Cybersecurity Is Part Of Food Protection
Kristin Demoranville
S4x24 - ICS Security Conference · Day 1 · Stage 2
Overview
Kristin Demoranville, a vocal advocate for integrating cybersecurity into the broader food industry, delivered a compelling talk at S4, arguing that cybersecurity is an indispensable component of food protection. Her presentation underscored the critical, yet often overlooked, intersection of digital technology and the global food supply chain, from farm to table. Demoranville passionately articulated that the rapid digitalization across agriculture, processing, and distribution has introduced profound cyber risks that, if unaddressed, threaten public health, economic stability, and even national security.

Key moments
- 0:00 Connecting food emotionally to cybersecurity and protection
- 2:00 Cybersecurity's vital, often overlooked, role in food
- 2:40 Food industry's digital adoption and desire for security partnership
- 3:45 Integrating security data for food defense investigations
- 4:28 Dairy farm scenario: Subtle data manipulation causing illness
- 5:55 Consequences: Outbreaks, brand damage, and financial ruin
- 6:40 Urging collaboration between cybersecurity and food teams
Cybersecurity Is Part Of Food Protection
Speakers: Kristin Demoranville
Conference: S4
YouTube: https://www.youtube.com/watch?v=iMPXGxETY5s
Overview
Kristin Demoranville, a vocal advocate for integrating cybersecurity into the broader food industry, delivered a compelling talk at S4, arguing that cybersecurity is an indispensable component of food protection. Her presentation underscored the critical, yet often overlooked, intersection of digital technology and the global food supply chain, from farm to table. Demoranville passionately articulated that the rapid digitalization across agriculture, processing, and distribution has introduced profound cyber risks that, if unaddressed, threaten public health, economic stability, and even national security.
The talk aimed to bridge the communication gap between cybersecurity professionals and traditional food safety teams, urging a collaborative, holistic approach. Demoranville challenged the audience to rethink their roles, not merely as technical experts but as essential partners in safeguarding one of humanity's most fundamental needs. She emphasized that while the food industry has eagerly adopted technology for efficiency and safety, the associated cyber vulnerabilities are often misunderstood or neglected, leading to potential catastrophic outcomes ranging from widespread foodborne illnesses to significant economic damage for producers.
Demoranville's message resonates deeply in an era where critical infrastructure is increasingly targeted. By drawing an emotional connection to food through personal anecdotes and stark scenarios, she highlighted why every individual, especially those in cybersecurity, should care about the resilience of our food systems. The talk served as a powerful call to action for cybersecurity professionals to step out of their silos and engage proactively with the food industry, recognizing that the integrity of our food supply is now intrinsically linked to the strength of our cyber defenses.
Background
▶ Watch: Connecting food emotionally to cybersecurity and protection (0:00)
The journey of food from "farm to table" has undergone a profound transformation, driven by a digital revolution that has swept through the agricultural and food processing industries. Historically, food safety and defense relied heavily on manual inspections, quality control checks, and physical security measures. While these remain crucial, the advent of automation, robotics, Internet of Things (IoT), and Operational Technology (OT) has fundamentally altered the landscape. This rapid adoption of technology, while boosting efficiency, reducing costs, and enhancing worker safety (e.g., robots in meat processing plants replacing hazardous manual tasks), has simultaneously introduced a vast and complex cyber attack surface.
Demoranville highlighted that the food industry's embrace of digital innovation has been swift and enthusiastic, often without a corresponding maturation of cybersecurity practices. Unlike sectors like oil and gas or finance, which have long been recognized as critical infrastructure with robust cyber defense frameworks, the food industry's cyber vulnerabilities have largely flown under the radar. This oversight stems partly from a traditional focus on production efficiency and tangible food safety risks (like contamination or spoilage), rather than the less visible, but equally potent, threats posed by cyber intrusions.
The problem is exacerbated by the tendency for cybersecurity professionals to operate in silos, often failing to recognize the unique challenges and opportunities within the food sector. Demoranville noted that while food industry professionals already employ principles like risk management, traceability, transparency, continuous monitoring, and incident response in their traditional food safety audits, these practices often do not extend to the cyber realm. This disconnect means that valuable data residing in security appliances might not be leveraged for food defense investigations, and conversely, food quality data might not be integrated into cyber incident response. The absence of a holistic, integrated approach leaves the food supply chain susceptible to manipulation, disruption, and contamination through digital means.
