Cybersecurity executives are urging foodservice distributors to prepare for cyberattacks as operational disruptions that can affect warehouses, trucks, customer orders and even the physical movement of freight.
The CISO Perspective at IFDA’s 2026 Solutions Conference
The message emerged during “The CISO Perspective: Navigating Cyber Risk in Foodservice Distribution,” a panel at the International Foodservice Distributors Association’s 2026 Solutions Conference in San Antonio.
The session on Monday focused on the growing connections between cybersecurity, transportation, warehouse operations, third-party vendors and business continuity. IFDA described the session as examining how cyberattacks can stop orders, shut down warehouses and jeopardize customer relationships, along with risks involving vendors and ransomware.
Brett Perry, head of cybersecurity and network at Dot Foods Inc., moderated the discussion. Panelists included Frank Smith, director of information security at The Palmer Family of Cos., James Cusack, chief information officer at Van Eerden Foodservice, and Jeff Shaffer, chief information security officer at Ben E. Keith Co.
Resilience Over Prevention
One of the central themes was that companies should no longer build cybersecurity programs around the assumption that every attack can be prevented.
Instead, Perry and the panelists said companies should focus increasingly on resilience — containing an intrusion before attackers can spread throughout an organization and disrupt critical operations.
“We know identities are going to get stolen. We know bad things are going to happen,” Smith said. “But if we can alert and contain those types of incidents, we’re going to be a much more resilient business without any operational impact.”
That distinction can be particularly important for food distributors, whose operations depend on interconnected warehouse management, transportation, ordering and communications systems. Unlike businesses whose operations are primarily digital, foodservice distributors also operate warehouses, trucks and other physical infrastructure while coordinating with customers, suppliers and transportation providers.
Hacked Carrier Leads to Cargo Theft
The executives said companies also need to look beyond their own networks because vulnerabilities at suppliers, technology vendors and transportation partners can expose the distributor.
One example discussed during the panel involved a third-party carrier whose email system was compromised. The attackers used information obtained through the carrier to arrange a fraudulent pickup. A truck arrived at a cold-storage facility with the correct paperwork and picked up a load of blueberries. The problem: The truck wasn’t actually working for the carrier.
“There goes a load of blueberries. Gone,” Shaffer said.
The incident illustrated how a cybersecurity breach involving a transportation provider can become a physical cargo theft — even if the food distributor’s own systems were never initially compromised.
Vulnerabilities in Warehouse Technology
Warehouse technology creates other vulnerabilities.
Security cameras, handheld devices, access-control systems and other connected equipment can provide additional points of entry into networks. The panelists recommended practices including network segmentation, least-privilege access and zero-trust security, under which users and devices continue to be verified after gaining access to a network.
Those protections can create friction for warehouse and transportation employees, however. “When security goes up, I can almost guarantee you from an operational standpoint, convenience is going down,” a panelist said. That means cybersecurity changes also require communication and change management so employees understand why additional authentication or other security measures are necessary.
Data as the New Currency
Another major concern is the sheer volume of information companies retain.
Businesses should determine what data they actually need, how long it should be retained, who should have access and when it should be permanently deleted, panel. That includes employee records, personally identifiable information, pricing information, litigation documents and other potentially sensitive material.
“Everybody has something that bad guys want,” one panelist said.
The discussion comes as cybercriminals increasingly use stolen information itself as leverage. Rather than encrypting a company’s network and demanding payment to restore access, attackers can exfiltrate information and threaten to publish it unless the victim pays.
“We’re seeing a real shift towards data as the new currency,” a panelist said.
Sensitive employee and company information therefore shouldn’t be scattered through email accounts, individual computers and cloud-storage folders, the panelists said. Companies should consider whether some sensitive information can instead be held by specialized third-party providers, reducing the amount stored internally. Reducing unnecessary data also reduces the potential material available for cybercriminals to steal — as well as the information companies may have to search and produce during litigation.
Manual Fallbacks When Systems Fail
Perhaps the most important operational question raised during the session was deceptively simple: How would the company continue operating if a critical system disappeared?
The executives urged distributors to identify their most important applications and determine how long the business can function without them. That could mean planning how employees would receive orders, contact customers, route deliveries and communicate with suppliers if normal networks or applications were unavailable.
“If it’s that critical of a system, we should have fallback to go back to a manual process,” one panelist said. Those procedures need to be developed and tested before an incident occurs.
One panelist described an incident in which his company’s recovery time and recovery point objectives were successfully met — only for executives to discover that the established recovery targets were still not fast enough for the business. Another example involved a company that detected an attacker inside its network but failed to respond effectively. The intruder remained inside the network for 16 months and 12 terabytes of information eventually left the organization, panel.
The lesson, panelists said, is that detection alone isn’t enough. Companies must be able to identify, contain, respond to and recover from incidents.
Source: FreightWaves
Compiled from international media by the SCI.AI editorial team.