New ISAC in Food and Agriculture Sector Helps Companies Defend Against Cyberattacks
As government-backed hackers target food and agriculture companies, the industry's newly formed cyber collaboration organization—the Food and Agriculture Information Sharing and Analysis Center (Food and Agriculture ISAC)—is accelerating its development. This article outlines its founding background, operational model, partnerships with CISA and USDA, and analyzes the unique cybersecurity risks facing the industry.

As food and agriculture companies increasingly become targets of government-backed hackers, threatening critical areas from animal health to crop innovation, the industry's new cybersecurity collaborative has had to develop rapidly.
For years, cyberattacks ranked low on the food industry's list of priorities. Corporate executives were more focused on obvious industry problems such as sick cows and moldy wheat. But eventually, ransomware attacks and state-sponsored espionage became too frequent to ignore. In May 2023, major industry players including PepsiCo, Tyson Foods, Cargill, and Conagra joined forces to establish the Food and Agriculture Information Sharing and Analysis Center (Food and Agriculture ISAC), filling a gap that experts had described as "uniquely dangerous."
Two years after the Food ISAC's founding, the organization finds itself busier than ever as it helps companies protect the U.S. food supply from cyberattacks that could have devastating consequences for the food supply chain. Victims in the industry include Dole, Mondelez, Sysco, and United Natural Foods, as well as dairy giant HP Hood, which had to shut down manufacturing plants after a breach in 2022.
"There's a lot of attention being paid to cybersecurity in the industry now," Scott Algeier, executive director of the Food ISAC, told Cybersecurity Dive. "There are a lot of issues in this space that are drawing people's attention, and in the past, I don't think cybersecurity always rose to the top. We're seeing that change."
Uniting the industry
When the Food ISAC launched, it did not start from scratch. Food and agriculture companies had previously exchanged cyber threat information and obtained security services through a "special interest group" within the IT-ISAC. Launching the standalone ISAC involved migrating these resources to the new organization without disrupting companies' access.
"We didn't want to start with zero capabilities," Algeier said. "They were used to having these robust capabilities... and relationships with technology providers."
The new organization also sought to distinguish itself from an earlier industry ISAC that launched in 2002 and shut down in 2008. That organization failed because members were reluctant to share information with competitors and worried about the antitrust implications of doing so. But 15 years later, new federal legal protections and the productive experience of the IT-ISAC prompted companies to try again. "They had built trusted relationships with each other," Algeier said, "and they had years of successful sharing experience."
Today, according to Algeier, the ISAC is the hub of robust information sharing among food and agriculture companies. "We're collecting better data," he said. "Our member companies are actively sharing with us... We have more accurate visibility into what's happening in the industry, and we're able to produce intelligence that reflects that." These improved insights have enabled the ISAC to update its cybersecurity guidance for small and medium-sized businesses, providing more specific information on adversary activity, such as attacks on remote monitoring and management tools.
The organization issues alerts on geopolitical conflicts, highlights particularly severe threat activity alongside other ISACs, and collaborates with universities to improve research and development. It also publishes threat reports, including one in May documenting a surge in ransomware attacks on food and agriculture organizations.
Doug Baker, vice president of industry relations at FMI, a major food industry trade group, said FMI benefits from the ISAC's "relevant, real-time insights that are both actionable and valuable." "When there's a threat in one part of the supply chain," Baker said, "they help us share that intelligence more broadly, enabling retailers and suppliers to anticipate and respond before disruptions escalate."
Robert Norton, a biosecurity and national security expert at Auburn University, praised the ISAC's work so far and said he hopes it will eventually fill a "long-standing gap" in the industry's resilience, including bringing smaller companies into its membership.
The ISAC does not publish its full membership list, but it lists some companies that have agreed to be public—all of which are industry giants. Algeier said the ISAC includes "companies of all sizes" headquartered in 22 states and four countries, noting that industry associations can pass ISAC information on to their members.
The number of small and medium-sized businesses in any ISAC is a key factor in how far its guidance reaches. Strong representation from smaller organizations helps the ISAC promote systematic improvements in its industry's cybersecurity posture. If small companies do not participate in the ISAC's programs or heed its recommendations, they will remain vulnerable to hackers, disrupting the operations of the large companies that depend on them.
CISA and USDA relationships
Despite being a relatively new organization, the Food ISAC has quickly built relationships with officials at key federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. Department of Agriculture. Algeier said that despite mass departures straining the agency's resources, his organization's relationship with CISA remains "fairly strong." Food ISAC leaders meet with CISA staff at least monthly, he said, to "compare notes," discussing threat activity, mission priorities, and publications in development.
"We still feel we have the contacts we need within CISA and USDA to get the job done," Algeier said.
The Trump administration's recently released National Farm Security Action Plan specifically names the Food ISAC as a key partner, which has energized the organization's leadership. Algeier said the plan "solidified" his organization's role as a hub for cyber intelligence sharing. "The government has clearly expressed support for engaging with us."
The ISAC's biggest policy concern is the upcoming expiration of the 2015 Cybersecurity Information Sharing Act, which created liability protections that helped encourage food and agriculture companies to reconsider the ISAC idea. Algeier said his organization hopes Congress will reauthorize the law, although ISAC members might continue sharing information even without liability protections.
Precision, with risks
Continued collaboration through the ISAC is vital to protecting food and agriculture businesses facing diverse cybersecurity risks.
Much of the concern stems from the industry's increasing use of digital processes and automation, from GPS-guided tractors to crop-monitoring drones to systems that track dairy cow milk production. "The reliance on certain technologies is now being integrated into food and agriculture in ways we haven't seen before," Algeier said. These operational technology platforms also generate far more data than farmers and food processors have traditionally had to store—and protect.
Attacks on these OT systems or the data they generate can have widespread consequences because the food industry's supply chain is vast. From farms to processing plants to wholesalers and supermarkets, the network that brings food to consumers' tables depends on the uninterrupted activity of many companies. These interdependencies make the U.S. food system more efficient, but they also expose every participant to greater risk.
"The interconnectedness of the food and agriculture sector, along with its just-in-time delivery characteristics, sets it apart from some other sectors," Algeier said.
Even short-term supply chain disruptions can be devastating for food and agriculture companies because their revenue typically depends on volume, a reliance not commonly seen in other sectors.
"That makes cybersecurity even more important," Algeier said, "because you need continuity to keep the business running."
Aggressive adversaries, determined defenders
Keeping the business running can be a challenge in the face of sophisticated hackers. The food and agriculture sector has experienced ransomware attacks, but the ISAC believes these have so far been opportunistic rather than targeted. Algeier said the industry's real adversaries are government-backed hackers intent on stealing trade secrets to benefit their regimes.
"There are seed technologies that are very valuable to these other countries," Algeier said. "Just as they steal intellectual property to enhance military capabilities, nation-state actors are interested in food and agriculture intellectual property to boost their agricultural programs at home."
Despite all the threats, companies in the sector have experienced relatively little downtime from cyberattacks, a promising sign of their preparedness for growing security risks.
"Some of these supply chains—they've bent a little, but they haven't broken," Algeier said. "The industry has shown some resilience in adapting to some of these disruptions."