Next Article in Journal
Grid-Forming Control Technologies for Cascaded H-Bridge Power Conversion Systems
Previous Article in Journal
Integrated Solenoid Inductors with Solid Ferrite Core
Previous Article in Special Issue
A Full-Node Blockchain Forensic Framework for Cross-Layer Virtual Asset Tracking
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Review

Smart Farming Cybersecurity: Key Risks and Security Principles

by
Sunmi Kong
1,†,
Chang Ha Park
2,†,
Kyung Jun Lee
3,
Tae-Su Kim
3,
Yeong-Seon Won
3,
Min-Ho Jo
3,
SongYi Han
3,
Ju Eun Ko
3,
Hyeon Ju Nam
3 and
Hyeon Ji Yeo
3,*
1
Graduate School of Pan-Pacific International Studies, Kyung Hee University, Kyunghee-daero, Dongdaemun-gu, Seoul 02447, Republic of Korea
2
Department of Smart Farm, Namseoul University, 91 Daehak-ro, Seonghwan-eup, Seobuk-gu, Cheonan-si 31020, Republic of Korea
3
Division of Bioresource Integration Research, Honam National Institute of Biological Resources, 99 Gohadoan-gil, Mokpo-si 58762, Republic of Korea
*
Author to whom correspondence should be addressed.
These authors contributed equally to this work.
Electronics 2026, 15(18), 4087; https://doi.org/10.3390/electronics15184087
Submission received: 12 August 2026 / Revised: 1 September 2026 / Accepted: 8 September 2026 / Published: 10 September 2026

Abstract

By combining digital sensing, network connectivity, data-driven analyses, cloud services, and automated controls, smart farming has been increasingly adopted in agricultural production. Although these technologies have improved the precision and efficiency of farm management, they also increase cybersecurity exposure as agricultural facilities are connected to external networks, platforms, and remote-control environments. This review seeks to clarify why cybersecurity should be considered a fundamental requirement in smart farming and details the major system components, cybersecurity risks, and network design considerations required for secure operation. This review first explains the concept and application scope of smart farming, and then examines how sensors, communication networks, gateways, control systems, data platforms, user interfaces, cloud infrastructure, and physical support systems contribute to farm management and cybersecurity exposure. The review also emphasizes that smart farming differs from ordinary information systems because digital data and control commands can directly affect physical processes, such as irrigation, ventilation, heating, nutrient supply, and livestock management. Based on these cyber-physical characteristics, the review summarizes the key architectural considerations for reducing cybersecurity risks, including network segmentation, data and command flow mapping, gateway and wireless security, remote access management, cloud access control, device inventory, logging, monitoring, resilience, and local fail-safe operation. Overall, ensuring cybersecurity in smart farming requires an integrated approach that protects not only data and accounts but also the reliability and continuity of agricultural production.

1. Introduction

The rapid digitalization of agriculture has accelerated the adoption of smart farming systems that aim to integrate information and communication technologies, sensors, communication networks, data platforms, artificial intelligence, and automated control technologies into agricultural production environments [1,2]. By enabling real-time monitoring, data-driven decision-making, and automated farm management, these systems contribute to the improvement in the precision, efficiency, productivity, and sustainability of agricultural production [1,3]. However, the same connectivity that enhances farm management also widens the cybersecurity exposure of agricultural facilities through wireless networks, cloud platforms, remote-control applications, and interconnected devices [4,5].
Unlike conventional information systems, smart farming systems operate as cyber-physical systems in which digital data and control commands directly affect physical farm environments [4,5]. Within this interconnected architecture, cybersecurity risks may emerge not only from individual devices but also from interactions among sensors, communication networks, gateways, control devices, data storage and analytics systems, user interfaces, and security mechanisms [4,5]. Vulnerabilities in sensor data acquisition, communication channels, gateways, remote access mechanisms, and control functions may expose smart farming environments to inaccurate decision-making, unauthorized access, data manipulation, service disruption, and malicious control [6,7,8,9].
Such cybersecurity incidents in smart farming may lead not only to data leakage or system unavailability but also to failures in irrigation, ventilation, heating, nutrient solution supply, livestock management, and other critical farm operations [8,10]. Therefore, before examining specific cybersecurity threats, the basic concepts, application areas, core components, incident-related risks, and secure network architectures of smart farming systems should be understood. In this section, we provide this foundation by first introducing smart farming systems and their application domains, then examining their major components and cybersecurity risks, discussing the potential impacts of cybersecurity incidents, and finally presenting the major considerations for establishing a secure smart farming network architecture [1,4,5,8,10,11,12].
Previous reviews have provided important perspectives on cybersecurity frameworks for Agriculture 4.0, IoT-enabled smart-agriculture architectures and security protocols, and communication-layer vulnerabilities in wireless agricultural networks [13,14,15]. However, the relationships among cyber threats, control processes, physical agricultural consequences, and architecture-level security requirements have remained comparatively fragmented. In this review, these aspects are integrated from a cyber-physical systems perspective by linking system components and attack surfaces with control and actuation processes, agricultural consequences, and corresponding architectural security principles. Particular emphasis is placed on cyber-physical disturbance propagation, agricultural edge-gateway threats, operational resilience, and the agriculture-specific interpretation of established OT-security practices.
The remainder of this review is organized as follows. The review methodology is first described, followed by an overview of smart-farming systems and their cyber-physical and software architectures. The major system components and associated cybersecurity risks are then examined, together with secure network-architecture principles. Finally, the principal limitations and future research directions are discussed, followed by the conclusions.

2. Review Methodology

A structured literature search was conducted using Scopus, Web of Science, IEEE Xplore, and ScienceDirect. Publications from 2015 to 2026 were primarily considered, while earlier studies and official standards were included when foundational concepts or widely adopted cybersecurity guidance were provided. Search terms included combinations of “smart farming,” “smart agriculture,” “precision agriculture,” and “Agriculture 4.0” with “cybersecurity,” “cyber-physical security,” “IoT security,” “network architecture,” “gateway,” “threat modeling,” and “security framework.”
Peer-reviewed articles, technically relevant conference papers, and recognized cybersecurity standards or governmental guidelines were included when direct relevance to smart-farming cybersecurity, IoT, cyber-physical systems, network security, edge or gateway security, cloud infrastructure, or operational technology was demonstrated. Duplicate records and studies without sufficient cybersecurity relevance were excluded. The selected literature was qualitatively synthesized according to system components, cyber-physical threats, architectural security principles, operational resilience, and emerging communication environments.

3. Smart Farming Systems

Smart farming integrates information and communication technologies, sensors, networks, data analytics, and automated control technologies into agricultural production sites to enable precise monitoring and management of farm environments (Figure 1) [1,2]. Smart farming facilitates a technological framework that extends traditional experience-based agricultural decision-making to data-driven decision-making [2]. The principle underlying smart farming lies in continuous real-time monitoring of farm conditions, analysis of the collected data, and maintaining optimal environmental conditions for crop and livestock growth [3]. Smart farming is not merely restricted to the installation of computers on farms; rather, it is an integrated agricultural management approach in which sensors, communication networks, control devices, and data platforms operate as an interconnected system [2]. Ultimately, smart farming aims to improve productivity, quality, efficiency, and sustainability by collecting and analyzing diverse data generated throughout the agricultural production processes [1].
In conventional agriculture, farmers’ experience and intuition play central roles in management decisions. In contrast, smart farming incorporates quantitative data such as temperature, humidity, soil moisture, solar radiation, carbon dioxide concentration, and nutrient solution information as key decision-making criteria [16,17,18]. Therefore, smart farming is not a replacement for farmers’ experiential knowledge; rather, it complements such knowledge with data-driven analyses and transforms farm management to facilitate a more precise, systematic, and reproducible process [19].
Smart farming can be applied to various agricultural sectors, including protected horticulture, livestock production, open-field agriculture, vertical farming, post-harvest storage, and distribution management [12]. In protected horticulture, smart farming has evolved toward AI- and data-based management of greenhouse temperature, humidity, ventilation, irrigation, nutrient solution supply, lighting, and shading systems [20]. In livestock production, smart farming is expanding toward the monitoring and management of animal biometric information, activity patterns, feed intake, housing environment, and ventilation conditions [21]. In open-field agriculture, smart farming enables the precise management of large-scale farmlands by incorporating soil conditions, meteorological information, crop growth data, geospatial information, and remote sensing data into decision-making [2,22].
Smart-farming systems can be differentiated according to their production environment and control requirements. In protected horticulture and vertical farming, environmental variables are continuously monitored and regulated through tightly coupled sensing and actuator-control loops. In livestock systems, environmental monitoring is integrated with animal-health, activity, feeding, and housing-management functions, whereas open-field systems are characterized by spatially distributed sensing, wireless connectivity, positioning, remote sensing, and machinery-based operations [12,20,21,22]. Despite these operational differences, sensing, communication, data processing, decision-making, and actuation are interconnected across these agricultural domains, thereby forming the cyber-physical foundation of smart-farming systems.

