
- 1 Study Key Takeaways
- 2 Aquaculture is not agriculture: the risk behind digitalizing aquatic farming
- 3 Main threat groups and their real-world impact
- 4 The cybersecurity gap threatening mussel and seaweed farming
- 5 Immediate cybersecurity measures for aquaculture facilities
- 6 Proportional regulations for aquaculture: protecting small producers
- 7 Back to the raft: from blind trust to operational security
- 8 Entradas relacionadas:
Study Key Takeaways
- Modern aquaculture relies increasingly on sensors, underwater cameras, automated feeders, mobile apps, and traceability platforms; however, each device represents a potential entry point for a cyberattack.
- The greatest threat is not necessarily monetary theft, but data manipulation, as a sensor reporting false metrics can lead to premature harvests, feeding errors, or the loss of vital certifications.
- An analysis reviewing over 27,000 studies revealed that cybersecurity in aquaculture is drastically under-researched, with sectors like mussel and seaweed farming representing a near-total blind spot—only one study addressed mussel farming, and none analyzed seaweed.
- Fortunately, the most effective defenses are often the simplest and most accessible: isolating field equipment from administrative networks, changing default passwords, maintaining regular backups, and training staff.
- For small farms and cooperatives, complying with European-style cybersecurity regulations will pose a heavy burden if applied identically to industrial enterprises, prompting authors to advocate for rules proportionate to producer size.
It is six in the morning on the Baltic. Before setting sail, a mussel farmer checks his mobile app to review overnight indicators: dissolved oxygen, water temperature, and the growth model of his culture lines. Everything is green, prompting him to delay deploying the maintenance crew, postpone the harvest by two weeks, and project smooth reporting for the nitrogen removal required by the environmental monetization program.
This chain of critical decisions hinges on a single factor: the authenticity of on-screen metrics.
What if they were not real? If someone altered that data remotely, the farmer would maintain false confidence, harvesting off-schedule, certifying non-existent nutrient removal, and detecting the issue only when irreparable. In digitized aquaculture, blind trust in information is the primary vulnerability.
A team of researchers from the Estonian Maritime Academy and Tallinn University of Technology, in collaboration with the University of Tartu, conducted a systematic literature review on digital risks in the sector. After filtering 27,324 studies, they exhaustively analyzed 212 to answer an urgent question: as facilities integrate sensors and software, how exposed do they remain to cyberattacks, and how should they respond?
The conclusion is categorical: aquaculture relies heavily on technology, yet system protection displays a critical lag. Paradoxically, the most vulnerable sector is the one most promoted for its environmental value—low-trophic aquaculture (mussels and seaweed)—where cybersecurity research is virtually non-existent. For the producer, farm digitization moves faster than defense mechanisms.
Aquaculture is not agriculture: the risk behind digitalizing aquatic farming
For years, digital security discussions in food production focused primarily on precision agriculture, connected tractors, and processing plants, incorrectly assuming aquaculture was simply an aquatic extension of farming subject to identical solutions.
However, marine farms operate far differently than terrestrial crops; submerged in corrosive salt or brackish water across offshore cages and lines, their equipment relies on low-power, interruption-prone wireless networks to monitor dynamic, living organisms. In this environment, sensor failures escalate beyond technical glitches—a single faulty oxygen reading directly triggers costly feeding or harvesting errors, transforming a communication outage into an immediate biological crisis.
This operational reality defines the unique attack surface of aquaculture facilities, which extends well beyond office computers to encompass the entire digital chain: from buoy sensors transmitting via low-power protocols like LoRaWAN or MQTT, to cloud platforms and product traceability systems certifying origin. Every link in this digital architecture represents a potential vulnerability.
Mantente siempre informado
Stay Informed
Únete a nuestras comunidades para recibir al instante las noticias, informes y análisis más importantes del sector acuícola.
Join our communities to get instant access to the most important news, reports, and analysis from the aquaculture industry.
Main threat groups and their real-world impact
By classifying threats based on their frequency in scientific literature, the researchers identified a clear pattern, listed from most to least recurring:
- Data Integrity Attacks (57 studies): The most common and dangerous threat to low-trophic farming, involving the injection of false sensor readings. Similar to a tampered thermostat reading 22 °C in a freezing room, altered aquaculture data distorts nutrient removal calculations, harvest scheduling, and environmental compliance.
- Network Attacks (52 studies): Communication disruption or interference; since offshore facilities operate on spotty connectivity, signal jamming proves severely damaging.
- Authentication and Access Control Failures (46 studies): Shared passwords, weak credentials, or factory-default keys—basic vulnerabilities that grant unauthorized access.
- Malware and Ransomware (32 studies): Malicious software targeting commercial and planning records, which severely compromises sales continuity and certifications despite lower occurrence.
- Physical and Environmental Threats (26 studies): Equipment sabotage, theft, corrosion, or biofouling, where physical damage can easily mask or simulate a cyberattack.
- Phishing and Social Engineering (17 studies): Manipulation techniques used to harvest credentials, often acting as the initial entry vector for larger breaches.