Key Findings
▶ Watch: Food industry's digital adoption and desire for security partnership (2:40)
The central finding of Demoranville's talk is the unequivocal assertion that cybersecurity is no longer a peripheral concern but an integral, fundamental component of food protection. This extends beyond traditional food safety (preventing accidental contamination) and food defense (preventing intentional contamination) to encompass the security of the underlying digital infrastructure that supports the entire food supply chain. The speaker identified several critical discoveries and contributions:
Firstly, the ubiquitous digitalization of the food industry has created a vast new attack surface. From automated milking machines on dairy farms to robots on processing lines and IoT sensors monitoring crops, nearly every stage of food production, processing, and distribution is now connected and susceptible to cyber threats. This connectivity means that a cyber incident can directly translate into physical harm, product spoilage, or widespread illness.
Secondly, the speaker highlighted the insidious nature of cyber-physical attacks in food systems. Unlike overt physical sabotage, a subtle manipulation of data—such as slightly altering the pH level of milk in an automated system—could allow contaminated or unsafe products to pass traditional quality inspections. This "minute little small adjustment" could lead to outbreaks, brand damage, costly recalls, and even deaths, potentially destroying small to mid-sized businesses. This finding underscores that existing food safety protocols, while robust for physical threats, are often inadequate against digitally induced compromises.
Thirdly, Demoranville revealed a significant gap in collaboration and awareness between cybersecurity teams and food defense professionals. While food industry personnel are often eager to partner, cybersecurity experts frequently remain in their "silos," failing to see the broader implications of their work for food protection. This lack of integrated thinking means that potential insights from security appliances are not utilized in foodborne illness investigations, and cyber risks are not adequately factored into business continuity plans.
Finally, the talk underscored the catastrophic potential of food system attacks at a national level. Demoranville provocatively suggested that a nation-state looking to destabilize an adversary might target food and water systems rather than just the power grid, given that societies are "four to six meals away from chaos." This elevates food protection to a critical national security imperative, demanding a strategic, whole-of-government and whole-of-industry approach to cyber resilience.
Technical Deep Dive
▶ Watch: Integrating security data for food defense investigations (3:45)
While the talk was more strategic than a deep dive into specific exploits or code, Demoranville provided crucial insights into the technical underpinnings of vulnerabilities within the digitized food supply chain. The core of her argument rests on understanding how the rapid adoption of cyber-physical systems has created new attack vectors that traditional food safety measures are ill-equipped to handle.
A prime example is the automation of dairy farms. Demoranville noted that "nobody milks cows by hand; it's all done by machine." These automated systems, often connected to networks for monitoring and control, manage critical processes like milking, temperature regulation, and even feed distribution. The vulnerability arises when an attacker, whether an insider or an external threat actor, can manipulate the data controlling these systems. Demoranville specifically cited the example of pH manipulation in milk. An attacker could make "minute little small adjustments" to the pH levels reported by sensors or controlled by automated systems. These adjustments could be subtle enough to fall within the acceptable margin of error for standard food quality inspections, yet significant enough to compromise the product, potentially causing widespread illness or spoilage down the line. This highlights a critical flaw: the digital integrity of the data now directly impacts the physical safety of the food.
Beyond dairy farms, the talk touched upon the pervasive use of robotics in food processing plants. These robots are not only for efficiency but also for "keep employees safe" by handling dangerous tasks like cutting meat. While beneficial, these machines are complex OT devices, often connected to industrial control systems (ICS) and enterprise networks. A compromise of these robots or their controlling systems could lead to physical damage to products, intentional introduction of contaminants, or disruption of production lines. The speaker contrasted this with a manual process where "somebody who's just happens to be there named Bob who's cutting meat" – a system with human error but fewer direct cyber vulnerabilities compared to an automated, networked equivalent.
