UK Food Supply Chain Faces Heightened Risk from Cyberattacks, Watchdog Warns
A UK watchdog has identified cyberattacks as a significant and growing threat to the nation's food supply chain, citing recent disruptions at major retailers.

The UK's food supply chain is increasingly vulnerable to cyberattacks, with the potential for severe disruptions that could impact national resilience, according to a stark warning from the National Audit Office (NAO). The watchdog's report highlights that while the sector has demonstrated resilience in the past, the likelihood and severity of cyber threats are on the rise, necessitating enhanced preparedness and collaboration between government and industry.
Recent incidents have underscored these concerns. Retail giants Marks & Spencer and the Co-op both experienced significant cyberattacks in the past year. Marks & Spencer estimated a staggering £136 million cost from an April 2025 incident, which led to the disconnection of warehouse management systems and consequently impacted online and in-store orders. Similarly, the Co-op confirmed that a cyberattack last year resulted in the theft of data belonging to 6.5 million of its members.
The NAO report emphasizes that the food supply chain's design, optimized for efficiency and cost reduction, inherently creates vulnerabilities. This lean structure, while beneficial for consumers in normal times, leaves it susceptible to significant shocks. The Department for Environment, Food & Rural Affairs (Defra) has been urged to learn from international best practices and bolster emergency preparedness by conducting joint exercises with local government and industry stakeholders.
Businesses within the food supply chain are already making substantial investments to counter growing cyber risks. However, the NAO notes that broader economic pressures are making it more challenging for these organizations to fund not only cybersecurity measures but also other essential resilience investments. This financial strain complicates efforts to fortify the sector against escalating threats.
While Defra has initiated food-specific exercises since 2023, with some focusing on cyber incident responses within the food sector, the report subtly questions the department's technical advisory capabilities. The NAO points out that Defra itself faces challenges with digitalization, with a significant portion of its customer interactions still relying on paper-based forms and a substantial percentage of its applications being out of support.
The increasing sophistication and frequency of cyber threats, coupled with the inherent vulnerabilities of a highly optimized supply chain, present a complex challenge. The NAO's findings serve as a critical call to action for Defra and the wider food industry to proactively address these risks before a major incident can cause widespread and potentially devastating consequences for the UK's food security.