Suggested region and language based on your location

    Your current region and language

    Guidance helps food and drink sector boost resilience to cyber threats

    BSI has updated PAS 96 to help sector strengthen resilience against cybercrime, malicious contamination and other deliberate attacks.

    20 July 2026: Guidance designed to reduce the risk of an attack that could paralyse the food and drink supply network has been updated by BSI, the UK’s national standards body. The revised document places increased emphasis on cyber-enabled threats, recognizing the sector’s growing dependence on connected systems, digital infrastructure and automated production.

    First published in 2008, the updated framework, Food Defence – Prevention and Protection from Deliberate Attack – Guide (PAS 960), provides a practical tool to guard against threats ranging from malicious contamination and terrorism to economically motivated adulteration.

    With the food and drink sector facing growing pressure from geopolitical instability, sophisticated cyber threats, and the impacts of climate change, the standard outlines how organizations can identify, assess, and mitigate the risks of malicious contamination, ideologically motivated attacks, and other intentional disruptions, helping to strengthen safety and resilience across the sector. PAS 96 has been updated with input from a steering group including UK government, the Food Standards Agency, global food brands such as Tesco and PepsiCo, academia, and industry bodies.

    Highlighting the vulnerability of our food and drink supply chain, BSI’s most recent supply chain risk report found that food and beverages were the most frequently targeted commodities in cargo theft, accounting for 14% of all incidents, followed by agricultural goods (8%). Strategic theft - highly organized, deceptive crime often involving fraud rather than force - now accounts for around 5% of incidents globally. Incidents are often cyber-enabled, using phishing, spoofed carriers or stolen identities to gain access to legitimate shipments and divert cargo.  BSI’s SCREEN Quarterly Risk Intelligence Outlook identified the top countries for thefts globally in the first quarter of the year: Brazil (27%), India (14%), the US (12%), Mexico (11%), and Germany (4%), and the top modalities: Truck (75%), Facility (15%), Sea (3%), Van (2%), and Rail (1%).

    The guidance responds to an increasingly risk-filled environment, building on lessons from the COVID-19 pandemic, which exposed vulnerabilities in global food trade and supply networks. Recent geopolitical tensions, including conflict in the Middle East and resulting pressures on global energy markets, have further increased operational and cost challenges for businesses.

    Emily Field, Food Sector Lead, BSI, said: “The food and drink supply network is a vital part of the UK’s critical national infrastructure, and it is under constant pressure, whether from rising costs and operational disruption, geopolitical conflict or climate events. These conditions create opportunities for malicious actors, like criminals, extremists and opportunists, to exploit vulnerabilities in supply networks.

    PAS 96 has guided the global food industry for nearly two decades, and this latest revision reflects the realities organizations now face, providing a practical, risk-based framework to strengthen resilience and safeguard operations. Ensuring the safety, integrity, and availability of food is crucial for business continuity and national resilience.”

    The guidance supports organizations across the food supply networks, from primary producers and manufacturers to retailers and SMEs. It promotes the Threat Assessment Critical Control Point (TACCP) methodology. It encourages organizations to think like threat actors by assessing their motivation, capability, and opportunity to carry out a deliberate act, and then implementing appropriate mitigation measures. As the threat landscape evolves, organizations are encouraged to ask four key questions:

    1.    Who might want to act against us?
    2.    How might they do it?
    3.    Where are we vulnerable?
    4.    How can we stop them?

    For example, the guidance encourages organizations to assess potential threat actors by considering four key factors:

    Motivation and determination – Does the threat actor have the intent and persistence to overcome barriers? Robust controls can often deter attackers and encourage them to seek easier targets.

    Capability – Does the threat actor possess the necessary skills, resources, and expertise? Organized groups may have access to greater resources and specialist capabilities than individuals.

    Opportunity – Can the threat actor gain access to carry out the act? While physical attacks require direct access to facilities or products, cyberattacks can be conducted remotely through connected systems and devices.

    Deterrence – Is the likelihood of detection, intervention, or legal consequence sufficient to discourage an attack?

    By embedding food defence into existing risk management and food safety systems, organizations can improve preparedness, strengthen supply network resilience, and contribute to wider national resilience.

    Access the standard free of change here.