Rami Riashy, transport assurance cyber security principal at NCC Group, discusses the evolving cyber threat to the agriculture sector, and how organisations across supply chains should tackle the rising risks

Modern global trade depends on stable, resilient and secure supply chains. From energy and pharmaceuticals to semiconductors and food, the reliable supply of goods underpins financial markets, social stability and national security. At the centre of these global systems sits agriculture.

Today, agriculture is no longer a low-tech, analogue industry. It is rapidly becoming one of the most technologically advanced sectors. Precision agriculture, cloud-connected equipment and autonomous machinery are transforming how food is grown, harvested, processed and delivered.

Across fields and facilities, technologies such as autonomous tractors, GPS-guided planters, cloud-based fleet management platforms, drone spraying systems, real-time soil telemetry and AI-driven irrigation are now commonplace. These deliver significant gains in efficiency and sustainability, but they must be matched with equally robust approaches to cyber resilience. 

Laying the foundations of digital agriculture 

As agriculture digitises, the sector’s exposure to cyber risk grows. Every link in the agricultural supply chain – from seed genetics and field telemetry to logistics and export documentation – introduces potential vulnerabilities. 

Instead of viewing this as a barrier to innovation, organisations should treat it as a design challenge. The focus should not be simply identifying threats but embedding resilience into the foundations of agricultural systems. 

Cyber security must move from reactive protection to proactive, system-wide design. Priority steps to take include: 

  • Embedding secure-by-design principles in machinery and platforms 
  • Designing systems that are safe and functional, even in degraded or offline conditions 
  • Ensuring security controls are proportionate to real-world operational environments, not just enterprise IT models 

As one of the most immediate points of impact, machinery should be engineered to fail safely, maintain integrity and continue operating even when connectivity is limited or disrupted. 

Designing for real-world agricultural conditions 

Agriculture operates under constraints that require tailored security approaches. Remote locations, long equipment lifecycles and mixed-brand ecosystems make traditional cyber models insufficient. 

Offline-capable security 

Security mechanisms must function without constant connectivity. This means: 

  • Local authentication and authorisation controls 
  • On-device integrity verification
  • Secure fallback modes that maintain safe operations 

Lifecycle conscious engineering 

With machinery often in use for decades, security cannot rely on frequent updates. Instead: 

  • Hardware roots of trust and secure boot should be standard 
  • Cryptographic key management must support long-term use 
  • Systems should be designed to remain trustworthy even if updates are infrequent 

Trust across ecosystems 

Multi-brand environments demand shared security frameworks. A federated trust mode, such as interoperable PKI, allows: 

  • Secure communication between different manufacturers’ systems 
  • Clear accountability without sacrificing competition 
  • Reduced risk of gaps between platforms 

By focusing on these principles, organisations can reduce systemic risk while maintaining operational flexibility. 

Strengthening resilience across the supply chain 

Agricultural cyber risk is not confined to machinery. It spans a broad ecosystem, including cloud platforms, dealer networks and manufacturing systems. 

To ensure that resilience is end to end, some practical steps to take include: 

  • Securing software supply chains, including firmware updates and third-party components 
  • Implementing strict identity and access management across dealer and service networks 
  • Monitoring for anomalies across IT and OT environments 
  • Establishing clear incident response plans that are in line with seasonal operations 

Integrating cyber security with safety 

In agriculture, cyber security is inseparable from physical safety. Compromised systems can directly affect machinery behaviours, operator safety and environmental outcomes. To address these risks, organisations should integrate cyber risk into functional safety assessments, conduct threat modelling that includes malicious and accidental failures, and ensure safety-critical systems are isolated, monitored and resilient. This helps to ensure that even in the event of an attack, systems can default to safe and controlled states. 

Protecting data as a strategic asset 

Agricultural data – from social conditions to yield forecasts – is increasingly valuable, and its integrity underpins decision-making across the supply chain. Protecting this data requires strong validation of data inputs and analytics outputs, safeguards against data manipulation, and clear governance over data ownership, access and usage. 