3.1. Cyber-Physical Dynamics and Attack Propagation

Smart farming systems can be represented as networked cyber-physical control systems in which physical agricultural states are measured by sensors, transmitted through communication networks, processed by control units, and regulated through actuators. To provide a generalized representation of cyber-physical disturbance propagation, a discrete-time formulation commonly adopted in networked cyber-physical control systems can be expressed as follows [23,24].
x k + 1 = f x k , u k d a , w k
where xk denotes the physical agricultural state vector, uk represents the actuator control input, da denotes the controller-to-actuator delay, wk represents process disturbances, and f(·) denotes the nonlinear dynamics of the agricultural system. The state variables may include temperature, relative humidity, soil or substrate moisture, carbon dioxide concentration, and livestock housing conditions, whereas the control inputs may include irrigation, ventilation, heating, cooling, nutrient delivery, and automated feeding.
Sensor measurements may additionally be affected by communication delays and false-data injection (FDI) attacks. Accordingly, the measurement received by the controller can be represented as
y k r e c = h x k d s + v k d s + a k
where ykrec denotes the measurement received by the controller, h(·) represents the measurement function, ds denotes the sensor-to-controller delay, vk represents measurement noise, and ak represents the malicious data-injection vector. Because heterogeneous control strategies may be implemented in smart farming systems, the controller can be represented using a generalized control law,
u k = K r k , y k r e c
where rk denotes the reference state and K(·) represents the implemented control policy. Around a nominal operating condition, the resulting physical-state deviation can be approximated as
Δ x k + 1 A k Δ x k + B k Δ u k d a
where Δxk and Δuk denote deviations from the nominal state and control input, respectively, and Ak and Bk represent the local state and input sensitivity matrices.
Accordingly, sensing delays or manipulated measurements can be propagated through the closed-loop control process, resulting in altered actuator commands and subsequent deviations in the physical agricultural state. For example, falsified soil- or substrate-moisture measurements may induce excessive irrigation, whereas manipulated temperature measurements may result in inappropriate ventilation, heating, or cooling. This formulation is intended to provide a generalized representation of cyber-physical disturbance propagation rather than a crop- or facility-specific dynamic model.

3.2. Software Architecture and Integration Views in Smart Farming

Software architecture constitutes an essential layer of smart-farming cyber-physical systems because sensing data, control commands, analytical services, cloud platforms, and external applications are integrated through software-mediated interfaces and services. To provide a structured architectural interpretation, the 1+5 Architectural Views Model can be adapted to smart-farming environments (Table 1) [25].
In this model, system architecture is represented through integrated processes, use cases, logical components, contracts, integrated services, and deployment views, thereby enabling business processes, software functions, interfaces, and physical deployment to be considered jointly.
Within smart farming, the integrated-services and contracts views are particularly relevant to cybersecurity because data and control commands are exchanged through middleware, message brokers, application programming interfaces, and device-management services. Security requirements should therefore be incorporated into service authentication, authorization, message integrity, interface contracts, protocol mediation, and software-component deployment. This architectural perspective complements device- and network-level security analysis by explicitly addressing the software mechanisms through which heterogeneous agricultural systems are interconnected.