- Supply Chain Vulnerabilities (16 studies): Relying on third-party software for traceability or analytics means inheriting their security gaps.
The authors emphasize these are not abstract digital risks—in aquaculture, such failures directly compromise biomass management, harvest timing, and certification validity.
The cybersecurity gap threatening mussel and seaweed farming
Here lies the finding that should most mobilize the industry: of the 212 studies analyzed by the researchers, only one directly addressed mussel farming, and none evaluated seaweed cultivation. Low-trophic aquaculture—globally promoted as an environmental solution to mitigate eutrophication in ecosystems like the Baltic Sea—represents a near-total blind spot in digital security research.
This deficiency is critical, as these facilities are not merely smaller-scale versions of a fish farm. Even if their automated systems are more limited, the authenticity of their environmental data remains paramount. Their operational model relies on auditable metrics: the volume of nitrogen removed, the geolocation of culture lines, and the traceability backing their environmental certifications. If a vulnerability allows the tampering of location records, growth rates, or water quality, the consequences extend far beyond operations—compromising ecosystem service payments, sustainable seals, and overall project legitimacy.
Compounding this vulnerability is the harsh marine environment, where salinity recalibrates sensors, while ice and storms shorten windows for preventive maintenance. Furthermore, concessions operate under complex, multidisciplinary regulations. For these reasons, the authors emphasize that extrapolating solutions designed for inland ponds or terrestrial agriculture is unfeasible; digital protection strategies must be tailor-made for the marine environment.
Immediate cybersecurity measures for aquaculture facilities
The primary takeaway is that the most effective defenses require neither cutting-edge technology nor inaccessible budgets. The scientific review concludes that high-impact actions correspond to fundamental practices, described by researchers as “unglamorous” yet indispensable measures:
- Inventory connected assets: It is impossible to protect devices whose presence on the network is unknown.
- Segment networks: Isolating field infrastructure from the administrative network prevents an incident in one segment from contaminating the rest of the operation.
- Manage credentials: Eliminating default keys and shared passwords represents the lowest-cost adjustment with the highest immediate impact.
- Implement two-factor authentication (2FA): Requiring an additional verification code for access to dashboards and cloud platforms.
- Maintain offline backups: Keeping copies of critical records in storage disconnected from the network.
- Audit vendors: Demanding secure update protocols from software and hardware developers.
- Simulate response protocols: Rehearsing incident management before high-production periods.
For energy-constrained devices—such as buoys or submerged sensors—the review advises applying lightweight encryption algorithms and adapted authentication, offloading intensive processing to onshore servers. Advanced tools like blockchain traceability, federated learning, or digital twins are promising, but only yield value once the underlying security architecture is fully consolidated.
Proportional regulations for aquaculture: protecting small producers
International frameworks for managing digital risk—such as NIST guidelines and the European NIS 2 directive—are valuable, but ill-fitted for marine farms. While integrated aquaculture corporations can absorb dedicated IT costs, small-scale mussel farmers and cooperatives lack that financial capacity, prompting authors to advocate for tiered regulation. Rather than uniform mandates, strategies like shared incident reporting, sector-specific guides, vendor baselines, and targeted subsidies yield better results. Crucially, cybersecurity also carries an environmental footprint; energy-intensive data transmission requires that digital security and sustainability be co-designed in eco-friendly sectors.
Back to the raft: from blind trust to operational security
Let us return to our six-o’clock-in-the-morning farmer, gazing at the green indicator on his mobile app. The difference between trusting blindly and operating with certainty lies not in purchasing the most expensive technology, but in consolidating fundamental practices: inventorying connected devices, changing default passwords, backing up operational records, and training staff to spot anomalies.
The scientific review concludes with an inescapable premise: cybersecurity is an inherent pillar of sustainable aquaculture, not an optional luxury. As digital dependency deepens, the core question for the sector—especially for mussel and seaweed farming, which remains a blind spot—is not whether to protect itself, but whether it will do so before or after the first incident. Ensuring that green indicator is authentic is the priority.
Contact
Indrek Adler
Estonian Maritime Academy, Tallinn University of Technology
Kopli 101, 11712 Tallinn
Estonia.
Email: indrek.adler@taltech.ee
Reference (open access)
Adler, I., Kotta, J., Vene, K., & Lugo, R. G. (2026). Cybersecurity in aquaculture: Risks, governance, and future directions across production systems. Journal of the World Aquaculture Society, 57(4), e70129. https://doi.org/10.1111/jwas.70129
Editor at the digital magazine AquaHoy. He holds a degree in Aquaculture Biology from the National University of Santa (UNS) and a Master’s degree in Science and Innovation Management from the Polytechnic University of Valencia, with postgraduate diplomas in Business Innovation and Innovation Management. He possesses extensive experience in the aquaculture and fisheries sector, having led the Fisheries Innovation Unit of the National Program for Innovation in Fisheries and Aquaculture (PNIPA). He has served as a senior consultant in technology watch, an innovation project formulator and advisor, and a lecturer at UNS. He is a member of the Peruvian College of Biologists and was recognized by the World Aquaculture Society (WAS) in 2016 for his contribution to aquaculture.





