Skip to content

Cybersecurity

OT cybersecurity in food & beverage: traceability, digital HACCP and production lines under attack

Italian food & beverage has a wide, poorly protected OT attack surface: dosing lines, digital HACCP systems, connected cold rooms for traceability. An OT attack here can compromise food safety and brand reputation.

5 min read
Automated food & beverage production line with conveyor belts and control systems

An OT-intensive and under-protected sector

Food & beverage is Italy's third-largest manufacturing sector by added value, with thousands of companies, from the small dairy cooperative to the multinational beverage producer, operating highly automated production lines. Pasteurizers, dosing and packaging lines, weighing systems, cold rooms, CIP (Clean-in-Place) washing plants: all controlled by PLCs and SCADA, increasingly networked to support traceability and quality requirements.

Connectivity has grown rapidly in recent years, driven by two forces: the need for end-to-end traceability imposed by European food regulations, and the digitalization of HACCP systems that brings process control data directly into IT quality systems. The result is a wide, heterogeneous OT attack surface, with IT/OT connections often not designed with security in mind.

The best-known food & beverage attack case is JBS Foods in 2021: the world's largest meat producer suffered a ransomware attack that halted plants in Australia, North America and other countries, causing several days of lost production and a ransom payment of eleven million dollars. But the impact was not only economic: the JBS plant shutdown created temporary supply shortages on the North American meat market, demonstrating how OT attacks on food & beverage have effects that go beyond the company directly hit.

Digital HACCP: when food safety meets IT

HACCP (Hazard Analysis and Critical Control Points) is the mandatory system for managing food safety in production plants. Traditionally implemented with manual, paper-based records, in recent years it has been progressively digitalized: temperature sensors at critical control points (CCPs) send real-time data to quality management systems; process alarms are recorded automatically; compliance certificates are generated from production data.

This digitalization has improved reliability and traceability, but it has created a new attack surface. Digital HACCP systems are typically web or client-server applications running on IT servers, yet they must collect data from OT sensors in real time. This integration creates connections between the corporate IT network and the production OT network, connections that, if not managed properly, become traversal paths for attackers.

Manipulating HACCP data is an attack vector specific to the sector: an attacker who managed to modify recorded temperature readings, making them appear compliant when they are not, could cause the distribution of products that do not meet food safety requirements, with serious consequences for public health and for the company's reputation. There is no need to compromise the entire production line: it is enough to alter the data recording chain.

Traceability as an access vector

Supply chain traceability is a growing regulatory requirement in European food & beverage. EU Regulation 178/2002 establishes the obligation of "one step forward, one step back" traceability for all food operators. More recent regulations, such as the Digital Product Passport envisaged by the Green Deal, are pushing toward even more granular traceability.

In practice, implementing traceability requires connections between systems: the ingredient lot code must be associated with the finished-product lot, which requires integration between the raw materials management system (often in the ERP) and the production systems (MES, SCADA). This integration chain creates paths that an attacker can exploit.

A documented pattern: attackers enter through a supply chain supplier's traceability system, which has integrated access to the customer's systems for exchanging lot data, and from there they move laterally toward the production systems. The food supply chain is long and branching, and every integration point is a potential access vector.

Secure traceability management requires that integration interfaces be treated as attack surfaces: strong authentication, traffic limited to what is necessary, monitoring of anomalies in queries and data transfers, separation between traceability data (which may be exposed externally) and production control systems (which should not be).

Dosing lines and weighing systems: process parameter manipulation

Dosing lines and weighing systems are among the most critical OT components in food & beverage: they determine product composition, recipe compliance, and conformity with nutritional declarations. A dosing error, accidental or deliberate, can have consequences ranging from product non-compliance to risks for consumers allergic to certain ingredients.

From an OT security standpoint, dosing lines have specific characteristics:

Precision as an indicator of compromise. Dosing systems operate with tight tolerances: deviations from the set point beyond certain thresholds trigger alarms. An attacker who wants to manipulate the process must do so in a way that stays within the tolerance windows or that disables the alarms before modifying the parameters. Both behaviors are detectable with adequate monitoring.

