Tag Archives: food defense

Cybersecurity

Food Protection: Challenges and Opportunities

By Food Safety Tech Staff
No Comments
Cybersecurity

The recent ransomware attacks on U.S. Government agencies and hundreds of private U.S. companies is a reminder that cybersecurity remains one of the most significant challenges facing the food and agriculture (Ag) industries today. It was a concern that took center stage at a recent OSPA (Outstanding Security Performance Awards) webinar entitled “Food Protection: The Ultimate Security Challenge?

Presenters Megan Francies, Food Protection Manager at LambWeston, Mark Wittrock, Assistant Director of Health, Food and Agriculture Resilience, Office of Health Security, U.S. Dept of Homeland Security, David Goldenberg, Chief of InfraGard National Sector Security and Resilience Program (NSSRP), Food and Agriculture Sector at UC Davis, Andy Griffiths, European Regional Security Director at Firmenich, Jason Bashura, MPH, RS, Sr. Manager of Global Food Defense at PepsiCo, and moderator Professor Martin Gill, Director of Perpetuity Research & Consultancy International (PRCI), addressed key questions, including:

  • How well protected is our food supply?
  • What are the risks and are we sure we are preparing and responding effectively?
  • How can increased information sharing between and amongst the public and private sectors help to reduce these risks?

Growing Risk for Food and Ag

Griffiths noted that due to hostile actors and regional conflicts, supply chains are seeing increased vulnerability making the implementation of effective transportation security and cargo theft mitigation more important—and more challenging—than ever.

In the U.S. there is a national response framework, but as Wittrock highlighted both public and private entities need to think broadly and holistically to prepare for and coordinate a response to attacks when they occur.

The need for strategic alliances and information sharing and analysis centers (ISACs) that allow organizations to share adverse events and strategies are important, but when there are many stakeholders with different—and often competing—interests, it is difficult to communicate in a language and in a timeline that meets the ideal requirements, added Wittrock. When living in an increasingly global world, we also must remember that “your friends today are not necessarily your friends tomorrow,” he said.

The risk of copycat attacks when an event occurs is also a concern, said Goldenberg.

The Need for Communication and Information Sharing

Francies championed the benefits of transparent and effective communication between government and the private sector. Her view was echoed by several panelists who encouraged more opportunities for organizations to share security breaches in a non-attributable manner to help others prepare for and reduce commonly experienced risks.

When asked, what is the biggest barrier to communication and information-sharing, Wittrock pointed to siloed discussion among key stakeholder groups. “When looking across the entirety of the food and Ag enterprise, it includes many different parts, pieces and stakeholders,” he said. “The communication happens largely in the vacuum of one particular discipline or stakeholder group. What’s lacking first and foremost is that strategic dialogue across communities.”

Efforts to improve communication are often challenged by lack of clear channels through which stakeholders can share information, said Francies. “A lot of times the communication goes out in a way that is not accessible to everybody, and it’s often last minute so people aren’t prepared to provide the insights that we need,” she said. “We need a defined way or area to communicate that is well known and publicly accessible to industry.”

In addition to clear channels, trust needs to be established among organizations and government agencies as well. “Industry has to have trust that the information they are sharing is going to be handled appropriately and that they are getting information that’s trustworthy from other sources,” said Goldenberg. “Unless there is trust across all the sectors and agencies among food and Ag, there is never going to be good communication.”

The need to protect brand reputation is often at the heart of unreported security incidents, said Griffiths. “But I do think there is a willingness to share certainly within industry and there is a need within law enforcement to obtain that information to determine how big the problem or issue is,” he added. “The problem is, there is no mechanism by which this information can be exchanged in a safe and confidential way that maintains the integrity of both the source and also the information that’s being shared. Yet, unless everyone shares across the board through collaboration or cooperation, we’re forever on the run.”

