top of page
Abstract Digital Mesh

Australian Agriculture Is Getting Connected. Let's Get the Basics Right First. Part 2

Sep 2
7 min read

Part 2 - Insights from the Dowerin Field Days



There is something quite refreshing about getting back into the Wheatbelt.

We recently spent the day at Dowerin talking to farmers, machinery suppliers, agtech businesses and plenty of other people who keep Australian agriculture moving.


And, frankly, it was great. The territory where every passing by car gets the raised index finger from the driver to say G’day.


The conversations were genuine. No polished conference presentations. No corporate buzzwords. Just people talking about what they're actually dealing with.

Fuel prices.

Fertiliser.

Weather.

Machinery.

Labour.

Government regulation.

Getting the crop in.

Getting the crop out.

And, increasingly, technology.


But something surprised me.


For all the talk about the future of agriculture, the technology landscape we saw wasn't quite as advanced as I expected.



We're Still a Long Way From the Netherlands

I've previously used the Netherlands as a comparison because it provides a pretty stark example of what highly automated agriculture can look like.


Dutch agriculture has embraced robotics, sensors, automation, controlled environments and connected systems on a scale that makes some Australian operations look positively old school.


Australia is different.


We're dealing with enormous properties, massive distances, connectivity challenges and a very different agricultural economy.


And perhaps there's also something else going on. There is a pretty strong Australian attitude of:

"We've always done it this way, and it works."

I'm not convinced that's necessarily a bad thing. Perhaps it’s the hard working Aussie spirit of putting in a hard day’s yakka.


In fact, after talking to people at Dowerin, I started wondering whether it might actually be giving us a bit of breathing room.Because there's another reality we need to acknowledge.


We haven't connected everything yet.

And that's probably fortunate.

Because the Cyber Security Basics Aren't Always There


We spoke with both farmers and agricultural technology vendors, and one thing became pretty clear.


With some notable exceptions, basic cyber security isn't necessarily embedded in agricultural operations yet.


MFA isn't universal.

Strong identity management isn't universal.

Formal backup and recovery processes aren't universal.

Security awareness isn't universal.

And having a documented process for dealing with a compromised email account or fraudulent payment isn't exactly standard operating procedure.


That might sound concerning.


It is.


But there's another way of looking at it.


We haven't yet connected every autonomous machine, irrigation system, sensor network, drone and farm management platform into an enormous digital ecosystem that nobody has properly secured. We've got a chance to get the basics right before we get there.

And I think we should take it.


Because before we worry about someone hacking the autonomous tractor, we should probably make sure they can't steal the money being used to buy the tractor.



The Attack Doesn't Need to Be Clever

One of the biggest misconceptions about cyber security is that a cyber attack needs to be technically sophisticated, some sexy Hollywood script.


It doesn't.


Sometimes the attacker doesn't need to exploit a zero-day.

They don't need to break into the tractor.

They don't need to deploy ransomware across the farm.

They just need access to someone's email.

And then they wait.


This is where Business Email Compromise (BEC) and payment redirection fraud become particularly nasty for agriculture.


The Australian Signals Directorate's latest Annual Cyber Threat Report identified email compromise and BEC fraud among the most commonly reported cybercrime types affecting Australian businesses. In 2024–25, BEC fraud resulting in financial loss accounted for 15% of self-reported business cybercrime threats.


And the financial impact isn't trivial.

The average self-reported cost of cybercrime for a small Australian business was $56,571 in 2024–25, according to ASD.


But averages can be misleading. BEC losses can be much, much larger.

Now think about the agricultural sector. Farmers and agricultural suppliers regularly move large amounts of money.

Seed.

Fertiliser.

Chemicals.

Fuel.

Machinery.

Grain.

Livestock.


It's not unusual for an invoice to be worth tens of thousands or hundreds of thousands of dollars. Sometimes considerably more. That makes agriculture an attractive target.

 

Here's How It Can Happen

Let's use a fictional example, though to be very honest, a very real “example”…


Say you're a fertiliser supplier in regional WA. You're a legitimate business. You've been operating for years. You've got a handful of staff in the office and a warehouse full of product.


It's March.

Everyone is busy.

You've got customers ordering fertiliser, invoices going out, trucks coming and going, and money moving in and out of the business constantly.


One morning, one of your staff clicks on a convincing Microsoft 365 phishing email.

They enter their username and password.

The attacker gets in.

Nothing happens immediately. No ransomware. No dramatic warning on the screen. No Hollywood-style hacker animation.


The attacker simply starts reading the mailbox…

And they wait…


A week later, they find an email thread between your accounts team and a large farming customer.

The customer is purchasing $280,000 worth of fertiliser.

The invoice is legitimate. The customer is legitimate. The fertiliser is legitimate.

Everything about the transaction is real.

Except the bank account…


The attacker quietly inserts themselves into the conversation and sends an email advising that the supplier has changed banks.

