Rami Riashy, transport assurance cyber security principal at NCC Group, discusses the evolving cyber threat to the agriculture sector, and how organisations across supply chains should tackle the rising risks

Modern global trade depends on stable, resilient and secure supply chains. From energy and pharmaceuticals to semiconductors and food, the reliable supply of goods underpins financial markets, social stability and national security. At the centre of these global systems sits agriculture.

Today, agriculture is no longer a low-tech, analogue industry. It is rapidly becoming one of the most technologically advanced sectors. Precision agriculture, cloud-connected equipment and autonomous machinery are transforming how food is grown, harvested, processed and delivered.

Across fields and facilities, technologies such as autonomous tractors, GPS-guided planters, cloud-based fleet management platforms, drone spraying systems, real-time soil telemetry and AI-driven irrigation are now commonplace. These deliver significant gains in efficiency and sustainability, but they must be matched with equally robust approaches to cyber resilience. 

Laying the foundations of digital agriculture 

As agriculture digitises, the sector’s exposure to cyber risk grows. Every link in the agricultural supply chain – from seed genetics and field telemetry to logistics and export documentation – introduces potential vulnerabilities. 

Instead of viewing this as a barrier to innovation, organisations should treat it as a design challenge. The focus should not be simply identifying threats but embedding resilience into the foundations of agricultural systems. 

Cyber security must move from reactive protection to proactive, system-wide design. Priority steps to take include: 

  • Embedding secure-by-design principles in machinery and platforms 
  • Designing systems that are safe and functional, even in degraded or offline conditions 
  • Ensuring security controls are proportionate to real-world operational environments, not just enterprise IT models 

As one of the most immediate points of impact, machinery should be engineered to fail safely, maintain integrity and continue operating even when connectivity is limited or disrupted. 

Designing for real-world agricultural conditions 

Agriculture operates under constraints that require tailored security approaches. Remote locations, long equipment lifecycles and mixed-brand ecosystems make traditional cyber models insufficient. 

Offline-capable security 

Security mechanisms must function without constant connectivity. This means: 

  • Local authentication and authorisation controls 
  • On-device integrity verification
  • Secure fallback modes that maintain safe operations 

Lifecycle conscious engineering 

With machinery often in use for decades, security cannot rely on frequent updates. Instead: 

  • Hardware roots of trust and secure boot should be standard 
  • Cryptographic key management must support long-term use 
  • Systems should be designed to remain trustworthy even if updates are infrequent 

Trust across ecosystems 

Multi-brand environments demand shared security frameworks. A federated trust mode, such as interoperable PKI, allows: 

  • Secure communication between different manufacturers’ systems 
  • Clear accountability without sacrificing competition 
  • Reduced risk of gaps between platforms 

By focusing on these principles, organisations can reduce systemic risk while maintaining operational flexibility. 

Strengthening resilience across the supply chain 

Agricultural cyber risk is not confined to machinery. It spans a broad ecosystem, including cloud platforms, dealer networks and manufacturing systems. 

To ensure that resilience is end to end, some practical steps to take include: 

  • Securing software supply chains, including firmware updates and third-party components 
  • Implementing strict identity and access management across dealer and service networks 
  • Monitoring for anomalies across IT and OT environments 
  • Establishing clear incident response plans that are in line with seasonal operations 

Integrating cyber security with safety 

In agriculture, cyber security is inseparable from physical safety. Compromised systems can directly affect machinery behaviours, operator safety and environmental outcomes. To address these risks, organisations should integrate cyber risk into functional safety assessments, conduct threat modelling that includes malicious and accidental failures, and ensure safety-critical systems are isolated, monitored and resilient. This helps to ensure that even in the event of an attack, systems can default to safe and controlled states. 

Protecting data as a strategic asset 

Agricultural data – from social conditions to yield forecasts – is increasingly valuable, and its integrity underpins decision-making across the supply chain. Protecting this data requires strong validation of data inputs and analytics outputs, safeguards against data manipulation, and clear governance over data ownership, access and usage. 