In light of the significant challenges raised related to communication and information sharing, Bashura shared successes that are taking place, including the ASIAS Aero Portal, which was developed by the FFA and Mitre to ensure security of the aviation industry, Operation Opson, a joint operation between Europol and INTERPOL developed to target fake and substandard food and beverages, the Food Industry Intelligence Network, and resources available through the Food Defense Resource Center. In terms of the importance of building trust among industry, Bashura encouraged leaders to reach out to each other. “Pick up the phone. Make a call, send an email, or shoot a text,” he said.

 

 

George Gansner

Now is the Time to Reassess the Food Industry’s Approach to Managing Risk

By George Gansner
No Comments
George Gansner

The food industry is under intense scrutiny, with concerns about food safety and quality making headlines around the world. Today, the industry faces unprecedented challenges when it comes to ensuring the safety and security of the global food supply chain. Leaders need to manage known concerns such as foodborne pathogens, food fraud and contamination, as well as emerging challenges, including ingredient scarcity and changes in consumer preferences that have created the need to reformulate recipes quickly, source from new suppliers, and increase imports—all of which contribute to increased risks.

Due to climate change and shifting environmental factors we are seeing crop failures, and new bacteria and antimicrobial resistance to foodborne pathogens, which increase the cost of managing food safety. As consumers demand greater transparency and look to place more trust in the food chain, changing buyer habits further compound these challenges by putting a greater onus on food handling, production, manufacturing, and supply companies to provide more education to consumers about foodborne illnesses.

Recalls are the biggest threat to a brand’s profitability and reputation, and this threat is growing. According to FDA reports, recalls increased by 700% in 2022, with undeclared allergens being the leading cause for the last five years. The Food Safety Authority in the UK tells a similar story with undeclared allergens accounting for 84 of the 150 recalls last year, followed by salmonella, listeria, and foreign body contamination.

As food regulations become more complex to navigate, it is now essential to reassess the industry’s approach to managing risk. Protocols such as VACCP and TACCP are regularly used as part of a solid food defense program to identify risks. But the traditional approach of relying solely on regulations and compliance-based systems is no longer sufficient to ensure food safety in today’s complex, volatile and globalized food supply chains. Now is the time to implement a more holistic and dynamic risk-based approach to managing food safety more effectively.

What Is a Risk-Based Approach to Food Safety?

A risk-based approach allows the industry to proactively identify potential food safety risks and take appropriate measures to mitigate them, rather than simply responding to problems as they arise. For example, mature food businesses are building on food safety management systems with food safety audits to identify and manage risk to stay ahead of the curve. A risk-based approach helps underpin the continuous improvement process and, by doing so, demonstrates the ability of a company to be a trusted partner in the global food supply chain.

One of the key aspects of a risk-based approach to managing food safety is proactive intervention and control, using relevant data analysis stored in a cloud-based platform. All stakeholders need access to accurate and actionable data during risk assessment and management to make informed decisions. However, there are many barriers to accessing risk-related data for smaller operators, many of which are still working in a largely manual way.

Data must be collated from across the business, and multiple data sources need to be collected and appropriately analyzed to protect both the brand and public health. It is estimated that we are at least 10 years away from any type of interoperability of industry data, which will allow better transparency and visibility of risk across the supply chain.

Stay Ahead of Emerging Legislation

Visibility of the emerging legislation in source countries of ingredients and raw materials is critical, as are contingency sourcing plans and good risk analysis protocols. Food integrity needs to be a standing agenda point as part of internal meetings, and ESG policies need to be visibly delivered. The industry needs to ensure that it is aware of changes in regulations that could impact the safety and quality of its products through horizon scanning tools. There is also an onus on the industry to make its risk assessments more dynamic to incorporate change at a frequency that is appropriate for risk evaluation with effective crisis management plans in place.

Supply Chain Management Is Critical

Sourcing raw materials and ingredients across supply chains requires best practices. You must ensure that your supply chain partners and suppliers know how to manage a crisis and that emerging risks are shared across the supply chain. Quality, food safety, and regulatory divisions must actively participate in risk assessments and receive relevant data and communication. ESG policies also need to include the supply chain; leaders in this space need to be able to verify that these policies are delivering.

