"Recent disruptions have shown the resilience of the UK’s food supply chain, but risks are increasing in likelihood and severity. Defra should learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry," said Gareth Davies, head of the NAO.
NAO flags cyber-attacks as a major threat to the food supply chain
The National Audit Office (NAO) has named cyber-attacks as one of the major threats to the UK food supply chain, warning that the sector's long drive for efficiency has also increased vulnerability to disruption. In a report published late last week the NAO said businesses have faced increased costs and, in some cases, disruptions to day-to-day operations following cyber incidents that affected core digital systems.
The 2025 incidents that prompted concern: Marks & Spencer and the Co-op
The NAO cited cyber-attacks in 2025 on major retailers as concrete examples of the damage such incidents can cause. Marks & Spencer estimated the April 2025 cyberattack will cost it around £136 million ($177.2 million) in total. The retailer said "one of the earliest actions it took in its incident response was to disconnect its warehouse management systems, which in turn meant online and in-store orders were adversely impacted."
The Co-op confirmed that thieves stole data from 6.5 million of the organisation's members during a cyberattack last year. The NAO used those and similar episodes to underline how attacks on digital infrastructure ripple through ordering, warehousing and customer services across the chain.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDefra's exercises and the department's digital constraints
Defra told the NAO it has carried out specific food-related exercises since 2023 that focused on testing responses to a cyber incident affecting the food sector. The report nonetheless notes structural weaknesses in the department's own digital posture: "In 2023, it admitted two-thirds of its interactions with its 21 million customers still require paper-based forms," and that "30 percent of its applications were out of support."
The NAO observed that while Defra is running preparedness exercises, the department "may not be best placed to offer tech advice" given those admitted shortcomings — a point the NAO used to recommend closer working between Defra and industry to bolster resilience.
Operational and economic impacts on businesses
The NAO found that cyber-attacks have increased operating costs for food supply chain businesses and disrupted core digital systems central to daily operations. Several organisations told the NAO they are making substantial investments to manage the threat and incidence of cyber-attacks, but the report also records that "overall economic pressure on businesses is making this and other resilience investments more difficult."
That pressure matters because, the NAO says, the food chain's efficiency-driven design reduces costs but "leaves the supply chain more vulnerable to disruptions." The report further warns Defra is "less confident about the ability of businesses to withstand shocks without government intervention in the next five to 10 years because of increasing risks and the potential for more severe disruptions."
What this means for technologists, policymakers, and consumers
- Technologists and security teams: Expect continued, and likely costly, investment in protecting warehouse management systems, ordering platforms and other core digital infrastructure — while grappling with constrained budgets as firms balance resilience spending against broader economic pressures.
- Policymakers and Defra: Will need to deepen collaboration with industry and local government through exercises and shared plans; the NAO specifically urged Defra to "learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry."
- Consumers and retail customers: May continue to see interruption to online and in-store ordering when operators take defensive steps such as disconnecting warehouse management systems — measures retailers say are part of early incident responses.
The NAO report sketches a clear trade-off: the efficiency that has lowered costs for businesses and consumers also concentrates risk into the digital nodes that run ordering, warehousing and customer records. With a recent, high-cost example in the £136 million impact on Marks & Spencer and a 6.5 million-member data theft at the Co-op, the question the NAO places before ministers and industry is concrete: can Defra and the sector stitch together better preparedness in time to prevent more severe shocks — especially when the department itself acknowledges gaps in its digital estate?




