← SecureAZ Blog

Security Awareness · 6 min read · Published 21 July 2026 · Reviewed 17 August 2026

Ransomware Stopped Coca-Cola Making Milk. Could It Stop Your NZ Business Making Anything?

A ransomware attack forced Coca-Cola to suspend all US Fairlife production and file an SEC disclosure. For NZ manufacturers and food producers, the lesson is not about Coca-Cola.

Coca-Cola this week disclosed to the US Securities and Exchange Commission that a ransomware attack had forced the company to suspend all US Fairlife production operations while it investigated a potential data breach. Fairlife — Coca-Cola's premium dairy brand generating over four billion dollars in annual revenue — was offline.

This is not a story about Coca-Cola. Large enterprises get attacked, have incident response teams, and recover. The story is about what ransomware does to operations, and what that means for NZ businesses that cannot absorb a week of production downtime the way a multinational can.

What Ransomware Does to a Manufacturing Business

Most public discussion of ransomware focuses on data encryption and ransom payment. For manufacturing and food production businesses, the more immediate consequence is operational. Modern production facilities run on interconnected systems — SCADA, ERP, inventory management, logistics coordination, quality control. When ransomware deploys across those systems, production does not slow down. It stops.

The Fairlife incident is not the first time ransomware has halted food production. JBS, the world's largest meat processor, paid 11 million dollars in ransom in 2021 after an attack shut down plants across the US and Australia. Dole suspended North American operations for days following a ransomware attack in 2023. In each case, the financial impact of the production stoppage dwarfed the ransom itself.

For a NZ food producer or manufacturer operating on tighter margins, a week of halted production is not an inconvenience. It can be an existential event.

The SEC Disclosure Angle

The fact that Coca-Cola filed an SEC disclosure is significant beyond the Fairlife production suspension. The US SEC's cyber incident disclosure rules — introduced in 2023 — require publicly listed companies to disclose material cybersecurity incidents within four business days of determining the incident is material.

NZ does not currently have an equivalent mandatory disclosure regime for listed companies, though the Cyber Security Resilience Bill proposes to change this for critical infrastructure operators. But the SEC disclosure model is increasingly the global standard, and NZ businesses with US operations, US investors, or US supply chain relationships are likely to encounter it.

The reputational and legal consequences of a ransomware attack are no longer limited to the direct impact. Disclosure obligations, customer notification requirements under the Privacy Act 2020, and supply chain disruption for customers depending on your output all compound the direct cost.

Why NZ Manufacturing and Food Production Is a Target

NZ's food and manufacturing sectors may not look like high-value ransomware targets compared to hospitals or financial institutions. They are increasingly targeted for two reasons.

First, operational technology (OT) environments — the industrial control systems running production equipment — have become connected to IT networks over the past decade in ways that create attack paths. A phishing email to an office worker can, in a poorly segmented network, provide a path to the SCADA systems controlling production.

Second, production stoppage creates pressure to pay. A company that cannot pay its staff or fulfil orders without restarting systems faces a fundamentally different calculus than one where the ransomware impact is contained to office productivity. Ransomware groups understand this and target operational businesses accordingly.

The Recovery-First Mindset

The IT Brief NZ reporting on the AI-ransomware trend this week specifically called out a shift in how leading security teams are thinking: from prevention-first to recovery-first. Prevention remains essential — you want to stop attacks before they succeed. But the security posture of a resilient business assumes that prevention will sometimes fail and asks: if ransomware deploys at 2am on a Friday, what is the recovery timeline?

The answers to that question determine the actual business impact of an attack:

  • Are backups stored offline and tested? Or are they connected to the same network the ransomware encrypted?
  • Is there a documented recovery procedure or will staff be improvising under pressure?
  • How long does it take to restore production systems specifically — not just office IT?
  • Who makes decisions about ransom payment if that becomes the only path to recovery in time?

See our guide to the first 24 hours of a ransomware attack for the specific steps that determine whether an attack becomes a recoverable incident or a business-ending event.

What NZ Manufacturers and Food Producers Should Do

  1. Audit the connection between your OT and IT environments. If there is no network segmentation between your production systems and your office network, a compromise of an office computer can reach your production systems. Fix this.
  1. Test your backups specifically against a ransomware scenario. That means offline or immutable backups that ransomware cannot encrypt, and a tested restore process with a documented recovery time.
  1. Train staff who work in production environments. Phishing is the most common initial access vector. Production staff are not immune to phishing and may not receive the same security awareness training as office staff. They should.
  1. Document a ransomware response plan. When production is stopped and the clock is running, you need a decision tree, not a committee. Who declares the incident? Who engages external IR support? Who authorises ransom payment consideration? Who communicates with customers and suppliers?

The Coca-Cola disclosure will not be the last ransomware incident affecting the food and manufacturing sector in 2026. The question is whether the next NZ business in that position has prepared.

Build security awareness across your entire workforce with SecureAZ

Sources & references