UK's Food Supply Is Fragile. Hackers Are One of the Reasons Why.
Britain's public spending watchdog says the government has not done enough to protect food supplies from climate shocks, disease outbreaks, and cyberattacks. Ordinary shoppers could feel the pinch when the next disruption hits.

Key points
- The National Audit Office (NAO), the UK's independent public spending watchdog, warned in 2024 that food supply chains face growing threats from climate change, disease, and cyberattacks.
- The NAO urged the Department for Environment, Food and Rural Affairs (Defra) to build closer ties with households, businesses, and communities to strengthen supply resilience.
- Cyberattacks on food and logistics companies are listed alongside climate events and disease as a top-tier risk to the flow of food into the UK.
- Britain has no strong plan in place to absorb supply shocks that the watchdog says are becoming more frequent and more severe.
Britain's shelves look full. Under the surface, the system keeping them that way is more fragile than most people realise, and the NAO wants the government to say that plainly.
The National Audit Office, which independently reviews how the government spends public money, published a report telling Defra, the government department responsible for food and farming policy, that it is not doing enough. The warning, first reported by The Guardian, covers three overlapping threats: a changing climate that disrupts harvests, animal and plant disease outbreaks, and cyberattacks on the companies and logistics networks that move food from farms to shops.
What does a cyberattack have to do with your weekly shop?
More than most people expect. Modern food supply chains run on software. Factories, warehouses, haulage firms, and port operators all rely on computer systems to manage orders, track refrigerated lorries, and coordinate deliveries. A cyberattack, where criminals or hostile states break into those systems to shut them down or hold the data hostage, can freeze a supply chain just as surely as a flood can.
This is not theoretical. In 2021, JBS Foods, one of the world's largest meat processors, paid roughly $11 million in ransom after criminals used ransomware, malicious software that locks a company's files until a payment is made, to shut down plants across the US, Canada, and Australia. The UK is not immune to the same class of attack hitting its own food sector.
The failure mode here is straightforward. A ransomware attack lands on a logistics provider. Deliveries stall. Supermarkets cannot restock fast enough. Prices spike or shelves go bare in specific categories. The people who feel it first are those with the least flexibility to absorb it.
Should ordinary people be worried?
Not panicked. Aware. The NAO's report is a planning warning, not a crisis alert. The concern is that a serious enough shock, whether a heatwave crushing European harvests or a cyberattack disabling a major distributor, could hit a system that has no real buffer.
In practice, the gap is not in the food itself but in the planning. Defra knows the risks. The watchdog's point is that knowing is not the same as preparing. Closer coordination with the businesses and communities that actually run the food system is what the NAO is calling for.
If you want to do something sensible: keep a basic household stock of staples. Nothing extreme. A few extra tins and dried goods means a short disruption does not become your emergency.
One thing the post-mortem will say, if a serious supply shock does arrive: the warnings were there, in writing, from the watchdog.



