Retail security responsibilities remain fragmented in complex tech environments

News provided byInfo-Tech Research Group · 3 min read
Retail technology environments are increasingly complex, with interconnected store systems, cloud platforms, IoT devices, and third-party services, yet security responsibilities remain fragmented across different teams, according to a new blueprint from Info-Tech Research Group. The company's latest resource aims to help retail leaders address these gaps and build stronger cyber resilience.
In a world where legacy point-of-sale (POS) systems, IoT devices, and cloud platforms operate independently, security accountability is often divided, leaving no single function with full visibility or control over cyber risks. This fragmented approach can leave retailers exposed to potential vulnerabilities.
To combat these issues, Info-Tech Research Group has published the "Build Cyber Resilience in Connected Retail" blueprint. This comprehensive guide offers a three-phase methodology and a threat and risk assessment tool to help organizations identify and prioritize cyber threats according to their operational and business impact.
"Retail leaders are keenly aware of the cyber risks in their environments," said Donnafay MacDonald, research director at Info-Tech Research Group. "The breakdown occurs when no single team can make, enforce, and explain decisions across stores, platforms, and vendors."
The blueprint addresses three key challenges: 1. Fragmented Systems Limit Decision Authority: Legacy POS systems, IoT devices, and cloud platforms were often deployed by different teams at different times, making it difficult for any one owner to have full visibility or control. 2. Compliance Complexity Hinders Consistency: Retailers must navigate overlapping requirements for payment information, personal data, and customer privacy. Applying these requirements across shared systems, markets, and channels can create conflicting expectations and inconsistent controls. 3. Rapid Attack Spread Outpaces Traditional Governance: Identity compromise, third-party access, and lateral movement can quickly spread through connected environments. Traditional escalation processes often move too slowly, increasing reliance on reactive and ad hoc decisions.
To address these issues, Info-Tech advises retail CIOs and security leaders to build an operating model around five connected decision domains: visibility, control boundaries, decision ownership, risk prioritization, and response coordination. These domains help organizations determine where exposure exists, how far a compromise could spread, who has authority to act, which threats matter most, and how teams and partners should respond.
The three-phase framework for building cyber resilience includes: 1. Define What Risk Matters in the Organization's Environment: Establish data classifications, risk tolerance, and severity scales before identifying and documenting the assets under assessment. Assets are organized across four categories: software, hardware, networks, and physical sites. 2. Determine Where Exposure Exists: Identify vulnerabilities within each system component, evaluate applicable threats, and develop concise risk scenarios that connect technical weaknesses to credible operational and business consequences. Generative AI can assist with scenario development when its outputs are reviewed and validated by subject matter experts. 3. Decide Which Security Risks Justify Action: Assess existing controls, estimate the likelihood and impact of each scenario, and compare severity scores against the organization's risk tolerance. Leaders can then prioritize treatment decisions, assign owners, and establish timelines for the most significant exposures.
"Risk assessments help businesses separate the critical issues from the minor ones, so they can prioritize what really needs attention," explained MacDonald. "That discipline helps teams address the right risks instead of allowing the loudest or most visible issue to dictate priorities."
The "Build Cyber Resilience in Connected Retail" blueprint includes the "Retail Security Threat and Risk Assessment Tool," which provides a structured view of threats across stores, platforms, IoT devices, and customer data. The tool maps exposures to affected systems and owners, evaluates likelihood and impact, and produces a prioritized risk register to guide investment, segmentation, and response decisions.
By applying Info-Tech's approach, retail organizations can strengthen accountability across IT, store operations, and vendors, contain the potential spread of an incident, and direct security resources toward the exposures most likely to disrupt the business or damage customer trust.