Agriculture and Farm Services

Harvest Cybersecurity Checklist: Five Checks Before Systems Go Down

Five practical checks for farms, grain elevators, co-ops, and farm-service businesses preparing for an email, account, or systems outage during harvest.

Harvest does not give an operations team much time to work out what happens when email, records, or a key account is unavailable. Use these five checks to find the gaps before they become an interruption.

A simple harvest readiness check

Mark each item Verified, Needs Attention, or Not Tested. Give every open item an owner and a date.

CapabilityEvidence to requestSuggested owner
Critical work and dependenciesA short priority list for receiving, scheduling, records, billing, payroll, and communicationsOwner or operations lead
Backup recoveryA dated restore test showing that a business user opened and checked representative recordsIT provider and record owner
Accounts and remote accessCurrent user and administrator lists, MFA status, vendor contacts, and a way to suspend accessIT provider with the business owner
Payment verificationA callback rule using a trusted number and a backup approver for urgent requestsFinance lead or owner

1. Identify the work that cannot stop

Start with activities, not applications. Ask what the team must be able to do during harvest: receive and weigh loads, find customer or supplier records, schedule hauling, invoice, run payroll, or contact people at another location.

For each activity, name the system or device it depends on, the person who owns it, and how long the business can operate without it. Include internet access, authentication, printers, power, and vendor support where they matter.

If every task is marked urgent, the list is not ready. Decide what returns first and who makes that decision.

2. Restore records before you need them

A successful backup notification is not the same as a usable recovery. Select a few representative records, such as a customer document, a recent delivery record, and an accounting or scheduling export.

Restore them to a safe test location. Have the person who uses each record confirm that it opens, is complete enough to use, and is recent enough for the business. Record the date, elapsed time, and any missing information.

Also ask who can reach the backup system if the normal administrator account is locked. Keep recovery instructions and provider contacts available outside the system they describe, but do not put passwords in a broadly shared checklist.

3. Review accounts and remote access

Review access to email, finance, shared files, equipment portals, and other essential systems. Remove former employees and unneeded vendor access, set end dates for seasonal accounts, and use individual accounts instead of shared passwords where possible.

Require multifactor authentication for important accounts and use separate administrator accounts where supported. List the remote-support routes used by your IT provider, equipment vendor, or other service companies. For each one, record its purpose, owner, approval process, and the steps for suspending access.

A vendor’s familiarity with the operation does not replace a current access review. Coordinate changes affecting equipment with the qualified vendor rather than improvising during an outage.

4. Slow down unusual payment requests

Make an independent callback mandatory for changes to supplier bank details, payment recipients, or deposit instructions. Use a number already in your records, not one supplied in the new email.

Use examples your team recognizes: a diesel supplier changes accounts, a machinery dealer requests another deposit, or a message asks the office to redirect a grain payment. Decide who can approve the change and what happens when that person is unavailable.

Urgency is not verification. If the trusted contact cannot be reached, the payment may need to wait.

5. Practice a short outage scenario

Use a simple scenario: “At 6 a.m., the office cannot sign in. A supplier reports a suspicious payment email from us. Trucks are due in an hour.” Walk through what pauses, who contacts IT, how staff communicate if email is unavailable, and what customers or haulers need to know.

Keep an offline contact sheet with critical providers, after-hours numbers, and the person who can authorize emergency support. If manual work is possible, test one fictional transaction and decide how it will be reconciled later. Some activities should pause when safe operation or reliable records cannot be maintained.

Write down the corrections from the exercise. A scheduled task is not a completed safeguard until someone verifies the result.

Choose the right next step

The free Zero-Access Business Exposure Review examines public signals around your company’s domains, email, websites, and internet-facing services. It does not log in, test farm equipment, verify internal safeguards, or prove that recovery will succeed.

When you need internal evidence reviewed, the $1,995 Business Security Baseline covers essential safeguards for businesses with up to 25 employees. It can help leadership distinguish what has been verified from what still depends on an assumption or a provider’s description.

Operational equipment and safe manual procedures still require the relevant equipment vendors and operations specialists. Scope those responsibilities clearly rather than treating a general review as proof that every system is ready.

Sources

For broader sector context, see the Food and Ag-ISAC threat report and NIST’s small-business ransomware guidance. These sources provide general guidance; they do not establish that a particular farm, elevator, or cooperative is compromised.

Know what is visible and what still needs proof.

The free Zero-Access Business Exposure Review looks at public signals around your domains, email protections, websites, and internet-facing services. The $1,995 Business Security Baseline goes further by reviewing evidence for internal safeguards for businesses with up to 25 employees.

Start the free exposure reviewSee the $1,995 Business Security Baseline