Marketing claims must be vetted and aligned with regulations and markets where products are sold. Procurement, supply chain and communication, and external partners such as NGOs and consumer associations are important groups to involve in risk profiling and ongoing management. While managing emerging issues and horizon scanning is critical, it is also important to remain vigilant on the basics, as most food safety and allergen incidents are known risks.

Detecting Food Fraud

Opportunistic food fraud cases are rising in the high food inflation market, with recent examples including everything from adulterated honey to the mislabeling of beef. To deter food fraud, businesses need to focus on risk-based auditing and testing through sampling programs. Knowing your supply chain, shopping around safely, being vigilant about ingredients and specifications, utilizing training, and building awareness and readiness are imperative to deter food fraud and create a culture of confidence and greater food safety.

Think Differently About Managing Risk

Now is the time for the food industry to reassess its approach to managing risk. A risk-based approach focusing on prevention, continuous improvement, and stakeholder collaboration is necessary to ensure a safe and secure food supply chain in an increasingly complex and challenging environment. The industry must prioritize data accessibility and accuracy, have a crisis management plan, be aware of emerging legislation, and include ESG policies in its risk management strategies. By focusing on risk-based auditing and testing, the industry can deter food fraud and create a culture of confidence.

The probability of eliminating all risks is very low, so the food industry must pivot and be agile to challenge the traditional approaches to managing food safety. It is time to think differently about managing risk and adopt new practices that promote prevention and collaboration.

Joseph Carson

Strategies To Identify and Prevent Cyber Attacks

By Joseph Carson
No Comments
Joseph Carson

Managing and combating cybercrime is no small feat; it can take over 200 days for companies to detect a cyber breach. The reason being cyber criminals often stay hidden even after gaining access to systems. They lie in wait for the best moment to access the information they want. Once they have it, they may use it to steal money or proprietary information or to collect a ransom. They also may sell access and information to other criminals who will take more aggressive means to exploit the organization.

Preventing cybercrime requires education and cooperation throughout an organization. Following are seven key components of cybersecurity food businesses should embrace to protect their businesses and products.

1.   Education and Awareness

One of the most effective countermeasures to cybercrime is building a culture of cyber defense and awareness that empowers all employees to ask for guidance and speak up when they see a suspicious situation. Educate employees on how they can prevent nefarious activity on their computers by:

  • Identifying suspicious applications with warnings and popups
  • Flagging suspicious emails with hyperlinks, attachments or unknown senders
  • Not clicking on links or ads from unfamiliar sources
  • Verifying the trustworthiness of a site before inputting credentials
  • Limiting activities on unsecured public Wi-Fi networks

This helps employees not only avoid breaches, but identify and report suspicious activity to help prevent cyber attacks.

Training should be top-down, beginning with the executive suite and department heads. This ensures that there is always someone accountable for implementing and maintaining security measures. From there, the rest of the team can be trained to assess and prevent cybersecurity threats and risks.

2.   Implement and Enforce Mobile App Security

Mobile apps on smartphones and tablets are at risk of security breaches that can expose large amounts of user data. All mobile apps have security controls to help developers design secure applications, but it’s up to the developer to choose the right security options.

Common problems with mobile apps may include:

  • Storing or unintentionally leaking data that could be read by other applications
  • Using poor authentication and authorization checks that could be circumvented by bad actors
  • Using data encryption methods that are vulnerable or easy to break
  • Transmitting sensitive data without proper encryption online

A simple app may not seem like a big deal, but they can allow a hacker to gain access to employee computers and networks. The following measures help improve mobile app security:

Guard sensitive information. Confidential data stored in an app without security measures in place are a target for hackers using reverse-engineering codes. The volume of data on the device should be reduced to minimize the risk.

Consider certificate pinning. Certificate pinning is an operating process that helps with app defense against intermediary attacks that occur on unsecured networks. There are limitations to this process, however, such as lack of support for network detection and response tools. Certain browsers make certificate pinning difficult, making it more difficult for hybrid applications to run.

