The Challenge
The client is an agribusiness that had invested heavily in precision farming: connected sensors across its properties, automated irrigation and equipment control, and a cloud platform aggregating the resulting data into the decisions that drive yield. The productivity gain was real, and so was the attack surface it created.
Agriculture sits inside national food supply chains, and disruption carries consequences well beyond a single business. Much of the operational technology and connected equipment was never designed with security in mind, ran outdated firmware and used default credentials, while seasonal, high-tempo operations meant downtime was rarely acceptable. The company needed to understand its real exposure across both IT and operational systems without disrupting live production.
Our Approach
StrikeCyber assessed the full estate, treating the operational technology with the caution that connected physical equipment requires.
- Assessment of the corporate IT environment and the cloud data platform holding production and supply chain information.
- Review of connected sensors and equipment controllers, covering firmware currency, authentication and network exposure.
- Mapping the paths between office IT, field equipment and the cloud platform, establishing what a compromise in one would yield in the others.
Active testing against equipment controlling live irrigation or automated machinery was performed only with agreement and outside operational windows. Elsewhere, passive analysis and configuration review established exposure without touching production.
What We Found
- Default credentials across connected equipment. A significant proportion of sensors and controllers retained factory credentials, several of which were documented publicly by the manufacturer.
- Direct internet exposure. Equipment intended to be reachable only from the internal network was accessible from the internet through a remote support configuration that had been left in place.
- A path from office IT to production control. Credentials held on office systems were valid for the equipment management platform, connecting an ordinary phishing compromise to physical operations.
- Cloud data platform over-permissioning. Access to aggregated production and supply chain data was broader than required, including for vendor accounts.
The Outcome
Default credentials were replaced across the estate, and the business adopted a commissioning checklist so new equipment does not arrive in the same state. The remote support exposure was removed and replaced with a controlled access route requiring multi-factor authentication. Credential separation between office IT and equipment management closed the path from a phishing email to production control.
A follow-up retest confirmed the critical findings were remediated, that the path from office IT into production controllers was closed, and that the external attack surface around the operational estate was materially reduced. Resilience improved without interrupting a single production cycle.
Why It Matters
As farming digitizes, the gap between IT security practice and operational reality becomes the weak point attackers exploit. Food and agriculture is designated critical infrastructure for good reason, and the sector has already seen incidents halt processing at national scale. Segmentation, credential hygiene and safe, validated testing of connected equipment are what keep a productivity gain from turning into an operational and food supply risk. To test your IT and operational estate safely, get in touch.
