5 Strategies for Minimizing Cyber Risks in Agribusiness

Brian Schnese, David Laks and Eric Lowe, Hub International 

AI-driven “smart” agriculture technologies, such as autonomous tractors, robotics and remote sensors, have the potential to transform dairy farming by boosting yields, cutting costs and reducing waste. In fact, the global market value of smart agriculture is projected to increase from around $15 billion dollars in 2022 to $33 billion by 2027.

Up to 40% of large farms in the United States have adopted at least one precision farming technique, such as GPS technology or remote sensors. Autonomous equipment is utilized for a variety of applications, including livestock feeding, monitoring animal health and waste handling, and these advancements play a crucial role in the industry by streamlining operations for milk producers while satisfying the growing need for high-quality dairy products.

While the benefits of technological advancements in agribusiness appear limitless, they also present a host of new opportunities for cybercriminals, who see these innovations as high-value targets. Farmers and ranchers are starting to experience what food and beverage processors have known for years: Automation, AI and advanced technologies make agricultural operations at farms and dairies vulnerable targets for cyberattacks.

Evolving risks in AI and agribusiness technology

Internet-enabled devices enhance automation and efficiency, monitor crop health and identify equipment needing repair. However, these devices often lack proper security, making networks susceptible to hackers.

Ransomware poses the greatest threat, as demonstrated by the $11 million attack on meat processor JBS in 2021. The dairy industry, similarly, has faced at least three major attacks in recent years.

In some incidents, cybercriminals might impersonate a landowner and deceive an agribusiness company into redirecting hundreds of thousands of dollars into their account – often called funds transfer fraud or business email compromise. Other risks include phishing schemes, data manipulation, supply chain disruptions, and theft of confidential information.

The repercussions of cybercrime in the agricultural sector extend beyond financial losses and business interruptions, posing risks to food safety and supply chain integrity. Furthermore, breaches in this field can impact the broader critical infrastructure, affecting water, power and logistical systems.

5 ways to enhance cybersecurity measures

Those running dairy farms and plants must consider a comprehensive approach to managing this complex and evolving risk domain.  That approach is best informed by adopting a governance framework that helps you manage the interrelated components and capabilities that comprise a cybersecurity risk management program.  There are numerous industry standards and frameworks to benchmark against that will help you understand where you are in the maturity spectrum. Here are five fundamental steps to protect your farm, dairy or ranch from cyber threats:

  1. Ensure your cyber monitoring systems are robust. Technical security controls, intrusion detection programs and firewalls should be strong and be able to quickly respond to cyber threats. Additionally, your operation should have in place comprehensive incident response plans that are regularly tested and updated.
  2. Implement additional layers of protection. Enhance your network access controls by utilizing measures like multifactor authentication (MFA). MFA can be configured to protect access to email, privileged and administrative accounts, as well as access to back-ups.
  3. Address third-party cyber risk in writing. Read the fine print and seek to minimize liability for automation hijacking, technology breakdowns or payroll partner fraud through contractual agreements. Without contractual agreements in place, third-party software vulnerabilities could become your responsibility.  You might also use these agreements to influence or compel your third-party providers to have certain cybersecurity controls in place.
  4. Authenticate all of your transactions. Directly contact your vendors and suppliers to verify any email-based transactions, such as invoices or unexpected changes to bank accounts. Instead of relying on attached documents for verification, employees should use source vendor files and public sources to ensure they are using legitimate telephone numbers to call vendors and confirm payments.  This is an area where job-specific cybersecurity training can act as a first line of defense against funds transfer fraud and other malicious activities.
  5. Transfer risk by obtaining a crime or cyber insurance policy. In addition to first party, third party, and business interruption coverages, insurance providers also offer 24/7 hotlines and immediate access to breach response experts who can assist in the aftermath of a data security or network incident. They can also be utilized as a resource for recommended actions to avoid incidents in the first place.

Navigating technology’s benefits while avoiding the risks

As technology and AI continue to revolutionize agriculture, it’s crucial for farmers to be aware of the accompanying risks. Implementing strategies to minimize these risks, such as protecting against ransomware, cyber fraud and sabotage, is essential for safeguarding farms, dairies and ranches in today’s digital age. By staying informed and proactive, farmers can harness the benefits of technology and AI while mitigating potential threats to their operations and data security.

Brian J. Schnese is a Senior Risk Consultant with Hub International’s Risk Services Division and a member of its organizational resilience consulting team. Brian has over 15 years of professional experience in regulatory compliance and managing risk in state and federal government agencies, and in private industry operations including brick and mortar and online retail, supply chain, transportation, healthcare, and the financial industry.

David Laks is Vice President/Risk Control Services Manager for HUB. He brings 30 years of experience in risk control consulting. He develops and implements solutions in the areas of property loss control, building envelop analysis, risk mitigation, construction management, training, business continuity, and regulatory compliance.

Eric Lowe is Vice President for the Risk Services Division of HUB. He has over 30 years of professional experience in safety and health management. He develops and implements solutions in risk mitigation, safety, security, fleet management, products liability, regulatory compliance, training, and worker’s compensation cost reduction.

Be the first to comment

Leave a Reply

Your email address will not be published.


*