Demoranville also emphasized the role of cyber-physical technology in detection. While presenting risks, these technologies also offer potential solutions. Security teams are urged to consider how "data that we actually have in our security devices and appliances" could "help assist to figure out exactly what had happened" in a foodborne illness investigation. This suggests leveraging existing cybersecurity tools—like Security Information and Event Management (SIEM) systems, Intrusion Detection/Prevention Systems (IDS/IPS), or network traffic analysis tools—to correlate cyber events with physical incidents. For instance, unusual network activity on a control system segment could be an early indicator of a potential food safety compromise.
The discussion extended to the broader IoT and OT landscape in agriculture. "Everything's connected to the internet in some capacity even on the farm field," Demoranville stated. This includes smart sensors for soil moisture, automated irrigation systems, and even robotic crop harvesters. The story of agricultural workers guarding a newly introduced robot with machetes, fearing job loss if it failed, illustrates the critical reliance on these new technologies and the potential impact of their compromise. While the fear was initially job security, the underlying message for cybersecurity is the immense value and vulnerability of these connected devices. A cyberattack could destroy crops, alter pesticide application rates, or disrupt harvesting schedules, leading to significant food loss and economic repercussions.
Finally, the talk briefly addressed the issue of foreign material contamination. While often attributed to negligence or accidental mechanical failure (e.g., a broken belt or something slipping off an employee), Demoranville's broader context implies that even these incidents could, in theory, be exacerbated or intentionally caused by cyber means, for example, by disabling safety sensors or manipulating assembly line speeds. The "peanut dust" incident and the "frog in something" example, while not directly cyber-related in the talk, serve as a reminder of the devastating impact of contamination and the need for robust, multi-layered defenses that include cyber.
Demo / Proof of Concept
▶ Watch: Consequences: Outbreaks, brand damage, and financial ruin (5:55)
Kristin Demoranville's talk did not include a live demonstration or a technical proof of concept. Instead, she relied on illustrative scenarios and thought experiments to highlight the potential vulnerabilities and impacts of cyberattacks on food systems. The most prominent example was the hypothetical manipulation of milk pH levels on an automated dairy farm, which served as a conceptual proof of how subtle digital changes could bypass traditional food safety checks and lead to widespread illness. While no actual code or exploit was shown, these vivid scenarios effectively communicated the technical risks involved.
Defensive Implications
▶ Watch: Urging collaboration between cybersecurity and food teams (6:40)
The defensive implications derived from Demoranville's talk are profound and necessitate a significant shift in mindset and operational strategy for both cybersecurity professionals and the food industry.
- Break Down Silos and Foster Collaboration: The most critical implication is the urgent need for cross-functional collaboration. Cybersecurity teams must actively engage with food safety, food defense, and operational technology (OT) teams. Demoranville emphasized that food protection professionals "want us to partner with them; they want us on their team." This means moving beyond being "the password people" or "blockers" to becoming educators and collaborators, understanding the unique challenges and priorities of the food industry.
- Holistic Systems Thinking: Defenders must adopt a holistic systems thinking approach. The food supply chain is an interconnected ecosystem, and a breach at one point can cascade through the entire system. Understanding the interdependencies between IT, OT, IoT, and traditional food safety processes is paramount. This includes integrating cyber risks into existing business continuity plans and disaster recovery strategies, ensuring that "have you talked to your cyber team?" becomes a standard question.
- Leverage Existing Security Investments for Food Defense: Cybersecurity appliances and data sources (e.g., SIEM logs, network telemetry) are not just for IT security. Defenders should explore how this data can be leveraged to assist in food defense investigations, particularly in tracing the origin of a foodborne illness or identifying anomalous activity that could indicate product tampering. "Would that data that we actually have in our security devices and appliances be able to help assist to figure out exactly what had happened?" is a key question.
- Understand the OT/IoT Landscape: Cybersecurity professionals need to gain a deep understanding of the specific Operational Technology (OT) and Industrial IoT (IIoT) deployed across the food supply chain, from automated farm equipment and processing robots to smart sensors. This includes identifying all connected assets, understanding their vulnerabilities, and implementing appropriate segmentation and access controls. Knowing "what's in there and what's not" is crucial.