Compliance with regulation and industry standards 

Regulatory frameworks such as the EU Cyber Resilience Act and NIS2 are elevating expectations across the sector. While requirements may vary globally, the direction of travel is clear: strong cyber security is becoming a baseline for participation in modern supply chains.

A collective responsibility to build resilience 

No single organisation can secure supply chains alone, and responsibility spans OEMs designing secure equipment, suppliers embedding trusted components, platform providers protecting data and infrastructure, farmers and regulators. The strength of the full system depends on its weakest link, meaning collaboration, transparency and shared accountability are all essential. 

The transformation of agriculture into a connected, data-driven ecosystem is both an opportunity and a collection responsibility. While cyber threats are real and evolving, they can be effectively managed through intentional design, coordination action and long-term strategy. 

Cyber security should be treated as a core enabler of resilience, instead of a defensive measure. By embedding security into machinery, data, operation and partnerships, the sector can ensure that innovation continues without the compromise of stability. 

  • Risk & Resilience

Will Benton, VP of EMEA at LevelBlue, explores the company’s research into the severe issue of cyber resilience within supply chain

Manufacturers today are operating in an environment where digital risk is escalating faster than many organisations can respond. The sector sits at the centre of the global economy, powering industries from energy and healthcare to transportation and consumer goods, which means an operational disruption has implications well beyond individual companies.

Recent research from LevelBlue highlights just how severe the situation has become. The study reveals a sharp rise in cyber threats, driven by advances in artificial intelligence (AI), increasingly complex supply chains and mounting geopolitical tensions. These pressures are exposing vulnerabilities across the UK’s industrial ecosystem, including major automotive manufacturers – like we saw with Jaguar Land Rover in 2025.  

AI as an accelerator for cyber threats

AI promises game-changing efficiency gains across production lines, quality control and workforce productivity. Simultaneously, it is also transforming how attackers operate. Criminal groups are now using AI to scale social-engineering operations, generate highly realistic deepfakes and identify exploitable vulnerabilities at unprecedented speed. 

Manufacturing leaders anticipate these risks rising sharply, many expect a surge in AI-enabled attacks and identity manipulation, yet preparedness lags significantly behind awareness. A major gap has emerged between the rapid adoption of AI technologies and the cybersecurity measures needed to use them safely. According to LevelBlue’s report, while 44% of executives expect AI‑driven attacks and 47% foresee threats like deepfakes or synthetic identities, only about one‑third feel confident in their ability to defend against them.

The consequence is an expanding attack surface that many organisations don’t yet have the structure or tooling to fully manage. AI adoption is happening too fast for regulations, governance or mature cybersecurity controls to keep pace, which expands the attack surface and increases exposure. Many leaders acknowledge these risks yet remain eager to roll out AI solutions, often without putting the necessary safeguards in place. This gap between rapid innovation and adequate protection highlights the pressing need for manufacturers to adopt a more proactive and flexible approach to building resilience.

Software supply chain exposure

Despite years of warnings and high-profile incidents, the software supply chain remains one of the manufacturers’ weakest defence points. Too few organisations have deep visibility across their vendor ecosystem, and only a small portion are making meaningful investments in supply chain security. LevelBlue’s research highlights this: just 31% of Chief Information Security Officers (CISOs) consider the software supply chain their primary security risk, while many continue to downplay concerns such as legacy systems (62%) or limited visibility for security assessments (64%).

The research shows manufacturers regularly underestimate risks such as outdated software, unsecured open-source components and inadequate transparency from third-party suppliers. These weaknesses give attackers an entry point into a company’s systems, allowing them to steal sensitive information, disrupt operations and even pass compromised software on to customers. Strengthening supplier verification, maintaining accurate software bills of materials and performing frequent risk assessments must become baseline practice for manufacturers looking to harden their defences.

