Skip to main navigation Skip to main content Skip to page footer

IT security – prevention on livestock farms

As at July 2026

  • Prof. Dr. Wolfgang Büscher, University of Bonn
  • Dr. Katharina Dahlhoff, Haus Düsse Research and Training Centre
  • Dr. Adriana Förschner, Baden-Württemberg Agricultural Centre
  • Dr. Jernej Poteko, Bavarian State Institute for Agriculture
  • Prof. Dr. Ralf Waßmuth, Osnabrück University of Applied Sciences

Guest:

  • Dr. Isabella Lorenzini, LfL

  • Dr. Rebecca Simon, Landesbetrieb Landwirtschaft Hessen
  • Saskia Markmann, Landesbetrieb Landwirtschaft Hessen
  • Leonie Schnecker, Landesbetrieb Landwirtschaft Hessen

Introduction

In a modern livestock farm, there is a wide range of digital devices and applications. These range from automatic milking systems to oestrus detection. Digitalisation has also become an integral part of cattle housing: feeding, milking, oestrus detection or the recording and assessment of health parameters – many systems relevant to health and animal welfare are digitally supported. A failure or malfunction can pose major challenges for a farm – including financial ones. 

Furthermore, it is important to raise awareness of the data held on the farm, which in some cases is also subject to documentation requirements. In addition to sensitive operational data and information, this includes the personal data of staff, as well as historical data and images, which may not be recoverable under certain circumstances. 

Awareness of the risks associated with the use of digital, internet-enabled technology is often still low. These risks are frequently underestimated, yet they are real and form part of everyday life in the digital environment.

Specific risks and challenges on farms

  • Close links between private and business life – including at a digital level
  • High dependence on (various) external service providers
  • External service providers often have almost unrestricted access to systems (remote maintenance, etc.)
  • Use of vulnerable operating systems and devices (out of support)
  • Many systems are permanently connected to the internet
  • High interconnectivity between systems
  • Reliance on smooth operational processes – problems can quickly affect animal health and welfare
  • Lack of resources – the farm manager is usually also responsible for IT security
  • Agricultural holdings may form part of critical infrastructure (KRITIS) in the food sector

Any device connected to the internet can be a target for attack, including, for example, those that can be controlled via remote maintenance. However, it is not only digital attacks that can lead to data loss and system failure on the farm, but also the simple loss of end devices (theft, malfunction). As a general rule: ‘Those who lock up and protect themselves have peace of mind – those who don’t invite thieves in.’ Typical targets and types of attack are shown in Table 1. 

AttackWhat is affected?How can this happen?Further explanations and consequences
Theft / LossFarm office PC, farm smartphone, storage media, industrial PC (built into systems)The loss of the smartphone results in the loss of access to the milking robot software and herd management systems. The systems cannot be used, or can only be used to a limited extent.

Theft or loss of the device can result in the loss of access to systems and data; in some cases, specialist software may no longer be accessible. Unbacked-up data may not be recoverable under certain circumstances.

Do not leave devices unattended!

Data leak (user data / mobile numbers)Messaging services (e.g. WhatsApp), the farm’s email address, telephone number, social media channelsReceipt of fake parcel notifications or invoices sent to the ‘leaked’ contact details → phishing (risk: infection of the company’s PC or mobile devices)Personal (contact) data is hijacked during a cyberattack on a service provider (e.g. online retailers), published without authorisation and then used by attackers to send targeted messages containing links to fake and infected websites or apps (phishing).
PhishingFarm PC, farm smartphone, messaging services (e.g. WhatsApp),
farm email address, bank details, social media channels
Obtaining access details by deception (e.g. milking robots, monitoring systems, bank details)

Theft of login or bank details via fake or infected websites, apps, QR codes or phone calls.

Subsequent data misuse or even identity theft.

Ransomware
(malware / encryption Trojans)
Farm PC, industrial PCClicking on an infected link triggers the installation of the ransomware, locking the entire PC running barn software (milking robots / monitoring systems, etc.). The screen may display a ransom demand as a static image.The PC is encrypted by ransomware. A ransom demand, often in Bitcoin, is made in order to unlock it. Even after payment, decryption only occurs in around 50 per cent of cases. The PC is no longer usable once encrypted.

DDoS

(Distributed Denial-of-Service attack)

All web- or cloud-based software solutions, e.g. cloud-based monitoring systemsThe servers of manufacturers, service providers, breeding associations, HI-Tier or similar organisations are so overloaded that services can no longer be accessed. For example, it is no longer possible to submit a movement notification via the database’s online form following the purchase of an animal.‘Bot’ networks / software send an endless stream of requests to the targeted web software or database. The heavy load of requests overloads the servers, rendering them inaccessible.
Protection is usually provided by the service provider / supplier.
SpamFarm PC, work smartphoneEmails promising, for example, a large inheritance, a job offer or the chance to meet your dream partner. They may also include fake communications from official bodies regarding alleged criminal charges. Demands for money are also common.These are generally emails that reach the target unsolicited. They contain advertising, attempts at fraud or fake links (see phishing / ransomware).
Computer viruses / wormsWork PC, company smartphoneIn most cases, PC users end up on infected websites via fake links whilst browsing, and thus download fake software (often small games).

