top of page
Abstract Digital Mesh

Australian Agriculture Is Getting Smarter. Is It Getting More Vulnerable? Part 1

Sep 1
6 min read


I've spent a fair bit of time around cybersecurity. I have also spent many years growing up on a farm and small wheat-belt town.


Lately, I've been thinking about something slightly different.


What happens when cybersecurity meets agriculture?


Not the big agribusinesses with dedicated IT teams and security budgets. I'm talking about the farmer running a modern broadacre operation, increasingly dependent on connected machinery, GPS, sensors, cloud platforms, mobile applications and automated systems to get the job done.


Because Australian agriculture is becoming a technology business. It feels quite funny saying this, I know so many farmers that barely know how to switch on their laptop, or having to do the dreaded "computer" work.


We just don't always call it that.


A modern farm can have GPS-guided machinery, connected tractors, automated spraying, satellite imagery, soil sensors, weather stations, livestock monitoring, cloud-based farm management software and machinery that can increasingly make decisions without someone sitting in the driver's seat.


That's fantastic.


It also means there are suddenly a lot more things that can be hacked.


Australia Isn't the Netherlands


If you look at somewhere like the Netherlands, the contrast is pretty striking.


Dutch agriculture has spent decades squeezing extraordinary amounts of productivity out of relatively small amounts of land. Highly automated greenhouses, precision climate control, sensors, robotics and computer-controlled growing environments are not particularly exotic there. Technology is deeply embedded in the production process.


Australia is very different!


We have enormous farms, enormous distances, different crops, different economics and some pretty serious connectivity challenges.


And yet the technology is arriving.


Maybe not uniformly. Maybe not as quickly as the most optimistic agtech brochures would have you believe.


But it is arriving.


Australia also has a surprisingly innovative agtech sector. Investment and adoption are increasing, and farmers are using technology to solve very Australian problems: labour shortages, water management, productivity, climate variability and the sheer problem of managing thousands of hectares of sun parched land.


The issue isn't whether Australian agriculture will become more connected.


It already is. The question is whether cybersecurity is coming along for the ride.


The Farm Is Becoming an IoT Environment


This is where things get interesting from a security perspective.


Think about what happens when a farmer connects a new piece of equipment.


It might have:


GPS and satellite connectivity.

Bluetooth or Wi-Fi.

A mobile application.

A cloud management portal.

Remote support functionality.

Firmware updates.

Telemetry and operational data.

An API connecting it to another system.


None of those things are inherently bad.


In fact, they're probably exactly why the equipment is useful.


But every connection introduces another dependency, another account, another piece of software and another potential attack surface.


And unlike an office environment, these systems can have a physical consequence.


If someone compromises your email, that's bad.


If someone compromises a system controlling something that moves, sprays, pumps, feeds, irrigates or harvests, the conversation gets considerably more interesting.


This is the part of agricultural cybersecurity that I think deserves much more attention.


We're not just protecting data anymore.


We're increasingly protecting operations.


The Research Is Already Raising Red Flags


A 2025 research chapter specifically examining cybersecurity risks in smart agriculture in regional Australia makes for fairly sobering reading.


The authors identify risks across IoT devices, drones, sensors, GPS, cloud systems, AI and automated machinery, and point to issues including unauthorised access, ransomware, data breaches, weak security practices and infrastructure limitations. They also highlight the particular vulnerability of smaller operators that may lack the resources, training or technical expertise to secure these systems properly.


There are some useful numbers in the research.


Australian farm businesses reported more than $1.2 million in scam losses between January and August 2022, according to ACCC Scamwatch data cited by the study. That represented an increase of more than 20 per cent compared with the same period the previous year.


The study also points to an uncomfortable combination of problems in regional Australia: limited connectivity, skills shortages, a lack of formal cybersecurity practices and the increasing complexity of smart farming systems.


And there's another statistic that caught my attention.


Research cited in the chapter found that 32 farmers interviewed about smart farming technology identified technical proficiency and mistrust as factors affecting IoT adoption.


That matters.


Because if we build increasingly complicated technology and then tell farmers they need to trust it, understand it, maintain it and secure it without giving them the resources to do so, eventually something has to give.


We've Already Seen What Happens Higher Up the Supply Chain


This isn't some theoretical future problem.


In 2021, JBS was hit by a major cyberattack that disrupted operations across its global business, including Australia. JBS had 47 facilities across Australia, and the attack resulted in Australian operations being temporarily shut down.


That's a particularly useful example because it demonstrates something important.


You don't necessarily need to attack the farmer to disrupt agriculture.


Attack the processor.


Attack the logistics provider.


Attack the grain handler.


Attack the software provider.


Attack the payroll system.


Attack the business that everyone else depends upon.


GrainCorp provides another example. In 2022, a ransomware attack against its third-party payroll provider Kronos caused prolonged disruption, including delays to payments for some harvest workers. GrainCorp's own reporting also highlights how dependent its operations are on its IT systems and those of key business partners, particularly across transactions, stock management and logistics.


That's the supply chain problem.


Agriculture isn't a collection of isolated farms anymore.


It's an interconnected ecosystem.


And cybersecurity doesn't stop at the farm gate.


But What About the Farmer?


This is the question I'm particularly interested in.


We know what cybersecurity looks like in a large enterprise.


We know what it looks like in a bank.


We know what it looks like in a government department.


But what does it actually look like on a modern Australian farm?


Are default passwords changed?


Are remote access services secured with MFA?


Who manages the firmware?


What happens when the manufacturer stops supporting a device?


What happens if the internet connection goes down?


What happens if the cloud platform is unavailable?


What happens if someone's Microsoft 365 account is compromised?


And perhaps the most important question:


Who are you supposed to call when something goes wrong?


I don't think we have good enough answers to all of those questions yet.


And I'm not blaming farmers for that.


If anything, I think we've made the classic technology mistake of putting enormous effort into making something work and considerably less effort into making sure it continues to work when someone deliberately tries to break it.


We're Going to Find Out


This is why we're heading to the Dowerin Machinery Field Days this week.


The 2026 event runs on 26–27 August and brings together farmers, primary producers, agribusinesses, machinery manufacturers and agtech providers from across Western Australia. The organisers describe it as bringing together the broader agricultural supply chain, including machinery, equipment, technology and professional services.


We're not going there to sell cybersecurity.


We're going there to ask questions.


We're going to speak with producers.


We're going to speak with machinery and technology vendors.


We're interested in what is actually being deployed in the field—not what the marketing brochure says is being deployed.


How connected are modern farms?


What systems are farmers relying upon?


Who manages them?


What security controls are built into the products?


Do vendors even get asked about cybersecurity during the buying process?


And when a farmer buys a piece of connected agricultural equipment, does anyone explain the security implications?


I suspect we'll hear some interesting answers.


Some will probably be reassuring.


Others might make us slightly nervous.


That's the point.


This Is Only Part One


I'm deliberately not going to finish this article by telling farmers to implement the Essential Eight, buy an EDR product and start doing quarterly vulnerability scans.


That would be missing the point.


Before we prescribe solutions, we need to understand the problem.


Australian agriculture is becoming more connected, automated and dependent on technology. That's a good thing. It has enormous potential to improve productivity and make Australian farming more resilient.


But cybersecurity needs to become part of that conversation.


Not as another compliance burden.


Not as another consultant telling farmers that everything they're doing is wrong.


And certainly not as another piece of software to buy.


We need to understand what is actually happening at the farm level first.


So that's what we're going to investigate.


We'll be at Dowerin this week talking to the people actually using and building this technology.


We'll report back on what we find.


More to follow next week.


Frederick Prinsloo

bottom of page