Cybersecurity becomes a business priority, but gaps persist

One encouraging shift is that cybersecurity is increasingly being seen as a strategic business issue rather than a technical afterthought. Many manufacturers now align security with business functions, incorporate cybersecurity KPIs at leadership levels, and invest in resilience, earlier in project lifecycles.

LevelBlue’s findings show that 68% of manufacturing executives believe their cybersecurity teams are well aligned with core business functions, and 65% say leadership roles are now directly linked to cybersecurity KPIs. Combined with rising media scrutiny and an increasingly sophisticated threat landscape, these factors are elevating cybersecurity on the corporate agenda, capturing C‑suite attention and driving greater prioritisation across organisations.

This change marks a broader move toward proactive cybersecurity, embedding protection into innovation efforts, enabling calculated risk-taking and fostering better awareness of threats across the workforce. Over half of manufacturers (55%) now set aside cybersecurity funding at the very beginning of new projects, embedding security into initiatives from day one. Additionally, 69% say that adopting an adaptive cybersecurity strategy allows them to take bolder innovation risks, and 70% are actively training employees to recognise social engineering threats. Together, these efforts signal a sector increasingly treating resilience as a core enabler of growth.

But progress continues to be uneven. Less than half of manufacturing organisations describe their cyber culture as fully effective. To reach the next stage of maturity, manufacturers will need stronger governance, deeper employee engagement and security practices that are integrated into the day-to-day functions, rather than just major initiatives. 

What manufacturers should prioritise next 

Manufacturers looking to strengthen their cyber resilience need to shift from simple awareness to concrete action:

  • The next step is strengthening governance so that board-level oversight translates into measurable accountability, clear ownership and consistent risk management across the organisation.
  • At the same time, organisations should work with various departments, particularly with HR, to build a stronger security-minded culture, encouraging safe digital behaviours and making it easy for employees to report suspicious activity. 
  • Another priority is investing more intentionally in protection by implementing layered security measures, adopting advanced detection technologies, and bringing in external expertise where needed to stay ahead of evolving threats.
  • Finally, manufacturers must fortify supply chain resilience by improving transparency across their vendor ecosystem, verifying the security practices of key suppliers and conducting regular assessments of higher-risk third-party systems.

Together, these steps help organisations move toward a more proactive and robust approach to cybersecurity. 

A defining moment for the industry

Manufacturers are at an inflection point. AI-enhanced attacks, deepfakes and increasingly targeted supply chain intrusions are reshaping the security landscape at a pace many organisations are struggling to keep up with. However, the industry is not standing still. With cybersecurity now elevated to the corporate agenda, the next step is building a culture and operating model that treats resilience as foundational to innovation and growth.

By embedding security into business strategy, manufacturers can close the readiness gap, and position themselves to thrive in a future defined by digital risk. 

  • Risk & Resilience

Financial services organisations are trusted with far more than just money; they’re also responsible for keeping customers’ highly sensitive personal and financial data under lock and key. We’re hyper-aware that the growing value of this data means financial organisations are prime targets for cyberattacks – but this isn’t the only threat they face.

In fact, not a day passes without these firms’ own employees putting data at risk from within, says Tony Pepper, CEO. Egress…

You might think that, when it comes to reducing overall breach risk, employees represent low-hanging fruit – surely it is easier to control the actions of a company’s own team members than it is to defend against external attackers? However, this not the reality experienced by financial firms worldwide. While external attackers are always motivated by malicious intent, the employee population is far more heterogenous and, in a sense, much more human. This makes understanding and mitigating insider risk a more nuanced exercise. Just because it is difficult, however, doesn’t mean it is impossible. It’s crucial that financial services companies shift the dial on insider risk and reduce breach frequency, because the penalties for failing to do so are becoming increasingly draconian and the repercussions from customers much more severe.

The recent Egress Insider Breach Survey aimed to understand the different attitudes towards data sharing and ownership among employees in financial services companies and the approaches that IT leaders in the sector are taking to managing insider breach risk.