Virus kits make it easy to put together malware and place it on fake websites or send it via email.


Attacks are usually aimed at phishing. This is now rather rare.

Social engineeringOffice PC, company smartphone, messaging services (e.g. WhatsApp),
company email address, bank details, social media channels
A purported support staff member gains access to login details by providing false information and can thus manipulate the system or steal sensitive data, either on-site or via remote access.People are exploited as a weak point. Attempts are made to gain trust through deception and manipulation, thereby persuading victims to disclose personal data (see phishing).

Table 1: Typical attack targets and types

Note

The set-up and maintenance of IT security systems can be outsourced to external service providers. There are now even providers who specialise in agricultural businesses. The use of such services, as well as taking out specialist cyber insurance, must be assessed and weighed up on a case-by-case basis for each individual business.

In order to proactively provide an organisation with the best possible protection against data or information being accessed, manipulated or destroyed, a number of IT security principles should be observed. The costs and effort involved in establishing basic protection (Fig. 2) are considered to be minimal. The aim is to minimise the risk of an analogue or digital IT failure. However, 100 per cent security cannot be guaranteed. Therefore, a contingency plan should be in place for the business in the event of an emergency. 

At present, training courses for managers and staff are still few and far between. IT security should form part of the induction programme, particularly when new staff are joining the organisation. 

The following information sheets and checklists are therefore intended to provide initial guidance on taking preventative measures for your own organisation and ensuring that you are prepared with the most important immediate actions in the event of an IT emergency. 

Go to the IT security checklist

Go to the IT Incident Checklist 

Here you will find the contact details of the central cybercrime contact point (ZAC) for businesses in your federal state, which you can enter into the IT incident checklist. 

Legal framework

Useful terms for IT emergencies and beyond

Samples of the malware, to analyse its origin, functionality and impact (cf. evidence at a physical crime scene)

A sequence of numbers used to uniquely identify a computer on a network. Every network-enabled device has its own IP address

An automatically generated log file that records processes and actions on a computer or network

Information and details of how communication took place with a potential perpetrator in the run-up to the attack

Two contrasting definitions are in common use:

  • A website where you can check whether your own data (email addresses, passwords, etc.) has been affected by a data breach and published online.
  • Platforms on which data from data breaches is published or sold by criminals.

An account with extended access rights. Unlike a standard user, an administrator can make changes to the system settings without restriction. 

A summary of key events in the computer system, login attempts and driver issues. 

Isolation or separation of systems or network segments to prevent the problem from spreading

Malware that can damage or take control of systems

Separation of different networks (private and work)

Describes the way in which the computer system is or was accessed:

  • local use = Access is via the use of the relevant device (e.g. computer or tablet) on site
  • Remote access = Access to a system via the internet or a local network. Remote maintenance systems frequently use this method.
  • VPN connection (Virtual Private Network) = A VPN connection can be used to conceal the IP address and mask the location in order to protect data from unauthorised third parties. A VPN connection enables an encrypted connection.
  • Cloud access = Cloud access allows data to be stored, retrieved and shared from any internet-enabled device. The data is stored in the cloud on external servers on the internet. There are various providers offering these services, some of which are free of charge.

The state of files or the entire system, for example following an IT incident. They may be lost or no longer traceable, encrypted – meaning they cannot be accessed – or there may simply be no further information available about them.

Describes the visible or measurable abnormalities, in a similar way to a medical condition. These may include:

  • Locked files
  • Login errors, e.g. due to locked-out accounts
  • Systems are unavailable
  • Systems are running more slowly than usual 
  • Error messages displayed, including error codes

Describes a method of manipulation using psychological tricks with the aim of persuading the victim to carry out specific, ill-considered actions. The individual is exploited as a weak point in order to gain access to data, systems or assets.

Messages, phone calls or even advertising mail that reach recipients in large numbers and without their consent. Often for advertising or fraudulent purposes.

A cyberattack in which servers, websites or networks are deliberately overwhelmed by massive volumes of requests, thereby preventing normal operation.

A cyberattack that attempts to trick people into revealing sensitive data via fraudulent messages, phone calls or websites.

Malware that can encrypt individual files or entire computer systems. Criminals use this method to extort a ransom in exchange for decryption.

Malware that replicates itself automatically and can thus infect or damage multiple files or systems. There are various types, such as Trojans and ransomware.