top of page

The latest news, trends, analysis, interviews and podcasts from the global food and beverage industry

FoodBev Media Logo
Nov - Food Bev - Website Banner - TIJ vs TTO 300x250.gif
Access more as a FoodBev subscriber

Sign up to FoodBev and unlock more insights from the international food and beverage industry. Subscribers have access to webinars, newsletters, publications and more...

Guest contributor

Guest contributor

30 July 2026

Why your bottling line is now an attack surface: Navigating security risk

Why your bottling line is now an attack surface: Navigating security risk
Ransomware headlines about food giants like Coca-Cola, JBS and Schreiber Foods come and go, but few plant managers have been told why their production floor is harder to defend than a corporate laptop. Here, Santoshi Muriki, food safety and quality assurance expert, breaks down the real mechanics of OT risk and what a mid-size manufacturer can realistically do about it without a seven-figure security budget.

Santoshi Muriki
Santoshi Muriki

Ask most plant managers what keeps them up at night: delayed suppliers, allergen changeovers, a line falling behind schedule. Rarely do you hear cybersecurity, and that’s the issue. In between ransomware attacks on food producers becoming front-page news and the moment those headlines cooled down, one thing got left out of the conversation. The machines running your bottling lines and packaging systems were never designed with today’s threats in mind, and slapping on IT-style cybersecurity isn’t going to solve that.


Don’t panic. But do understand what you’re trying to protect, because it’s probably not what most security vendors think you are.



IT security habits don't transfer to the plant floor


When a company’s IT department secures a network, the usual approach is well-known: keep patching, reboot when necessary, segment the network, and assume each device can handle a few seconds of downtime while applying a fix. But none of that works on a production line.


A programmable logic controller (PLC) controlling a filler can't be rebooted mid-shift. A supervisory control and data acquisition (SCADA) system managing a pasteurisation loop can't handle a patch that requires even a brief pause. That pause can mean a product sitting at the wrong temperature, a batch record with a gap, or a shutdown that costs tens of thousands of dollars an hour.


Many control systems in use today were installed over a decade ago. They were built to last twenty years on a factory floor, not to receive monthly security updates. Some run operating systems that stopped getting vendor support years ago because replacing them means replacing the physical equipment they are attached to. That's the main issue: OT security is not just a smaller version of IT security. It's a different field with different priorities. Treating it as an afterthought to the corporate network can lead to phishing emails in accounts payable or shutting down a packaging line in a different building.



The real cost isn't the ransom


One temptation might be to think of this as a data issue: someone lifting your customer database or stealing product formulas. That happens, but rarely makes the lead story. It is usually an operational exposure: a line halting midway through a batch; a failed batch being untraceable due to a locked historian; a cold-chain sensor reporting going offline right in the middle of an investigation related to a product recall.


To a medium-sized manufacturer, the cost of a single lost day on a critical line may exceed the average ransomware payout by factors of more than ten, and that's not factoring in lost products, missed delivery deadlines, and retailers who are not forgiving of a broken delivery window.


Do your own quick math on your facility and the business case for pre-emption sells itself: virtually every security investment that can make a material dent in that kind of exposure costs significantly less than a day lost in production. Sprinkle in the regulatory element – FDA and USDA inspectors seeking records that are sitting on an encrypted server or network storage device now unreachable – and suddenly the economics start looking quite similar to the economics of food safety. In fact, it is starting to become one and deserves to sit on the same corporate risk register that lists recall exposure and supplier risks – rather than getting tucked away into an IT budget that plant managers never see.


Segmentation without stopping the line


It is technically correct to apply the instinctive fix – to completely sever the plant network from the corporate network – but this is rarely as easy as a single flip of a switch. In most facilities, you find years of improvised network connectivity: a vendor's remote connection utility used to service a filler, a laptop occasionally plugged directly into a control cabinet, a historian server that has quietly built a bridge between both networks because someone needed a dashboard.


The starting point in a real facility isn't a complete network redesign. It's an inventory. Most plant managers could probably walk the floor and identify every major piece of equipment, but far fewer could do the same for the network. Who is communicating with whom? Which connections extend to the public Internet? An inventory, as mundane as it sounds, is by far the single highest value first step because it defines what must be separated.


From this inventory, the next priority becomes isolating remote access, particularly vendor connections. The access to plant machinery required by a vendor support call is among the simplest ways for outside traffic to get in, and it's one of the easiest ways to isolate a connection without affecting production – time-limited access, a session under monitoring, no unattended, open connections left behind by the vendor.



A roadmap that doesn't require a CISO


Every manufacturer doesn't have the budget for a security team, and saying so does nothing but pave the way to inaction. It is far better to proceed incrementally than to attempt an all-or-nothing upgrade: begin with visibility. Figure out what hardware is running, connected to what, and most likely what it’s connecting to. This alone brings obvious threats to the surface for most operations.


Secure remote access connections. Scrutinise vendor and contractor access to the plant floor prior to purchasing a single piece of gear. Segment based on consequences, not convenience. Distinguish those systems where downtime is the end of the world (cold chain or batch control) from those where downtime simply inconveniences users (guest Wi-Fi or office printers).


Plan for the worst. Most well-secured operations will be attacked. Determining in advance which lines can be run manually, how long data can be reconstructed offline, and who calls to shut down a section of the network mid-shift will be far more valuable than the latest whiz-bang detection gadget. None of these require an IT security executive.


They do, however, require plant managers and IT managers talking – perhaps for the first time in depth – to prioritise and decide how best to spend their money. Viewing the production floor as a piece of critical infrastructure, worth protecting for its own sake rather than simply the office’s support system, is a business, not technology, choice, and belongs in conversations about capital spending and supplier risk.


The manufacturers that stay ahead of the curve will be those who begin treating operational technology not as someone else’s department to fix, but as something critical that needs their own focused attention.

Shimadzu Leader | June 2026
bottom of page