It is the industrial sector hit hardest by ransomware and the one that least expects it. You do not have to be critical infrastructure for a week-long packaging shutdown to be catastrophic.
The environment
Food production operates on tight margins with perishable products: a shutdown costs not only production, but also expiring raw materials, a broken cold chain and large-retailer orders that will not wait. Attackers know this—which is why dozens of ransomware cases in the sector have been reported—and management often discovers the risk only after its own first scare or that of a competitor.
Technically, the typical pattern is a network that grew with the factory: packaging lines connected to the MES, the MES to the ERP, scales, labellers and machine vision connected throughout, and machinery suppliers with permanent remote access to “their” line. None of this is unusual or anyone's fault: it is the usual starting point.
How we work here
The first step is an assessment that almost always brings surprises: more connected equipment appears than anyone realised. Once the picture is clear, the highest-value action is to separate the production network from the corporate network—so ransomware entering through email cannot reach packaging—and bring machinery manufacturers' access under control.
From there, we establish monitoring sized to the company's actual scale and an incident response plan that addresses sector-specific issues: which batches are compromised, how traceability is maintained during an incident and when distributors must be notified.
Applicable regulations
NIS2 includes food production and distribution in Annex II: most medium-sized and large companies in the sector are “important entities”, subject to the same Article 21 measures and incident-reporting requirements as essential entities. IEC 62443 remains the technical reference for structuring the factory.