4. Components and Cybersecurity Risks of Smart Farming Systems

A smart farming system is a complex and interconnected system comprising sensors, communication networks, control devices, data storage and analytics systems, user interfaces, and security mechanisms [4]. Smart farming systems consist of multiple components that measure farm environments, transmit data, and control agricultural facilities based on analytical outputs [5]. Understanding these core components is essential, as cybersecurity threats in smart farming do not arise solely from isolated devices but instead from the interconnected architecture of the entire system.
Smart-farming components can be organized into a layered architecture. The physical and sensing layer includes sensing devices; the communication and edge layer comprises communication networks and gateways; the control and actuation layer includes controllers and actuator-based control systems; and the data and application layer comprises data storage, analytics, user interfaces, and cloud platforms. Power and physical infrastructure are classified as a supporting infrastructure layer, whereas cybersecurity is treated as a cross-cutting security and governance layer because security controls are required across all technical layers.
Cybersecurity and operational risks can be differentiated according to their origin. Malicious cyber threats may be characterized by unauthorized access, spoofing, false-data injection, command manipulation, and denial-of-service attacks, whereas accidental technical faults may include sensor malfunction, communication failure, hardware failure, and power interruption. Operational errors and data-quality anomalies may also be introduced through system misconfiguration, inappropriate parameter settings, missing data, or inaccurate measurements. Although these disturbances arise from different sources, similar cyber-physical consequences may be induced when sensing, communication, or control functions are compromised or disrupted.
The first core component of smart farming is a sensor. Sensor-generated data serve as the starting point for automated control and decision-making in smart farming systems [6,7]. If sensor data are inaccurate, the system may make decisions based on incorrect environmental information. For example, if a soil moisture sensor reports a value lower than the actual soil moisture level, unnecessary irrigation may be initiated. Similarly, if a temperature sensor reports a value higher than the actual environmental temperature, connected ventilation or cooling devices may operate unnecessarily. Therefore, in smart farming, sensors do not serve merely as measurement devices, but as critical components that provide a basis for farm management decisions [26].
The second core component is the communication network. Communication networks provide pathways through which data and commands are exchanged between sensors, controllers, gateways, servers, cloud platforms, and mobile applications [27]. Agricultural environments often involve large spatial areas with high humidity, dust, temperature fluctuations, unstable power supplies, and long communication distances [28]. Smart-farming communication networks must therefore be designed by considering not only the transmission speed but also stability, power efficiency, communication range, and fault tolerance [27]. If the communication network is unstable, sensor data may be delayed or lost, and control commands may not be delivered in a timely manner. Although communication networks enhance the convenience of smart farming, they can also serve as potential access points for external attackers [8].
The third core component is the gateway. A gateway is an intermediate device that collects data from multiple sensors and agricultural devices and transmits them to servers or cloud platforms [29]. It can also connect to different communication protocols and data formats [29]. For instance, sensors inside a greenhouse may transmit data using ZigBee or LoRa, and the gateway forwards these data to a cloud server through an internet connection. Because gateways connect internal smart-farming devices with external networks, they occupy a particularly important position from a cybersecurity perspective. If a gateway is compromised, attackers may be able to monitor sensor data flows or interfere with control command transmission. Gateways thus require security management measures, such as changing default passwords, updating firmware, restricting access privileges, and encrypting communication [9].
A structured threat-modeling framework was applied to smart-farming cyber-physical systems by mapping protected assets, threat actors, attack entry points, attack techniques, security objectives, agricultural consequences, and corresponding mitigation controls. The same framework was applied in greater detail to agricultural edge gateways because these devices constitute critical trust boundaries between field-level assets, control systems, and external networks.
Agricultural edge gateways constitute critical trust boundaries because heterogeneous field devices, local controllers, farm-management systems, and external cloud services are interconnected through these devices. Consequently, gateway security should be evaluated using a structured threat-modeling approach that considers protected assets, threat actors, attack surfaces, attack techniques, security objectives, and potential cyber-physical consequences (Table 2) [30,31,32]. In smart-agricultural environments, relevant gateway assets include sensor data, actuator commands, authentication credentials, firmware, cryptographic keys, and communication sessions, whereas major attack surfaces include wireless interfaces, remote-management services, firmware-update mechanisms, application programming interfaces, and cloud-facing connections [31,32].
Gateway-related threats can be categorized using a STRIDE-informed approach, including spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege [32]. Such attacks may result in manipulated sensor data, unauthorized control commands, disruption of monitoring services, or compromised access to internal control networks. Therefore, gateway protection should incorporate authentication, least-privilege access control, secure firmware management, communication protection, interface hardening, network segmentation, logging, and anomaly monitoring according to the potential agricultural consequences of gateway compromise [31,32].
The fourth core component is the control system, which comprises controllers and actuators. In smart farming systems, sensors collect environmental or biological data, controllers make control decisions based on these data or operator commands, and actuators perform physical actions by operating farm facilities such as pumps, valves, ventilation fans, heaters, cooling systems, shading screens, lighting systems, nutrient solution supply systems, and automatic feeding devices [10,11]. Through actuators and control functions, smart farming operates not only as a monitoring system but also as an automated system that can directly modify farm environments [33]. However, because actuators directly affect farm conditions, errors in control commands or actuator operation can lead to the inappropriate operation of farm facilities and unstable environmental conditions. For example, malfunctioning irrigation systems can cause excessive moisture or water deficiency in the crops. Similarly, abnormal ventilation control may rapidly alter the greenhouse temperature and humidity.
The fifth core component is the data storage system. Smart farming continuously generates various types of data, including sensor data, crop growth data, device operation logs, work records, shipment records, and meteorological information [34,35,36]. This data can be stored on local farm servers, cloud platforms, databases, or platform-based services [34,35,36]. Data storage systems preserve farm operation histories and enable long-term growth analyses and production forecasting [35,36]. Stored data can be used to identify optimal environmental conditions for specific crops, compare seasonal production patterns, and trace the causes of operational problems [35,36]. However, if stored data are not properly protected, farm operation information, production know-how, transaction data, and cultivation strategies can potentially be exposed to external parties. Therefore, data storage systems in smart farming should be managed with appropriate security measures such as backup procedures, access control, encryption, and logging mechanisms.
The sixth core component is a data analytics system. Data analytics systems interpret collected data and provide evidence for farm management decisions [37]. Data analytics can be applied to growth status assessment, disease risk prediction, yield forecasting, energy use optimization, and the improvement of irrigation and nutrient solution strategies [38]. In smart farming, data analytics can extend beyond basic statistical analyses to artificial intelligence and machine learning approaches [38]. For data analytics to function accurately, input data must be of sufficient quality [39]. If erroneous data are entered into an analytical system, the resulting outputs may be inaccurate. Therefore, smart farming data analytics systems should incorporate data quality verification and anomaly detection during the data collection stage.
The seventh core component is the user interface. The user interface is the point of interaction between the farmer and the smart farming system [40]. Through the user interface, farmers can monitor the temperature, humidity, irrigation status, device operation, warning alerts, and crop growth data [41]. They can also issue control commands for ventilation, irrigation, heating, lighting, and nutrient solution supply [41]. If the user interface is overly complex, farmers may not be able to fully utilize system functions. If the interface is unclear, operators may enter incorrect settings or fail to recognize important alerts. Therefore, smart farming user interfaces should provide clear information structures, intuitive warning displays, and safe control procedures.
The eighth core component is the cloud and platform infrastructure. Cloud systems provide a foundation for storing and analyzing farm data, enabling remote access and integrating external services [42]. These platforms can connect to multiple farms, devices, datasets, and analytical services within a unified operational environment [42]. Cloud and platform infrastructures support the scalability and convenience of farm management [42]. However, they also introduce cybersecurity risks, including account compromise, API misuse, data leakage, and service disruption [42]. Accordingly, cloud-based smart-farming systems should be designed with account management, access control, data protection, and service continuity planning.
The increasing use of cross-farm data platforms, proprietary agricultural machinery APIs, and multi-tenant cloud infrastructures introduces additional concerns regarding data privacy, ownership, and sovereignty. Agricultural data may include production records, geospatial information, machinery-operation data, yield information, and farm-management strategies, and uncertainties may arise regarding data ownership, secondary use, data portability, and contractual control when such data are shared across farms or external service providers [43,44]. In addition, compromised API credentials, excessive access privileges, insufficient tenant isolation, or misconfigured cloud-storage policies may enable unauthorized access to farm data or remote-management functions. Accordingly, agricultural data-sharing environments should be supported by explicit data-governance policies, purpose-limited access, tenant isolation, auditable authorization mechanisms, and clearly defined rights for data access, use, retention, and transfer [43,44].
The ninth component is the power supply and physical infrastructure that supports smart farming operations. Smart farming devices require a stable power supply to continuously collect data, transmit information, and execute control commands [45,46]. Sensors, communication devices, gateways, and control equipment may also be exposed to humidity, dust, temperature fluctuations, unstable power conditions, and other physical effects in agricultural environments [46]. Power failures or equipment damage can lead to interruptions in data collection, communication failures, and control operation errors [47,48]. Therefore, smart farming should be understood not only as a digital system, but as a field-based infrastructure in which equipment durability, stable power supply, and physical protection are essential.
The tenth core component is the cybersecurity framework [13,30]. A smart farming cybersecurity framework should protect interconnected components such as sensors, communication networks, gateways, controllers, servers, cloud systems, user accounts, and data repositories [13,30,49]. Smart farming is a cyber-physical system in which digital data, control decisions, and commands can influence physical farm environments through monitoring, control, and actuation processes [13,30,49]. Consequently, cybersecurity incidents in smart farming may affect information confidentiality and the reliability of monitoring, control operations, and farm management [30]. Therefore, cybersecurity should not be considered an optional function added after system deployment but rather a fundamental element of any smart farming system that should be incorporated from the design stage.
The components of smart farming do not operate independently but function as an interconnected system [4,5,22]. Sensors generate data, communication networks transmit data, gateways aggregate data, servers and cloud platforms store data, analytics systems extract meaning from data, and control systems operate farm facilities [4,5,22]. If one part of this interconnected structure becomes unreliable, the reliability of the entire smart farming operation can potentially be reduced. For example, sensor errors can lead to incorrect analysis and inappropriate control decisions [6,7,12,26], whereas communication network failures can cause data delays or interruptions in remote operations [8,27,28,50]. Similarly, account compromise may increase the risk of unauthorized access to cloud data and control functions [13,30,42,49]. Therefore, understanding a smart farming system requires more than recognizing the function of each individual device; it also requires understanding the overall flow of data and commands [4,5,22]. Farmers and system operators should be familiar with what types of data are collected by sensors, where the data are transmitted and stored, who can access them, and which devices may operate automatically based on these data [13,20,30,49]. A clear understanding of the core components of smart farming also enables more specific identification of security vulnerabilities [13,20,30,49]. Sensors may become targets of data manipulation [6,7,12,26], communication networks may be exposed to eavesdropping or interference [8,27,28,50], gateways may serve as entry points for internal intrusion [9,29], cloud systems may be exposed to unauthorized access or data leakage [13,30,42,49], and control systems may be affected by incorrect commands or unauthorized manipulation [10,11,13,30,33,49]. The core components of smart farming are not only assets that enhance productivity, but also assets that require systematic security management. The strength of smart farming lies in its connectivity, but its risks originate from the same connectivity (Table 3) [13,20,30,49].
Representative cyber-physical attack scenarios can be further differentiated according to their evidential basis. Accordingly, reported incidents or experimentally demonstrated attacks should be distinguished from representative scenarios developed to illustrate plausible agricultural consequences (Table 4).

