Kristin King on Cyberattacks Inside Our Food Chain
Two decades into a career in technology and security, Kristin King noticed something odd: the sector that puts food on every table in the country had almost no one watching how its systems could fail. A cybersecurity consultant and host of the podcast Bites and Bytes, King is the author of the forthcoming Wiley book Securing What Feeds Us: Cybersecurity in Food and Agriculture, which traces the technology threaded through every stage of the food system—from a sensor on a dairy farm to a router in a distribution warehouse.
“We can live without power. We can’t live without food or water. Our adversaries know that, and they exploit it.”
You have a forthcoming book, Securing What Feeds Us, which maps the full supply chain from farm to retail. What is the one thing you most needed readers to understand?
I wanted to lift the veil. I walked through every sector of the food and agriculture industry—agriculture, dairy, fisheries—and tried to make the invisible visible: what technology is actually in there and how it’s been attacked.
I also wanted people to think in systems. I linked the chapters deliberately, because no other critical infrastructure runs without food and agriculture. Soy is a good example—it’s not just what humans eat. It’s in tires, in the glue that holds your floorboards down, in clothing. If the soybean crop ever failed, we’d be in real trouble, and most people have never thought about that.
The moment that hit me hardest was the chapter on food security—not cybersecurity, access to food itself. I was writing about school lunches and realized the same supply system that feeds a school cafeteria often feeds elderly people’s home-delivered meals and hospital kitchens too. If a caterer or distributor is hit by a supply chain attack, that ripples into every one of those places at once, and these often aren’t ordinary meals—they’re medically necessary diets. That realization stuck with me: this is how far disruption reaches.
When a cyber incident hits a hospital, it causes delays in care. What happens when it hits a food facility or retailer?
When a hospital is hit, the harm is direct and immediate. Food is different—the damage moves through a chain of consequences before most people notice. I always point to one ransomware attack on a major beef processor: about $10 million in ransom alone, and certainly more to fix. When the ransomware hit, they halted every system—slaughterhouses, distribution, processing, everything—across Australia, Canada, and North America. It was severe enough that the U.S. couldn’t even price beef for a day, because the beef simply wasn’t moving.
The regional supply chain collapsed before it ever reached the national level, which is the part people miss. Picture it concretely: ranchers who’ve raised cattle for years now have those animals stuck in overcrowded trailers. That’s an animal welfare crisis and a human safety crisis at once. Once the plant comes back online, you’re rushing to process a backlog, which is exactly when the worst injuries in food production happen because production is moving faster than it should. Then you have to move an enormous surge of meat, and any spoils can lead to an environmental disaster stacked on top of the food safety, animal welfare, human safety, and economic damage. It’s a single event that fans out into almost every category of harm you can imagine.
You draw a direct line between attacks on food systems and cascading failures in water, energy, and logistics. Walk us through what that chain of consequences looks like.
Food and agriculture is the thing every other critical sector depends on. Water, energy, logistics—all of it needs people to be fed to keep functioning. I think about it this way: we can live without power. It would be miserable, but we’ve proven we can do it before. We cannot live without food or water. Our adversaries know that, and they exploit it. What worries me most isn’t abstract—it’s a cybersecurity event causing a foodborne illness outbreak, or a cybersecurity event causing an actual food shortage. You can see the signs if you’re paying attention—closed-door rooms with ranchers and producers, and almost everyone in that room has a story about being hit by a cyberattack or knowing someone who was. That’s from a small sample of people in one country. I can’t imagine what the full picture looks like.
Insider sabotage features prominently in your book. Most people picture cyberattacks as something that comes from outside—a criminal, a foreign government. What changes when the threat is already inside the building?
Insider threat changes everything, because the controls we build are designed to keep people out, not to account for someone who already has legitimate access and a reason to misuse it. In food and agriculture, radicalizing someone is often easier than hacking in. Disinformation plays into this directly. It’s very easy to hijack people’s emotions online around food, and if you can convince someone that what they’re doing is wrong, you’ve built yourself an insider threat without ever touching a firewall.
In food specifically, an insider doesn’t need sophisticated access to cause damage—they can alter allergen labeling, or introduce a chemical into a process where it shouldn’t be. Those aren’t hypotheticals. Those have happened. If you already have a disgruntled worker and someone plants the right idea in their head, you have the ingredients for exactly this kind of event—and it’s one of the hardest attack vectors to regulate, because you’re trying to manage human emotion.
Nation-states are targeting food production. How did we get to the point where such attacks are a matter of fact?
We got here for a very simple reason: we connected things to the internet without securing them. A default-password router on a farm network is an open door—that’s the whole story in one sentence. And using food as an attack vector against an adversary isn’t new. Historically, armies poisoned water supplies to damage a rival’s military readiness. We’re doing the same thing today; we’ve just traded old methods for hacking groups and drones.
Once nation-states realized how much of our food infrastructure was internet-connected and unsecured, they started probing it. Dairy has been hit hard by nation-state activity for years now. Dairy has become deeply embedded in daily life beyond a glass of milk—cheese, yogurt, ice cream, protein products—so disrupting a dairy supply chain is lucrative. Attackers know operators need to get back online fast, because the biological clock doesn’t stop for a ransom negotiation. That urgency means a payout is almost guaranteed, and often attackers walk away with more than the ransom itself through data theft.
The people running farms and processing plants are not cybersecurity professionals. What do you ask of them that is realistic?
If you’re securing food and agriculture operations, work with your food safety and food defense team rather than around them. Blending a cybersecurity culture with an existing food safety culture, so people understand that cybersecurity is food safety, must happen at the executive level. What isn’t realistic is expecting a farmer or a plant operator to become a security professional. Most of the technology they use wasn’t built with security in mind to begin with, so it’s unfair to hand them the entire burden and tell them to change a default password and hope for the best. The tech must be more secure by design. Asking someone who was never trained or hired as a technologist to defend against a nation-state is setting them up to fail.
You collected accounts from practitioners across the sector. What did you hear that surprised you most?
I’ve had people tell me, seriously, that there’s no real technology in food and agriculture, so there’s nothing to secure. I’ve had people say there’s no money in the sector, so it’s not worth pursuing for support. I’ve heard, “there’s plenty of food in the world, why does this matter?”—which tells me that person has never gone hungry.
A lot of it comes down to people not wanting one more thing to worry about. They want to believe the food system will simply always be there for them, so they don’t examine it. Meanwhile we’ve seen an increase of more than 100 percent in reported food and agriculture cyberattacks in just the last few years—and that’s only counting what gets reported. What we need is for more people to come forward about what happened to them, without shame, because right now the silence is protecting the problem, not the people.
You have one year and one change to make. What would you do?
That’s a tough one, honestly, but I’d want to see larger regional bodies put this on the agenda rather than just a national effort. Just getting it onto the docket at that level would be a win.
Beyond that, we need to get people to talk about this—more people asking questions, more people sharing about the incidents, more of this becoming a normal conversation. I want food and agriculture taken as seriously as oil and gas, because unlike oil and gas, everyone eats.