Skip to content
Guide·Business continuity·3 min

Food industry: what really stops when IT goes down

On a production site, an IT failure does more than get in the way: it blocks shipping, traceability and sometimes the line itself. Here is how to prioritise.

The essentials in 30 seconds

In the food industry, not all applications are equal when a failure hits. Traceability and labelling block shipping within minutes, weighing and supervision stop the line, office tools can wait. The method is to rank each system by the downtime it causes further down the chain, then give priority protection only to those whose stoppage costs the most per hour.

In the food industry, the question is not whether IT will fail, but what will stop with it. And the answer often surprises management: it is almost never email.

Rank by consequence, not by technology

SystemWhat stopsTime until it blocks
Traceability and labellingShipping: no label, no pallet leavesA few minutes
Weighing and quality controlRecording of checks, and therefore batch complianceA few minutes
Line supervisionProduction itself on some linesImmediate
ERP and ordersPreparation for the next dayA few hours
Email and office toolsWorking comfortOne day

The network before the servers

On an industrial site, the failure rarely comes from the server. It comes from the path leading to it: a switch in a dusty technical room, an internal fibre damaged during building work, a power supply with no backup in a forgotten enclosure.

  • Critical network equipment must be on a UPS, just like the servers.
  • A multi-building site needs two physical paths between buildings, or must accept that a cut to one isolates the other.
  • Technical rooms in production areas are exposed to dust, humidity and washdowns. A sealed enclosure costs less than replacing a switch twice a year.

Separate production from everything else

A network where machine controllers, office workstations and guest Wi-Fi share the same space exposes production to any office IT incident.

Splitting the network into segments, with explicit rules between them, limits the damage: a compromised office workstation cannot see the supervision system. This work is carried out with the integrator of the production equipment, whose warranty constraints take precedence.

Measure recovery time, not the backup

Knowing that you have backups is not enough. The useful question is: how long does it take to bring traceability back into service from scratch?

That time is measured by doing it, once, outside production hours. Until it has been timed, it is an estimate, and estimates in this area are optimistic by a factor of three.

Frequently asked questions

Where do you start when securing continuity at a food production site?
With a list of systems ranked by how quickly their stoppage blocks shipping or production. This list is built with the shop floor managers. It then determines where to invest, and avoids giving priority protection to systems whose stoppage can be tolerated for a day.
Should the production network be separated from the office network?
Yes, as soon as production depends on connected equipment. Splitting into separate segments prevents an office incident, in particular a compromised workstation, from reaching the systems that control or trace production.
How do you know whether your backups will let you restart?
By carrying out a real restore, outside production, and timing how long it takes to bring the most critical application back into service. Until that test has taken place, the recovery time remains an assumption.

Next step

Assess my site's continuity

Published 6 September 2026 · Équipe Skill Group, Conseil & pilotage

Going further

Explainer·Internet & connectivity

When the internet goes down, who is actually responsible?

Three providers, three diagnoses, and a company at a standstill while they argue. This is not bad faith: it is a predictable consequence of splitting the work.

3 min·
Read the resource
Guide·Cybersecurity

Ransomware: what to do in the first hour

The decisions taken in the first sixty minutes largely determine how long the shutdown lasts. Here is the order of actions, and the three mistakes to avoid.

3 min·
Read the resource