The National Audit Office has told Defra that cyber-attacks are one of the major threats to Britain's food supply chain, warning that while the UK food supply chain has shown resilience after 2025's retail breaches, increasing risks mean organisations should strengthen backup and disaster recovery solutions and engage in closer industry testing.
View the data behind this chart
| Nation-state | Other actors | |
|---|---|---|
| Incidents | incident…150 | incident…50 |
NAO sounds the alarm on food supply chain cyber risk
The National Audit Office published its assessment late last week, concluding that the UK food supply chain has so far absorbed shocks reasonably well — but that the likelihood and severity of disruption are both climbing. NAO head Gareth Davies put it bluntly: "Recent disruptions have shown the resilience of the UK's food supply chain, but risks are increasing in likelihood and severity. Defra should learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry."
That call for joint testing with local government and industry is the crux of the report, and it's a direct challenge to any operator still treating cyber incident response as a purely internal IT exercise rather than a coordinated continuity function.
M&S, Co-op and a chilled-food supplier: how 2025 attacks hit costs and operations
The NAO's warning isn't theoretical. It points to real financial and operational damage from last year's attacks on Marks & Spencer and the Co-op, both of which rippled through food supply chain businesses in the form of higher costs and, in some cases, day-to-day disruption.
Marks & Spencer has estimated the total cost of the cyberattack it suffered in April 2025 at around £136 million. The Co-op, meanwhile, confirmed that thieves stole data belonging to 6.5 million members during its own incident. Separately, Peter Green Chilled — a chilled and frozen food logistics firm supplying UK supermarkets — was hit by ransomware that temporarily halted deliveries, a reminder that the risk sits as much in warehousing and distribution as it does in retail head offices.
Part of a bigger pattern hitting UK critical infrastructure
The food sector isn't an isolated case. The NCSC's chief has said hostile actors launched close to 200 attacks on UK critical infrastructure between June 2025 and May 2026, with roughly three-quarters of those linked to nation-state activity. The NCSC's Annual Review 2025 describes the threat to CNI as remaining high and recommends isolating operational technology and shrinking the attack surface as core defensive priorities.
For food logistics and distribution operators, that framing matters: this is not generic cybercrime opportunism, it's sustained pressure from capable, patient adversaries who understand that disrupting deliveries has knock-on effects far beyond a single retailer's balance sheet.

Why DR and segmentation playbooks need updating now
For CNI-adjacent operators — food logistics, warehousing, cold-chain distribution — the practical takeaway is that recovery speed and network segmentation are now board-level resilience issues, not back-office IT tasks. Segmenting operational technology from corporate IT, following the NCSC's own guidance, limits how far an intrusion can spread before it stops pallets moving or chills breaking down.
Equally important is proving that recovery actually works under pressure. Businesses that can calculate the cost of downtime in their own operation have a much stronger case for investment than those relying on assumption, and pairing that with proper sizing your backup and DR infrastructure avoids the common failure mode of discovering backups are inadequate mid-incident.
Regulatory direction: expect more scrutiny on backup resilience
The NAO's push for Defra to test emergency plans jointly with local government and industry signals where policy is heading — towards mandated exercises and demonstrable readiness, not just written plans sitting in a drawer. Operators who get ahead of that curve by adopting immutable backup architectures and rehearsing clean room recovery strategies will be far better placed when regulators or insurers start asking for evidence.
Layering in managed detection & response across distributed warehouse and logistics networks also addresses the specific weakness the NCSC has flagged: attackers dwelling inside dispersed IT/OT environments long enough to cause maximum disruption before anyone notices.
A practical checklist for infrastructure buyers
None of this requires reinventing resilience from scratch — it requires treating the NAO's warning as the trigger to test what's already in place.
- •Map which systems, if disrupted, would stop goods moving — and segment them from general IT under zero trust principles
- •Test recovery time objectives against real ransomware protection strategies, not just backup completion reports
- •Run joint exercises with logistics partners and local authorities, echoing the NAO's call for cross-sector testing
- •Review overall exposure with a comprehensive cybersecurity solutions assessment and understand ransomware for UK businesses before the next incident forces the issue
- 01The Register — UK food supply chain at risk from hostile attacks · 7 September 2026
- 02Computer Weekly — Hostile states launched nearly 200 attacks on UK infrastructure in 12 months, says NCSC chief · 17 June 2026
- 03NCSC Annual Review 2025 — Cyber threat to the UK · 1 January 2025
- 04NCSC Annual Review 2025 — Defending the UK's critical national infrastructure · 1 January 2025
- 05TechRadar — Co-op and M&S food supplier hit by ransomware attack · 1 May 2025
- 06theregister.com
- 07theregister.com
- 08theregister.com
