July's Fairlife Ransomware Attack Should Be a Wake-Up Call

Cyberattacks on food or beverage companies have become less reported, but this may be a good time to check your company’s or plant’s cybersecurity preparedness.

Food & beverage manufacturers are especially attractive to attackers because IT and operational technology (production, batching, packaging controls) are tightly connected. “So a breach that starts in the corporate network can quickly reach the plant floor,” says Cacciola.

That certainly is one well-traveled route. The human layer, not the firewall, is increasingly the entry point, he says. Email-based fraud (fake invoices, payment-redirect, vendor impersonation) continues to generate the highest volume of claims.

And now artificial intelligence is helping attackers to craft flawless phishing, clone voices and impersonate executives and vendors at scale.

But Joe Weiss of Applied Control Solutions sees a different chink in the armor. “Until cybersecurity programs expand their focus beyond protecting networks to ensure the integrity of electronically communicated process information, we will continue to solve the wrong problem.”

Food & beverage plants use pumps, valves, motors, drives, relays, analyzers, process sensors, engineering workstations, operator displays and communication networks. “Because these systems depend on electronic communications to monitor and control physical processes, control system cyber incidents occur whenever electronically communicated process information becomes corrupted, delayed, unavailable or untrustworthy,” says Weiss.

“Network cybersecurity has unquestionably reduced many cyber risks,” he continues. “However, incident data demonstrates that many of the most severe physical consequences originate from corrupted, delayed, unavailable or otherwise untrustworthy electronically communicated process information rather than compromised networks.”

Here’s a third opinion: Nearly 90% of respondents to a 2024 survey said one or more cyberattacks of the previous 12 months originated from third-party supplier access to the cyber-physical systems (CPS) environment. 41% said that was the cause of five or more attacks.

More than half (57%) admitted to having only partial or no understanding of third-party connectivity to their CPS environment, according to Claroty, a cyber security provider, which commissioned that independent global survey of 1,100 professionals involved in information security, operations technology (OT), engineering, clinical & biomedical engineering, and facilities management & plant operations.

An August 2022 guest column we carried from Hub International offered seven steps processors should take to protect themselves against a cyberattack and to recover in case of a successful incursion:

  • Do a deep-dive assessment for a baseline understanding of your cybersecurity. With every part of a food company’s production system traced, tracked and verified electronically, outdated software and systems practically invite bad actors to step in. Knowing your vulnerabilities starts with an assessment.
  • Control access and implement multifactor authentication. Employees should only have access to the parts of the network they need to do their jobs. Multifactor authentication and encryption should be mandatory to minimize unauthorized access and passwords being compromised.
  • Human error can be eliminated with strong training. Remind your workforce to take precautions and reiterate key security training concepts. It’s also important to respond to any security incidents promptly.
  • Back up data and test the system. Scanning across the entire network infrastructure, including databases, is critical. If a cyberattack occurs, quick access to data is key to overcoming the issue. Have data redundancy plans in place, such as a production copy, a local copy and a cloud-based copy. However, remember that data doesn’t always get properly backed up or is not always immediately available after a cyberattack.
  • An emerging technology, endpoint detection and response can help address continuous monitoring and response to advance threats. In addition, an automated security protocol can kick people engaging in unusual activity off the network. Other automated vigilance includes spam filters, website blockers and an application list to prevent the installation of unauthorized software.
  • Prepare multiple incident response plans. These should define the meaning of an “incident” as well as the people in charge of activating those plans. Plans also must have guidelines for notifying these stakeholders and include a cyber policy that details how to offset costs and allocate resources post-breach.
  • Offload cyber risk to insurance coverage. Minimizing cyber incidents and their negative effects entails in-house management protocols. However, cyber insurance helps transfer that risk to a third party. Cyber insurance is expensive, and nearly impossible to procure without multifactor authentication or endpoint detection.

“The financial, operational and reputational consequences of an attack frequently extend well beyond the ransom demand itself and often outlast the technical remediation,” Cacciola warns.

“The fallout [includes] production shutdowns and spoiled inventory (operational); ransom payments, incident response costs and lost sales (financial); missed fill-rate commitments and empty shelves (supply chain); mandatory breach disclosures and regulatory scrutiny (legal); and lasting brand damage tied to consumer perceptions of food safety, even when product quality was never actually compromised. Data theft can also lead to secondary extortion well after initial recovery.

“Companies that have tested IT/OT segmentation, verified offline backups, and rehearsed a cross-functional incident response plan recover meaningfully faster than those that haven't,” Cacciola concludes.

About the Author

Dave Fusaro

Editor in Chief

Dave Fusaro has served as editor in chief of Food Processing magazine since 2003. Dave has 30 years experience in food & beverage industry journalism and has won several national ASBPE writing awards for his Food Processing stories. Dave has been interviewed on CNN, quoted in national newspapers and he authored a 200-page market research report on the milk industry. Formerly an award-winning newspaper reporter who specialized in business writing, he holds a BA in journalism from Marquette University. Prior to joining Food Processing, Dave was Editor-In-Chief of Dairy Foods and was Managing Editor of Prepared Foods.

Sign up for our eNewsletters
Get the latest news and updates