Compliance with regulation and industry standards 

Regulatory frameworks such as the EU Cyber Resilience Act and NIS2 are elevating expectations across the sector. While requirements may vary globally, the direction of travel is clear: strong cyber security is becoming a baseline for participation in modern supply chains.

A collective responsibility to build resilience 

No single organisation can secure supply chains alone, and responsibility spans OEMs designing secure equipment, suppliers embedding trusted components, platform providers protecting data and infrastructure, farmers and regulators. The strength of the full system depends on its weakest link, meaning collaboration, transparency and shared accountability are all essential. 

The transformation of agriculture into a connected, data-driven ecosystem is both an opportunity and a collection responsibility. While cyber threats are real and evolving, they can be effectively managed through intentional design, coordination action and long-term strategy. 

Cyber security should be treated as a core enabler of resilience, instead of a defensive measure. By embedding security into machinery, data, operation and partnerships, the sector can ensure that innovation continues without the compromise of stability. 

  • Risk & Resilience

Will Benton, VP of EMEA at LevelBlue, explores the company’s research into the severe issue of cyber resilience within supply chain

Manufacturers today are operating in an environment where digital risk is escalating faster than many organisations can respond. The sector sits at the centre of the global economy, powering industries from energy and healthcare to transportation and consumer goods, which means an operational disruption has implications well beyond individual companies.

Recent research from LevelBlue highlights just how severe the situation has become. The study reveals a sharp rise in cyber threats, driven by advances in artificial intelligence (AI), increasingly complex supply chains and mounting geopolitical tensions. These pressures are exposing vulnerabilities across the UK’s industrial ecosystem, including major automotive manufacturers – like we saw with Jaguar Land Rover in 2025.  

AI as an accelerator for cyber threats

AI promises game-changing efficiency gains across production lines, quality control and workforce productivity. Simultaneously, it is also transforming how attackers operate. Criminal groups are now using AI to scale social-engineering operations, generate highly realistic deepfakes and identify exploitable vulnerabilities at unprecedented speed. 

Manufacturing leaders anticipate these risks rising sharply, many expect a surge in AI-enabled attacks and identity manipulation, yet preparedness lags significantly behind awareness. A major gap has emerged between the rapid adoption of AI technologies and the cybersecurity measures needed to use them safely. According to LevelBlue’s report, while 44% of executives expect AI‑driven attacks and 47% foresee threats like deepfakes or synthetic identities, only about one‑third feel confident in their ability to defend against them.

The consequence is an expanding attack surface that many organisations don’t yet have the structure or tooling to fully manage. AI adoption is happening too fast for regulations, governance or mature cybersecurity controls to keep pace, which expands the attack surface and increases exposure. Many leaders acknowledge these risks yet remain eager to roll out AI solutions, often without putting the necessary safeguards in place. This gap between rapid innovation and adequate protection highlights the pressing need for manufacturers to adopt a more proactive and flexible approach to building resilience.

Software supply chain exposure

Despite years of warnings and high-profile incidents, the software supply chain remains one of the manufacturers’ weakest defence points. Too few organisations have deep visibility across their vendor ecosystem, and only a small portion are making meaningful investments in supply chain security. LevelBlue’s research highlights this: just 31% of Chief Information Security Officers (CISOs) consider the software supply chain their primary security risk, while many continue to downplay concerns such as legacy systems (62%) or limited visibility for security assessments (64%).

The research shows manufacturers regularly underestimate risks such as outdated software, unsecured open-source components and inadequate transparency from third-party suppliers. These weaknesses give attackers an entry point into a company’s systems, allowing them to steal sensitive information, disrupt operations and even pass compromised software on to customers. Strengthening supplier verification, maintaining accurate software bills of materials and performing frequent risk assessments must become baseline practice for manufacturers looking to harden their defences.

Cybersecurity becomes a business priority, but gaps persist

One encouraging shift is that cybersecurity is increasingly being seen as a strategic business issue rather than a technical afterthought. Many manufacturers now align security with business functions, incorporate cybersecurity KPIs at leadership levels, and invest in resilience, earlier in project lifecycles.

