Menu

Call us on 03450 21 21 51

What does effective cybersecurity in the retail sector look like?
The SRM Blog

What does effective cybersecurity in the retail sector look like?

Claire Greathead

Written by Claire Greathead

31st May 2023

Share this article

cybersecurity in retail

Retail businesses have a unique set of cyberthreats that they must plan for

In the past two decades, the way we use technology has changed exponentially, and one of the industries most impacted by these changes is retail. From cash to card to contactless, and from high streets to online shopping, the way we carry out retail transactions has changed substantially.

Because of this, retail organisations are constantly on the receiving end of cybersecurity incidents. Attackers are no longer simply focusing on card data; instead they are incentivised to target the large volumes of sensitive personal data added to retailer systems when customers buy online.

An increase in retail cyber threats mean it’s more important than ever for retailers to keep ahead of hackers and cyber criminals, even if they are working towards PCI DSS best practice.

Human error and ransomware

According to figures from the British Retail Consortium (BRC), 36% of retailers cite human error as the leading cause of cyberthreat. Retail workers are constantly handling customer data, putting through numerous transactions a day, so it’s no surprise that mistakes are made which cybercriminals then profit from.

65% of retailers listed malware as the leading threat against their data. What’s more, while 55% of retailers have experienced a cyberattack, only a third prioritise multi-factor authentication (MFA) in their transactions. Of these, only 8% use MFA in their onsite premises.

Retail cybersecurity in numbers

The numbers from BRC highlight the severity of cybercrime as an issue in the retail sector, as less than half of retailers (46%) feel confident that they know where their data is stored. And while 33% of retailers have experienced a breach in the last twelve months, only 48% have a formal ransomware plan in place.

Alongside human error, retailers find themselves at risk of software vulnerabilities, third-party risks, lack of encryption and insider threats. Simple oversights like weak passwords can increase vulnerability in retail businesses, both online and in store.

Phishing is another common cause of cybercrime in retail businesses. In fact, Deloitte reports that 91% of all cyberattacks begin with a phishing email.

The rise of online shopping

Our increased reliance on technology – and the lockdowns implemented during the COVID-19 pandemic – have made online shopping the go-to for many customers. In fact, 2022 saw almost 60 million e-commerce transactions in the UK alone.

But while convenient, online shopping isn’t without its risks. Customers who shop on unprotected websites put their data at risk, sharing sensitive information on a platform that can all too easily be compromised by hackers.

Retailers must treat their online security like their physical one, taking the necessary steps to prevent a theft from taking place. The retail industry depends on high value constantly available systems that look attractive to hackers. Awareness of changing risks can help retailers stay ahead of the threat and keep their data safe.

Retail cybersecurity best practices

Knowledge is power when it comes to cybersecurity. Retailers must assess their risk both instore and online in order to educate themselves about where their data is held and where the risk level falls.

Ensuring data is sufficiently protected and encrypted is essential – not least because under UK GDPR, organisations may be fined up to 4% of their annual global turnover or €20 million (whichever is greater) for severe violations. Beyond the threat of fines, rigorous data protection is critical to building consumer trust.

Businesses are also required to adhere to guidelines like PCI DSS, designed to protect customers’ payment card information and prevent a cybercrime from taking place. Following the principles set out in these frameworks can help retailers make sure they’re doing all they can.

With human error being such a common cause of retail cybercrime, cybersecurity training across all staff is essential. Create and maintain a cybersecurity awareness program for all employees so they can confidently navigate risks and spot the signs of a phishing attempt.

Make effective cybersecurity a key part of your retail business to protect your data and keep customers onside. Get in touch with the SRM team to find out how we can help you bolster your business defences and give you the peace of mind you’re looking for.