The National Audit Office has identified cyber-attacks as one of the major threats to the UK's food supply chain, following damaging incidents at retailers Marks & Spencer and the Co-op last year. In a report published late last week, the NAO said that while the sector has shown some resilience, risks are increasing in both likelihood and severity.
Gareth Davies, head of the NAO, said: “Recent disruptions have shown the resilience of the UK’s food supply chain, but risks are increasing in likelihood and severity. Defra should learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry.”
The report found that businesses in the food supply chain have faced increased costs and, in some cases, disruptions to day-to-day operations. Marks & Spencer estimated that the cyber-attack in April last year will cost it around £136 million ($177.2 million) in total. The retailer said one of its earliest incident response actions was to disconnect warehouse management systems, which adversely impacted online and in-store orders. Meanwhile, the Co-op confirmed that thieves stole data from 6.5 million of its members during a separate cyber-attack.
The NAO noted that the food supply chain has evolved to prioritise efficiency, reducing costs for businesses and consumers but leaving it more vulnerable to disruptions. It said Defra and food supply chain stakeholders see risks increasing, and businesses are investing to address threats such as cyber-attacks. However, the watchdog added that Defra is less confident about the ability of businesses to withstand shocks without government intervention in the next five to ten years.
Some organisations cited substantial investments made to manage cyber threats, but overall economic pressure on businesses is making further resilience investments more difficult. The Department for Environment, Food & Rural Affairs (Defra) said it has undertaken specific food-related exercises since 2023, focusing on testing responses to a cyber incident affecting the food sector. However, the department may not be best placed to offer tech advice; in 2023 it admitted two-thirds of its interactions with 21 million customers still require paper-based forms, and 30% of its applications were out of support.