Minimize application permissions. Permissions allow applications to operate more effectively, but they also open vulnerabilities to cyber attacks. Apps should only be given permission for their key functions, and nothing more, to reduce this risk.

Enhance data security. Data security policies and guidelines should be implemented. Measures such as having well-implemented data encryption, security tools and firewalls can protect information that’s being transferred, for example.

Do not “save” passwords. Some applications allow users to save their passwords for convenience, but if a theft occurs, these passwords offer access to a lot of personal information. If the password is unencrypted, it has a better chance of being stolen. Ultimately, users should never save passwords on mobile apps.

Log out after sessions. Users often forget to log out of an app or website, which can increase the risk of a breach. Apps with sensitive information, such as payment or banking apps, often enforce session logouts after a certain period of time, but it’s important for users to also get in the habit of logging out of all apps when they’re finished using them.

Add multi-factor authentication. Multi-factor authentication adds another layer of security for users on an app. This method can also shore up security for users with weak or old passwords that are easy to breach. With multi-factor authentication, the user receives a code that needs to be entered with the password to log in. The code may be sent through email, the Google Authenticator app, SMS or biometric methods.

3.   Analyze Logs for Suspicious Activity

Companies should continuously analyze security logs to identify unusual or suspicious activities, such as logins or application executions that occur outside of usual business hours. These measures not only help identify criminal activities, they can help companies determine the root cause of a breach and how it can be prevented in the future.

4.   Keep Systems Patched and Current

Patches identify and correct vulnerabilities in software and applications that may make them susceptible to cyber attacks. All systems and applications should be kept up to date with the latest security patches to prevent hackers and cyber criminals from accessing systems through existing vulnerabilities. Patching and updates may also fix bugs, add new features or increase stability to help the app or software perform better and reduce access points for hackers.

5.   Use Strong Passwords and Protect Privileged Accounts

Any password used in your organization should be strong and unique to the account. It’s also important for employees to change their passwords often. Most applications do not alert users to older or weak passwords. Accountability for password protection falls on the user.

If employees have multiple accounts and passwords, companies can create an enterprise password and account vault to manage and secure credentials. Encourage employees to avoid using the same password multiple times.

If employees have local administrator accounts or privileged access, that has a huge impact on organizational security. If a single system or user account is compromised, it can put the entire organization at risk. Your company should continuously audit and identify privileged accounts and applications that require privileged access and remove administrator rights when they’re not needed. You should also adopt two-factor authentication to prevent accounts from being hacked.

6.   Do Not Allow Installation of Unapproved or Untrusted Applications

Organizations that allow users to have privileged access also allow these users to install and execute applications as needed, no matter where they source the installation. As a result, ransomware and malware are able to infect your system easily, and the cyber criminal can install tools to permit future access at any time.

Privileged users may read emails, browse sites, click on links or open documents that install malicious tools onto their devices. The criminal now has access and may be able to launch attacks throughout the organization’s system or demand ransom for unlocking proprietary data.

There are security controls that can prevent applications and tools from being installed. They include: Application Allowlisting, Dynamic Listing, Real-Time Privilege Elevation and Application Reputation and Intelligence.

7.   Be Deceptive

Whether online or in person, predictability is a boon for criminals. Burglars stake out houses and look for residents with predictable routines, and the same is true of cyber criminals. Automation makes this even easier with scans that are run on a routine, and patches that are implemented on the same day every month, for example.

A predictable company is a vulnerable one, so it is vital to be deceptive. Use random activities and an ad-hoc approach for updates and assessments. With this method, hackers have a more difficult time staying hidden and it’s easier to detect cyber attacks as soon as they occur to mitigate their effects.

Cybercrime is a risk facing all businesses, and the food industry is no exception. Companies that take a proactive approach are in a much stronger position to protect against cyber threats and shore up security. No method is foolproof, but if a breach does occur, identifying it early and mitigating its effects can make a world of difference for your company’s financial health and reputation.