Recipes as critical configuration. Production recipes, the parameters that define quantities, sequences, temperatures and times for each product, are critical configurations that should be protected with robust access controls and versioning. Unauthorized changes to recipes are a form of attack specific to the sector.

Integration with automatic weighing. Automatic weighing systems (check weighers) are often networked for statistical process control (SPC). If this data is manipulated, the SPC system fails to detect process drift, losing its early warning function.

Cold rooms and the cold chain: critical infrastructure often forgotten

Cold rooms and industrial refrigeration systems are an integral part of food & beverage production, yet they are often treated as infrastructure separate from the production line. From an OT security standpoint, they are instead fully part of the attack surface.

Refrigeration control systems (compressors, expansion valves, temperature monitoring systems) are typically based on PLCs or proprietary systems that communicate over standard protocols such as Modbus or BACnet. Many are connected to the internet for remote monitoring by the service provider, often through connections that the company does not manage or monitor.

An attack on cold rooms can have immediate food safety impacts: raising the temperature of a refrigerated-product cold room even for a few hours can lead to bacterial proliferation in products that are then distributed to consumers. The history of food safety has examples of serious health crises caused by cold chain anomalies; a deliberate attack on refrigeration control systems is a scenario that companies in the sector must consider.

Auditing automated line vendors

Food & beverage production lines are typically supplied by specialized system integrators: companies that design, install and often maintain the lines for years. This long-term relationship means that the vendor has continuous access to the control systems (for maintenance, updates, troubleshooting) and that the vendor's security becomes part of the company's security.

Few food & beverage producers conduct systematic security audits of their automation vendors. The questions that should be part of the qualification process and of ongoing vendor management include: how is remote access to the installed systems managed? Who holds the credentials to access the line's PLCs? How are firmware and software updates handled? Is there an incident response process that includes notifying the customer?

The answers to these questions often reveal practices that would not be acceptable in other contexts: credentials shared among all the vendor's technicians, permanent VPN access without MFA, updates applied without prior notice to the customer. Making these practices visible is the first step toward changing them through contracts and technical requirements.


Italian food & beverage faces a concrete and urgent OT security challenge. The good news is that the starting point, visibility into what is on the network and how it communicates, is accessible even for medium-sized companies. Building that visibility, before any other measure, is the investment with the highest risk/benefit ratio a food producer can make today.

The MON5 angle

The silent manipulation of dosing parameters or HACCP readings, described in this article, is the kind of attack that traditional IT controls do not see. MON5 works where it matters: passive monitoring of OT traffic, even on protocols like Modbus used by pasteurizers and refrigeration systems, with anomaly detection that learns the process baseline and flags deviations, from a set point modified outside its window to anomalous access to a line PLC.

Continuous inventory also covers the forgotten assets of the cold chain, often connected to the internet by the service provider without the company's knowledge. For a food producer, the first snapshot comes from an OT assessment, without stopping the lines.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Related articles

Petrochemical plant with industrial piping and control valves

Cybersecurity

OT Cybersecurity in the Chemical Industry: Where Cyber Security and Physical Safety Meet

In the chemical industry a cyber incident can cause the release of hazardous substances, explosions and harm to people. Safety/security convergence is no abstraction: the Triton attack on Safety Instrumented Systems proved the last physical line of defense can be compromised.

5 min read
Robotic automotive assembly line with KUKA arms in an industrial setting

Cybersecurity

OT Cybersecurity in Automotive Manufacturing: Robotic Lines and Supply Chains Under Attack

Automotive is among the sectors most exposed to OT attacks: robotic lines with proprietary protocols, MES/ERP integration and vendor remote access create a wide, hard-to-control attack surface.

5 min read
Automated warehouse with AS/RS systems, vertical racking and AGVs on the floor

Cybersecurity

OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover

Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.

6 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna