Agriculture and Farm Services

Cybersecurity for Agriculture: What Can Attackers See About Your Business?

Learn what public email records, forgotten websites, and remote logins reveal about your agricultural business – and which security checks to prioritize first.

Why public exposure matters during a busy season

You replaced the website, switched email providers, or stopped using an old ordering portal. The next question is whether the old systems actually disappeared from the internet.

For a seed supplier, feed dealer, agricultural cooperative, or farm-service business, a public exposure check is a way to find those loose ends before they create confusion. An old portal may still have no clear owner. A supplier can be imitated through a lookalike domain. A remote login may be reachable even though nobody remembers who uses it.

None of those observations proves a breach. They do tell you where to ask better questions – especially before planting, harvest, or seasonal ordering puts pressure on email, payments, and delivery coordination.

1. Your email domain reveals part of your security setup

Your domain’s public email settings can show which provider handles your mail and which services are allowed to send messages in your name. SPF, DKIM, and DMARC are the checks receiving mail systems use to help decide whether those messages are legitimate.

One useful check is the DMARC policy. A policy of `p=none` asks receiving systems to report failures, but not to quarantine or reject them. That can be a reasonable starting point while email is being mapped, but it is not an enforcement policy.

Before tightening that policy, identify legitimate senders, including invoicing software and marketing platforms. Microsoft’s DMARC guidance explains the staged rollout.

Ask: “Which systems send email for us, have they been checked, and who reviews the reports?”

DMARC helps address direct-domain spoofing. It does not stop lookalike domains or fraudulent messages sent through a compromised legitimate mailbox. Verify supplier bank-detail changes using a known contact method, regardless of how convincing the email looks.

2. Your old website may still be reachable

A redesigned homepage does not establish that the previous website, test environment, or separate customer portal was retired.

Imagine an agricultural retailer launches a new website while an older order-request application remains accessible at another address. That does not mean the application is unsafe. It does mean someone should confirm whether it is still needed, who maintains it, and whether it still holds information.

An old-looking page is not proof of a vulnerability. But a reachable application with no clear owner deserves investigation.

Ask: “Which websites and portals do we still operate, who patches them, and which can we safely retire?”

3. Forgotten subdomains can outlast the services behind them

Addresses beginning with `orders.`, `portal.`, or `remote.` can sit alongside your main website. They may still appear in public records even when your homepage no longer links to them.

A particular concern is an internet address that still points to a discontinued third-party service. Depending on the provider and configuration, an attacker may be able to claim the abandoned resource and serve content through the business’s subdomain. Microsoft documents this risk as subdomain takeover.

A broken page alone does not prove takeover is possible. The record, service, and ownership need verification.

Ask: “When we cancel a hosted service, do we also remove or update its DNS records?”

4. Remote-login pages show where access needs scrutiny

A publicly reachable VPN, Remote Desktop service, or administrative login can reveal an access point worth reviewing. That may be intentional, but it should have a known owner and a reason to be online.

Some public login pages are intentional. Their presence does not tell an outsider whether MFA is enforced, software is patched, or access is appropriately restricted. Those controls require separate verification.

CISA recommends reviewing internet-facing services and disabling unnecessary exposure or restricting access to users who need it.

Ask: “Which remote-access services are reachable, who uses them, and what evidence confirms their protection?”

For agriculture, keep business IT and equipment controls distinct. A review of your website and email cannot establish the security of irrigation systems, grain-handling equipment, or production controls.

Visible does not mean vulnerable – or breached

A public review is a starting point, not a penetration test or incident investigation. Use the result to decide what needs confirmation.

A public login page means an access point is discoverable. It does not prove that the service is weak.

A confirmed weakness means a safeguard needs attention. It does not prove that someone exploited it.

Evidence of unauthorized access or activity is different: preserve what you have and investigate it with your IT provider or an incident-response specialist.

The same limit applies to email, websites, and DNS. Public visibility cannot prove that internal accounts, backups, or payment procedures are secure – or rule out a breach.

A five-question checklist for agricultural business owners

Use these questions with your staff or IT provider. Write down the answer and the evidence behind it:

  1. What do we own? List current and former business domains, websites, customer portals, and remote-access services.
  2. Who is responsible? For each one, record the business owner, IT provider, renewal date, and whether it is still needed.
  3. How is our email authenticated? List legitimate sending services and record the current DMARC policy and who reviews its reports.
  4. What remains accessible? Review remote access, old applications, and records pointing to retired services. Do not remove anything until its owner confirms it is no longer needed.
  5. What happens next? Record each confirmed issue, its business impact, the responsible person, the evidence still needed, and a target date.

Start with a public exposure review

You do not need a complete technical inventory to take the first step. The Free Zero-Access Exposure Review examines public signals around your business email, domains, websites, and internet-facing services. It requires no passwords or internal access and gives you a plain-English conclusion and first recommended next step.

If you need to know whether internal safeguards are actually working, the $1,995 Business Security Baseline is the next step. It verifies agreed evidence around email protection, Microsoft 365 access, remote access, backups, and recovery readiness.

Your existing IT provider can remain responsible for day-to-day work. The useful outcome is a short list of confirmed issues, clear ownership, and a date for checking that the fix is complete.

What a finding means

A public signal tells you what to investigate next. It does not, by itself, tell you that a system is vulnerable or that anyone got in.

CheckEvidence to requestSuggested owner
Public login pageAn access point is visible from the internet; this does not prove the service is weakBusiness owner and IT provider
Old website or portalA former application may still be reachable; this does not prove it is unsafeBusiness owner and application maintainer
DNS record for a canceled serviceAn internet address may still point to a provider you no longer useDomain owner and IT provider
DMARC policy set to p=noneReceiving mail systems are asked to report failures, not quarantine or reject themEmail administrator or IT provider
Evidence of unauthorized activityA possible compromise needs investigationBusiness owner, IT provider, or incident-response specialist

Choose the right next step

Start with the free review if you want to know what outsiders can see. If you need internal safeguards verified, the $1,995 Business Security Baseline reviews agreed evidence around email, Microsoft 365 access, remote access, backups, and recovery readiness.

Start the Free Exposure ReviewExplore the $1,995 Baseline