‘It’s Not When, It’s Again’: An Ag-Cybersecurity Pioneer on Getting CEA Operations Ready for the Unthinkable
Andrew Rose has spent nearly a decade trying to convince the agriculture sector that a cyberattack can shut down an operation as fast as an equipment failure—and he’s not optimistic that most operators are there yet. As an advisor at BIO-ISAC and a longtime voice on cyberbiosecurity in food and ag, Rose has watched threats evolve from opportunistic ransomware to targeted corporate espionage aimed at proprietary genetics, automation IP, and production data. In this month’s Indoor Ag-Content Q&A, Rose explains why “secure-by-design” thinking needs to start on day one of any CEA build-out, why untested backups aren’t really backups at all, and why the industry’s next decade of risk may come down to a very old-fashioned question: what happens when the internet doesn’t work? Rose will expand on these themes as a speaker in the session Data Management and Cyber Security in CEA at CEA Summit East this September in Danville, VA.
You started raising cybersecurity awareness in the ag sector back in 2016, well before most people were connecting the words “farming” and “cybercrime.” What did you see back then that made you realize agriculture was an unrecognized target—and how has that threat landscape changed as CEA operations have become more connected and data-driven?
In 2016, I ran a business continuity exercise at a large agricultural lender. A good way to pressure-test an organization is through a realistic crisis exercise. I designed a ransomware scenario that included every “worst-case” element: data exfiltration, encrypted and permanently disabled systems, and a ransom demand. It was enlightening to see the gaps we uncovered in our response plans.
That made me wonder whether the rest of the agricultural sector was equally unprepared. Nearly a decade later, I can confidently say that agriculture is still one of the most under-defended critical industries, and an un-recognized threat by our cyber defenders. Much of my work today remains focused on building basic awareness around cybersecurity threats and counter measures.
An important lesson I learned early on is the importance of secure-by-design thinking. Security shouldn’t be added after a greenhouse is built, a robot is deployed, or software is released, it needs to be high on the list from day one. Every organization should be asking two simple questions: How will we defend our products? and How will we defend ourselves?
Unfortunately, those questions are often overlooked. I’ve had CEOs tell me everything from, “I hadn’t even considered security,” to, “We know it’s an issue, but we’re waiting until our next funding round to address it.” Those responses make me shake my head and feel the blood run a little colder in my veins.
Today’s threat environment extends far beyond ransomware. Corporate espionage is white-hot, with competitors (team on team), organized criminal groups, and even nation-state actors seeking proprietary genetics, automation technologies, production methods, and to pick up a crippled company’s assets for pennies on the dollar. You are a target.
A lot of growers assume cybersecurity is an “IT problem” for banks and retailers, not something that applies to a greenhouse or vertical farm. What’s actually at stake for a CEA operator if their systems are compromised, and why should that risk be top of mind for someone running a growing operation—not just their IT vendor?
For a controlled environment agriculture operation, a cyberattack can directly threaten production. Environmental controls, irrigation systems, lighting schedules, nutrient delivery, climate management, inventory records, food safety documentation, and customer information all depend on connected systems. If those systems become unavailable or are manipulated, entire crops can be lost within hours or days.
For operations with narrow margins, a disruption can fast become a financial crisis. Beyond replacing hardware or recovering data, companies must also rebuild trust with customers, distributors, insurers, and regulators. Without accurate production and traceability records, it may be impossible to move products into the marketplace.
Another consideration is cyber insurance. Many policies now require organizations to demonstrate basic cyber hygiene: multi-factor authentication (MFA), strong password management, network segmentation, regular patching, and secure backups. If those fundamental safeguards weren’t in place, insurance coverage may be reduced or denied.
The organizations that recover most successfully are those that recognize cybersecurity isn’t solely an IT responsibility. Operations, management, communications, legal, and executive leadership all have roles to play. Without a practiced recovery plan, valuable time is often lost assigning blame rather than restoring operations.
Can you tell readers a little about BIO-ISAC and the work you do there? How does the organization approach threat awareness and information-sharing specifically for the bioeconomy, and what does that look like in practice for a food and ag business trying to stay ahead of adversaries?
The BIO-ISAC was founded after recognizing that significant portions of the bioeconomy were being overlooked by traditional cybersecurity efforts. Originally, the term bioeconomy referred primarily to agriculture, forestry, and marine industries. Today, it encompasses the broader life sciences ecosystem, from ag production, biotechnology, pharmaceuticals, diagnostics, and related sectors.
Our mission is to improve the cyberbiosecurity and resilience of organizations that rely on biological systems.
We accomplish this in several ways. We share timely threat intelligence with our members, publish public advisories, provide incident response support, and serve as a trusted safe harbor for responsible vulnerability disclosure. If a researcher or company discovers a cybersecurity vulnerability in a product or system, BIO-ISAC helps coordinate responsible reporting with the appropriate vendors and stakeholders.
