UK food supply chain vulnerable to cyber-attacks, warns National Audit Office

Watchdog calls for stronger government-industry cooperation after costly breaches at Marks & Spencer and Co-op

edit
By LineZotpaper
Published
Read Time3 min
The UK's food supply chain faces increasing risk from cyber-attacks, with recent breaches at major retailers costing hundreds of millions and exposing millions of customer records, according to a report by the National Audit Office (NAO). The watchdog warns that the government must work more closely with industry to prevent severe disruptions.

The National Audit Office has identified cyber-attacks as one of the major threats to the UK's food supply chain, following damaging incidents at retailers Marks & Spencer and the Co-op last year. In a report published late last week, the NAO said that while the sector has shown some resilience, risks are increasing in both likelihood and severity.

Gareth Davies, head of the NAO, said: “Recent disruptions have shown the resilience of the UK’s food supply chain, but risks are increasing in likelihood and severity. Defra should learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry.”

The report found that businesses in the food supply chain have faced increased costs and, in some cases, disruptions to day-to-day operations. Marks & Spencer estimated that the cyber-attack in April last year will cost it around £136 million ($177.2 million) in total. The retailer said one of its earliest incident response actions was to disconnect warehouse management systems, which adversely impacted online and in-store orders. Meanwhile, the Co-op confirmed that thieves stole data from 6.5 million of its members during a separate cyber-attack.

The NAO noted that the food supply chain has evolved to prioritise efficiency, reducing costs for businesses and consumers but leaving it more vulnerable to disruptions. It said Defra and food supply chain stakeholders see risks increasing, and businesses are investing to address threats such as cyber-attacks. However, the watchdog added that Defra is less confident about the ability of businesses to withstand shocks without government intervention in the next five to ten years.

Some organisations cited substantial investments made to manage cyber threats, but overall economic pressure on businesses is making further resilience investments more difficult. The Department for Environment, Food & Rural Affairs (Defra) said it has undertaken specific food-related exercises since 2023, focusing on testing responses to a cyber incident affecting the food sector. However, the department may not be best placed to offer tech advice; in 2023 it admitted two-thirds of its interactions with 21 million customers still require paper-based forms, and 30% of its applications were out of support.

§

Analysis

Why This Matters

  • The UK's food supply chain is a critical national infrastructure; cyber-attacks can disrupt food availability, increase prices, and undermine consumer confidence.
  • The NAO's warning signals that current resilience measures may be insufficient, especially as businesses face economic pressures that limit investment in cybersecurity.
  • If Defra cannot effectively coordinate with industry, the UK could face more severe shocks, particularly given the increasing frequency of cyber-attacks targeting retailers.

Background

The UK's food supply chain has become highly efficient and interconnected over decades, but this efficiency comes at the cost of fragility. A single cyber-attack on a major retailer or logistics provider can cascade through the system, affecting everything from warehouse operations to online ordering. The NAO report follows a series of high-profile breaches in 2025 that demonstrated these vulnerabilities. The government has acknowledged the need for better preparedness, but questions remain about whether Defra has the technological capability to lead.

Key Perspectives

  • NAO (Watchdog): Cyber-attacks are a growing, severe risk. Defra must learn from other countries and test emergency plans with industry and local government. Businesses need support to make resilience investments.
  • Retailers (M&S, Co-op): They face significant financial and operational impacts from cyber-attacks. They are investing in security but are constrained by economic pressures. Incident response often involves disconnecting systems, which itself disrupts operations.
  • Defra (Government): The department has conducted exercises focused on cyber incidents in the food sector since 2023. However, its own digital infrastructure is outdated, raising doubts about its ability to provide effective technical guidance to industry.
  • Consumers: Ultimately bear the cost of disruptions and data breaches. They may face higher prices or reduced availability if supply chain resilience is not strengthened.

What to Watch

  • Further cyber-attacks on UK food retailers or logistics providers, which could test resilience plans.
  • Defra's response to the NAO's recommendations, including any new initiatives or funding for industry collaboration.
  • The level of investment by food supply chain businesses in cybersecurity relative to other pressures. Economic downturns could slow progress.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.