Agriculture and Farm Services

Who Can Access Your Farm’s Digital Systems? What a New Agriculture Cybersecurity Proposal Means for Your Business

Iowa State researchers propose an agriculture cybersecurity consortium. Use five questions to review farm accounts, vendor access, payments, and recovery.

Iowa State researchers have proposed a national agriculture cybersecurity consortium. While it remains a proposal, farms and agribusinesses can review who has system access, how payment changes are approved, and what they would do during an outage.

Iowa State’s proposed agriculture cybersecurity consortium

Iowa State University reports that “Cybersecurity and Resiliency in Agricultural and Food Systems” was published in Nature Food on October 1, 2026, following three regional workshops and follow-up sessions involving more than 150 participants.

The work is led by Manimaran Govindarasu, an electrical and computer engineering professor, and Doug Jacobson, director of Iowa State’s Center for Cybersecurity Innovation and Outreach. Their “Cybersecurity for Smart Agriculture” project, supported by the university’s Presidential Interdisciplinary Research Initiative, is the basis for the proposed consortium.

The proposal calls for five regional centers and a coordinating hub, linking research and testing with education and Extension support for smaller operations.

It is still a proposal, not an operating nationwide service. Establishing it would require substantial government funding and public-private support.

What this means for a smaller farm or agribusiness

You can start by checking who owns your email accounts, supplier portals, remote-support connections, and business records.

For example, an equipment dealer’s technician gets access to troubleshoot software. The job is finished, but nobody records when that access should end. Months later, the owner cannot tell whether the account belongs to the current technician, someone who left the dealership, or a shared support team.

That gap does not mean anyone has misused the account. But it can make it harder to approve support, investigate an unfamiliar login, or know whom to call when something goes wrong.

Use these five questions with your office team, IT provider, software vendors, and equipment dealers. They are practical checks, not findings about any particular farm.

1. Who can sign in—and who approves their access?

Start with business email, accounting, purchasing, shared files, and farm-management or customer portals. Ask each system owner for a current user list, including administrators, vendor users, and seasonal staff.

For each account, identify the person or organization using it, the business reason, and the employee responsible for approving it. Investigate accounts that nobody recognizes. Review former employees and expired vendor relationships before disabling access, so necessary work and records are preserved.

Use individual accounts where supported instead of sharing one password. Where available, require multifactor authentication (MFA)—a second sign-in check—especially for email, administrator accounts, and remote access. Record any exceptions and ask the provider how they are protected.

  • Ask your provider: “Can you show us who currently has access, which accounts have administrator powers, and which are excluded from MFA?”

2. Who can connect remotely—and can you see when they do?

Remote support can save a service visit, but it still needs an owner and a clear purpose. For each connection, find out:

Ask whether access can be limited to the systems needed and enabled only for an approved service window. If the vendor needs ongoing access, document why and how it is supervised. CISA’s guide explains how legitimate remote-support tools can be misused and how organizations can improve oversight.

Coordinate changes affecting irrigation, ventilation, grain handling, or other production equipment with the responsible operator and qualified vendor. An office access review should not become an unplanned change to equipment during active operations.

  • Which provider and support tool are involved, and what systems can they reach?
  • Does someone approve each session, or is access always available?
  • How does the provider verify its staff, and who reviews session records?
  • How is access removed when the work or relationship ends?
  • Ask the vendor: “Can we identify who connected, when they connected, and which systems they could reach?”

3. Who can change where supplier payments go?

An account review should include permissions to change supplier records and payment destinations. A person who can read an invoice does not necessarily need permission to change the bank account receiving payment.

Choose a clear rule: independently verify bank-detail changes before processing them. Use an established contact number or trusted business channel, not the details supplied in the change request. Record who confirmed the request and who approved the change; use a separate approver where practical.

For a small business where one person handles purchasing and payments, the owner can review changes through the approved payment system before release.

  • Ask accounting: “Show me how we verified the last supplier bank change—not just the email asking for it.”

4. What happens if a provider or platform goes offline?

Your own computers may still work while an essential cloud service is unavailable. Decide which information your operation needs to continue the next few tasks: open orders, delivery schedules, supplier contacts, customer commitments, or production records.

Ask the provider what you can export, what it backs up, and what you must protect separately. Keep permitted, current copies of essential records in a secure location that remains accessible if the primary service fails.

Walk through a short scenario: “The ordering platform is unavailable this morning. How do we identify today’s deliveries, contact customers, and record changes?” Assign responsibility for reconciling temporary records when the service returns.

For systems you back up, request evidence of a restoration test: what was restored, when, and whether the result was usable. A successful backup notification alone does not answer that question.

5. Who takes charge when something looks wrong?

An unfamiliar remote session, unexpected administrator account, or disputed payment instruction needs a clear reporting path.

Name the business decision-maker and technical contact. Keep verified contact details for your bank, insurer, IT provider, and critical vendors available outside the systems they support. Include an alternate for each essential role.

Preserve relevant messages, account notices, and activity records. If money may have been diverted, contact the bank immediately through a verified channel. If equipment behavior creates a safety or production concern, follow established operational procedures and involve the qualified vendor promptly.

  • Ask your team: “If this happens after hours, who receives the report, who can authorize action, and how do we reach them?”

Practical agriculture cybersecurity resources are already available

The consortium may take time to establish. In the meantime, farms and agricultural businesses can use resources that are already available.

NC State Extension and AgDefenders partners launched a Farm Cybersecurity hub in August 2026, with a connected-device inventory, farmer-focused guidance, and incident-response information. It is a separate initiative from Iowa State’s proposal.

This week, pick one important provider. Ask for its access list, agree who at your business owns the relationship, and confirm how to report unexpected activity. Use the worksheet below to record anything that still needs attention.

When you need a closer review

The $1,995 Business Security Baseline reviews agreed business IT safeguards and available evidence, including Microsoft 365 access protections, device security, backups, and incident readiness. It provides prioritized findings and next steps for business leaders and their IT provider.

A review of private farm platforms or vendor access needs its own agreed scope. Testing or changing connected equipment and production controls requires separate specialist work. Our guide to public exposure explains what an outside-in review can—and cannot—show.

A worksheet for your next provider conversation

Use each row to guide the conversation about an important system or vendor connection. In your notes, mark each answer verified, needs attention, or not verified, then add a named owner, next step, and due date. Keep the notes secure; refer to restricted account or payment records rather than copying passwords or full banking details. Ask for records where available, not just verbal assurances.

CheckEvidence to requestSuggested owner
Who may sign in?Current users, administrator roles, approval records, and MFA exceptionsSystem owner and IT provider
Who may connect remotely?Approved tool, permitted systems, session records, and access-ending procedureVendor relationship owner and IT provider
Who may change payment details?Permissions, independent verification record, and approval exampleAccounting lead and business owner
How do we continue without the service?Available exports, fallback instructions, and restoration-test evidenceOperations lead and service provider
Who leads the response?Named lead, alternate, verified contacts, and escalation instructionsBusiness owner and technical lead

Choose the right next step.

The free Zero-Access Business Exposure Review examines public signals around your email, domains, websites, and internet-facing services; it does not verify internal access or recovery. The $1,995 Business Security Baseline is responsible for agreed internal safeguard verification.

Start the free exposure reviewExplore the $1,995 Business Security Baseline