The increasing utilization of emerging technologies in the Food & Agriculture (FA) sector has heightened the need for security to minimize cyber risks. Considering this aspect, this manuscript reviews disclosed and documented cybersecurity incidents in the FA sector. For this purpose, thirty cybersecurity incidents were identified, which took place between July 2011 and April 2023. The details of these incidents are reported from multiple sources such as: the private industry and flash notifications generated by the Federal Bureau of Investigation (FBI), internal reports from the affected organizations, and available media sources. Considering the available information, a brief description of the security threat, ransom amount, and impact on the organization are discussed for each incident. This review reports an increased frequency of cybersecurity threats to the FA sector. To minimize these cyber risks, popular cybersecurity frameworks and recent agriculture-specific cybersecurity solutions are also discussed. Further, the need for AI assurance in the FA sector is explained, and the Farmer-Centered AI (FCAI) framework is proposed. The main aim of the FCAI framework is to support farmers in decision-making for agricultural production, by incorporating AI assurance. Lastly, the effects of the reported cyber incidents on other critical infrastructures, food security, and the economy are noted, along with specifying the open issues for future development.
翻译:食品与农业领域新兴技术应用的日益增长,使得降低网络风险的安保需求愈发迫切。基于此,本文对食品与农业领域已披露和记录的网络安全事件进行了系统综述。为此,我们识别出2011年7月至2023年4月间发生的30起网络安全事件。这些事件的详细信息来源于多个渠道:联邦调查局发布的私营行业警报与即时通知、受影响组织的内部报告,以及可获取的媒体资料。依据现有信息,本文逐一阐述了每起事件的安全威胁特征、勒索金额及对组织造成的影响。综述表明,针对食品与农业领域的网络安全威胁频率呈上升趋势。为降低这些网络风险,本文还探讨了主流网络安全框架及近期农业专用网络安全解决方案。此外,本文阐释了食品与农业领域引入人工智能保障的必要性,并提出以农民为中心的人工智能框架。该框架的核心目标是通过融合人工智能保障技术,辅助农民进行农业生产决策。最后,本文指出了已报告网络事件对其他关键基础设施、粮食安全及经济的影响,并明确了未来发展中亟待解决的开放性问题。