Why Medium-Sized Companies Should Strategically Embed Information Security
The digital transformation of the food industry is advancing at a rapid pace. Production facilities are becoming increasingly interconnected, supply chains are digitally managed, and operational processes are ever more automated. While these developments enhance efficiency and transparency, they also expand the attack surface for cybercriminals.
The dairy industry in particular has experienced firsthand in recent years the impact of successful cyberattacks. Production outages, supply chain disruptions, and significant financial losses are no longer abstract risks but real threats to business continuity and operational stability.
Against this backdrop, Hohenloher Molkerei eG made a conscious decision to view information security not merely as an IT responsibility, but as a strategic issue for the future of the company.
Acting Early Instead of Reacting Too Late
A key driver behind this decision was the European NIS2 Directive, which introduces significantly stricter requirements for cyber risk management across many organizations.
Although at the start of the project the dairy cooperative was still operating just below the threshold for critical infrastructure classification, the company deliberately chose to establish the necessary organizational and technical foundations at an early stage.
The objective was clearly defined: not to react only when regulatory pressure emerged, but to proactively strengthen resilience and actively shape the company’s future rather than being driven by external requirements.
This highlights an important lesson for the entire industry. Cyber resilience does not begin when regulations take effect or security incidents occur. Successful organizations start early by identifying critical processes, defining responsibilities, and systematically building effective security structures.
Tailored Security Structures for Medium-Sized Businesses
Together with the team from TÜV TRUST IT GmbH, a member of TÜV AUSTRIA Group, Hohenloher Molkerei developed a security framework tailored specifically to the company’s size and the unique requirements of the food industry.
The project focused on establishing a structured Information Security Management System (ISMS) alongside a Business Continuity Management (BCM) framework.
The approach was deliberately pragmatic: rather than implementing oversized compliance structures, the goal was to create an economically viable solution aligned with the organization’s actual risks and requirements.
Over several project phases, the existing security posture was assessed, critical business processes were identified, and clear responsibilities for information security were defined. Step by step, a robust security framework emerged that not only addresses future regulatory requirements but also strengthens the dairy’s operational resilience over the long term.
This approach serves as a practical example for medium-sized businesses. Information security must fit the organization. What matters most is not the maximum number of security measures, but rather achieving the right balance between risk, effort, and business value.
Strong Support from Executive Management
The success of the project is largely attributable to the strong commitment and support of the company’s executive leadership.
For Martin Boschet, information security is a strategic business decision:
“Information security is a key issue for our future. That is why we consciously decided to establish the right structures at an early stage. With this project, we have chosen the right path and found exactly the support we need in our partner.”
According to Boschet, the collaboration has been characterized by trust, pragmatism, and a clear understanding of the company’s requirements.
Arnd Wollinger, Authorized Officer and Commercial Director of Hohenloher Molkerei, also plays a key operational role in driving the project forward.
For other companies in the food industry, the project offers an important insight: cyber resilience is not solely the responsibility of the IT department. Sustainable security structures can only be achieved when management, business units, and external specialists work together toward a common goal.
This experience is also reflected in the statement from Axel Amelung, Head of Sales at TÜV TRUST IT:
“Our collaboration with Hohenloher Molkerei demonstrates how successfully information security can be implemented when management, business departments, and partners work closely together. The company’s pragmatic approach and clear strategic commitment to greater cyber resilience are key success factors.”
Setting an Example for the Dairy Industry
With this initiative, Hohenloher Molkerei is already sending a strong signal to the entire dairy sector. While many organizations are only beginning to address topics such as cyber resilience and business continuity, the necessary foundations have been established here at an early stage.
The experience gained from this project clearly demonstrates that medium-sized companies can prepare for increasing cyber risks in a structured and economically sustainable manner.
The key lies in an approach that addresses regulatory requirements while remaining aligned with the size, organizational structure, and operational reality of the business.
Hohenloher Molkerei embarked on this journey at the right time and is setting a powerful example for the industry. After all, cyber resilience does not begin with a legal obligation, but with the strategic decision to take responsibility for the organization’s long-term future and viability.