UK food chain cyber risks on the rise
National Audit Office warns cyber-attacks threaten food supply, adding to costs and price inflation.
The UK's food supply chain faces a growing threat from cyber-attacks that could cause serious disruption, according to a new report from the National Audit Office (NAO). The watchdog's warning follows damaging incidents at retailers Marks & Spencer and the Co-op last year, which have already pushed up operating costs and, in some cases, halted day-to-day operations.
NAO flags cyber as major threat
In its report published late last week, the NAO named cyber-attacks as one of the major threats to the food supply chain. It said the sector has shown some resilience to such attacks, but urged the government to work with industry to help mitigate their impact.
The report specifically calls on the Department for Environment, Food & Rural Affairs (Defra) to work closely with businesses to prevent severe shocks, and to draw lessons from approaches taken in other countries.
Attacks hit retailers hard
The report found that businesses in the food supply chain have faced increased costs and, in some cases, disruptions to day-to-day operations, citing the 2025 cyber-attacks on Marks & Spencer and the Co-op as examples.
Leading UK retailer Marks & Spencer estimated the cyberattack that took place in April last year will cost it around £136 million ($177.2 million) in total. The retailer said one of the earliest actions it took in its incident response was to disconnect its warehouse management systems, which in turn meant online and in-store orders were adversely impacted.
Food retailer the Co-op confirmed that thieves stole data from 6.5 million of the organization's members during a cyberattack last year.
Efficiency leaves supply chain vulnerable
The NAO's report highlights how the structure of the food supply chain itself compounds the risk. It notes that the way the chain has developed over time has prioritized efficiency, which reduces costs for businesses and consumers, but leaves the supply chain more vulnerable to disruptions.
“Defra and food supply chain stakeholders see risks increasing, and businesses are investing to address growing risks such as increased threats of cyber-attacks,” the report says. “Defra is less confident about the ability of businesses to withstand shocks without government intervention in the next five to 10 years because of increasing risks and the potential for more severe disruptions.”
Investment under pressure
Several food supply chain organizations cited the substantial investments businesses are making to manage the threat and incidence of cyber-attacks.
However, some said overall economic pressure on businesses is making this and other resilience investments more difficult, the NAO added. The watchdog also noted that cyber-attacks were among the disruptions that had increased operating costs for businesses and disrupted day-to-day operations, affecting their core digital systems.
Defra's own tech gaps
The report suggests Defra may not be best placed to offer tech advice. In 2023, the department admitted that two-thirds of its interactions with its 21 million customers still require paper-based forms, after decades of digital government initiatives. Additionally, 30 percent of its applications were out of support.
The department said it has undertaken specific food-related exercises which, since 2023, have focused on testing responses to a cyber incident affecting the food sector.
Why it matters
The NAO's warning comes as the food supply chain is already coping with rising costs, and cyber-attacks are adding to that pressure, potentially feeding into food price inflation. With Defra expressing limited confidence in businesses' ability to withstand major shocks without government help, the stakes for the sector are clear. The report suggests that without stronger collaboration between government and industry — and perhaps a more robust digital foundation within Defra itself — the UK's food supply could be increasingly exposed to disruptions that ripple from cyber incidents into everyday shelves.
Sources
- The Register Original source
Continue Reading
Windows Server 2016 hit by 0xc0000409 after August updates
Microsoft says August 2026 security updates trigger 0xc0000409 errors on Windows Server 2016 when Compatibility Appraiser is enabled.
Google Warns on AI Coding Tool Threats
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
Adobe Commerce bug exploited before hotfix
Sansec reports active attacks on a max-severity Magento flaw, with backdoors and secondary access found.