Cybersecurity executives are urging foodservice distributors to prepare for cyberattacks as operational disruptions that can affect warehouses, trucks, customer orders and even the physical movement of freight.
The message emerged during “The CISO Perspective: Navigating Cyber Risk in Foodservice Distribution,” a panel at the International Foodservice Distributors Association’s 2026 Solutions Conference in San Antonio.
The session on Monday focused on the growing connections between cybersecurity, transportation, warehouse operations, third-party vendors and business continuity.
IFDA described the session as examining how cyberattacks can stop orders, shut down warehouses and jeopardize customer relationships, along with risks involving vendors and ransomware.
Brett Perry, head of cybersecurity and network at Dot Foods Inc., moderated the discussion. Panelists included Frank Smith, director of information security at The Palmer Family of Cos., James Cusack, chief information officer at Van Eerden Foodservice, and Jeff Shaffer chief information security officer at Ben E. Keith Co.
One of the central themes was that companies should no longer build cybersecurity programs around the assumption that every attack can be prevented.
Instead, Perry and the panelists said companies should focus increasingly on resilience — containing an intrusion before attackers can spread throughout an organization and disrupt critical operations.
“We know identities are going to get stolen. We know bad things are going to happen,” Smith said. “But if we can alert and contain those types of incidents, we’re going to be a much more resilient business without any operational impact.”
That distinction can be particularly important for food distributors, whose operations depend on interconnected warehouse management, transportation, ordering and communications systems.
Unlike businesses whose operations are primarily digital, foodservice distributors also operate warehouses, trucks and other physical infrastructure while coordinating with customers, suppliers and transportation providers.
A cyberattack against any part of that network can create downstream consequences.

A hacked carrier can become a cargo theft problem
The executives said companies also need to look beyond their own networks because vulnerabilities at suppliers, technology vendors and transportation partners can expose the distributor.
One example discussed during the panel involved a third-party carrier whose email system was compromised.
The attackers used information obtained through the carrier to arrange a fraudulent pickup. A truck arrived at a cold-storage facility with the correct paperwork and picked up a load of blueberries.
The problem: The truck wasn’t actually working for the carrier.
“There goes a load of blueberries. Gone,” Shaffer said.
The incident illustrated how a cybersecurity breach involving a transportation provider can become a physical cargo theft — even if the food distributor’s own systems were never initially compromised.

Warehouse technology creates other vulnerabilities.
Security cameras, handheld devices, access-control systems and other connected equipment can provide additional points of entry into networks. The panelists recommended practices including network segmentation, least-privilege access and zero-trust security, under which users and devices continue to be verified after gaining access to a network.
Those protections can create friction for warehouse and transportation employees, however.
“When security goes up, I can almost guarantee you from an operational standpoint, convenience is going down,” a panelist said.
That means cybersecurity changes also require communication and change management so employees understand why additional authentication or other security measures are necessary.
The executives said security controls shouldn’t simply be viewed as obstacles to productivity. Properly designed controls can instead provide guardrails allowing employees to use technology more confidently.
Artificial intelligence creates another dimension to that challenge.
Companies need to consider three questions surrounding AI, the panelists said: how to secure employees’ use of AI, how to use AI to improve cybersecurity and how to protect their businesses against attackers using AI.
Data itself is increasingly the target
Another major concern is the sheer volume of information companies retain.
Businesses should determine what data they actually need, how long it should be retained, who should have access and when it should be permanently deleted, according to the panel.
That includes employee records, personally identifiable information, pricing information, litigation documents and other potentially sensitive material.
“Everybody has something that bad guys want,” one panelist said.
The discussion comes as cybercriminals increasingly use stolen information itself as leverage.
Rather than encrypting a company’s network and demanding payment to restore access, attackers can exfiltrate information and threaten to publish it unless the victim pays.
“We’re seeing a real shift towards data as the new currency,” a panelist said.
Sensitive employee and company information therefore shouldn’t be scattered through email accounts, individual computers and cloud-storage folders, the panelists said. Companies should consider whether some sensitive information can instead be held by specialized third-party providers, reducing the amount stored internally.
Reducing unnecessary data also reduces the potential material available for cybercriminals to steal — as well as the information companies may have to search and produce during litigation.
When systems fail, can trucks still move?
Perhaps the most important operational question raised during the session was deceptively simple: How would the company continue operating if a critical system disappeared?
The executives urged distributors to identify their most important applications and determine how long the business can function without them.
That could mean planning how employees would receive orders, contact customers, route deliveries and communicate with suppliers if normal networks or applications were unavailable.
“If it’s that critical of a system, we should have fallback to go back to a manual process,” one panelist said.
Those procedures need to be developed and tested before an incident occurs.
One panelist described an incident in which his company’s recovery time and recovery point objectives were successfully met — only for executives to discover that the established recovery targets were still not fast enough for the business.
Another example involved a company that detected an attacker inside its network but failed to respond effectively. The intruder remained inside the network for 16 months and 12 terabytes of information eventually left the organization, according to the panel.
The lesson, panelists said, is that detection alone isn’t enough. Companies must be able to identify, contain, respond to and recover from incidents.
Testing business-continuity plans can also expose weaknesses that aren’t necessarily cyber-related.
One panelist recalled an outage involving the power grid and backup generators that revealed employees didn’t fully understand which generators supported different systems or what procedures to follow if equipment failed.
“Disaster recovery is an action and resilience is an outcome,” a panelist said.
Cyber risk extends across the supply chain
Third-party risk was another major focus.
Foodservice distributors increasingly depend on an ecosystem of technology providers, suppliers, transportation companies and other vendors whose systems they don’t control.
The executives recommended scrutinizing vendors’ cybersecurity practices before entrusting them with business-critical operations. Contracts should also be reviewed closely for provisions that limit a provider’s liability if a cyber incident causes an outage.
“If they’re not willing to [change it], you have to take a good hard look at whether or not it’s a partner that you should have,” a panel member said.
The panel ended with practical advice for business executives.
Identify the system, application or third-party integration most critical to the company and ask how the business would operate without it for more than 48 hours.
Then document the response and determine who has authority to make decisions during an emergency.
Business leaders should also sit down with their IT and cybersecurity teams and ask a straightforward question: What are you worried about?
That conversation, the panelists said, can identify risks executives may not realize exist — before those vulnerabilities become operational crises.
Why it matters: Cyber criminals don’t necessarily have to penetrate a shipper’s network to disrupt its supply chain — compromised carriers, vendors and other business partners can provide the information needed to steal freight or interrupt operations.
Brokerage Compliance Symposium
The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.
F3 Awards Dinner
The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.
F3: Future of Freight Festival
Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.
The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register NowThe night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register NowIndustry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now