Back to insights
Playbooks & Best PracticesOperational Technology & Industrial Control System SecurityPoultryFeb 28th, 2026 · 3 min read

Bowtie Diagrams - Understanding Cybersecurity Threats in Food Production

Understanding threats and the different controls needed

Steve Mustard
President & CEO

Share this insight

Food producers are highly experienced in structured risk thinking. HACCP plans, critical control points, prerequisite programs, and recall procedures are embedded into daily operations. As I noted in an earlier insight, when it comes to cybersecurity, particularly operational technology (OT) cybersecurity, risk is often described in abstract technical terms rather than i operational consequences.

Another notable problem is that food producers may overlook potential threats and focus their efforts elsewhere, leaving themselves exposed to intolerable risk.
In a recent insight I described the use of the Swiss cheese model to visualize cybersecurity risk. A complementary visual tool is the bowtie diagram.

The bowtie diagram uses the same concepts as the Swiss cheese model, dividing the problem into prevention controls, which reduce the likelihood of an incident, and mitigation controls, which reduce the consequences once an incident occurs.

The bowtie diagram adds another important visual dimension: it clearly illustrates how multiple distinct threats can converge to trigger a single incident — and how that single incident can then lead to multiple, potentially severe consequences. By mapping causes on the left and outcomes on the right, the structure makes the pathways of risk explicit. The term “bowtie” simply reflects the shape that emerges, with the central incident forming the knot and the expanding threats and consequences creating the two sides of the tie.

Consider this generic example. The co-mingling of IT and OT networks, which is quite common in food-producing environments, can lead to a potential network compromise. The potential consequences include loss of visibility on OT systems or loss of control of process equipment, which can lead to product safety risks or production interruption. In addition, the exfiltration of sensitive information, such as recipes, can be catastrophic for a food producer, as can the compromise of IT systems with ransomware, which can lead to the inability to invoice or ship product.

The bowtie structure forces clarity:

  1. What can cause this?
  2. What prevents it?
  3. If prevention fails, what limits the damage?

That clarity is essential in a highly regulated, high-consequence industry.

Human Error, the Overlooked Cyber Threat

One of the most important insights from bowtie analysis in food manufacturing is this: Human error is fundamentally different from external attack. External attackers are unauthorized, and the prevention controls can slow or halt their progress. This is not true of internal personnel, who are authorized to access systems and networks.
Consider examples in a food plant:

  • An administrator bypasses change control to “quickly fix” a PLC logic issue.
  • A technician disables alarms due to nuisance alerts and forgets to re-enable them.
  • A supervisor shares credentials during a night shift to speed up troubleshooting.
  • A vendor with approved access makes an untested configuration change.

These are not external attacks. They are authorized actions, potentially unsafe ones.

In the case of human error, preventive measures are often limited to policies, procedures, training, and supervisory oversight. These are procedural controls, and by their nature, they are less effective than engineered or technical safeguards. Like personal protective equipment, they are only effective if consistently and correctly applied. The bowtie diagram makes this limitation explicit, revealing where risk reduction depends more on human behavior than on built-in system protections. This should lead to the organizations focus on better training, clearer procedures, and stricter oversight.

Although not shown in this simplified example, the bowtie diagram can show the mitigation controls specific to each consequence. As with prevention controls, this can highlight where mitigation controls are weakest, allowing the organization to redirect their focus there.

A Food Industry Imperative

Food producers already understand layered protection through HACCP and food defense plans. Bowtie diagrams extend that thinking into cybersecurity.
They help answer critical questions:

  • Are our preventive barriers strong enough?
  • Where are we relying on human discipline instead of engineering safeguards?
  • If a network compromise occurs, how quickly can we contain it?
  • Do our mitigation controls protect consumers and brand integrity?

In a sector where consequences can include foodborne illness, regulatory enforcement, and public recall, cybersecurity cannot remain a technical afterthought.

About the leader

Steve Mustard
Steve Mustard
President & CEO

Steve Mustard is an industrial automation consultant with more than 35 years of engineering experience across multiple sectors. He is a licensed Professional Engineer (PE) in Texas and Kansas, a Liveryman of the Worshipful Company of Engineers, an ISA Certified Automation Professional® (CAP®), a UK registered Chartered Engineer (CEng), a European registered Engineer (Eur Ing), a GIAC Global Industrial Cyber Security Professional (GICSP), and a Certified Mission Critical Professional (CMCP). He was the 2021 President of the International Society of Automation (ISA) and is a Life Fellow of the Society. He is a Fellow of the Institution of Engineering and Technology, and a member of the Water Environment Federation (WEF) Safety and Security Committee. Mustard writes and presents on a wide array of technical topics and is the author of “Industrial Cybersecurity, Case Studies and Best Practices” and ‘Mission Critical Operations Primer”, both published by ISA and “A Guide to Cybersecurity for Water and Wastewater Utilities”, published by WEF. He has also contributed to other technical books, including “Project Management: A Technician’s Guide”, published by ISA, WEF’s “Design of Water Resource Recovery Facilities, Manual of Practice No.8, Sixth Edition” and “The Digital Twin” book., published by Springer Nature. Mustard’s previous and current client list includes: the UK Ministry of Defence; NATO; major utilities, such as Anglian Water Services and Sydney Water Corporation; major oil and gas companies, such as bp, BG Group and Shell; Fortune 500 companies, such as Quintiles Laboratories; and other leading organizations.

Share this insight

Report a copyright concern

Bowtie Diagrams - Understanding Cybersecurity Threats in Food Production · CSAFI