Skip to content
LinkedIn YouTube

Focus on cybersecurity: Preparing the food sector for NIS 2 and emerging AI threats

The security and continuity of the food supply chain remain a critical concern. With the cyber threat landscape rapidly expanding, notably due to new attack vectors leveraging Artificial Intelligence (AI), the need for robust cybersecurity governance is more pressing than ever.


The NIS 2 implementation status

Directive (EU) 2022/2555 (NIS 2) is a landmark piece of European Union legislation aimed at achieving a high common level of cybersecurity across the Union. Member States were required to transpose the Directive into national law by 17 October 2024.

Current status: The legal deadline for transposition has passed. Nineteen Member States have failed to meet this deadline and have yet to fully implement NIS 2 (see the latest status here: European Commission – NIS transposition).

Despite varying progress in national implementation, the requirements set out in NIS 2 are establishing the benchmark for cybersecurity in sectors deemed essential, including the food sector.


Key obligations and the risk-based approach

NIS 2 mandates that affected entities — which now explicitly include food production, processing, and distribution companies — must implement robust measures focusing on:

  1. Mandatory risk management: Implementing effective, technical, and organisational risk management measures.
  2. Incident reporting: Reporting significant cyber incidents to relevant national authorities.
  3. Accountability: Establishing clear personal accountability for management regarding compliance with cybersecurity obligations.
  4. Supply chain security: Prioritising the security of supplier and supply chain relationships, especially by regulating security requirements with providers during modernisation projects and the construction of new facilities.

Call to action: Proactive preparation is essential

While the NIS 2 Directive primarily addresses Member States' legislative obligations, companies in the food sector should not delay preparation until their national laws are fully enacted. The growing threat landscape, particularly the sophistication introduced by AI, demands immediate action.

An immediate and thorough risk analysis is crucial. This analysis must:

  • Integrate new threats: Systematically identify and evaluate new and evolving threats, specifically those facilitated by AI, which can escalate the sophistication and speed of attacks.
  • Assess impact: Define the potential consequences and cascading effects of these threats on operational technology (OT), supply chain integrity, and product safety.
  • Determine proportional measures: Allow for the application of appropriate and proportionate security measures designed to effectively minimise the identified risks and ensure business continuity.

Proactive governance based on a solid risk analysis is the most effective strategy for mitigating the growing threat landscape and aligning with the principles of NIS 2.

Cybersecurity and product defence are increasingly recognised as interconnected pillars of risk management in the food sector. The IFS Product and Food Defence Guideline version 2 provides valuable insights on aligning these disciplines to safeguard operations and maintain consumer trust. Find the guideline here.

We encourage all food companies to assess their current cybersecurity maturity and risk posture now.



About the author

Dawid Stępień is an ISO 27001 Lead Auditor and Sales Expert with a strong background in certification and standards. He previously worked as a Product Manager in a certification body, focusing on quality management systems (IFS, BRCGS, ISO 22000, ISO 9001) within the food industry.

Today, he combines proven management practices with the dynamic world of cybersecurity, bridging two traditionally separate fields. Dawid is also an active voice in raising security standards and has notably contributed to the IFS Product and Food Safety Standard version 2 on cybersecurity.

He is a key part of the team at Dynacon, a manufacturer of network communication solutions, monitoring systems, cybersecurity tools, and information-visualisation technologies supporting business continuity and optimisation.

Blog

Blog IFS Editorial Team 11.05.2026

IFS Faces – Serena Venturi

In this IFS Faces blog article, we introduce Serena Venturi. She is Senior Technical Manager within the IFS Standard Management department and IFS Representative for Italy. With more than 18 years...
Lire la suite
IFS Faces – Serena Venturi
Blog IFS Editorial Team 19.03.2026

IFS Faces – Konstantina Papastamopoulou

In this edition of our IFS Faces blog, we introduce Konstantina Papastamopoulou, who recently took on the role of IFS Broker Standard Manager. With a strong scientific background in food safety,...
Lire la suite
IFS Faces – Konstantina Papastamopoulou
Blog IFS Editorial Team 05.03.2026

Unannounced audits: the key to improved results and showing commitment to food and product safety

The IFS Standards stipulate that unannounced audits are either mandatory or voluntary, depending on the standard. For GFSI-recognised standards such as IFS Food, Broker, Logistics and PACsecure,...
Lire la suite
Unannounced audits: the key to improved results and showing commitment to food and product safety
Blog IFS Editorial Team 30.01.2026

IFS Faces - Britta Müllender

Through the IFS Academy, we transform standards and sustainability requirements into practical learning solutions that support auditors, certification bodies, and companies across the entire supply...
Lire la suite
IFS Faces - Britta Müllender
Blog IFS Editorial Team 15.10.2025

Focus on cybersecurity: Preparing the food sector for NIS 2 and emerging AI threats

The security and continuity of the food supply chain remain a critical concern. With the cyber threat landscape rapidly expanding, notably due to new attack vectors leveraging Artificial...
Lire la suite
Focus on cybersecurity: Preparing the food sector for NIS 2 and emerging AI threats
Blog IFS Editorial Team 05.08.2025

Frimesa's journey from IFS Progress Food to IFS Food

In Brazil's dynamic food market, food safety and quality management are crucial for both producers and consumers. Frimesa is one of the companies committed to excellence in these areas. By utilising...
Lire la suite
Frimesa's journey from IFS Progress Food to IFS Food
Blog IFS Editorial Team 09.07.2025

How the IFS ESG Compliance Check empowers businesses in sustainable practices

Environmental sustainability, social responsibility, and corporate governance (ESG) are becoming key priorities for consumers, investors, and regulators. To help small and medium-sized businesses...
Lire la suite
How the IFS ESG Compliance Check empowers businesses in sustainable practices
Blog IFS Editorial Team 24.06.2025

IFS Faces - Tina Brune

I am passionate about helping businesses identify and manage supply chain risks, supporting them to improve and grow. Tina Brune, Director Risk Management Tina has been a valued member of the IFS...
Lire la suite
IFS Faces - Tina Brune
Blog IFS Editorial Team 19.06.2025

Effective Risk Assessment in Packaging: Seven Simple Guidelines for Ensuring Safety and Quality

The IFS PACsecure Standard and Progress PACsecure Program adopt a risk-based approach to assessing the safety and quality of packaging materials. This methodology allows you to perform...
Lire la suite
Effective Risk Assessment in Packaging: Seven Simple Guidelines for Ensuring Safety and Quality