5. Establishing a Secure Smart Farming Network Architecture

Establishing a secure smart-farming network architecture involves systematically segmenting and protecting sensors, control devices, gateways, servers, cloud platforms, mobile applications, and external access pathways such that they are not indiscriminately connected [14,54]. As smart farming connects physical devices within farms to external digital services, network design is an important starting point for cybersecurity [14,54]. If the network architecture and communication channels are not properly secured, attackers can potentially exploit vulnerable devices, access points, or unsecured data transmission protocols, thereby compromising data security and system reliability [54,55].
The first principle involves network segmentation and security zoning. A secure smart-farming network should avoid placing all the devices on a single flat network. Instead, the sensor, control, management, business, guests, cloud connection, and external maintenance zones should be separated according to their functions and risk levels [14,54]. Communication between these zones should be limited to only what is necessary. This separation can reduce unnecessary connections and prevent attackers from moving across other parts of the farm system after compromising a single vulnerable device [14,54].
The second principle involves data and command flow mapping. Before designing a smart farming network, it is necessary to identify the devices that generate data, where the data are transmitted and stored, who can access them, and which devices operate based on these data [14,54]. Data flow mapping helps determine which communication should be allowed or blocked [54]. It also clarifies the pathways through which control commands move from management servers, gateways, and cloud platforms to control devices [14,54].
The third principle involves the secure management of gateways, wireless networks, and remote access. Gateways must be protected because they connect internal sensors and control devices to external networks and cloud platforms [9,29]. Wireless networks should be separated according to their purpose, and farm operation networks should not be shared with visitors or external workers [15]. Remote access should be minimized, limited to specific devices and time periods, combined with strong authentication and access logging, and closed after the required maintenance tasks have been completed [56].
The fourth principle involves cloud connectivity and access control. Cloud platforms provide useful functions, such as data storage, data analysis, remote monitoring, and service integration in smart farming systems [42]. However, the use of cloud-based IoT infrastructures may also result in the creation of external pathways through which farm data, system configurations, and user information can be exposed to cybersecurity risks [55]. Therefore, cloud connections should transmit only the necessary data, and cloud accounts and APIs should be managed according to the principle of least privilege [55,57]. Access privileges should only be granted to users, services, or external providers who require them for clearly defined purposes [57].
The fifth principle involves device inventory, logging, and monitoring. Smart farming operators must maintain an inventory of connected devices, including sensors, gateways, controllers, servers, wireless routers, cloud accounts, mobile applications, and remote access tools [54,58]. Network and system logs record login attempts, remote access, control commands, device errors, and network connections [59]. Such records enable the identification of abnormal accesses, unusual commands, communication failures, and the cause or scope of damage after an incident [54,59].
The sixth principle is resilience and local fail-safe operations. Smart farming networks should be designed such that critical farm operations can continue safely even when internet connectivity, cloud services, or remote access functions are disrupted [60,61]. Essential functions such as irrigation, ventilation, and temperature control should be able to operate through local control rules or manual procedures whenever possible [60,61]. Manual operational procedures, backup data, equipment inspections, and recovery procedures should also be prepared so that farms can restore normal operations after failures or cybersecurity incidents [61,62].
The six security principles presented in this review are not intended to replace established cybersecurity standards. Rather, they are intended to provide an agriculture-specific interpretation of recognized operational technology (OT) and cybersecurity practices. The proposed principles can be aligned with the NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-82 Rev. 3, and the IEC 62443 series [60,63,64,65]. Network segmentation and security zoning are consistent with OT segmentation and zone-and-conduit concepts, whereas device inventory, access control, logging, and continuous monitoring are aligned with established asset-management, protection, and detection requirements. Similarly, remote-access restrictions and cloud-access controls can be mapped to authentication, authorization, least-privilege, and external-connectivity requirements. Accordingly, the security principles presented herein should be interpreted as an agricultural adaptation of established cybersecurity and OT-security practices rather than as an independent replacement framework (Table 5).
In agricultural cyber-physical systems, conventional fail-safe strategies should be applied with particular caution because the complete shutdown of critical control functions may itself produce severe biological or production consequences [60,66]. Operational responses should therefore be differentiated among fail-safe, fail-secure, and fail-operational strategies. Under a fail-safe strategy, a system is transitioned to a predefined state in which immediate physical hazards are minimized. Under a fail-secure strategy, security controls are preserved and unauthorized access is prevented even when normal operation has been disrupted. In contrast, under a fail-operational strategy, essential functions are maintained under degraded or isolated operating conditions [60,66].
For agricultural production systems, fail-operational or degraded-mode operation may be required when biological survival or environmental stability depends on uninterrupted control. In greenhouse production, local ventilation and essential climate-control functions may need to be maintained when cloud connectivity or remote supervisory functions are unavailable [67]. In livestock facilities, ventilation and thermal regulation should not be indiscriminately terminated because prolonged interruption may directly affect animal welfare and production performance [68]. Therefore, operational fallback strategies should be selected according to the biological criticality, environmental sensitivity, and cyber-physical consequence profile of the corresponding agricultural sub-sector (Table 6).
Overall, a secure smart farming network architecture should be designed to reduce unnecessary connectivity, control data and command flows, protect external access points, and maintain essential farm operations during disruptions. These architectural considerations provide a practical foundation for reducing cybersecurity exposure in interconnected smart farming environments [14,15,54,55,56,57,58,59,60,61,62]. The integrated framework highlights the need to protect not only digital assets and data flows but also the reliability and continuity of physical agricultural operations (Figure 2 and Table 7).

6. Discussion, Limitations, and Future Research

The reviewed literature indicates that cybersecurity in smart farming should be considered a system-level cyber-physical requirement rather than an isolated information-security function. Vulnerabilities originating from sensing, communication, gateway, software, cloud, and control layers may be propagated across interconnected system components and may ultimately result in disturbances to physical agricultural operations. Accordingly, coordinated security mechanisms, including network segmentation, access control, continuous monitoring, secure software integration, operational resilience, and local control continuity, are required to mitigate system-wide cyber-physical risks. In this review, component-level vulnerabilities, cyber-physical consequences, threat-modeling approaches, and architecture-level security principles were integrated within an agriculture-specific operational context.
Several practical limitations should be considered when the proposed security principles are applied to operational smart-farming environments. Deployment may be constrained by implementation costs, limited cybersecurity expertise, resource-constrained farm infrastructure, and the continued use of legacy devices that do not support modern security functions. Human factors, including configuration errors, credential management, and insufficient security awareness, may further affect system reliability. In addition, measurable resilience indicators and standardized evaluation criteria for agricultural cyber-physical systems remain insufficiently established. Future studies should therefore focus on cost-effective security mechanisms, legacy-system integration, human-centered security practices, quantitative resilience metrics, and validation through realistic agricultural testbeds that reproduce operational sensing, communication, control, and actuation conditions.
The evolution of smart farming toward 6G-enabled aerial–terrestrial communication environments is expected to increase the use of UAVs, aerial intelligent reflecting surfaces, and high-throughput edge connectivity. In such environments, highly dynamic three-dimensional mobility and time-varying channel conditions may limit the effectiveness of security mechanisms based solely on static segmentation or fixed gateway policies. Recent studies on UAV-enabled integrated sensing and communication and aerial intelligent reflecting surface-assisted MIMO systems have demonstrated the increasing importance of dynamic channel modeling, mobility-aware resource allocation, and adaptive optimization in next-generation wireless systems [69,70]. Accordingly, the security principles proposed in this review should be extended toward dynamically reconfigurable and context-aware mechanisms incorporating adaptive access control, communication-path validation, and channel-aware security optimization. These principles should therefore be regarded as scalable architectural foundations for emerging three-dimensional agricultural communication systems rather than as fixed network configurations.