LevelBlue’s findings show that 68% of manufacturing executives believe their cybersecurity teams are well aligned with core business functions, and 65% say leadership roles are now directly linked to cybersecurity KPIs. Combined with rising media scrutiny and an increasingly sophisticated threat landscape, these factors are elevating cybersecurity on the corporate agenda, capturing C‑suite attention and driving greater prioritisation across organisations.

This change marks a broader move toward proactive cybersecurity, embedding protection into innovation efforts, enabling calculated risk-taking and fostering better awareness of threats across the workforce. Over half of manufacturers (55%) now set aside cybersecurity funding at the very beginning of new projects, embedding security into initiatives from day one. Additionally, 69% say that adopting an adaptive cybersecurity strategy allows them to take bolder innovation risks, and 70% are actively training employees to recognise social engineering threats. Together, these efforts signal a sector increasingly treating resilience as a core enabler of growth.

But progress continues to be uneven. Less than half of manufacturing organisations describe their cyber culture as fully effective. To reach the next stage of maturity, manufacturers will need stronger governance, deeper employee engagement and security practices that are integrated into the day-to-day functions, rather than just major initiatives. 

What manufacturers should prioritise next 

Manufacturers looking to strengthen their cyber resilience need to shift from simple awareness to concrete action:

  • The next step is strengthening governance so that board-level oversight translates into measurable accountability, clear ownership and consistent risk management across the organisation.
  • At the same time, organisations should work with various departments, particularly with HR, to build a stronger security-minded culture, encouraging safe digital behaviours and making it easy for employees to report suspicious activity. 
  • Another priority is investing more intentionally in protection by implementing layered security measures, adopting advanced detection technologies, and bringing in external expertise where needed to stay ahead of evolving threats.
  • Finally, manufacturers must fortify supply chain resilience by improving transparency across their vendor ecosystem, verifying the security practices of key suppliers and conducting regular assessments of higher-risk third-party systems.

Together, these steps help organisations move toward a more proactive and robust approach to cybersecurity. 

A defining moment for the industry

Manufacturers are at an inflection point. AI-enhanced attacks, deepfakes and increasingly targeted supply chain intrusions are reshaping the security landscape at a pace many organisations are struggling to keep up with. However, the industry is not standing still. With cybersecurity now elevated to the corporate agenda, the next step is building a culture and operating model that treats resilience as foundational to innovation and growth.

By embedding security into business strategy, manufacturers can close the readiness gap, and position themselves to thrive in a future defined by digital risk. 

  • Risk & Resilience

Anthony Perridge, VP International, ThreatQuotient In 2017, the value per Bitcoin reached over €20,000 (£17,324) – a climax in the…

Anthony Perridge, VP International, ThreatQuotient

In 2017, the value per Bitcoin reached over €20,000 (£17,324) – a climax in the hype surrounding the cryptocurrency. However, confidence has been lacking for the price to remain stable. To date, online currencies are more speculation than real means of payment as concerns around security are being raised. An establishment is only possible if users believe in the value’s sustainability, and this applies to every means of payment.

In no industry is the subjective perception of security as important as in the field of finance. Both private users and large customers are increasingly handling transactions online, so the fear of digital innovation isn’t what stop them from adopting this type of currency. It’s security they really care about, or rather their data’s security. The financial sector has acknowledged this and, must above all focus on security to appease the apprehensions some might have.

Blockchain is considered safe to this day, yet speculation is causing such great uncertainty that cryptocurrencies have not yet developed into serious competition for established currencies. IT decision-makers should therefore always keep in mind the importance of the users’ sense of security in their industry. As part of their digital transformation, many financial organisations have implemented several security tools and also have their own security teams.

These are necessary to comply with legal requirements. After all, almost all other sectors depend on the financial sector. Of course, it is also about the security of customers and partners’ data. Therefore, it is not surprising that this industry has taken a pioneering role over the years. While some organisations already have their own Security Operations Centres (SOCs) to respond to potential threats and identify Indicators of Compromise (IoCs), they should think about other ways to optimise their organisation’s cybersecurity.