In many cases, organizations contact us after experiencing a cyber incident. Occasionally, we identify malicious activity affecting a member before they’re even aware of it. Either way, our goal is to provide practical support, technical expertise, and trusted information-sharing that helps limit damage and improve resilience.
The single best recommendation I give organizations is to rehearse the unthinkable.
Assume you’ve been hacked. Your systems are offline. Production has stopped. Customers are calling. Criminals are demanding payment. Then ask your team: What happens next? Who’s in charge?
Running tabletop exercises with both leadership and operational staff exposes gaps before a real crisis occurs. It builds muscle memory, clarifies decision-making, and significantly reduces the confusion that follows a cyberattack. BIO-ISAC regularly works with agricultural and life science organizations to conduct these exercises because preparedness is one of the most effective forms of cybersecurity.
CEA operators would be wise to review the checklist we provided to Indoor-Ag and hold their vendors accountable. Simple questions like: Does this have a password? and How can I change it? are a good start.
The old saying was, “It’s not if, it’s when.” Today, it’s more accurate to say, “It’s not when, it’s again.” Plan accordingly.
The CEA Summit East session you’ll be part of will touch on “practical strategies” for data management that keep records audit-ready and operations running without interruption. Can you share one habit or safeguard you see too many CEA operators skipping—and what would you tell a grower who wants to get their house in order but doesn’t know where to start?
The most overlooked safeguard is one of the simplest: reliable, tested backups.
Many organizations assume they’re backing up their data, but they’ve never actually verified that those backups can be restored quickly. A backup you can’t recover isn’t really a backup.
Critical operational data should follow the 3-2-1 principle: maintain multiple copies, store them on different types of media, and keep at least one copy offline or otherwise isolated from your primary network. Adversaries frequently target backup systems first because they know organizations are more likely to pay a ransom if recovery isn’t possible.
I also encourage organizations to remember that some information is perfectly acceptable to keep offline. Paper records can’t be hacked, and removable drives that are disconnected from the network provide an important layer of resilience.
Ask yourself a few simple questions:
- If all of your systems disappeared today, when was your last successful backup?
- How long would it take to recover your data?
- How long before production returned to normal?
If you don’t know those answers, that’s where you should start. Make backups routine, automate them whenever possible, and regularly test that you can restore them successfully.
You describe yourself as an agricultural futurist focused on a world for people whose parents haven’t been born yet. As connectivity, automation, and data collection keep expanding in CEA, where do you see the biggest cybersecurity blind spots emerging in the next five to ten years—and what should the industry be doing now to get ahead of them?
The most significant change over the next decade will be the continued expansion of artificial intelligence, both as a defensive tool and as a weapon for cybercriminals.
AI allows attackers to automate reconnaissance, identify vulnerabilities, and launch attacks against thousands of organizations simultaneously. Criminal groups increasingly use AI-powered tools to gain initial access, then sell that access to ransomware operators or other malicious actors.
AI has also dramatically increased the effectiveness of social engineering. Deepfake audio and video have become convincing enough to damage reputations, manipulate employees, and create confusion during a crisis. It’s easy to imagine a future where a fabricated video appears to show a CEA executive admitting contaminated products were shipped or making statements that never occurred. The technical barriers to producing that content continues to fall.
As an agricultural futurist, the further I look, the more analog it gets.
Modern agriculture depends on digital infrastructure that most take for granted: GPS timing, internet connectivity, cloud services, electronic payments, and automated logistics. Those systems work so reliably that we’ve forgotten they’re potential points of failure.
If geopolitical conflict or a major infrastructure disruption were to affect GPS or internet availability, how would a CEA operation continue functioning? Could deliveries still be made? Could employees navigate with paper maps and do they have them? Can you process payments in a non-digital fashion? Could production continue without cloud connectivity? Do you still have manual operating procedures, paper documentation, or legacy equipment that functions independently of the internet? More importantly, does anyone still know how to use them?
It pays to be prepared.
About Andrew Rose
Andrew Rose is an agricultural futurist. He focuses on endeavors which benefit people whose parents haven’t been born yet, on a world as it will be.
He is an advisor at the BIO-ISAC (www.isac.bio), helping to bring cybersecurity (and related threat) awareness/mitigation/response to the bioeconomy with a focus on the agriculture and food sector. He has served as the Chief Strategy Officer in Residence at the Emerging Technologies Centers, the Chair of the Advisory Council for the Maryland Cybersecurity Association, and a judge for the first two years (2019/2020) of the Grow-NY AgInnovation in conjunction with Cornell. Andrew helped found the GIVE Program, a leadership training program in Maryland for rising professionals.
Andrew began a cybersecurity awareness program in 2016 while at a major agricultural bank after recognizing that the ag sector wasn’t getting the attention it needed about the risks posed by cybercriminals and other adversaries. In addition to his experience in cybersecurity, he has a deep understanding of banking/finance, risk management, and other professional service sectors related to food and agriculture.
Andrew is an avid hiker and has summited 35 (of the 56) 14k+ mountains in Colorado.