7. Conclusions

Smart farming is increasingly operated as an interconnected cyber-physical system in which sensing, communication, software, cloud, control, and actuation processes are closely coupled. Consequently, cybersecurity incidents may be propagated beyond information assets and may ultimately affect physical agricultural operations, including irrigation, ventilation, thermal regulation, nutrient delivery, and livestock management. In this review, component-level vulnerabilities, cyber-physical attack propagation, gateway-related threats, software-integration risks, and architecture-level security principles were examined within an agriculture-specific operational context. The proposed security principles were further aligned with established OT-security frameworks to support their practical interpretation and application.
Secure smart-farming architectures should therefore be designed by considering not only confidentiality, integrity, and availability but also operational continuity, biological criticality, and physical production consequences. Network segmentation, access control, continuous monitoring, secure software integration, and appropriately differentiated fail-safe, fail-secure, and fail-operational strategies should be implemented according to the characteristics of individual agricultural production systems. Further validation through realistic agricultural testbeds and adaptation to emerging aerial–terrestrial and dynamically connected environments will be required to strengthen the scalability and operational applicability of smart-farming cybersecurity architectures.

Author Contributions

Conceptualization, H.J.Y., S.K. and C.H.P.; methodology, S.K. and C.H.P.; validation, H.J.Y., S.K. and C.H.P.; formal analysis, S.K. and C.H.P.; investigation, S.K. and C.H.P.; resources, K.J.L., T.-S.K., Y.-S.W., M.-H.J., S.H., J.E.K., H.J.N. and H.J.Y.; data curation, S.K. and C.H.P.; writing—original draft preparation, S.K. and C.H.P.; writing—review and editing, H.J.Y., S.K. and C.H.P.; visualization, S.K. and C.H.P.; supervision, H.J.Y.; project administration, H.J.Y.; funding acquisition, H.J.Y. All authors have read and agreed to the published version of the manuscript.

Funding

This work was supported by a grant from the Honam National Institute of Biological Resources (HNIBR), funded by the Ministry of Climate, Energy and Environment (MCEE) of the Republic of Korea (HNIBR2026-B-1-21).

