold Chain Federation has reached a similar conclusion.

Because relatively few companies sit at the centre of Britain’s chilled food supply chain, they have become increasingly attractive targets.

“There are probably 100-200 stores that the majority of food passes through and they’re operated by 40 or 50 companies at most,” he says.

If one company is attacked, the system can often adapt. But the industry now fears something else.

“Our concern is really a co-ordinated attack,” he says.

“If four or five of those key suppliers are locked out, then that really would cause impacts very quickly on the shelves. That’s what the industry lives in fear of.”

That means having incident response plans, resilient supply chains and backup operational capabilities.

It also means recognising that cyber resilience should become as fundamental to farming as biosecurity or food safety. “I think we’re at that tipping point,” says Mr Southall.

“Agriculture has always managed biological risks because the consequences are immediate and visible. Cyber-risks have now become operational risks.”