- Prioritize Data Integrity: Given the risk of subtle data manipulation (e.g., pH levels in milk), ensuring data integrity across all cyber-physical systems is paramount. This involves robust authentication, authorization, logging, and monitoring mechanisms for control systems and sensor data. The ability to detect even "minute little small adjustments" in critical process parameters is vital.
- Recognize National Security Implications: Defenders, particularly at governmental and critical infrastructure levels, must recognize that the food supply chain is a critical national security target. Strategies for protecting the food and water sectors should be elevated to the same level as energy or financial sectors, including robust threat intelligence sharing and coordinated response frameworks against nation-state actors.
- Advocate for Budget and Resources: Demoranville suggested that cybersecurity teams could "partner with them on a business level and start paying for your program yourself." This implies demonstrating the tangible value of cybersecurity to food protection, potentially leading to shared budget allocations or direct funding from food safety budgets, recognizing cyber as an enabling function for overall food integrity.
- Educate and Raise Awareness: Every individual who eats needs to care. Cybersecurity professionals have a role to play as educators, raising awareness among colleagues, management, and even the public about the interconnectedness of cyber health and food safety. Emphasizing the emotional and societal importance of food can drive greater engagement and investment in its protection.
Key Takeaways
- Cybersecurity is Fundamental to Food Protection: Due to the rapid digitalization of the food industry, cyber defenses are no longer optional but are intrinsically linked to food safety, food defense, and overall food security.
- Subtle Cyber-Physical Attacks Pose Significant Risks: Digital manipulation of operational data, such as slightly altering pH levels in automated systems, can bypass traditional quality checks and lead to widespread illness, recalls, and severe economic damage.
- Collaboration is Crucial: Cybersecurity professionals must break down silos and proactively partner with food safety and OT teams, acting as educators and collaborators rather than just technical blockers.
- Leverage Existing Security Data: Data from cybersecurity appliances can be a vital asset in investigating foodborne illnesses and other food defense incidents, underscoring the need for integrated data analysis.
- Food Systems are Critical National Infrastructure: The food and water supply chains are prime targets for nation-state attacks, making their cyber resilience a matter of national security, demanding strategic and integrated protective measures.
- Holistic Thinking is Required: A comprehensive understanding of the entire "farm to table" journey, including all connected IT, OT, and IoT devices, is necessary to build robust, end-to-end food protection strategies.
About the Speaker(s)
Kristin Demoranville is a passionate and vocal advocate for integrating cybersecurity into the critical domain of food protection. She hosts a podcast where she initiates conversations by asking guests about their favorite food and food memories, aiming to forge an emotional connection to food that underscores its cultural, spiritual, and significant importance. This approach highlights her belief that understanding the personal value of food is key to appreciating the urgency of its protection. Throughout her talk, Demoranville demonstrated deep empathy for victims of foodborne illnesses, sharing that hearing stories of children lost to E. coli poisoning profoundly affected her. She is committed to challenging cybersecurity professionals to recognize their role beyond traditional IT, urging them to engage with the food industry as essential partners in safeguarding public health and national security. Her work focuses on fostering collaboration and holistic thinking within the interconnected world of food and technology.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Demoranville's talk masterfully articulates the critical, often overlooked, intersection of cybersecurity and food protection. While not a deep dive into exploit code, it provides a profoundly impactful strategic perspective, highlighting how the rapid digitalization of the food supply chain introduces novel cyber-physical attack vectors, such as subtle manipulation of automated processes like milk pH. The presentation serves as a crucial call to action, challenging cybersecurity professionals to break silos and recognize their essential role in safeguarding national security and public health through a holistic approach to food system resilience.
Heather Calloway (CISO) — STRONG ACCEPT
This talk by Kristin Demoranville masterfully articulates the critical, often overlooked, intersection of cybersecurity and food protection. By highlighting the pervasive digitalization across the "farm to table" journey, Demoranville compellingly demonstrates how cyber risks translate directly into public health, economic, and national security threats. She forcefully calls for breaking down organizational silos, urging cybersecurity professionals to integrate deeply with food safety and operational teams to ensure data integrity and systemic resilience, underscoring that accountability for food security now fundamentally extends into the cyber realm.