Debra Freeman FPDI

Food Protection and Defense Institute Announces New Director

By Food Safety Tech Staff
No Comments
Debra Freeman FPDI

Debra Freedman, Ph.D., is the new director of the Food Protection and Defense Institute (FPDI) at the University of Minnesota. Dr. Freedman is an experienced educator, curriculum scholar and researcher. She has worked at FPDI since 2014, collaborating with researchers and scholars, government officials (USDA, FDA, DHS), food industry professionals, public school teachers and Emergency Responders (e.g., Rapid Response Teams, Law Enforcement). Her focus is on development of food defense curricula, online learning programs, learning objects, workshops, certificate programs, professional courses and training guides.

“Over the past four years, FPDI transitioned from a Homeland Security Center of Excellence with a large research portfolio to a successful, self-sustaining center focused on workforce development and education in the food defense and intentional adulteration arenas. Deb has been with FPDI for eight years leading the education portfolio so it is a natural evolution for her to assume the director role,” said outgoing director Jennifer van de Ligt, Ph.D. “I would also like to thank everyone for such an enjoyable tenure as FPDI director. The communities of expertise worldwide that this role has offered have been extraordinary. I will carry the experiences into my future endeavors as I transition to a regulatory and scientific affairs role in the private sector.”

 

Food Safety Consortium

10th Annual Food Safety Consortium Back In-Person with New Location and Focus

By Food Safety Tech Staff
No Comments
Food Safety Consortium

EDGARTOWN, MA, Feb. 23, 2022 – Innovative Publishing Company, Inc., publisher of Food Safety Tech, has announced the dates for 2022 Food Safety Consortium as well as its new location. Now in its 10th year, the Consortium is moving to Parsippany, New Jersey and will take place October 19-21.

“COVID-19’s impact on the food safety community has been significant and its impact will continue to be felt for years,” said Rick Biros, president of Innovative Publishing Company and director of the Food Safety Consortium, in his blog about the current state of the food industry. “The goal now is not to get food safety back to 2019 levels but to build it better. These issues must be discussed among peers and best practices must be shared. This year’s event will help facilitate this much needed critical thinking and meeting of the minds.”

The 2022 program will feature panel discussions and concurrent breakout sessions intended for mid-to-senior-level food safety professionals that address important industry issues, including:

  • C-Suite Communication
  • Employee Culture
  • What is the State of Food Safety and Where is it Going?
  • Audits: Blending in-person with Remote
  • Quality 4.0: Data Analytics and Continuous Improvement
  • Digital Transformation of Food Safety & Quality
  • Technology: How Far is Too Far?
  • The Days FSQA Folks Fear the Most
  • FSQA’s Role in Worker Rights and Conditions
  • Analyzing and Judging Supplier’s Human Rights and Environmental Records
  • New Trends in Food Fraud
  • Diversification of Supply Chain Capacity
  • Product Reformulation Challenges due to Supply Chain Challenges
  • Traceability
  • Preparing the Next Generation of FSQA Leaders
  • Food Defense & Cybersecurity
  • Food Safety and Quality in the Growing World of e-commerce
  • Quality Helping Improve Manufacturing Efficiency with How Does Quality Show Value to the Organization?

The event will also feature special sessions led by our partners, including the Food Defense Consortium, GFSI, STOP Foodborne Illness and Women in Food Safety.

Tabletop exhibits and custom sponsorship packages are available. Contact Sales Director RJ Palermo.

Registration will open soon. To stay up to date on registration, event keynote and agenda announcements, opt in to Food Safety Tech.

About Food Safety Tech

Food Safety Tech is a digital media community for food industry professionals interested in food safety and quality. We inform, educate and connect food manufacturers and processors, retail & food service, food laboratories, growers, suppliers and vendors, and regulatory agencies with original, in-depth features and reports, curated industry news and user-contributed content, and live and virtual events that offer knowledge, perspectives, strategies and resources to facilitate an environment that fosters safer food for consumers.