From information to intelligence

The SANS Institute recently investigated the latest developments in security and revealed that companies are increasingly taking advantage of Cyber Threat Intelligence (CTI). The findings show a development that goes beyond the expertise of IOC and gives a new perspective of Threat Intelligence.

It is well known that public sources such as the National Cyber Security Centre (NCSC), security vendors and open source communities publish reports and threat feeds on current threats. At the same time, security tools such as Security Information and Event Management (SIEM) or firewalls also collect information that can be used to combat threats and create a situational picture. In addition, there are industry-specific Information Sharing and Analysis Centres (ISACs) that organisations can participate in. The number and quality of both information sources and IoCs continues to grow and is currently the most important resource for an effective cyber-defence.

However, the trend is moving towards Tactics, Techniques and Procedures (TTPs), meaning a better understanding of how the attackers want to penetrate victims’ networks. Instead of focusing only on the evidence of attacks, IT teams should work to stay one step ahead of the criminals by anticipating their next steps: leveraging cyber threat intelligence.

Thus, it is necessary to step away from the manual evaluation of individual fragments to the building of strategic knowledge about the danger landscape and the extent of the threats for the own systems. Without support, the analysis of IoCs is extremely time-consuming. Indeed, IT teams in the financial sector can sometimes find themselves having to compare and check data from different sources manually. In this situation, there’s no agreement on the activities between the individual teams, the work become inefficient and information silos start to emerge. At the same time the number of attacks continues to increase, and the growing networking infrastructures are also more complex.

When IT departments do not have an overview of their own security situation, there is no basis for creating trust – the basic but crucial quality that we mentioned earlier. CTI works at this point: SANS notes that after deploying an appropriate platform, 81 percent see their defence and detection capabilities as improved. It involves partial or complete automation to turn the available information into actionable intelligence and use it in your own organisation.

Building your own Threat Library in practice

It takes a variety of tools and processes to set up your own cyber threat intelligence platform. However, most financial companies already have the most important components for implementation. Often internal data sources already exist: SIEM solutions or threat information from security providers whose solution is used (IDS, Firewall, End Point Security). As mentioned, government agencies and open source offerings (such as www.malwaredomainlist.com) also have reports and analysis. In addition, information from industry associations and their own analyses of network traffic can be incorporated.

The challenging final step is building a cross-platform. The SANS speaks of a collection management platform (CMF), which is characterised mainly by building a local threat database, in which all data from external and internal sources are stored in a central location. In addition, information should then be automatically aggregated, normalised and de-duplicated, as well as relevance and priority for the own company be checked by means of a scoring system. The Threat Library serves as a “single source of truth” for all teams and systems within a company.

In terms of personnel, there are many departments that should be considered: in addition to SOCs and incident response teams, IT operations and security teams can also coordinate their actions with one another via a CTI platform. Of course, the departments are very differently positioned, especially in the financial area. This is why there are also own teams for compliance and audits, but also for the management of vulnerabilities. Moreover, service providers also took on such tasks.

Depending on the size and budget of an organisation, service providers play an important role. However, SANS experts are increasingly recommending partnerships and cooperation rather than considering outsourcing altogether. Proper management of the threat situation is essential, since the cyber threats are already an integral part of everyday life in the area of ​​finance, and organisations must prepare themselves for further attacks. The question then arises as to whether and how strongly your own company is affected.

Conclusion

The Threat Intelligence Platform figures speak for themselves: survey respondents recognise the greatest benefits in improving their security operations, threat detection and attacks, and blocking. Coordinating the use of CTI proved to be of particular value to 90 percent of users stating that it has improved the visibility of threats in their own network environment. Additionally, in almost all cases, the accuracy and speed of eliminating noise improved.

These are all areas that directly affect the user experience. Banking and payment in the digital world are particularly dependent on customers’ trust and subjective sense of security. Therefore, players in the industry need to have a clear understanding of the overall threat situation and their individual threat situation in order to respond properly at all times.