We found a whole range of diverse profiles of people who put sensitive financial data at risk for very different, but very human, reasons. Some need monitoring to keep their less-than-honest traits from getting the better of them, while others need a helping hand to save them from making genuine, well-meaning mistakes. And across all respondents, we also found confusion over who really owns data, contributing to the more cavalier attitudes displayed by some.

Deliberate “data breachers” – from well-intentioned but reckless to disaffected and destructive

Our study found that the financial services sector has more than its fair share of deliberate “data breachers”. Of the thousand employees we questioned, almost a third (32%) said they or a colleague had intentionally broken company policy when sharing or removing information in the past year. This compares with just 15% of healthcare workers and 11% of government sector employees.

The reasons given for this deliberate flouting of security policy varied. One-third said they were simply trying to get their job done but didn’t have the appropriate tools to share data safely. On the face of it we might have some sympathy with those employees, but would consumers and businesses want to bank with those firms?

It’s more difficult to be sympathetic with those motivated by self-gain, including the 41% who took data with them because they were moving to a new job. And we have even less sympathy for the 15% who compromised data because they were angry with the company and wanted to deliberately cause harm.

Operator error – mobile, tired, under pressure

Even with their firm’s best interests at heart, employees still make mistakes. 30% of financial sector workers said they or a colleague had caused an accidental data breach in the past year – again more than twice as many as their public sector counterparts. A third had sent an email to the wrong person and a further third had clicked on a link in a phishing email.

Their reasons behind these breaches varied from the pressure of working in a stressful environment, to tiredness and rushing. A significant proportion, however, said they made an error due to using a mobile device – and given the current requirement for mobile remote working during this COVID-19 pandemic, this is a definite cause for concern.

Breach detection gaps and technology limitations

Next, we examined what IT leaders in the sector have in place to mitigate insider breach risk. Concerningly, 60% said the most likely way they would discover an insider data breach was via internal hand-raiser reporting by either the employee themselves or a colleague. Only one third felt that their breach detection systems would pick up the issue.

In a similar vein, traditional data protection technology use was surprisingly inconsistent across financial firms. Email encryption, anti-malware and secure collaboration software were in use by fewer than half of financial sector companies. Again, raising the question whether consumers and businesses would be willing to trust their data to financial firms if they knew they didn’t have systems in place to protect it.

So, why is this the case? From the data we uncovered, it seems as though organisations are resigned to a proportion of insider breach incidents occurring, accepting them as an inevitable result of doing business and employing people. But this doesn’t need to be the case. It is possible to apply human layer security solutions to mitigate these risk factors and make a positive impact on breach frequency figures.

Human layer security – a helping hand and a watchful eye

Take the issue of rushing or tiredness. This can lead to users adding the wrong recipients to emails or failing to spot the subtle changes in familiar email addresses that denote targeted phishing attempts. This risk can be overcome with tools that use contextual machine learning to analyse what the good security behaviour looks like for each user and support them with alerts that tell them they’ve added an unusual recipient to an email, or that they are about to answer a phishing email. A small prompt is all these users need to stop them from making an error and causing a data breach.

Similarly, when using mobile devices with smaller screens, it is very easy to choose the wrong attachment and send sensitive data outside the organisation to the wrong recipient or to the right person unprotected. If an employee is less than honest, our always-on, constantly connected culture also enables them to deliberately do so too. However, it is possible to stop these incidents with an intelligent solution that scans email and attachment content and identifies data such as personally identifiable information (PII) or bank account details to alert users that they are about to send information to an unauthorised recipient, or without the correct level of encryption applied. If the user persists, the risky email can be blocked from being sent and administrators alerted to a potentially intentional attempt to breach data, so they can respond accordingly.

Ultimately, the most effective way to address human-activated threats to security is by implementing tools that support and manage users when they are at their most humanly vulnerable; tired, rushing, under pressure, angry or self-interested. As our research and wider evidence shows, the financial services sector is more than averagely vulnerable to insider data breaches, meaning human layer security must be a priority for IT leaders in the field if they hope to reduce breach frequency and keep sensitive data firmly in the vault.