Editor’s question: How to build long-term cyber resilience for retailers

Editor’s question: How to build long-term cyber resilience for retailers

The recent spate of cyberattacks targeting prominent UK retailers has starkly exposed critical vulnerabilities within the sector’s digital defences. From data breaches to operational disruptions, these incidents underscore a pressing need for a robust and proactive approach to cybersecurity.  

As retailers navigate an increasingly complex threat landscape, the challenge extends beyond simply patching immediate flaws. It demands a strategic shift towards building enduring resilience against ever-evolving cyber-risks. 

We gathered insights from three leading experts in cybersecurity and retail technology and put this pivotal question to them: ‘What strategies and protocols can retailers adopt to not only prevent future attacks but also build long-term resilience against evolving cyber-risks?’  


Spencer Young, SVP EMEA, Delinea:  

“The cyberattacks affecting major retailers, including M&S, Co-Op, and more recently Adidas and North Face, all in a very quick succession, is a concern for the whole retail industry. Seeing the long-lasting effect that M&S, who has only been able to partially resume online orders after six weeks, has experienced shows just how significant the disruption is and can be for any other retailer.  

Attackers are reminding us that IT infrastructure remains vulnerable, especially if businesses fail to assess cyber-risks and monitor access. Research shows that over two-thirds (69%) of organisations globally have fallen victim to ransomware, with 27% being hit more than once, showing for pervasive these attacks are. Despite fewer companies (57%) paying, bad actors remain incentivised to strike, with 60% of ransomware now featuring data theft-related extortion.  

Despite identity and credentials security growing in importance, there are still significant vulnerabilities that organisations need to address – particularly when it comes to remote access. In fact, with privileged credential misuse involved in 80% of breaches, securing identities has never been more critical. Static credentials in particular can be a serious liability in today’s fast-moving world. Passwords alone – especially unrotated ones – leave organisations vulnerable to phishing, credential stuffing and Pass-the-Hash attacks.  

 
While passwordless technologies like biometrics are gaining momentum, passwords aren’t disappearing – they’re simply becoming one of multiple defence layers. That’s why credential vaulting and automated password rotation are foundational to stopping lateral movement. By continuously rotating credentials and limiting their lifespan, organisations can invalidate stolen hashes and prevent attackers from moving freely within a network and abusing customer data.  

However, good password hygiene isn’t enough. Where passwords persist, robust Identity Security solutions must enforce frequent rotation, temporary keys and just-in-time access to stay ahead of threats. Strong protection starts with adopting a Zero Trust mindset and implementing Privileged Access Management (PAM) to control who can access sensitive systems, when and how. Helping organisations make “never trust, always verify” the reality is key – as safeguarding data begins with smarter, verified access. 
Organisations are becoming increasingly aware of the identity security threat and its importance to overall business resilience, with 78% of businesses expecting to increase their budgets in the next year. Businesses need to implement layered defences that include effective training and awareness programmes, risk-based patching, regular backups, app controls, anti-malware, network monitoring, and a regularly tested incident response plan. Comprehensive, centralised visibility and control over all employee and machine identities will help to lock the bad actors out and limit the harm they can do if they compromise your resources. 

By putting strong identity management practices in place, including multi-factor authentication, Zero Trust, and least-privilege principles, businesses will be better protected from cyberattacks like these and maintain consumer trust.” 


Xavier Sheikrojan, Senior Risk Intelligence Manager at Signifyd:  

“The recent wave of cyberattacks on major UK retailers, including Marks & Spencer, Co-Op and Harrods, is a stark warning to the ecommerce industry. Reports suggest M&S is expecting to lose £300 million in sales and see disruption until July, which is a reminder that the damage can go well beyond immediate financial loss. It can take months or even years to rebuild customer trust and operational stability. 

Retailers are prime targets because of the volume of identity and payment data, as well as other PII (Personally Identifiable Information) they hold. This data, which includes contact details, dates of birth, and other sensitive identifiers, is likely being sold to fraudsters who will use it to carry out phishing attacks and attempt fraud across other retailers for immediate fraud, but also to test the waters through account takeover, credential-stuffing attacks and sleeper accounts that mimic legitimate customers before being exploited at scale.  