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Raj, M.; Prahadeeswaran, M. Revolutionizing agriculture: A review of smart farming technologies for a sustainable future. Discov. Appl. Sci. 2025, 7, 937. [Google Scholar] [CrossRef] [Scilit]
  2. An, C.Y.; Kang, T.A.; Jeong, H.; Park, Y.J.; Lee, H.; Ryu, J.; Bae, H.; Song, C.; Park, J. Design and implementation of an integrated control system for smart agriculture in open-field food crops. J. Agric. Life Environ. Sci. 2025, 37, 219–234. [Google Scholar]
  3. Happy, K.; Gang, R.; Ban, Y.; Yang, S.; Rahmat, E.; Okello, D.; Komakech, R.; Cyrus, O.; David, K.O.; Kang, Y. Agricultural sustainability through smart farming systems: A comparative analysis between the Republic of Korea and Republic of Uganda. J. Plant Biotechnol. 2024, 51, 167–201. [Google Scholar] [CrossRef] [Scilit]
  4. Ayaz, M.; Ammad-Uddin, M.; Sharif, Z.; Mansour, A.; Aggoune, E.H.M. Internet-of-Things (IoT)-based smart agriculture: Toward making the fields talk. IEEE Access 2019, 7, 129551–129583. [Google Scholar] [CrossRef] [Scilit]
  5. Manono, B.O. Smart farming for small farms: Technologies, challenges, and opportunities for small-scale producers. Green 2026, 1, 3. [Google Scholar] [CrossRef] [Scilit]
  6. Javaid, M.; Haleem, A.; Singh, R.P.; Suman, R. Enhancing smart farming through the applications of Agriculture 4.0 technologies. Int. J. Intell. Netw. 2022, 3, 150–164. [Google Scholar] [CrossRef] [Scilit]
  7. Paul, K.; Chatterjee, S.S.; Pai, P.; Varshney, A.; Juikar, S.; Prasad, V.; Bhadra, B.; Dasgupta, S. Viable smart sensors and their application in data driven agriculture. Comput. Electron. Agric. 2022, 198, 107096. [Google Scholar] [CrossRef] [Scilit]
  8. Naidoo, N.; Munga, N. Cyber Security in Smart Agriculture Technology. Snode Technologies. Available online: https://www.snode.com/resources/snode-agri-tech-white-paper.pdf (accessed on 15 June 2024).
  9. Arabi, Z.; Oskouei, R.R.; Hosseinzadeh, M. Enhancing security in IoT networks: A multifaceted approach to vulnerability analysis and protection. Array 2025, 29, 100626. [Google Scholar] [CrossRef] [Scilit]
  10. Raza, S.; Faheem, M.; Guenes, M. Industrial wireless sensor and actuator networks in Industry 4.0: Exploring requirements, protocols, and challenges—A MAC survey. Int. J. Commun. Syst. 2019, 32, e4074. [Google Scholar] [CrossRef] [Scilit]
  11. Vatistas, C.; Avgoustaki, D.D.; Bartzanas, T. A systematic literature review on controlled-environment agriculture: How vertical farms and greenhouses can influence the sustainability and footprint of urban microclimate with local food production. Atmosphere 2022, 13, 1258. [Google Scholar] [CrossRef] [Scilit]
  12. Assimakopoulos, F.; Vassilakis, C.; Margaris, D.; Kotis, K.; Spiliotopoulos, D. AI and related technologies in the fields of smart agriculture: A review. Information 2025, 16, 100. [Google Scholar] [CrossRef] [Scilit]
  13. BustamanteV, D.; Sánchez, L.E.; Rosado, D.G.; Santos-Olmo, A.; Fernández-Medina, E. Towards a sustainable cybersecurity framework for Agriculture 4.0 based on a systematic analysis of proposals. Comput. Secur. 2025, 159, 104650. [Google Scholar] [CrossRef] [Scilit]
  14. Vangala, A.; Das, A.K.; Chamola, V.; Korotaev, V.; Rodrigues, J.J. Security in IoT-enabled smart agriculture: Architecture, security solutions and challenges. Clust. Comput. 2023, 26, 879–902. [Google Scholar] [CrossRef] [Scilit]
  15. Rouzbahani, H.M.; Karimipour, H.; Fraser, E.; Dehghantanha, A.; Duncan, E.; Green, A.; Russell, C. Communication layer security in smart farming: A survey on wireless technologies. arXiv 2022, arXiv:2203.06013. [Google Scholar]
  16. Mondal, A.M.; Rehena, Z. IoT based intelligent agriculture field monitoring system. In Proceedings of the 2018 8th International Conference on Cloud Computing, Data Science & Engineering (Confluence), Noida, India, 11–12 January 2018; pp. 625–629. [Google Scholar]
  17. Rehman, A.; Saba, T.; Kashif, M.; Fati, S.M.; Bahaj, S.A.; Chaudhry, H. A revisit of internet of things technologies for monitoring and control strategies in smart agriculture. Agronomy 2022, 12, 127. [Google Scholar] [CrossRef] [Scilit]
  18. Sreekantha, D.K.; Kavya, A.M. Agricultural crop monitoring using IOT—A study. In Proceedings of the 2017 11th International Conference on Intelligent Systems and Control (ISCO), Coimbatore, India, 5–6 January 2017; pp. 134–139. [Google Scholar]
  19. Roy, M.; Medhekar, A. Transforming smart farming for sustainability through agri-tech innovations: Insights from the Australian agricultural landscape. Farming Syst. 2025, 3, 100165. [Google Scholar] [CrossRef] [Scilit]
  20. Ouafiq, E.M.; Saadane, R.; Chehri, A.; Jeon, S. AI-based modeling and data-driven evaluation for smart farming-oriented big data architecture using IoT with energy harvesting capabilities. Sustain. Energy Technol. Assess. 2022, 52, 102093. [Google Scholar] [CrossRef] [Scilit]
  21. Dayoub, M.; Shnaigat, S.; Tarawneh, R.A.; Al-Yacoub, A.N.; Al-Barakeh, F.; Al-Najjar, K. Enhancing animal production through smart agriculture: Possibilities, hurdles, resolutions, and advantages. Ruminants 2024, 4, 22–46. [Google Scholar] [CrossRef] [Scilit]
  22. Bhaskar, G.; Srikant, S.V. Smart farming in agriculture. Int. J. Latest Technol. Eng. Manag. Appl. Sci. 2025, 14, 415–427. [Google Scholar] [CrossRef] [Scilit]
  23. Liu, K.; Selivanov, A.; Fridman, E. Survey on time-delay approach to networked control. Annu. Rev. Control 2019, 48, 57–79. [Google Scholar] [CrossRef] [Scilit]
  24. Padhan, S.; Turuk, A.K. Design of false data injection attacks in cyber-physical systems. Inf. Sci. 2022, 608, 825–843. [Google Scholar] [CrossRef] [Scilit]
  25. Górski, T. The 1+5 Architectural Views Model in Designing Blockchain and IT System Integration Solutions. Symmetry 2021, 13, 2000. [Google Scholar] [CrossRef] [Scilit]
  26. Chourlias, A.; Violos, J.; Leivadeas, A. Virtual sensors for smart farming: An IoT- and AI-enabled approach. Internet Things 2025, 32, 101611. [Google Scholar] [CrossRef] [Scilit]
  27. Soussi, A.; Zero, E.; Sacile, R.; Trinchero, D.; Fossa, M. Smart sensors and smart data for precision agriculture: A review. Sensors 2024, 24, 2647. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  28. Shen, Y.; Yang, F.; Wu, J.; Shuai, L.; Zohaib, K.; Lanke, Z.; Liu, H. Advances and future trends in electrified agricultural machinery for sustainable agriculture. Agriculture 2025, 15, 2367. [Google Scholar] [CrossRef] [Scilit]
  29. Beniwal, G.; Singhrova, A. A systematic literature review on IoT gateways. J. King Saud Univ. Comput. Inf. Sci. 2022, 34, 9541–9563. [Google Scholar] [CrossRef] [Scilit]
  30. Mahlous, A.R. Security analysis in smart agriculture: Insights from a cyber-physical system application. Comput. Mater. Contin. 2024, 79, 4781–4803. [Google Scholar] [CrossRef] [Scilit]
  31. Zanella, A.R.A.; da Silva, E.; Albini, L.C.P. Security challenges to smart agriculture: Current state, key issues, and future directions. Array 2020, 8, 100048. [Google Scholar] [CrossRef] [Scilit]
  32. Shaaban, A.M.; Chlup, S.; El-Araby, N.; Schmittner, C. Towards optimized security attributes for IoT devices in smart agriculture based on the IEC 62443 security standard. Appl. Sci. 2022, 12, 5653. [Google Scholar] [CrossRef] [Scilit]
  33. Chicaiza, K.; Paredes, R.X.; Sarzosa, I.M.; Yoo, S.G.; Zang, N. Smart farming technologies: A methodological overview and analysis. IEEE Access 2024, 12, 164922–164941. [Google Scholar] [CrossRef] [Scilit]
  34. Rossi, S.; Gemma, S.; Borghini, F.; Perini, M.; Butini, S.; Carullo, G.; Campiani, G. Agri-food traceability today: Advancing innovation towards efficiency, sustainability, ethical sourcing, and safety in food supply chains. Trends Food Sci. Technol. 2025, 163, 105154. [Google Scholar] [CrossRef] [Scilit]
  35. Dineva, K.; Atanasova, T. Cloud data-driven intelligent monitoring system for interactive smart farming. Sensors 2022, 22, 6566. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  36. Melzer, M.; Bellingrath-Kimura, S.; Gandorfer, M. Commercial farm management information systems—A demand-oriented analysis of functions in practical use. Smart Agric. Technol. 2023, 4, 100203. [Google Scholar] [CrossRef] [Scilit]
  37. Chergui, N.; Kechadi, M.T. Data analytics for crop management: A big data view. J. Big Data 2022, 9, 123. [Google Scholar] [CrossRef] [Scilit]
  38. Dhal, S.B.; Kar, D. Transforming agricultural productivity with AI-driven forecasting: Innovations in food security and supply chain optimization. Forecasting 2024, 6, 925–951. [Google Scholar] [CrossRef] [Scilit]
  39. Rangineni, S.; Bhanushali, A.; Suryadevara, M.; Venkata, S.; Peddireddy, K. A review on enhancing data quality for optimal data analytics performance. Int. J. Comput. Sci. Eng. 2023, 11, 51–58. [Google Scholar] [CrossRef] [Scilit]
