Agriculture

Cybersecurity for Modern Farm Operations

A modern Idaho or Utah farm looks like a small business with an unusually wide attack surface. Payroll runs online. Banking runs online. Precision-ag data lives in vendor clouds. Telematics beams equipment status from every tractor and combine. Cameras cover shop, parlor, and yard. Remote access lets the operator start irrigation from a phone. Every one of those connections is a potential entry point.

Farm cybersecurity is not a hypothetical threat anymore. Ransomware groups target agriculture the same way they target any other business, and business-email compromise scams show up on farm bank accounts every week. The practical question is not whether to think about it, but what a family or mid-size farm should do this year without hiring a security team.

The two attacks that actually land

Cybersecurity press covers dozens of threat categories. On real farm operations, two attack types dominate actual losses:

  • Business email compromise (BEC). An attacker gains access to (or spoofs) an email account, then either redirects an invoice payment to a fraudulent account or convinces someone in the operation to wire funds urgently to a fake vendor. Losses per incident range from thousands to hundreds of thousands.
  • Ransomware. An attacker encrypts business files and demands payment to restore them. On a farm, that can mean payroll records, accounting files, precision-ag data, and control-system files all locked. Losses include ransom, downtime, and data-loss impact.

Both are opportunistic. Attackers do not target farms specifically; farms with weak controls are simply available targets in an environment where controls generally exist.

The five practices that move the needle

The controls that materially reduce risk for a mid-size farm:

  • Multi-factor authentication on every business account. Email, banking, payroll, precision-ag platforms, cloud storage. MFA blocks most credential-theft-based attacks. Cost is near-zero. Not doing this is the single largest gap on most farms.
  • Offline backups, tested quarterly. Backups stored on a device connected to the network can be encrypted along with the main files. Offline (or immutable) backups tested with actual restore drills quarterly are the difference between a ransomware attack that is a bad week and one that ends the business.
  • Employee training on invoice-change fraud. The most common BEC pattern is a “please update our banking info” email that appears to come from a real vendor. Training every person who touches accounts payable to verify banking changes by phone (using a number from a previous known-good invoice, not one in the fraudulent email) blocks the majority of BEC attacks.
  • Patching of connected equipment. Precision-ag controllers, telematics units, camera systems, and network equipment all get security patches. Applying them is not automatic on most operations.
  • Cyber insurance with a real incident-response line. Not every cyber policy is equal. The valuable feature is not the payout; it is the 24-hour incident-response phone number that connects to actual incident-response professionals. When something goes wrong at 2 AM, that phone number matters more than the policy limit.

Precision-ag data risk

Precision-ag data (yield maps, application maps, soil-moisture data, telematics history) has real value and lives on someone else’s cloud. Questions worth answering before signing a precision-ag contract:

  • Who owns the data? The farm, the vendor, or shared?
  • Can the farm export its data in a portable format if it changes vendors?
  • What happens to the data if the vendor is acquired, goes out of business, or has a security breach?
  • Is the data encrypted at rest? During transmission?
  • Where is the data hosted, and is it subject to laws the farm cares about?

Most vendors have reasonable answers. Some do not. Contracts signed without asking these questions leave the farm exposed.

Payroll and banking controls

The controls that protect farm cash directly:

  • Dual approval on wires above a threshold.
  • Callback verification for any account-change request, using a number from the operation’s records, not the request itself.
  • Separation of duties for check preparation and signature.
  • Positive pay or similar bank service that flags outgoing checks not on the operation’s issued-check list.
  • Reconciliation of bank statements within days of receipt, not months.

What to do in the first 24 hours of an incident

If something goes wrong:

  • Do not power down infected systems. Powering down can destroy forensic evidence. Isolate from the network instead.
  • Call your cyber insurer or IR firm. If you have one. The incident-response professional coordinates the response.
  • Preserve logs. Firewall logs, email server logs, endpoint logs. Do not clear them.
  • Involve counsel. Especially if state breach notification laws are likely to apply.
  • Report per state law. Idaho and Utah both have breach notification requirements with specific timing.

This overview is general information, not security advice for your specific operation. Talk with Cooper Norman’s ag advisors and consider our internal-control review to evaluate your farm’s control environment. Review your farm’s control environment with Cooper Norman before the incident, not during.

Back to the Journal

Newsletter

Practical owner guidance, monthly.

Tax, transition, and decision insights from the Cooper Norman team.