This is not a risk limited to high-profile brands. Any ecommerce business holding customer data could be targeted. Monitoring for unusual behaviour among existing users is essential, along with strengthening authentication measures. Often, just one set of compromised credentials is enough to put internal systems at risk. Encouraging password resets, promoting strong and unique passwords, and enabling two-factor authentication are all sensible preventative steps. 

As attacks become more targeted and sophisticated, ecommerce businesses need to think beyond firewalls. Attackers are increasingly using bots and automated tools to test stolen credentials and launch attacks at scale. Detection systems must be capable of adapting in real time to keep pace. Resilience built into digital infrastructure is the strongest defence against these attacks. That includes putting in place robust fraud and abuse detection systems, not just to block threats but to keep trusted customers moving through. Being able to recognise legitimate customers in real time, stop bad actors without disrupting the experience, and maintain continuity under pressure is now essential. 

Overly cautious fraud systems risk rejecting loyal shoppers and damaging the customer experience, which creates a different kind of loss. This is where network-based intelligence becomes critical. Manual review teams should be kept informed of the latest fraud tactics linked to data breaches, while machine learning systems must be continuously optimised to detect changing patterns. By tapping into real-time signals from a global network of merchants, retailers can detect threats early, adapt quickly and protect both revenue and reputation. 
 
Looking ahead, retailers who take action now and invest in digital resilience will be far better equipped to not only minimise the fallout from future attacks and protect both their customers and their business in the months ahead, but gain a competitive advantage by delivering secure, seamless experiences when it matters most.” 


John Linford, Security Portfolio Forum Director, The Open Group:  

“The cyberattacks on retailers in the UK and globally show that cyber risk is inexorable. The increasing rate of attacks, the diversification of methods accelerated by AI, and the growing financial losses being caused are concerns for cybersecurity and business leaders alike.  

While awareness the Zero Trust approach and implementation of Zero Trust strategies and techniques are becoming more widespread, there are still organisations who haven’t sufficiently implemented the principles that can protect them from threats posed by ransomware groups and other cybercriminals.  

Ultimately, it’s simply no longer feasible for organisations to consider any elements of the service topology as ‘trusted’. Rather than assuming any user or device on a network must have passed adequate security checkpoints and therefore can be trusted, organisations must utilise models which secure the data and assets those networks are there to carry, requiring continuous verification of trustworthiness in order to ensure computer security.  

By assuming every action is potentially malicious and performing security checks on an ongoing, case-by-case basis, Zero Trust reduces successful attacks and protects organisations in the event of a breach as other data and assets remain secure, rather than being accessible by an attacker. Zero Trust ensures computer security for users, data/information, applications, APIs, devices, networks, cloud, etc., wherever they are – instead of forcing a “secure” network within a company. 

However, allowing Zero Trust to become a stationary target is itself fraught with risk. It is now clear that well-implemented, well-governed Zero Trust strategies really do mitigate the damage that a breach can cause. The problem is that anything highly valuable, whether it is a precious metal or a vital technology is vulnerable to error, hype, and counterfeiting. Enterprises must be sure that their approach to Zero Trust, and the tools they use to enable it, really do live up to the standards that the term promises and are continuously adjusted and updated as threat vectors and techniques continue to evolve. The ‘zero trust’ of Zero Trust lies in the fact that the authority to access those assets is never assumed, as it might be when users connect through a secured network; instead, access privileges are revalidated at each point of contact, and those privileges must also be assessed regularly. 

To fight against cybercriminals, we need a shared understanding of what truly is (and, just as importantly, what is not) Zero Trust. Any organisation pursuing Zero Trust should start from a position of relying on robust, open, tested, vendor-neutral definitions of the methodology, as well as standards and best practices, in order to assure that the systems they roll out really will meet the demands of future security threats. Moreover, implementing Zero Trust does not require a complete ‘rip and replace.’ Rather, organisations will be able to keep many of their existing tools and strategies in place while strengthening them with Zero Trust (and maybe eventually replacing them with better solutions). 

The effort involved is worth it, though, because the changing nature of cyber threat is quickly outpacing the ability of the traditional security perimeter model to combat it. Malicious actors are becoming ever more skilled at moving laterally to points of value within networks once the perimeter is breached, and there is only so much that security teams can do to ameliorate that damage.”  

Browse our latest issue

Intelligent CISO

View Magazine Archive