Personalise customers’ in-store experiences. First step: security

Issue 5 2023 Retail (Industry), Information Security


Mark Scanlan.

Adding more personalised digital consumer experiences in the store, and on-the-go, opens the door for new opportunities … and vulnerabilities. Digital transformation enables retailers to meet consumers’ ever changing expectations across all channels, but also means potential exposure of highly valuable personal and financial data.

Protecting the consumer (and the brand) is part of the new retail experience that shoppers want and expect. Not to mention, integrating an effective security strategy brings the added bonus of mitigating the financial consequences of a security breach, a large portion of which are in domains other than IT.

Security at the core

Retailers already represented a major target for bad actors due to the amount of payment data and personally identifiable information (PII) that is held on consumers. During the pandemic, this was exacerbated because many retailers needed to rapidly pivot to meet the demands of a completely new and unexpected business landscape, often at the expense of solution security – it was viewed as ‘something we’ll take care of, once we catch our breath’. Ultimately, this resulted in a significant increase in cyberattacks against retailers, according to the FBI.

Consumers want to shop anywhere, anytime, on any device, while engaging with a retail brand – including online shopping while in-store. As a response, retailers are working towards providing a frictionless shopping experience where security is at the core. As such, the consumer’s device can both be at risk from the retailer’s environment, and conversely can form an attack vector into the environment. With so many digital touchpoints, an integrated, security-by-design, end-to-end solution has become critical.

Retailers know that security is of utmost importance now more than ever, but finding the right security solution that fits the size and subtleties of their enterprise and budget can be quite a daunting task. While a robust, resilient infrastructure, and network and endpoint security tools are essential enforcement mechanisms, cybersecurity starts with people and process – if appropriate policies are not defined and staff are not educated and trained, then an organisation can own every tool in existence, but they may be ineffective in their application.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.