About the Food Safety Consortium

Food companies are concerned about protecting their customers, their brands and their own company’s financial bottom line. The term “Food Protection” requires a company-wide culture that incorporates food safety, food integrity and food defense into the company’s Food Protection strategy.

The Food Safety Consortium is an educational and networking event for Food Protection that has food safety, food integrity and food defense as the foundation of the educational content of the program. With a unique focus on science, technology and compliance, the “Consortium” enables attendees to engage in conversations that are critical for advancing careers and organizations alike. Delegates visit with exhibitors to learn about cutting-edge solutions, explore three high-level educational tracks for learning valuable industry trends, and network with industry executives to find solutions to improve quality, efficiency and cost effectiveness in the evolving food industry.

Alert

New Physical Security Guidance Seeks to Provide Risk-Based Food Defense Insights to the Food and Beverage Industry

By Food Safety Tech Staff
No Comments
Alert

The ASIS Food Defense and Agriculture Community (FDASC) released a recently developed resource and is currently seeking contributions and feedback to ensure that all perspectives are considered and represented. The document, “Physical Security Guidance for the Food and Beverage Industry to Improve Food Defense Outcomes” was developed through a partnership of food defense professionals, intending to provide a “security lens” to help the food and beverage industry consider these risk-based mitigation strategies.

Comments and feedback on the document are welcome by February 15, 2022. Please return comments to Frank Pisciotta (Business Protection Specialists) and/or Rich Widup (Reckitt).

When providing comments on the guidance document draft, please specify the following:

  • Page number
  • Line # start and line # end
  • Observation on current content
  • Proposed resolution
  • Reference (if applicable)

In addition, FDASC will be hosting an upcoming session to discuss comments received prior to January 28, 2022. If you are interested in providing comments or joining the working session on February 1, 2022, please contact ASIS FDASC Chairman Frank Pisciotta or vice-chair Jason Bashura.

The ASIS FDASC plans to talk through the Physical Security guidance during a future Food Defense Consortium meeting that will be convened during the next Food Safety Consortium. More information on these events is forthcoming. More information about the Food Defense Consortium can be found in Food Safety Tech’s Food Defense Resource Center.

 

About ASIS International

Founded in 1955, ASIS International is a global community of security professionals, educators, and 11 practitioners, all of whom has a role in the protection of assets – people, property, and/or information. Our members represent virtually every industry in the public and private sectors, and organizations of all 14 sizes. From entry-level managers to Chief Security Officers (CSOs) to CEOs, from security veterans to 15 consultants and those transitioning from law enforcement or the military, the ASIS community is global and 16 diverse.

About the Food Defense Consortium

The Food Defense Consortium is a voluntary, collaborative opportunity for Food and Beverage (F&B) Industry & non-government organizations (NGOs) to communicate in an Anti-trust environment to advocate for F&B industry perspectives pertaining to developing and sharing Food Defense best practices and helping firms to gain insights to aid in compliance with the FSMA Intentional Adulteration (IA) Rule.

Food Safety Consortium Virtual Conference Series

2021 FSC Episode 8 Preview: Food Defense: Yesterday, Today and Tomorrow

By Food Safety Tech Staff
No Comments
Food Safety Consortium Virtual Conference Series

You don’t want to miss this week’s episode of the 2021 Food Safety Consortium Virtual Conference Series. The session, Food Defense: Yesterday, Today and Tomorrow, will discuss pre-FSMA IA Rule voluntary food defense programs, compliance timelines, and regulatory compliance vs. enterprise risk based approaches to food defense. Presenters will address the status of Food Defense plan quick checks and share insights on Food Defense Plan reanalysis. Participants will gain insights on threat intelligence sources and food defense-based research updates. Other topics to be covered include a brief overview of recently released insider risk mitigation reference material, cyber/IT “vulnerabilities”, critical infrastructure protection and how an all-hazards mindset to “all of the above” can help to contribute to a Food Protection Culture.

