Skip to main content

Info-Tech: Fragmented Ownership Undermines Retail Cyber Defenses

Image
Info-Tech: Fragmented Ownership Undermines Retail Cyber Defenses

Arlington, Va. – September 08, 2026 -- Retail organizations are struggling to defend increasingly connected store systems because no single team holds end-to-end authority over cyber risk, according to a new blueprint from Info-Tech Research Group. The firm's Build Cyber Resilience in Connected Retail report identifies fragmented ownership across legacy point-of-sale systems, IoT devices, cloud platforms, e-commerce applications, and third-party vendors as the core barrier to consistent security decision-making.

Divided ownership leaves no team with full visibility over retail cyber risk

Info-Tech's research finds that legacy POS systems, IoT devices, cloud platforms, and customer-facing applications are frequently deployed by different teams at different times, leaving no single owner with sufficient control to enforce decisions across the entire environment. "Retail leaders understand the cyber risks in their environment. The breakdown happens when no one can make, enforce, and explain decisions across stores, platforms, and vendors," said Donnafay MacDonald, research director at Info-Tech Research Group.

Compliance overlap and fast-moving attacks strain traditional governance models

The blueprint points to overlapping requirements governing payment data, personal information, and customer privacy as a source of conflicting controls across shared systems, markets, and channels. It also warns that identity compromise, third-party access, and lateral movement can spread through connected retail environments faster than traditional escalation processes can respond, pushing organizations toward reactive, ad hoc decisions.

Info-Tech recommends five connected decision domains for retail security operating models

The firm advises CIOs and security leaders to structure their operating model around five domains: visibility, control boundaries, decision ownership, risk prioritization, and response coordination. These domains are designed to clarify where exposure exists, how far a compromise could spread, who has authority to act, which threats matter most, and how teams and partners should coordinate a response.

Three-phase framework guides retailers from asset mapping to a prioritized risk register

Phase one requires organizations to establish data classifications, risk tolerance, and severity scales, then document assets across four categories: software, hardware, networks, and physical sites. Phase two identifies vulnerabilities and threats within each system component and develops risk scenarios linking technical weaknesses to operational and business consequences, with generative AI permitted to assist scenario development if outputs are validated by subject matter experts. Phase three assesses existing controls, estimates likelihood and impact, and compares severity scores against risk tolerance to assign owners and timelines for the most significant exposures.

Risk assessment tool separates critical payment failures from minor operational disruptions

"A problem with the payment system could stop sales, while a problem with a digital sign might just be an inconvenience. Risk assessments help businesses separate the critical issues from the minor ones, so they can prioritize what really needs attention," MacDonald said. The accompanying Retail Security Threat and Risk Assessment Tool maps exposures to affected systems and owners, evaluates likelihood and impact, and produces a prioritized risk register intended to guide investment, segmentation, and response decisions across stores, platforms, IoT devices, and customer data.

Published by
fairsonline_team
News Type