This article is based on the latest episode of CYBR.Signal and features CYBR.SEC.CON Co-Founder Sam Van Ryder. Full episode here:

When most people hear about a cyberattack affecting a food company, they immediately focus on the breach itself. How did it happen? Was it stolen credentials? A VPN compromise? Could it have been prevented?
Those are important questions, but they're not the ones that stuck with me recently.
I was out riding my bike through the mountains here in Nidwalden, Switzerland, passing through the familiar fields where dairy cows graze. It's one of those places that gives you time to think. As I rode past the farms, I found myself reflecting on the recent Fairlife incident — not so much about the technical details, but about what happened afterward.
Fortunately, the compromise affected just one producer. That's easy to overlook, but it's actually a significant lesson in resilience.
Yes, it was a problem. Nobody wants to see a company disrupted by a cyberattack, especially one responsible for producing something as fundamental as food. But consumers didn't suddenly lose access to milk. Other producers continued operating. Grocery shelves weren't emptied overnight. Life went on because the supply chain wasn't dependent on a single source.
To me, that's what real resilience looks like.
In cybersecurity, we spend a lot of time talking about backups, redundancy, disaster recovery, and business continuity. Those are all critical. But we don't spend nearly enough time recognizing that diversity itself is a security control.
A diverse supply chain limits the blast radius when something goes wrong.
That principle extends far beyond dairy products.
More on supply-chain security:


Look at our electrical grids. They're designed with multiple layers of redundancy and failover capabilities because everyone understands that a single point of failure is unacceptable. Manufacturing works much the same way. Many organizations maintain warehouses full of finished products specifically so they can continue serving customers if production is interrupted. Those inventory buffers aren't inefficiencies — they're resilience engineered into the business.
The same thinking applies across virtually every critical industry.
Competition often gets discussed in economic terms, but it also creates resilience. Having multiple companies capable of producing similar goods means society is less vulnerable when one organization experiences an outage, whether that outage is caused by ransomware, a supply chain attack, a natural disaster, or any other disruption.
From a cybersecurity perspective, that's worth paying attention to.
Too often we focus exclusively on defending individual organizations. That's necessary, but it's only part of the picture. We also need to think about how resilient entire ecosystems are when — not if — one participant experiences a serious incident.
No organization is invulnerable.
Eventually, someone gets compromised.
The real question becomes whether that compromise cascades into a much larger societal problem or remains a contained business disruption.
That's why diversification matters.
It's easy to view supply chain diversity purely as an economic issue, but I think it's increasingly becoming a cybersecurity issue as well. The more concentrated our critical industries become, the greater the consequences when one company experiences an operational failure.
Resilience isn't just about building stronger defenses.
Sometimes it's about making sure there are enough alternatives that society can continue functioning even when those defenses fail.
And if you ever find yourself riding through the Swiss countryside, stop for a glass of fresh milk. Trust me — it'll change your life.