  40. Osman, M.J.; Idris, H.; Majid, Z.; Mohd Salleh, M.R.; Ismail, Z. Assessment of farmer characteristics and design preferences on location-based pest and disease reporting service for digital agriculture: A preliminary analysis. IOP Conf. Ser. Earth Environ. Sci. 2023, 1274, 012006. [Google Scholar] [CrossRef] [Scilit]
  41. Ramesh, S.; Karmukilan, N.; Lavanya, R.; Muvinkumar, M.; Samuthra, P. IOT based smart AI plant irrigation system. Int. J. Eng. Res. Technol. 2025, 13. [Google Scholar] [CrossRef]
  42. Eyasin, M.S.H.; Sobhani, M.E.; Nasrin, S.; Al Rafi, A.S.; Islam, A.M. CropSynergy: Harnessing IoT solutions for smart and efficient crop management. Crop Des. 2026, 5, 100127. [Google Scholar] [CrossRef] [Scilit]
  43. Sullivan, C.S.; Gemtou, M.; Anastasiou, E.; Fountas, S. Building trust: A systematic review of the drivers and barriers of agricultural data sharing. Smart Agric. Technol. 2024, 8, 100477. [Google Scholar] [CrossRef] [Scilit]
  44. Dembani, R.; Karvelas, I.; Akbar, N.A.; Rizou, S.; Tegolo, D.; Fountas, S. Agricultural data privacy and federated learning: A review of challenges and opportunities. Comput. Electron. Agric. 2025, 232, 110048. [Google Scholar] [CrossRef] [Scilit]
  45. Kim, D.; Won, J.; Park, H.; Choi, J.G.; Park, S.; Lee, G. Toward the 3rd generation of smart farming: Materials, devices, and systems for E-plant technologies. Adv. Funct. Mater. 2026, 36, e12264. [Google Scholar] [CrossRef] [Scilit]
  46. Liang, S.; Liu, P.; Zhang, Z.; Wu, Y. Research on fault diagnosis of agricultural IoT sensors based on improved dung beetle optimization–support vector machine. Sustainability 2024, 16, 10001. [Google Scholar] [CrossRef] [Scilit]
  47. Tür, M.R. Solution methods and recommendations for power quality analysis in power systems. J. Eng. Technol. 2018, 2, 1–9. [Google Scholar]
  48. Nawaz, M.; Babar, M.I.K. IoT and AI for smart agriculture in resource-constrained environments: Challenges, opportunities and solutions. Discov. Internet Things 2025, 5, 24. [Google Scholar] [CrossRef] [Scilit]
  49. Waseem, M.; Batool, H.; Ur Rehman, T.; Majeed, Y.; Ahmad, F.; Habib Syed, H.; Nadeem, T. Transforming agriculture with cyber-physical systems: An insight into future smart farming. Preprints 2026, 2026061181. [Google Scholar]
  50. Subeesh, A.; Chauhan, N. Agricultural digital twin for smart farming: A review. Green Technol. Sustain. 2026, 4, 100299. [Google Scholar] [CrossRef] [Scilit]
  51. Pasca, E.M.; Delinschi, D.; Erdei, R.; Baraian, I.; Matei, O.D. A vulnerable-by-design IoT sensor framework for cybersecurity in smart agriculture. Agriculture 2025, 15, 1253. [Google Scholar] [CrossRef] [Scilit]
  52. Barnes-Thornton, S.; Gardiner, J.; Rashid, A. The Internet of Insecure Cows—A Security Analysis of Wireless Smart Devices Used for Dairy Farming. In Proceedings of the 5th Workshop on CPS and IoT Security and Privacy (CPSIoTSec 2023); Association for Computing Machinery: New York, NY, USA, 2023; pp. 67–73. [Google Scholar] [CrossRef] [Scilit]
  53. Carvalho, L.; Adão, T.; Morais, R.; Costa, A.R.; Peres, E. Conventional and Zero Trust security measures for precision agriculture devices: The mySense’s VineInspector case-study. Procedia Comput. Sci. 2025, 256, 246–254. [Google Scholar] [CrossRef] [Scilit]
  54. Vakhnovskyi, A. Threat modeling and attack surface analysis of IoT-enabled controlled environment agriculture systems. arXiv 2026, arXiv:2604.13308. [Google Scholar]
  55. Singh, N.; Buyya, R.; Kim, H. Securing cloud-based Internet of Things: Challenges and mitigations. Sensors 2025, 25, 79. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  56. Cybersecurity and Infrastructure Security Agency. Configuring and Managing Remote Access for Industrial Control Systems. Available online: https://www.cisa.gov/sites/default/files/2023-01/RP_Managing_Remote_Access_S508NC.pdf (accessed on 11 July 2026).
  57. National Institute of Standards and Technology. Least Privilege. Available online: https://csrc.nist.gov/glossary/term/least_privilege (accessed on 11 July 2026).
  58. Cybersecurity and Infrastructure Security Agency. Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators. Available online: https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators (accessed on 11 July 2026).
  59. Kent, K.; Souppaya, M. Guide to Computer Security Log Management; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2006. Available online: https://nvlpubs.nist.gov/nistpubs/legacy/SP/nistspecialpublication800-92.pdf (accessed on 11 July 2026).
  60. Stouffer, K.; Pease, M.; Tang, C.; Zimmerman, T.; Pillitteri, V.; Lightman, S.; Hahn, A.; Saravia, S.; Sherule, A.; Thompson, M. Guide to Operational Technology (OT) Security; NIST Special Publication 800-82 Rev. 3; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2023. [Google Scholar]
  61. Cybersecurity and Infrastructure Security Agency. Primary Mitigations to Reduce Cyber Threats to Operational Technology. Available online: https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology (accessed on 11 July 2026).
  62. Cybersecurity and Infrastructure Security Agency. StopRansomware Guide. Available online: https://www.cisa.gov/stopransomware/ransomware-guide (accessed on 11 July 2026).
  63. Pascoe, C.; Quinn, S.; Scarfone, K. The NIST Cybersecurity Framework (CSF) 2.0; NIST Cybersecurity White Paper 29; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef] [Scilit]
  64. IEC 62443-3-2:2020; Security for Industrial Automation and Control Systems—Part 3-2: Security Risk Assessment for System Design. IEC: Geneva, Switzerland, 2020.
  65. IEC 62443-3-3:2013; Industrial Communication Networks—Network and System Security—Part 3-3: System Security Requirements and Security Levels. IEC: Geneva, Switzerland, 2013.
  66. Knowles, W.; Prince, D.; Hutchison, D.; Disso, J.F.P.; Jones, K. A survey of cyber security management in industrial control systems. Int. J. Crit. Infrastruct. Prot. 2015, 9, 52–80. [Google Scholar] [CrossRef] [Scilit]
  67. Bournet, P.-E.; Boulard, T. Effect of ventilator configuration on the distributed climate of greenhouses: A review of experimental and CFD studies. Comput. Electron. Agric. 2010, 74, 195–217. [Google Scholar] [CrossRef] [Scilit]
  68. Su, M.; Aerts, J.-M.; Norton, T. A review of current research and development for mechanical ventilation systems in poultry houses. Energy Build. 2025, 353, 116903. [Google Scholar] [CrossRef] [Scilit]
  69. Ma, Z.; Liang, Y.; Zhu, Q.; Zheng, J.; Lian, Z.; Zeng, L.; Fu, C.; Peng, Y.; Ai, B. Hybrid-RIS-Assisted Cellular ISAC Networks for UAV-Enabled Low-Altitude Economy via Deep Reinforcement Learning with Mixture-of-Experts. IEEE Trans. Cogn. Commun. Netw. 2026, 12, 3875–3888. [Google Scholar] [CrossRef] [Scilit]
  70. Ma, Z.; Lu, S.; Peng, Y.; Zhou, J.; Xu, J.; Luo, G.; Luo, M. Geometrical-Based Modeling for Aerial Intelligent Reflecting Surface-Based MIMO Channels. Electronics 2026, 15, 875. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Schematic overview of main components of a smart farming system and data and control flows among sensors, gateways, control systems, data platforms, cloud infrastructure, user interfaces, and physical farm equipment.
Figure 1. Schematic overview of main components of a smart farming system and data and control flows among sensors, gateways, control systems, data platforms, cloud infrastructure, user interfaces, and physical farm equipment.
Electronics 15 04087 g001
Figure 2. Conceptual overview integrating core components and representative cybersecurity risks, secure architecture principles, and cyber-physical consequences and security goals in smart farming systems.
Figure 2. Conceptual overview integrating core components and representative cybersecurity risks, secure architecture principles, and cyber-physical consequences and security goals in smart farming systems.
Electronics 15 04087 g002
Table 1. Application of the 1+5 Architectural Views Model to Smart-Farming Software Architecture.
Table 1. Application of the 1+5 Architectural Views Model to Smart-Farming Software Architecture.
1+5 Architectural ViewSmart-Farming Interpretation
Integrated ProcessesMonitoring, decision-making, irrigation, ventilation, feeding workflows
Use CasesFarmer, operator, technician, cloud provider, equipment vendor
LogicalAnalytics services, control services, databases, IAM, message brokers
ContractsAPIs, message formats, authorization rules, timing and service requirements
Integrated ServicesGateway, MQTT/REST/OPC UA, cloud and third-party service integration
DeploymentSensors, controllers, gateways, edge servers, cloud platforms, mobile systems
Table 2. Threat Model for Agricultural Edge Gateways in Smart Farming Systems.
Table 2. Threat Model for Agricultural Edge Gateways in Smart Farming Systems.
Gateway Asset/InterfaceThreat Actor/Entry PointRepresentative ThreatSecurity ObjectiveAgricultural ConsequenceSecurity Control
