Ransomware against food plants is up 62%. Patch-everything won't save you.
· By Ilyass Motya
Source: Industrial Cyber — Food and Ag-ISAC 'State of the Threat'
The sector is being swept up in volume
The Food and Ag-ISAC counts 227 ransomware incidents in the sector through July 2026, a 62% jump over the same period last year, out of 4,272 tracked attacks across 108 threat groups globally. Most of that activity is opportunistic: campaigns scan for exposed systems, buy access from brokers, phish the first organization that surfaces. The food industry gets caught in that indiscriminate wave as often as it is singled out.
The report also surfaces what it calls shadow OT: grain silo sensors, automated feeder controls, cold chain thermometers — added for efficiency, connected to networks, and invisible to traditional IT asset management. Every one of those devices is a potential entry point for lateral movement.

The 'patch everything' model breaks on a processing line
The recommendation section is the practical part. A processing line cannot be taken offline mid-harvest to apply an update, and many of the PLCs running those lines are years old with firmware that may have no patch at all. Treating every CVE as equally urgent is a strategy for firms that can restart a batch in minutes. In food, it is a recipe for downtime.
What the report actually argues: triage, not coverage. Know which vulnerabilities in your environment are likely to be exploited, prioritize those, and hold lower-risk ones for the next scheduled maintenance window. In a sector where a disrupted cold chain means product loss instead of a ticket, that ordering is the difference between a patched network and a running plant.
What I'd start with on a food site
The pattern is the same one I'd apply at any plant, and food makes it urgent because the calendar is unforgiving. Inventory the OT you can't see: every sensor, controller, and thermometer that touches a network. Put the IT/OT boundary somewhere real, not on a shared switch. Control every vendor and remote access path — the report identifies contractor-style access as a primary route, and a cold line's after-hours service engineer is exactly the trust boundary attackers abuse.
AI-accelerated detection is helping surface that shadow inventory faster. But nothing surfaces it earlier than a good discovery pass and segmentation done on the plant's calendar, not the vendor's.