The following is the line up of speakers for Thursday’s episode, which begins at 12 pm ET.

  • Jason Bashura, PepsiCo (moderator)
  • Food Defense Yesterday with Raquel Maymir, General Mills
  • FBI HQ Perspectives of Food Defense with Helen S. Lawrence and Scott Mahloch, FBI
  • Food Defense Tomorrow with Frank Pisciotta, ASIS Food Defense & Ag Security Community and Cathy Baillie, Mars, Inc.
  • Risk-based Food Defense with Jessica Cox, Department of Homeland Security, Chemical Security Analysis Center
  • Food Defense & Supply Chain Perspectives: Regional Resilience Action Plan with Jose Dossantos, Department of Homeland Security/CISA

The Fall program runs every Thursday from October 7 through November 4. Haven’t registered? Follow this link to the 2021 Food Safety Consortium Virtual Conference Series, which provides access to all the episodes featuring critical industry insights from leading subject matter experts!

Alert

National Counterintelligence and Security Center (NCSC) and DoD’s Center for Development of Security Excellence Publish Risk Mitigation Guide for Food and Agriculture Sector

By Food Safety Tech Staff
No Comments
Alert

Today the National Counterintelligence and Security Center (NCSC) and the Department of Defense’s Center for Development of Security Excellence (CDSE) published a risk mitigation guide to help organizations in the food industry understand insider risks, establish insider risk programs, and develop mitigation strategies. The “Insider Risk Mitigation Programs: Food and Agriculture Sector Implementation Guide” was developed in collaboration with federal partners and stakeholders, including the FDA.

The Fall edition of the 2021 Food Safety Consortium Virtual Conference Series will feature an episode on Food Defense Strategies | Register Now“Organizations in the food and agriculture sector play a critical role in protecting public health and safety, as well as U.S. economic and national security,” said NCSC Acting Director Michael Orlando in an NCSC press release. “This guidance is designed to help these entities create effective programs to deter, detect, and mitigate potential insider threats before they can cause harm.”

The guide includes links to federal resources in food and agriculture, and case studies concerning food adulteration, IP theft and active shooter incidents that were carried about by insiders. Any organization can be exposed by an insider threat, which is a person who has authorized access and uses it to commit harm to the organization. “Those with authorized access to facilities, personnel, or information can include employees, vendors, partners, suppliers, or others,” according to NCSC. “Most insider threats exhibit risky behavior prior to committing negative workplace events. If identified early, many insider threats can be mitigated before harm to the organization occurs.”

Insider threats can target food organizations through food adulteration, food fraud, theft and workplace violence.

Cybersecurity

As Cyber Threats Evolve, Can Food Companies Keep Up?

By Maria Fontanazza
No Comments
Cybersecurity

The recent cyberattack that shut down meat supplier JBS should be a wakeup call to the food industry. These attacks are on the rise across industries, and food operations both large and small need to be prepared. In a Q&A with Food Safety Tech, Brent Johnson, partner at Holland & Hart, breaks down key areas of vulnerability and how companies in the food industry can take proactive steps to protect their operations and ultimately, the consumer.

Food Safety Tech: Given the recent cyberattack on JBS, how vulnerable are U.S. food companies, in general, to this type of attack? How prepared are companies right now?

Brent Johnson, Holland & Hart
Brent Johnson, partner, Holland & Hart

Brent Johnson: Food companies are in the same boat as other manufacturers. Cyber threats are constantly evolving and hackers are developing increasingly sophisticated delivery systems for ransomware. Food companies are obviously focused on making and delivering safe and compliant products and getting paid for them. Cybersecurity is important, but it’s difficult for manufacturers to devote the resources necessary to make their systems bulletproof when it’s an ancillary part of their overall operations and a cost driver. Unfortunately, hackers only have one job.

We tend to think of big tech and financial services companies as the prime targets for ransomware attacks because of the critical nature of their technology and data, but food companies are really no different. Plus, unlike tech companies and the financial services industry, food companies haven’t, as a general matter, developed the robust defenses necessary to thwart attacks, so they’re easier targets.

