Food industry must tighten security

The Canadian Food Inspection Agency should take a more active role in ensuring cybersecurity in light of the recent attack on JBS’s computer systems, says the writer. | Reuters photo

Meat processing giant JBS recently paid out a US$11 million ransom following a cyberattack, according to reports.

Most of its meat-packing facilities, including the one in Brooks, Alta., remained idle for a few days.

Most of us link the concept of cyberattacks with information technology companies, governments and media. But experts have warned the food industry for years about the threat of becoming a target for hackers.

Efforts to counter cyberattacks in the industry have been timid, at best.

The fact that the world’s largest beef and pork processor was targeted by hackers last month is a cause for concern and can serve as a major wake-up call. We can easily imagine companies like Cargill, Olymel, Maple Ridge Farms, McCain, Maple Leaf, Lassonde, Sysco, Loblaw’s, Sobeys, Metro and other major players also becoming targets.

Cybersecurity goes to the core of a company’s operational nature since it goes beyond the food we eat. Ransoms aren’t intuitively compatible with how food companies manage risks.

The food industry is a critical piece of our economy and changes in the industry make it a more likely target. Operations are adopting high-tech innovations like drones, GPS mapping, soil sensors, autonomous tractors, artificial intelligence and more. These changes are needed, but they can make the industry a primary target.

As the industry becomes more data-driven, it will also become more vulnerable to cyberattacks.

On the other side of the digital spectrum, many food operations still use outdated operating systems. One can only hope that most management teams in the food industry are reviewing their IT systems and figuring out how vulnerable they are to cyberattacks.

For consumers, the potential consequences of these attacks aren’t trivial. Disruptions can lead to food shortages and higher prices at retail. Or worse, cybersecurity breaches could lead to procurement issues and inadvertent alterations to ingredients put into the food sold at retail.

Ransom requests are just the beginning. Evil has no shame, no limits and it can harm a great number of consumers within days, perhaps even hours. The fact that JBS paid a ransom signalled to perpetrators that it can work. We should expect more attacks.

Virtually no mandatory cybersecurity rules govern the agri-food businesses that account for close to 20 percent of the Canadian economy. Some trade groups may have voluntary guidelines, but that’s the extent of it.

The Canadian Food Inspection Agency has no material on cybersecurity — not a single mention on its website. Its world is often exclusively about pathogens and allergens. Its focus requires a broader view, now more than ever.

More information-sharing mechanisms would be required for the industry to protect itself and the CFIA should be playing a more active role.

With the attack on JBS, the food industry has experienced its own Tylenol moment. In 1982, someone tampered with bottles of Tylenol in Chicago-area retail stores and poisoned several people, killing at least seven. Many bottles were laced with potassium cyanide.

The murderers took the industry completely by surprise, but it led to significant changes in how bottles are sealed and secured. Hopefully, the JBS incident will also lead to increased security and protection.

Sylvain Charlebois is senior director of the agri-food analytics lab and a professor in food distribution and policy at Dalhousie University. This article first appeared on Troy Media. It has been edited for length.

About the author

Sylvain Charlebois's recent articles


Stories from our other publications