Watchdog Warns On Food Supply Cyber Risk
Britain’s National Audit Office has issued a stark warning about growing cyber security threats facing the country’s food supply chain, pointing to costly attacks on major retailers Marks and Spencer and the Co-op as evidence that risks within the sector are increasing in both likelihood and severity. The public spending watchdog’s report calls on the

Britain's National Audit Office has issued a stark warning about growing cyber security threats facing the country's food supply chain, pointing to costly attacks on major retailers Marks and Spencer and the Co-op as evidence that risks within the sector are increasing in both likelihood and severity. The public spending watchdog's report calls on the Department for Environment, Food and Rural Affairs to work more closely with industry partners to help prevent severe disruption to food availability.
Gareth Davies, head of the National Audit Office, said recent disruptions have demonstrated genuine resilience within the UK's food supply chain, but warned that underlying risks continue growing more likely and more severe over time. He specifically called on Defra to study approaches taken by other countries and strengthen emergency preparedness by testing response plans jointly with local government and industry partners, rather than relying on isolated, single organization contingency planning.
The report's warnings carry substantial financial weight given recent real world examples cited within the assessment. Marks and Spencer has estimated the total cost of a cyberattack it suffered in April last year at approximately one hundred thirty six million pounds, reflecting the severe operational and reputational damage such incidents can inflict on major retailers. The Co-op, meanwhile, confirmed that attackers stole personal data belonging to six and a half million members during its own separate security incident around the same period.
Beyond these headline grabbing retail breaches, the National Audit Office also highlighted a ransomware attack against Peter Green Chilled, a chilled and frozen food logistics company supplying UK supermarkets, which temporarily halted deliveries during the incident. That example serves as a reminder that supply chain vulnerabilities extend well beyond retail headquarters and customer facing systems, reaching deep into the warehousing and distribution infrastructure that keeps food actually moving from producers to store shelves.
Britain's National Cyber Security Centre has separately reported that hostile actors launched close to two hundred attacks against UK critical national infrastructure between June last year and May this year, with roughly three quarters of those incidents linked to nation state activity rather than purely financially motivated criminal groups. That distinction matters significantly, since state backed actors often pursue disruption or intelligence gathering objectives that differ meaningfully from the straightforward ransom demands typically associated with criminal cyber gangs.
Officials have generally maintained that recent food sector attacks specifically appear to reflect the work of financially motivated cybercriminals rather than direct state sponsored warfare, even as security analysts note that groups operating from Russia and Eastern Europe sometimes align with broader hostile state interests even while pursuing primarily financial motivations. Food distribution in particular attracts criminal attention given the time sensitive, perishable nature of the goods involved, which increases pressure on victim organizations to pay ransoms quickly rather than risk spoiled inventory during prolonged system outages.
The broader food security context adds further weight to these cyber specific warnings. The United Kingdom relies on overseas imports for more than a third of its total food supply, with the majority of those imports entering through just four major ports, Dover, Felixstowe, Southampton, and London Gateway. That concentration of import infrastructure at a limited number of physical entry points leaves the broader supply chain genuinely exposed to disruption at these critical geographic chokepoints, compounding the cyber related vulnerabilities identified within warehousing and distribution systems further along the chain.
As Defra considers how to respond to the National Audit Office's recommendations, the coming months will likely see increased pressure for coordinated tabletop exercises and cross industry incident response planning, testing whether Britain's food supply chain can genuinely withstand a major coordinated disruption rather than simply weathering the more limited, isolated incidents experienced by individual retailers over the past year.