The branding is correct.

The signature is correct.

The email thread is correct.

The invoice looks correct.

The amount is correct.


The farmer’s wife is busy and has paid dozens of invoices this month.

She makes the payment.


$280,000 leaves the account.


Nobody realises anything is wrong until the fertiliser supplier calls a few days later asking why the invoice hasn't been paid.


By then, the money has moved through multiple accounts. Maybe overseas.


And now everyone starts asking the same question:

"How did this happen?"

The answer is depressingly simple.


Someone got into an email account.

That's it.


The attacker didn't need to understand fertiliser.

They didn't need to understand farming.

They just needed to understand trust.


This isn't some far-fetched attack scenario. The ACSC describes exactly this type of invoice fraud: attackers compromise a supplier's email account, access legitimate invoices, change the payment details and send the modified invoice to the customer.

And WA has seen BEC cases involving losses of more than $1 million. In fact, just last week we helped a local WA business with this exact type of attack!

 

The Really Annoying Part

This attack can be stopped without buying a $100,000 security platform.


That's the frustrating part. A few relatively boring controls can make a substantial difference.

MFA.

Not SMS MFA if it can be avoided. Stronger authentication is better.


Good Microsoft 365 security configuration.

Don't just buy the licence. Configure it properly.


Separate administrative accounts.

Don't run the entire business from an account with global administrator privileges.


Mailbox monitoring.

Attackers often create forwarding rules, inbox rules or other persistence mechanisms after compromising an account.


Payment verification.

If a supplier says their bank details have changed, pick up the phone. Not the phone number in the email.

The number you've had for years.


Two-person approval for significant payments.

Especially when bank details have changed.


The ACSC specifically recommends independently verifying changed payment details and being suspicious of urgent payment requests or unexpected changes to bank accounts.

None of this is particularly exciting.

But neither is changing the oil in a tractor.

You still do it.

 

Farmers Are Not the Only Target

There's another reason I think this matters.


The agricultural supply chain is connected whether we like it or not.

A farmer might have excellent security but purchase fertiliser from a supplier whose email has been compromised.


The farmer pays the invoice.

The money goes somewhere else.


Or the supplier might have good security but a farmers gmail account is compromised.

Or a machinery dealer.

Or a transport company.

Or an accountant.


The weak point doesn't necessarily sit where you expect it to.


That's exactly why the larger attacks against agricultural organisations we've discussed in Part 1 matter. You don't have to attack the farm.


You can attack something the farm depends upon.


Cyber security therefore needs to be thought about across the agricultural ecosystem-not just inside individual businesses.

 

There's a Bigger Opportunity Here

This is probably the most optimistic thing I took away from Dowerin.


We're not too late.


In fact, we might be early.


Australia is going to become more automated.

The machinery is coming. The sensors are coming. The connectivity is coming. Autonomous systems are coming. AI is coming.


And eventually we're going to have agricultural environments where the distinction between IT and operational technology becomes increasingly difficult to draw.


When that happens, cyber security is going to matter enormously.


But I'd much rather see Australian agriculture enter that future with the fundamentals already sorted.


I'd rather see an agricultural supplier with MFA enabled, properly configured email, reliable backups, sensible payment controls and a plan for responding to a compromised account before we start putting fully autonomous machinery in the paddock.


Get the boring stuff right first. Then build the clever stuff on top.

 

The Aussie Farmer Has Enough Problems

And I'll say this as someone who genuinely enjoys spending time around the people who make this industry work.


Farmers have enough to worry about.


They're dealing with weather they can't control, commodity prices they don't control, input costs that seem to keep climbing, fuel, fertiliser, machinery, logistics and an ever-growing pile of regulation and government paperwork.


They're working bloody hard to produce the food that keeps this country going.


The last thing they need is to add:

"I accidentally sent $280,000 to a cybercriminal."

to the list.


Cyber security doesn't need to become another burden placed on farmers. It needs to become part of the machinery that supports them.

Simple.

Practical.

Proportionate.


And preferably without another 400-page policy document sitting in the office collecting dust.

 

Let's Get the Basics Right

Our conversations at Dowerin reinforced something for me.


There is an enormous opportunity for Australian agriculture to embrace technology.


But we shouldn't confuse connected with secure.


Before we put more autonomous systems onto Australian farms, let's make sure the people and businesses operating them have the basic cyber security foundations in place.

Protect the email.

Protect the money.

Protect the supply chain.


Then let's start talking about autonomous machinery.

Because I reckon Australian farmers will embrace the technology when it genuinely makes their lives easier.


They've always been pretty good at that.


And when we do eventually see highly connected, highly automated farms across the Wheatbelt, I'd like to know we've built them securely from the ground up.


Not bolted security on afterwards when somebody gets hacked.

That's the next conversation.


Frederick Prinsloo


bottom of page