El Niño forces South African farms to trust sensors more than ever – what happens if they’re hacked?

What farmers can do to protect the technology they rely on

Written by Doros Hadjizenonos, Regional Director for Southern Africa at Fortinet

South Africa’s winter grain harvest is arriving into potentially one of the driest, hottest spring outlooks in over a decade.

Forecasters at the South African Weather Service expect below-normal rainfall and above-normal temperatures across most of the country between October and December, as a very strong El Niño event builds towards its peak.

“On many commercial farms, a pivot irrigator now adjusts itself by the minute, and a soil sensor decides when a field gets watered – work that used to depend on a person walking the rows,” says Doros Hadjizenonos, Regional Director – Southern Africa at Fortinet. “Cybercriminals were not part of the design brief for much of it.”

Above: Doros Hadjizenonos, Regional Director for Southern Africa at Fortinet

The stakes have grown alongside the technology. According to South Africa’s Department of Agriculture, agricultural exports reached R268.7 billion in 2025, up from R243.7 billion in 2024, and in the second quarter of 2026, exports reached approximately R65 billion, according to recent agricultural trade analysis. That’s around 10% higher than the same period a year earlier. 

At the same time, farmers are being asked to do more with less purchasing power, resources and even land: intentions to plant wheat were recorded at 486,400 hectares in April, the smallest area in 12 years, according to the Crop Estimates Committee, and final yields will tell a whole other story too. With a drier season to work with going forward, the sensors and automated irrigation compensating for the pressures faced by the nation’s breadbasket are becoming more and more essential.

Harvests increasingly travel through a single, connected data trail. The Perishable Products Export Control Board rolled out a digital container-loading system this year, sharing real-time pallet and status data with Transnet’s port terminals and other stakeholders. This has replaced manual file exchanges that used to slow shipments at every handover. “It is a significant efficiency gain, but greater digital connectivity across the agricultural supply chain also reinforces the importance of securing every point where systems, users and data interact,” says Hadjizenonos.

The global food and agriculture sector is also facing increasing cyberthreat activity. Food and Ag-ISAC’s 2026 State of the Threat report shows that ransomware activity affecting the global food and agriculture sector continues to increase. The organisation recorded 295 ransomware incidents in 2025, a 29% increase year over year. Through July 2026, it had already recorded 227 incidents, 62% more than during the same period in 2025.

The reason agriculture is facing such an onslaught is two-fold: the rapid deployment of networked technology, paired with the crucial nature of its operations. 

“The attackers want a target that can’t afford to stop, regardless of what it grew or processed. There’s a growing trend of attacks aimed at operational technology (OT) centres where physical infrastructure and processes become part of the attack surface as they increasingly get connected to the internet,” explains Hadjizenonos. Attackers target water, energy, manufacturing and other organisations in the OT space because the effects are physical and can be highly disruptive. It’s no different for agriculture.

“A network does not behave differently because it happens to be running a pivot irrigator instead of a factory line or a customs system,” Hadjizenonos says. “Every connected device can potentially expand the attack surface. Many of the same security principles used to protect connected systems in sectors such as energy or retail also apply to connected agricultural environments, including understanding what is connected, controlling access and segmenting critical systems.”

Hadjizenonos argues that the more common mistake is treating farm technology purely as a productivity upgrade rather than a piece of infrastructure with obligations attached.

“Once agricultural systems exchange data with a port authority, logistics providers, or an export certification body, cybersecurity becomes part of a broader supply-chain resilience challenge rather than an issue confined to the farm itself ” he says.

The harvest starts moving off South African farms within weeks. Whether the systems steering it through the country’s driest spring in over a decade were built to withstand more than bad weather is a question most of them have never been asked, but thankfully are in a position to adapt based on the lessons of other OT-intensive sectors that have been on the frontlines much longer. 

There are practical steps farmers can take:

  • Know what is connected: Understand which devices, systems and technology are connected to the farm’s network.
  • Control access: Make sure access to connected systems is controlled and limited to the people who need it.
  • Separate critical systems: Keep important operational systems separate so that a problem in one part of the network doesn’t automatically affect everything else.
  • Don’t treat connected technology as just another productivity tool: Once irrigation, farm operations and other processes depend on connected systems, they become part of the infrastructure keeping the farm running.
  • Think beyond the farm: When agricultural systems connect with ports, logistics providers and export certification bodies, a problem can become a wider supply-chain issue rather than something contained to one farm.