Sensor–gateway linkExternal attacker/wireless interfaceSpoofing, FDI, replayIntegrity, authenticityIncorrect sensing and control decisionsMutual authentication, integrity verification, replay protection
Gateway firmwareRemote or supply-chain attacker/update mechanismFirmware tamperingIntegrityPersistent gateway compromiseSecure boot, signed firmware updates
Remote-management interfaceExternal attacker/remote serviceCredential attack, elevation of privilegeAuthentication, authorizationUnauthorized access to internal farm networksMFA, least privilege, restricted remote access
Gateway–controller linkCompromised gateway/control interfaceCommand injectionIntegrity, availabilityAbnormal actuator operationCommand validation, allowlisting, segmentation
Cloud/API interfaceExternal or third-party attacker/APIAPI abuse, token theftConfidentiality, integrityData leakage or remote-control misuseScoped credentials, access control, logging
Gateway serviceExternal attacker/network serviceDoSAvailabilityLoss of monitoring or control connectivityRate limiting, redundancy, local fallback
Table 3. Core Components, Main Functions, and Cybersecurity Risks of Smart Farming Systems.
Table 3. Core Components, Main Functions, and Cybersecurity Risks of Smart Farming Systems.
LayerComponentMain FunctionCybersecurity/Operational RiskReferences
Physical and Sensing LayerSensorCollects environmental and biological dataData errors, data manipulation, inaccurate decision-making[7,26,31]
Communication and Edge LayerCommunication networkTransmits data and control commandsData delay, packet loss, eavesdropping, interference, external access[8,15,27]
GatewayAggregates data and connects internal devices to external networksEntry point for intrusion, sensor data monitoring, command interference[9,29]
Control and Actuation LayerControl systemUses controllers and actuators to operate farm facilitiesIncorrect commands, actuator malfunction, unstable farm conditions[10,11,13,30,33,49]
Data and applicationData storage systemStores farm data, logs, records, and historical informationData leakage, loss of production know-how, exposure of farm records[13,30,43,44]
Data analytics systemInterprets collected data and supports decision-makingInaccurate outputs caused by poor-quality or erroneous data[37,38,39]
User interfaceAllows farmers to monitor system status and enter control commandsIncorrect settings, missed alerts, account misuse[40,41]
Cloud/platform infrastructureSupports data storage, analysis, remote access, and service integrationAccount compromise, API misuse, data leakage, service disruption[13,30,43,44]
Supporting infrastructurePower and physical infrastructureSupports continuous operation of smart farming devicesPower failure, equipment damage, data collection interruption, communication failure[45,46,47,48]
Cross-cutting security and governanceCybersecurity frameworkProtects interconnected system componentsSystem-wide security failure, reduced reliability of monitoring and control[13,20,30,49]
Table 4. Representative Cyber-Physical Attack Scenarios in Smart Farming Systems.
Table 4. Representative Cyber-Physical Attack Scenarios in Smart Farming Systems.
Agricultural DomainAttack ScenarioEvidence TypeCyber-Physical ConsequenceReference
GreenhouseDDoS combined with sensor fault/measurement maskingExperimental demonstrationCritical greenhouse temperature increase was masked, potentially delaying climate-control response[51]
LivestockFalse-data injection into wireless cow-monitoring sensorsPractical experimental demonstrationManipulated animal-health data and compromised monitoring reliability[52]
Open-field/precision agricultureSensor-reading manipulation and communication tampering in a precision-viticulture IoT devicePractical case study/representative attack scenarioCorrupted field data and potentially inappropriate management decisions[53]
Table 5. Alignment of smart-farming security principles with established cybersecurity frameworks and standards.
Table 5. Alignment of smart-farming security principles with established cybersecurity frameworks and standards.
Smart-Farming Security PrincipleNIST CSF 2.0/NIST SP 800-82IEC 62443Agriculture-Specific Interpretation
Network segmentation and security zoningProtect; OT network segmentationZones and conduitsSeparation of sensing, control, farm-management, guest, and cloud-connected networks
Data and command-flow mappingIdentify; ProtectControlled communication pathwaysIdentification of sensing, control, and actuator-command pathways
Gateway, wireless, and remote-access securityProtectIdentification and access-control requirementsRestriction of vendor, maintenance, and remote-control access
Cloud connectivity and access controlGovern; ProtectExternal communication and access-control requirementsManagement of farm–cloud connections, APIs, credentials, and privileges
Device inventory, logging, and monitoringIdentify; DetectAsset identification and security-event monitoringVisibility of heterogeneous agricultural IoT, edge, and control assets
Resilience and local operationRespond; RecoverAvailability and system-integrity requirementsContinuation of critical agricultural functions during external-service disruption
Table 6. Operational failure-response strategies for agricultural cyber-physical systems.
Table 6. Operational failure-response strategies for agricultural cyber-physical systems.
Operational StrategyPrimary ObjectiveRepresentative Agricultural Application
Fail-safeImmediate physical hazards are minimized by transition to a predefined stateNoncritical actuator operation is suspended when an unsafe operating condition is detected
Fail-secureUnauthorized access and control are prevented during system degradation or compromiseExternal remote access is blocked after a suspected gateway or account compromise
Fail-operationalEssential functions are maintained under isolated or degraded conditionsLocal ventilation, heating, irrigation, water supply, or nutrient delivery is maintained during cloud or network disruption
Table 7. Security Principles and Key Security Measures for Secure Smart Farming Network Architecture.
Table 7. Security Principles and Key Security Measures for Secure Smart Farming Network Architecture.
Security PrincipleSecurity ObjectiveKey Security MeasuresReferences
Network segmentation and security zoningPrevent indiscriminate connectivity among devices and systemsSeparate sensor networks, control networks, management networks, business networks, guest networks, cloud connection zones, and external maintenance zones[14,54]
Data and command flow mappingClarify how data and control commands move across the systemIdentify data sources, storage locations, access points, command pathways, and allowed or blocked communications[14,54]
Secure management of gateways, wireless networks, and remote accessProtect major connection points between internal farm systems and external networksSecure gateways, separate wireless networks by purpose, restrict remote access, apply authentication and access logging[9,15,29,56]
Cloud connectivity and access controlReduce risks associated with cloud-based IoT infrastructureLimit transmitted data, manage cloud accounts and APIs, apply least-privilege access control[42,55,57]
Device inventory, logging, and monitoringImprove visibility of connected assets and abnormal activitiesMaintain device inventories, record login attempts, remote access, control commands, device errors, and network connections[54,58,59]
Resilience and local fail-safe operationMaintain critical farm operations during connectivity or service disruptionsPrepare local control rules, manual procedures, backup data, equipment inspection, and recovery procedures[60,61,62]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Kong, S.; Park, C.H.; Lee, K.J.; Kim, T.-S.; Won, Y.-S.; Jo, M.-H.; Han, S.; Ko, J.E.; Nam, H.J.; Yeo, H.J. Smart Farming Cybersecurity: Key Risks and Security Principles. Electronics 2026, 15, 4087. https://doi.org/10.3390/electronics15184087

AMA Style

Kong S, Park CH, Lee KJ, Kim T-S, Won Y-S, Jo M-H, Han S, Ko JE, Nam HJ, Yeo HJ. Smart Farming Cybersecurity: Key Risks and Security Principles. Electronics. 2026; 15(18):4087. https://doi.org/10.3390/electronics15184087

Chicago/Turabian Style

Kong, Sunmi, Chang Ha Park, Kyung Jun Lee, Tae-Su Kim, Yeong-Seon Won, Min-Ho Jo, SongYi Han, Ju Eun Ko, Hyeon Ju Nam, and Hyeon Ji Yeo. 2026. "Smart Farming Cybersecurity: Key Risks and Security Principles" Electronics 15, no. 18: 4087. https://doi.org/10.3390/electronics15184087

APA Style

Kong, S., Park, C. H., Lee, K. J., Kim, T.-S., Won, Y.-S., Jo, M.-H., Han, S., Ko, J. E., Nam, H. J., & Yeo, H. J. (2026). Smart Farming Cybersecurity: Key Risks and Security Principles. Electronics, 15(18), 4087. https://doi.org/10.3390/electronics15184087

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop