Back to insights
Playbooks & Best PracticesOperational Technology & Industrial Control System SecurityPoultryFeb 20th, 2026 · 3 min read

Swiss Cheese - Visualizing Cybersecurity Risk in the Food Industry

A practical way to understand the difference between prevention and mitigation

Steve Mustard
President & CEO

Share this insight

In my last insight (https://csafi.org/insights/do-you-really-understand-your-cybersecurity-risk) I talked about understanding cybersecurity risk. My key point was that the real risk is not the compromise of computer equipment or data but the impact on food industry operations – whether it be related to raw material intake, pasteurization, blending, packaging, labeling, cold storage, or any other critical business process.

One way to help visualize this is to use the so-called “Swiss cheese model”. This model was originally proposed by psychologist James Reason. The concept is simple: each slice of cheese represents a barrier designed to prevent an incident, and the holes represent weaknesses or failures such as unsafe actions, gaps in procedures, and so on. An incident occurs when the holes align across multiple layers allowing a hazard to cause an accident, like so:

For food producers, this model is particularly powerful. Food production environments contain layered systems of protection, including food safety plans, quality checks, environmental monitoring, and physical safeguards. These can be represented as slices of Swiss cheese in the model. This not only shows the different layers of protection but also helps visualize potential holes in these layers, allowing food producers to address them.

Cybersecurity Management Using the Swiss Cheese Model

While awareness of cybersecurity risk has grown, there is still considerable misunderstanding about what it really means to food producers. Cyber risk often feels abstract. It is considered an isolated IT issue, related to data or computer equipment. The reality is that cybersecurity is just another hazard that can affect food safety, regulatory compliance, and brand integrity.

The Swiss cheese model can be used to represent the different layers of protection related to cybersecurity, as shown below:

The diagram shows that a hazard can cause an incident, and this incident can lead to an impact. This is a crucial point. In cybersecurity, ransomware (the hazard) can disable one or more computers (incident), but the impact (e.g., production outage, contamination, regulatory or brand issues) will depend on how the organization responds to the incident.

One of the most important insights for food manufacturers is therefore understanding the difference between:

  • Prevention barriers or controls – designed to stop the incident from occurring
  • Mitigation barriers or controls – designed to reduce impact after the incident has begun

Why This Matters in the Food Industry

Cybersecurity risk in the food sector is fundamentally about operational impact to the producer — not abstract data loss.

A cyber event in a processing facility can translate directly into:

  • Foodborne illness affecting consumers
  • Intense regulatory scrutiny and enforcement action
  • Highly visible recalls that damage brand trust
  • Costly downtime in an industry where margins are often thin

When viewed through this lens, cybersecurity is inseparable from food safety and production assurance.

The Swiss cheese model provides a practical way to understand that risk. By clearly distinguishing prevention controls (those that stop an incident from occurring) from mitigation controls (those that limit harm once an incident has begun), organizations can see where protections are required and where vulnerabilities exist.

This visualization also strengthens cross-functional alignment. IT, OT, food safety, quality, and operations teams can collectively identify who owns each barrier and how those barriers interact. It enables a disciplined question: “For this specific scenario, are our prevention layers strong enough — and if they fail, are our mitigation layers ready to contain the impact?”

In food manufacturing, that distinction is not theoretical. Prevention protects production. Mitigation protects consumers, brand integrity, and the company’s license to operate.

When cybersecurity is framed this way, it moves beyond being perceived as an IT overhead expense. It becomes what it truly is: a core operational risk management function, integral to food safety, regulatory compliance, and long-term business continuity.

About the leader

Steve Mustard
Steve Mustard
President & CEO

Steve Mustard is an industrial automation consultant with more than 35 years of engineering experience across multiple sectors. He is a licensed Professional Engineer (PE) in Texas and Kansas, a Liveryman of the Worshipful Company of Engineers, an ISA Certified Automation Professional® (CAP®), a UK registered Chartered Engineer (CEng), a European registered Engineer (Eur Ing), a GIAC Global Industrial Cyber Security Professional (GICSP), and a Certified Mission Critical Professional (CMCP). He was the 2021 President of the International Society of Automation (ISA) and is a Life Fellow of the Society. He is a Fellow of the Institution of Engineering and Technology, and a member of the Water Environment Federation (WEF) Safety and Security Committee. Mustard writes and presents on a wide array of technical topics and is the author of “Industrial Cybersecurity, Case Studies and Best Practices” and ‘Mission Critical Operations Primer”, both published by ISA and “A Guide to Cybersecurity for Water and Wastewater Utilities”, published by WEF. He has also contributed to other technical books, including “Project Management: A Technician’s Guide”, published by ISA, WEF’s “Design of Water Resource Recovery Facilities, Manual of Practice No.8, Sixth Edition” and “The Digital Twin” book., published by Springer Nature. Mustard’s previous and current client list includes: the UK Ministry of Defence; NATO; major utilities, such as Anglian Water Services and Sydney Water Corporation; major oil and gas companies, such as bp, BG Group and Shell; Fortune 500 companies, such as Quintiles Laboratories; and other leading organizations.

Share this insight

Report a copyright concern