Your Farm Has Fences, But Does Your Data? 4 Guardrails to Protect Your Operation

You wouldn’t leave your barn unlocked—here is how to apply the same common-sense security to your organization’s most valuable data.

4-Guardrails-to-Protect-Your-Operation.jpg
(Farm Journal)

Before you can protect something, you need to know it exists. This may seem rather obvious, but Angel Andaya, manager of digital solutions for Silver Support, says that’s a step that often gets overlooked.

“Having a clear inventory of what data our business holds, where it lives, who is responsible for it, and how sensitive it is, is a critical first step that is often overlooked,” she says. “Without this, it is easy for important information to go unprotected simply because no one realized it needed protecting.”

Don’t Give it Away for Free

Tracy Soper, senior director of data excellence at Keystone Cooperative, believes the biggest mistake farmers make today when it comes to their data is failing to realize who they might be giving it away to for free.

“It’s being in a hurry and blindly accepting terms and conditions just to gain access to a tool, platform or service without fully understanding what rights they’re giving away in the process,” Soper says. “The reality is that many of those agreements contain important details about data ownership, data sharing, retention, model training and third-party access that can have long-term implications.”

He says the challenge is finding the right balance between protecting farm data and creating value from it. Data locked away has limited value while data shared without understanding the terms can create unintended risk.

“The goal should be to make informed decisions when it comes to that data and to determine what value it might have to others and any concerns around sensitivity or competitive advantage,” Soper says. “The rise of AI chatbots makes this even more important as it has never been easier to leak data without understanding what is happening. Ironically, AI may also be one of the best tools to solve the problem.”

Many terms of service and privacy agreements are written in language that most people don’t have the time or legal expertise to decipher. Soper encourages using AI tools to help summarize contracts, identify data ownership provisions, highlight risks, compare subscription tiers and explain what protections certain paid plans offer over free versions.

“As with most things, free is usually not free and the cost is usually the data being supplied,” he says.

Farmers don’t need to become attorneys, but they do need to become informed consumers of technology, Soper says. Before accepting any agreement, understand who owns the data, who can access it, whether it can be used for AI training, how it may be shared with third parties and what happens if they decide to leave the platform.

Here are four tips to put up guardrails to protect your farm or business from cybersecurity threats.

1. Implement role-based access.

Not all information should be accessible to everyone in the team or be available publicly. Proper mapping and identification of what type of data should be accessed by whom and the type of activities permitted on that data should be set in place. Andaya says this establishes two important things – tracking and accountability.

“Ensuring each role has clearly defined boundaries means that access is intentional, not accidental; that actions on data can be traced back to a specific person or team; and that when something goes wrong, there is a clear chain of responsibility,” she says. “No one should have more access than what their role requires to do their job.”

Just like in successful farms where everyone knows their role and stays within them, managing data for a farm or business is the same.

“You may have a team handling operations, and another for managing the finances,” Andaya says. “Both of these jobs are very vital to the business, but they don’t access each other’s domains; specific information is only available to certain groups. That same principle applies to how we manage data inside our organization, the right information, to the right people, for the right reasons.”

2. Secure all devices.

Within Andaya’s team, certain configurations are set in place within the company to ensure only the allowed devices from the team can access the network.

“Login to software applications requires authentication from our registered device to ensure that this is the correct person accessing the system, and not someone else using stolen or shared credentials,” she says. “This means that even if a password is compromised, an unrecognized device will still be blocked from getting in.”

3. Always have a backup plan.

Critical information should always have a copy stored somewhere safe and separate from the original, Andaya adds. If a system crashes, a device is lost, or something gets accidentally deleted; a backup means you can recover without starting from zero.

“Every farm has a contingency plan for bad weather or a failed operation; you don’t wait for the storm to hit before figuring out what to do,” she says. “Organization should have a clear, simple plan for what to do if data is lost, stolen, or compromised, who to call, what to do first, how to contain the damage, and how to recover. Everyone on the team should know this plan, not just the people at the top.”

4. Hold continual training for your team.

Protecting information and data within an organization, regardless of the industry, is always a team effort and not only the responsibility of one group. Proper training and alignment with the team on how to properly protect the information they are handling such as avoiding phishing emails, not clicking unrecognized links, and never sharing passwords is a must.

“The main line of defense will always be the user,” Andaya says. “If our users are knowledgeable on how to protect data, they become an active layer of protection on top of all the configurations and settings already in place.”

Training cannot be a one-time event.

“Threats evolve, new vulnerabilities emerge and people forget,” she says.

Regular training sessions, periodic reminders and timely updates whenever a new issue arises should be built into the farm or business’ routine.

“Think of it the way a farm prepares its workers every season, the conditions change, the risks change and everyone needs to be updated on how to respond,” Andaya says. “Data protection works the same way. Keeping the team informed consistently is what keeps the whole organization resilient.”

Know What You Have

When it comes to farming, nothing is left untracked because the success of the farm depends on knowing exactly what you have at any given time, Andaya explains.

“Our data deserves the same level of awareness,” she says. “Know what you have, know where it is, and know what would happen if it were lost or exposed.”

DHM Logo-Black-CL
Get News Daily
Get Market Alerts
Get News & Markets App