Cultivating Cyber Resilience: A Unified Approach for the Floral Industry

0
1

Key Takeaways

  • Cyber incidents in the floriculture sector are increasing; preparation is no longer optional.
  • Levoplant combines strong leadership vision with dedicated IT expertise to drive digitalisation while managing risk.
  • Core defenses include two‑factor authentication, strict password policies, mandatory e‑learning, app‑protection rules, and automated invoice verification.
  • Network segmentation limits breach impact and is reinforced by clear security agreements with suppliers.
  • Upcoming European legislation (effective 2027) will raise compliance obligations for automated glasshouse horticulture, prompting Levoplant to work with suppliers and its IT partner Yielder on readiness.
  • The grower’s perception of cyber risk has shifted from “what could they gain?” to recognizing the sector as an attractive target, especially as AI‑enabled phishing becomes more sophisticated.
  • In April Levoplant was the first to report a sector‑wide phishing attack to the Cyber Resilience Centre Greenport, triggering a rapid coordinated response that limited damage.
  • The incident highlighted the value of sector‑wide collaboration; sharing experiences through channels such as the Cyber Resilience Centre strengthens collective resilience.
  • Small‑scale growers often lack resources for robust cyber programs; Levoplant advocates for support mechanisms and inclusion of cybersecurity in certification schemes like MPS.
  • Royal FloraHolland’s leadership—through the Cyber Resilience Centre and free Cyber Subscription—provides a model for industry‑wide improvement.

Overview of Cyber Threats in Floriculture
Cyber security is no longer a peripheral concern for the floriculture industry; incidents are rising steadily, and experts now frame the risk as a matter of “when, not if.” Growers and buyers alike must therefore build resilience against attacks that could disrupt production, supply chains, and financial transactions. Recognising this inevitability, many companies are moving beyond basic hygiene measures to adopt comprehensive, proactive strategies that address both technical vulnerabilities and human factors.

Levoplant Company Background
Levoplant, an orchid grower situated in Honselersdijk, exemplifies a forward‑looking approach to digital transformation. Ron Fransen, the company’s director and co‑owner, admits he is not an IT specialist, yet he understands that digitalisation will only grow in importance. This awareness drives his investment in modern machinery and technological solutions that streamline daily operations, while also prioritising robust digital systems to protect those advancements.

Role of IT Staff at Levoplant
Emile Aleman, who has served as Levoplant’s IT Architect & Coordinator for eight years, articulates the internal dynamics that enable successful cyber initiatives. He notes that every IT professional in the floriculture sector aspires to push digitalisation forward, but progress hinges on a management board that actively supports those ambitions. At Levoplant, such backing exists, allowing the IT team to implement advanced tools and maintain a security‑conscious culture across the organization.

Digital Infrastructure and Network Segmentation
Levoplant’s new facility is being equipped with cutting‑edge technology where all systems intercommunicate and exchange data, creating numerous operational opportunities. Emile emphasizes that this interconnectivity also raises risk, making network segmentation a cornerstone of their defence strategy. By segregating systems, the company ensures that a compromise in one area does not automatically jeopardise others. Clear security requirements are imposed on suppliers, covering connection types and protective measures, recognizing that not all vendors possess equal expertise in cyber hygiene.

Standard Cybersecurity Practices
Beyond segmentation, Levoplant has institutionalised several baseline controls for years. Two‑factor authentication (2FA) and a stringent password policy are mandatory for all staff, complemented by compulsory cybersecurity e‑learning. A special app‑protection policy governs access to company data on mobile devices, requiring devices to meet strict security thresholds before email or other corporate resources can be used. Accounting software automatically validates invoices and bank account details to thwart fraudulent payments, adding another layer of financial safeguard.

Future Regulatory Landscape
Looking ahead, European legislation set to take effect in 2027 will impose additional responsibilities on companies that automate glasshouse horticulture. Levoplant views this forthcoming regulation as a shared challenge and is already collaborating with suppliers—and its IT partner Yielder—to develop practical solutions that ensure compliance while preserving space for innovation. This proactive stance aims to help the entire supply chain meet upcoming standards without sacrificing competitiveness.

Changing Perception of Threat Landscape
Ron Fransen’s own mindset has evolved markedly. Initially he wondered what cybercriminals could possibly gain from targeting an orchid grower, but he now recognises that the sector’s growing digital footprint makes it an attractive target. Phishing emails have been sent in his name—even in Polish to Polish contacts—and fraudulent WhatsApp messages featuring his likeness (likely harvested from LinkedIn) have circulated. Emile observes that cybercriminals are increasingly cunning, with AI amplifying their tactics, which heightens the importance of human intuition: staff must question unexpected communications and be ready to raise the alarm.

April Phishing Incident and Response
In April Levoplant experienced a phishing attack that rippled through part of the floriculture sector. The company was the first to notify the Cyber Resilience Centre Greenport, an initiative launched with Royal FloraHolland’s support. Upon learning that a customer had been hit, Emile’s team alerted Ter Laak Orchios and monitored their own sales department, which also received the malicious messages. Colleagues exercised caution, refraining from clicking links, and Frank van Holsteijn escalated the alert to Plantform and the Cyber Resilience Centre. The swift coordination enabled a rapid response team within Royal FloraHolland to mobilise, limiting damage—a outcome Emile credits partly to Ter Laak Orchios’s effective actions.

Collaboration and Sector‑Wide Resilience
Emile stresses that the incident underscores the necessity of collective action. Because the floriculture industry is still relatively nascent in cyber maturity, criminals view it as a lucrative target. By sharing threat intelligence and best practices through platforms such as the Cyber Resilience Centre, companies can bolster each other’s defences. Ron adds that Royal FloraHolland’s leadership—both in launching the Centre and offering a free Cyber Subscription—provides essential resources, especially for smaller growers who lack the means to invest heavily in personnel and equipment.

Calls for Certification Integration
To further embed security into the sector’s fabric, Ron advocates for making cyber resilience a component of existing certification schemes, notably MPS (Milieu Project Siertei). Integrating digital security into such frameworks would assure buyers that certified producers meet rigorous cyber standards, thereby raising the baseline protection across the industry. He sees this as a logical next step, complementing technological investments and collaborative initiatives to create a holistic defence posture against evolving cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here