September 24, 2026

ACT4FOOD at ESIF 2026: Why Food Supply Chains Need SOC 4.0

On 15 September, ACT4FOOD joined the European SOC Innovation Forum (ESIF 2026) in Bucharest, bringing the food supply chain perspective into a wider European discussion on Security Operations Centers and critical infrastructure. The Forum brought together EU-funded cybersecurity projects working on areas including threat detection, cyber threat intelligence, SOC interoperability, incident response, and critical infrastructure resilience.

For ACT4FOOD, the event offered an opportunity to exchange lessons with other European initiatives and show how cybersecurity monitoring can be linked to the physical and food-safety consequences of a cyber incident.

Why Food Cybersecurity Demands a Different Approach

ACT4FOOD was represented during the Securing Critical Infrastructure session by Iuliana Floricică, Communication, Dissemination, Exploitation and Standardization Work Package Leader, who presented:

“SOC 4.0: Correlating OT, IoT and food-safety risk in one pipeline.”

The presentation began with a straightforward point: a cyber incident in a food facility does not necessarily remain a digital problem.

Modern food production depends on a complex combination of IT systems, industrial control systems, connected sensors, logistics platforms and operational technology. A manipulated temperature reading, for example, can affect a refrigeration process or a pasteurization control point. The consequence may therefore go beyond system downtime and reach the physical product itself.

This creates a challenge for conventional cybersecurity monitoring. A standard SOC may detect suspicious network activity, but it does not automatically understand what that activity means for a pasteurizer, a cold-storage unit, or an automated feeding system.

As Iuliana explained during the presentation, ACT4FOOD is developing its approach around this connection between the digital event and its physical food-safety consequence.

Moving Beyond Fragmented Data to SOC 4.0

Food producers deal with data split across isolated systems: ICS/SCADA equipment, IoT gateways, ERP software, and logistics platforms. Because these systems use different formats, are managed by different owners, and rarely feed into a single collection point, building a unified security view is difficult.

ACT4FOOD addresses this with SOC 4.0, acting as an orchestration and correlation hub.

The consortium is building a modular ecosystem of 17 dedicated components covering threat intelligence, anomaly detection, data collection, and incident response. All modules connect through clear interfaces and a centralized Integration Control Workbook to keep tracking simple across partners.

The platform relies on four core layers:

  • Data Collection & Integration: Bringing together data from IoT, industrial control systems, enterprise platforms, and logistics sources.
  • Detection & Threat Intelligence: Layering AI anomaly detection alongside rule-based monitoring and automated penetration testing.
  • Orchestration & Response: Where SOC 4.0 correlates events to give analysts clear, actionable context.
  • Validation & Pilots: Testing real scenarios across aquaculture, dairy, and retail, supported by a dedicated Cyber Arena for team training.

TACCP 4.0: Prioritizing Threats by Food Impact

One of the most food-specific elements presented at ESIF was TACCP 4.0.

Traditional cybersecurity prioritization often focuses on how technically severe a vulnerability or alert is. ACT4FOOD is exploring another dimension: What actually happens to the food if this attack succeeds?

By bringing food-defense principles into the cyber-physical world, TACCP 4.0 measures risks across three metrics:

  1. Likelihood: Vulnerability levels and attack feasibility.
  2. Safety Severity: Risks to food integrity, contamination, and public health.
  3. Economic Severity: Financial loss, operational downtime, and supply disruption.

This helps analysts spot hidden dangers. An alert that appears relatively minor from a network perspective may require greater attention if it could affect a critical food process, such as temperature control or pasteurization. The approach is also being developed with relevant requirements such as NIS2 incident-reporting obligations in mind.

Real-World Testing: Aquaculture, Dairy, and Retail

A cybersecurity architecture for the food sector cannot be validated in only one type of facility. ACT4FOOD is validating its architecture across three distinct operational environments:

  • Aquaculture: Securing water-quality sensors and feeding systems at remote sites with unstable connectivity.
  • Dairy Processing: Safeguarding high-speed, automated lines where pasteurization and cooling setpoints are critical.
  • Retail & Cold Chains: Protecting interconnected systems spanning inventory control, point-of-sale, and refrigeration.

Alongside these pilots, the project’s Cyber Arena gives food-industry staff and SOC teams a safe space to practice responding to simulated attacks before facing real incidents.

Key Takeaways Shared with the ESIF Community

The Forum was not only an opportunity to present the architecture. ACT4FOOD also shared lessons emerging from its first integration cycle.

These included the importance of defining interfaces before developing individual components too far, providing mock data early so detection teams are not blocked while waiting for pilot access, and maintaining one shared source of truth for modules and dependencies.

Another important lesson was that safety severity and economic severity should not automatically be treated as the same thing. An incident can have a limited financial impact while still creating a serious food-safety consequence.

The project has also found that heterogeneity needs to be treated as a basic design requirement. Aquaculture, dairy and retail operate with very different technologies and data environments, so flexibility has to be part of the architecture from the beginning rather than added later.

These points connect closely with the wider message of ESIF 2026: cybersecurity capabilities become more valuable when projects exchange what they have learned and look for ways to make their solutions work together.

Looking beyond one project

ACT4FOOD closed its session with three questions for the broader European cybersecurity community:

  1. How can SOCs share threat indicators without exposing sensitive commercial data?
  2. Can alert priorities reflect physical safety impacts instead of just technical asset values?
  3. How can European projects share cyber-range scenarios to avoid reinventing the wheel?

As food production relies increasingly on connected digital systems, protecting the infrastructure behind the food chain is becoming part of protecting the food itself.

Europe’s critical sectors face different technical challenges, but many underlying problems are shared: fragmented data, complex operational environments, the need for faster threat detection, trusted information exchange, and better cooperation between organizations.

For ACT4FOOD, participating in ESIF 2026 was therefore more than an opportunity to present SOC 4.0. It was a chance to place food supply chain cybersecurity within the broader European critical infrastructure conversation, learn from projects addressing similar challenges in other sectors, and identify areas where collaboration can strengthen the solutions being developed.

This is a staging environment