Data breaches are costly. According to a recent Ponemon Institute study, the average breach costs an organisation $3.86 million. A…

Data breaches are costly. According to a recent Ponemon Institute study, the average breach costs an organisation $3.86 million. A separate study found that, although the share price of breach-affected companies shows its sharpest drop 14 days after the breach is made public, there is still a discernible impact on the organisation’s stock valuation three years post-event.

By Josh Lefkowitz, CEO of Flashpoint

Business impacts at this level affect the fundamental financial performance and sustainability of an organisation, which means cybersecurity must no longer be considered an IT issue; it’s a matter for the board in its role as custodian of shareholder value. By managing cyber risk as part of the overall organisational risk strategy, boards can put it into a commercial context and drive the cultural awareness of risk that is essential to promote cyber resilience across the business.

Making the shift from technology-centric to business-centric risk management

Elevating cyber risk management to the board level is not without challenges, however. We are still very much in the midst of a shift in mindset from a technology-centric to a business-centric view of cyber threats. This can result in a disconnect: many boards find it difficult to interpret the information they receive from the IT team, while many IT functions struggle to understand what data the board really needs to carry out effective oversight. This challenge was underlined by EY interviews that found difficulties “obtaining relevant, objective and reliable information, presented in business-centric terms…[and this] affects board members’ ability to understand the risk facing their organisations and evaluate management’s response to these risks.”

This area is where the evolving role of the CISO—sitting between the business and the board—requires a mix of skills. CISOs need both technical expertise in analysing and interpreting threat metrics and technology performance, and the ability to apply these skills in a broader business context for board directors so they can deliver strategic cyber risk oversight and governance for the business.

Reporting to the board – from numbers to narrative

While increasingly boards are factoring cyber skillsets into their succession planning when recruiting new board members, most current board directors don’t have deep experience in cybersecurity. This means that any metric-based reporting should be simple to interpret, including auditable figures that provide an overview of the organisation’s security posture.

Reports should also be framed in terms of the impacts specific security incidents have on the business. For example, a DdoS attack might cause reputational risk, operational risk and strategic risk. And, of course, the flipside of risk is compliance, so the board also needs to know how cybersecurity incidents could impact data privacy and governance.

It’s the role of the board to challenge senior management robustly in order to deliver effective oversight, so CISOs should be ready to answer questions around the organisation’s cybersecurity maturity and the frameworks established to manage emerging threats.

However, while numbers and frameworks are valuable in helping boards evaluate and audit cyber risk posture, when it comes to setting a risk-aware culture, directors really need deeper context around the types of threats specific to their organisation. If board directors are given a window into the environment, tactics, and motivational psychology of actors that target their sector and business, they can better understand the risks themselves. Once that has been achieved, board directors can become an asset to the CISO in promoting a cyber risk-aware culture not just as a tick-box exercise, but because they have genuine appreciation of the factors, and indeed actors, in play.

To achieve this board-level buy-in, CISOs need to move from numbers to narrative to drive the message home. This is where business risk intelligence provides the context that helps bring risk to life.

It’s undoubtedly useful for senior leaders to understand the frequency and type of the cyber-attacks the business experiences, but it’s also valuable for them to know the extent to which the organisation is the topic of conversation in the illicit online communities that initiate those attacks.

Deep and dark web forums, chat services, and other platforms are often where cybercriminals discuss tactics to defraud or infiltrate the organisation. These types of venues are also where company secrets, intellectual property, and stolen data may be offered for sale. An overview of the company’s profile across the deep and dark web, as well as other illicit online communities, and the kinds of tactics that are being discussed, is a powerful way CISOs can help directors gain context to understand what the business faces.

Illustrating third-party risk

Third-party risk, including supply chain weaknesses, is a hot topic among board rooms as businesses realise that keeping their own house in order is not enough. Intelligence gleaned from illicit online communities can also be used to illustrate potential weaknesses in, or threats to, partner organisations. This intelligence can help boards meet objectives to manage supply chain risk.