Food Safety Tech: What is the overall impact of a cyberattack on a food company, from both a business as well as a consumer safety perspective?

Johnson: It may come as a bit of a surprise to those who don’t work in the food industry, but food production (from slaughterhouses to finished products) is highly automated and data driven. That’s one of the lessons of the JBS ransomware attack. The attack shut down meat processing facilities across the United States and elsewhere. I work in Utah and the JBS Beef Plant in Hyrum was temporarily shut down. JBS cancelled two shifts at its meatpacking operation in Greeley, Colorado where my firm has a large presence as well, because of the ransomware attack. So, the impact on a food company’s business from a successful ransomware attack is dramatic.

On the consumer safety side, a ransomware attack that impacts automated safety systems would cause significant problems for a food manufacturer. Software controls much of the food industry’s safety systems—from sanitation (equipment washdowns and predictive maintenance) to traceability (possible pathogen contamination and recalls) to ingredient monitoring (including allergen detection). Every part of a food company’s production system is traced, tracked, and verified electronically. A ransomware attack on a food maker would very likely compromise the company’s ability to produce safe products.

Food Safety Tech: What proactive steps should food companies be taking to protect themselves against a cyberattack?

Johnson: I wish there was an easy and foolproof system for food companies to implement to protect against cyber attacks, but there isn’t. The threats are always changing. The Biden Administration’s recent memorandum to corporate executives and business leaders on strengthening cyber defenses is a good starting point, however. The White House’s Deputy National Security Adviser for Cyber and Emerging Tech, Anne Neuberger, reiterated the following “Five Best Practices” from President Biden’s executive order. These practices are multifactor authentication, endpoint detection and response, aggressive monitoring for malicious activities on the company’s networks and blocking them, data encryption, and the creation of a skilled cyber security team with the ability to train employees, detect threats and patch system vulnerabilities.

Food Safety Tech: Are there specific companies within the food industry that are especially susceptible?

Johnson: Not really. Hackers are opportunistic and look for the paths of least resistance. That said, as can be seen from the recent Colonial Pipeline and JBS ransomware attacks, hackers have transitioned from the early days of going after individuals and small businesses to whale hunting. The money is better.

It’s important to observe that the recent attacks have been directed at industries that present national infrastructure concerns (oil, the food supply). There’s no evidence of any involvement by a foreign government in these attacks, but it’s a fair question as to whether the hackers, themselves, expect that the federal government will step in at some point to assist the victims of cyber attacks financially due to their critical importance.

Food Safety Tech: Where do you see the issue of cybersecurity and cyberattacks related to the food industry headed in the future?

Johnson: Other than the certainty that the attacks will increase in both intensity and sophistication, I have no prediction. It’s not a time for complacency.

Cybersecurity

Cyberattack on Meat Supplier JBS Forces Shut Down of Multiple U.S. Plants

By Food Safety Tech Staff
No Comments
Cybersecurity

On Sunday Brazil-based JBS was targeted by a cyberattack that forced the shutdown of its facilities in Arizona, Colorado, Michigan, Nebraska, Pennsylvania, Texas, Utah and Wisconsin. The ransomware attack affected servers that support the company’s IT systems in North America and Australia. It is suspected to have originated from an organization based in Russia, according to reports.

It is expected that most of the company’s beef, pork, poultry and prepared food plants will be operational today, JBS said in a statement last night. Thus far the company is unaware of any customer, supplier or employee data that has been compromised.

Cyberattacks coming from Russia have increased at a significant rate and are likely to continue. “The fact that this kind of activity is happening with a relatively high frequency and also all signs sort of leading back to Russia, that is very disturbing,” said Javed Ali, a former National Security Council director of counterterrorism, in an ABC News report. “I don’t think we’ve seen a period of this kind of high-intensity cyber operations from Russian soil directed against a variety of different U.S. targets arguably ever, unless the government has been tracking this and the public details of those types of operations haven’t been revealed before.”