Cybersecurity isn’t something many farming businesses have had to think about seriously until recently. A livestock farm or an arable operation running on paper records, cash payments, and a mobile phone wasn’t a particularly valuable target for cybercriminals. But the digitisation of UK agriculture over the past decade has changed that equation, and the pace of change has outrun the pace of awareness.

The Rural Payments Agency portal, farm management software, precision agriculture systems, GPS-guided machinery, smart sensors, and digital supply chain connections to processors and retailers have made UK agricultural businesses meaningfully dependent on digital infrastructure — and meaningfully exposed to the attacks that follow.

What Cybercriminals Are Actually After

The criminal motivation in most agricultural sector attacks is simple: money. The specific routes into farm businesses tend to cluster around a few patterns.

Rural Payments Agency and subsidy fraud is the most specifically agricultural threat. The RPA portal holds bank account details for BPS (Basic Payment Scheme, now transitioning to SFI) payments that represent significant income for many farms. Phishing emails impersonating the RPA — asking farmers to log in to “verify payment details” or “update records before the deadline” — are consistently reported by Action Fraud and the NCSC. A successful attack changes the bank account details in the portal, diverting the next subsidy payment to the attacker’s account. Payments diverted this way can be recovered, but the process is slow and the impact on farm cash flow can be severe.

Invoice fraud targeting farm supply chains takes advantage of the fact that many farms have regular large payment relationships with agricultural merchants, feed suppliers, machinery dealers, and contractors. Criminals who have access to email — either through phishing or by compromising a supplier’s email system — intercept payment instructions and substitute their own bank details. A £30,000 payment to a machinery dealer or a £50,000 payment for fertiliser going to the wrong account is a significant loss for any farm business.

Ransomware targeting farm management systems has affected a number of UK agricultural businesses over the past two years. Farm management software — Gatekeeper, Farmplan, Trimble Ag — holds crop records, financial records, livestock data, and traceability information that is needed for compliance, auditing, and sale. Ransomware that encrypts this data causes immediate operational disruption and has led to farms paying ransoms to recover records before audits or livestock sales.

The Systems That Create Exposure

Most farming businesses now have more digital systems than they have conscious awareness of:

Farm management software is often running on an office PC or a shared laptop, connected to the internet, and in many cases not regularly backed up or updated. These systems are targets both for data theft and for ransomware.

Precision agriculture equipment increasingly comes with cloud connectivity — John Deere Operations Center, CNH’s AFS Connect, AGCO’s Fuse system. These portals hold operational data, field records, and machinery settings. The accounts that access them are often set up during equipment purchase and then not revisited — single factor authentication, shared passwords, and no account recovery planning.

Smart farming sensors — weather stations, soil moisture sensors, livestock monitoring systems — connect via Wi-Fi or cellular and need software updates that don’t always happen automatically. Unpatched firmware on internet-connected devices creates pathways into farm networks.

The farm email account is the highest-risk single system in most agricultural businesses. Most farm business emails are accessed via a smartphone, on a personal account with no multi-factor authentication, and are used for everything from RPA correspondence to bank communications to supplier invoicing. A compromised email account gives an attacker access to all of these simultaneously.

Practical Steps That Actually Help

The security measures that make the most difference for farm businesses are not complex or expensive. The National Cyber Security Centre’s Cyber Essentials framework provides a sensible baseline that addresses the most common attack routes.

Multi-factor authentication on the RPA portal and email accounts is the single highest-priority action for most farms. The RPA portal supports authenticator app MFA. Enabling it means that a stolen password doesn’t give an attacker access to subsidy payment details. Enable MFA on your farm email accounts — both the email provider’s MFA and, if you use Microsoft 365 or Google Workspace for business, the MFA controls in those platforms.

Verify bank account change requests through a separate channel. If you receive an email saying a supplier’s bank details have changed, call the supplier on a number you already have — not the number in the email — to confirm before making any payment. This one practice would prevent the majority of invoice fraud losses in agricultural businesses.

Regular backups of farm management software data to a drive that is disconnected from the computer after the backup completes (or to a cloud backup service with version history). If ransomware encrypts your farm management system, a recent clean backup means recovery without paying a ransom. Weekly backups are the minimum; daily is better during busy periods when records are actively changing.

Software updates on farm office computers and precision agriculture portals. The most common route for ransomware onto business computers is unpatched software — operating systems, browsers, and farm management applications that have security updates available but not applied. Enable automatic updates where possible, and ensure the office PC or laptop used for farm management and RPA access is not running Windows 7 or 8 (both unsupported and extensively targeted).

Separate networks for smart farming equipment and the office network if your farm has both. Many router configurations support a guest network or VLAN that isolates IoT devices — sensors, monitoring cameras, precision agriculture equipment — from the computers used for financial administration. If a sensor is compromised, the isolation prevents the attacker from using it to reach the farm management PC.

Where to Get Help

The NCSC’s Small Business Guide (available at ncsc.gov.uk) covers the practical basics without assuming technical knowledge. The Cyber Resilience Centre for the region covering your farm area (there are nine regional Cyber Resilience Centres in England) provides free cyber health checks and advice specifically aimed at smaller businesses. The NFU (National Farmers’ Union) has run cybersecurity guidance and webinars through its legal and rural affairs teams that are worth accessing if you’re an NFU member.

Action Fraud (actionfraud.police.uk, 0300 123 2040) is the reporting route for any successful fraud. For RPA-specific fraud, the RPA’s dedicated fraud team should be notified directly as they can often halt or reverse a fraudulent payment if contacted promptly.

The risks in agricultural cybersecurity are real but manageable. Most farm businesses that have been successfully attacked were caught by one of a small number of well-understood and preventable attack patterns. The protection is not technically demanding — it’s primarily about consistent application of a small number of basic practices.