Successful cyber risk oversight by company boards relies on them receiving a combination of auditable metrics, risk impact assessments and contextual information enabling them to provide informed oversight of cyber risk. Greater understanding of the threat actor environment also assists boards in leading a risk-aware culture across the business, moving from a tick-box approach to a genuine cultural shift.  

Is your company safeguarded against cyber-attacks? In this day and age, new threats to your business’s security are being developed…

Is your company safeguarded against cyber-attacks?

In this day and age, new threats to your business’s security are being developed daily. Ransomware, phishing and data leaking are a constant danger, threatening to take money, steal employee details and damage your customer data.

To prevent damaged relationships between clients and other key stakeholders, you’ll want to ensure that your cyber-security is up to scratch. But, just how is this possible within an ever-evolving digital landscape?

We recommend the following five simple, but effective hacks:

Email

It all starts with a simple email masked as a trusted source, which quickly – and unexpectedly – transforms into a simple way to gain vital, confidential information. Spear phishing has become a successful and popular tool for attackers to gain access to company files and details. With 91 percent of cyber-attacks beginning this way, it’s vital that you acknowledge the threat and generate awareness throughout your business, starting with each and every member of your team.

A key hack that prevents this from happening is keeping as many company emails off your website, opting instead for contact forms. Secondly, ensure employees never send sensitive information via email and educate them about the dangers of sharing company information outside of the workplace. While you may think this should be common knowledge, some staff members do and will overlook the potential consequences.

WiFi

Ever wondered about the dangers of WiFi hacking? Type a quick query into Google and thousands of results will be listed, advising you how to gain access to wireless internet and, more concerningly, how to reap plenty of ‘rewards’ by harvesting information.

The first step to protecting your network is enabling WiFi Protected Access, using encryption to lock all accessible routes. Then, change the SSID’s (wireless network names) in every office. Using the default name allows attackers to use prebuilt password crackers that are associated with common names, so the lengthier and more random the name, the better. This should be coupled with a strong password that will discourage and defence against potential hacks.

Update computers

Ensure that all device updates are implemented company-wide. You may remember the Equifax hack in 2017 where hackers gained access to the details of nearly 150 million people. The breach was caused by an application with vulnerabilities, ones which could have been fixed with a software update 2 months prior to the attack.

This highlights how important updates are. Hackers can easily find vulnerabilities in any software if they search long and hard enough, so in response, updates release new code that can patch up any holes and protect your company’s devices from malicious malware. Never overlook the value of software updates – they may appear annoying or inconvenient, but they serve a very valuable purpose.

Backup

If your company spans multiple offices, then you’ll likely be employing a cloud service so different departments have access to relevant files. Unfortunately, these digital filing cabinets are very susceptible to hacks. A fail safe method to guarantee protection is hard to come by, but there are simple measurements you and your staff can put in place.

A two-step authentication process should be introduced that requires your staff to confirm a code. The best way to do this is through the use of apps like Duo which constantly change and update the code required. Another option is through a key that can be plugged into a computer. It’s an extra-secure method that can be used with some of the most popular cloud storage options.

Employee education

Arguably the most effective thing you could do when developing your cyber-security strategy is educating your staff.

In accordance with the GDPR regulations, every member of staff should be aware of how to handle private and confidential information securely and safely, regardless of the department they work in. However, there is no harm in taking the time to set up full and comprehensive protocols for all aspects of cyber-security.

Introduce policies for how all information should be stored, provide password support that ensures no password is used twice and encourage the use of two factor authentication. Also, be sure to develop protocols should a data breach happen and only provide staff access to files that are required for their job roles. It’s recommended that regular training takes place in every office to keep staff up to date with the latest security changes.

These 5 tips may appear simplistic, but in the fast-paced environment associated with the modern businesses, it can be easy to opt for ease over safety. Make sure everything digitally hosted is fully protected from potential threats and consider what could be the biggest danger for your company to prepare for.

Tim Holman is CEO at 2|SEC Consulting, a cyber and information security consultancy