
Connected Retail Is Widening the Cyber Attack Surface While Security Ownership Remains Fragmented, Info-Tech Research Group Warns
Store systems, cloud platforms, IoT devices, vendor connections, and customer applications now operate as a connected ecosystem, while security accountability remains divided across technology domains and teams. Info-Tech Research Group's Build Cyber Resilience in Connected Retail blueprint helps CIOs and security leaders set clear decision boundaries, align ownership, and prioritize threats according to operational and business impact.
ARLINGTON, Va., Sept. 3, 2026 /PRNewswire/ -- Retail technology environments are becoming more interconnected while the decisions that protect them remain fragmented. Legacy point-of-sale (POS) systems, IoT devices, cloud platforms, e-commerce applications, and third-party services are often owned and managed by different teams, leaving no single function with full visibility or end-to-end authority over cyber risk.
To help retail leaders address these gaps, Info-Tech Research Group, a global research and advisory firm, has published its Build Cyber Resilience in Connected Retail blueprint. The resource provides a three-phase methodology and supporting threat and risk assessment tool to help organizations identify assets, map threats and vulnerabilities, evaluate potential business impact, and establish clear priorities for action.
"Retail leaders understand the cyber risks in their environment. The breakdown happens when no one can make, enforce, and explain decisions across stores, platforms, and vendors," says Donnafay MacDonald, research director at Info-Tech Research Group. "Cyber resilience is strengthened when organizations are able to clearly define decision-making responsibilities and assign accountable owners."
Why Connected Retail Security Decisions Break Down
According to Info-Tech's research, connected retail environments introduce structural constraints that prevent organizations from making consistent and defensible security decisions. The blueprint identifies three central challenges:
- Fragmented systems limit decision authority: Legacy POS systems, IoT devices, cloud platforms, and customer-facing applications were often deployed by different teams at different times. No single owner has sufficient visibility or control to make and enforce decisions across the entire environment.
- Compliance complexity makes consistency harder: Retailers must account for overlapping requirements governing payment information, personal data, and customer privacy. Applying these requirements across shared systems, markets, and channels can create conflicting expectations and inconsistent controls.
- Attack speed outpaces traditional governance: Identity compromise, third-party access, and lateral movement can spread quickly through connected environments. Traditional escalation processes often move too slowly, increasing reliance on reactive and ad hoc decisions.
The firm advises retail CIOs and security leaders to build an operating model around five connected decision domains: visibility, control boundaries, decision ownership, risk prioritization, and response coordination. Together, these domains help organizations determine where exposure exists, how far a compromise could spread, who has authority to act, which threats matter most, and how teams and partners should respond.
Info-Tech's Three-Phase Framework for Building Cyber Resilience in Connected Retail
The Build Cyber Resilience in Connected Retail blueprint moves organizations from defining their assessment criteria to producing a prioritized risk register ready for treatment decisions. The three phases include:
Phase 1: Define What Risk Matters in the Organization's Environment. Establish data classifications, risk tolerance, and severity scales before identifying and documenting the assets under assessment. Assets are organized across four categories: software, hardware, networks, and physical sites.
Phase 2: Determine Where Exposure Exists. Identify vulnerabilities within each system component, evaluate applicable threats, and develop concise risk scenarios that connect technical weaknesses to credible operational and business consequences. Generative AI can assist with scenario development when its outputs are reviewed and validated by subject matter experts.
Phase 3: Decide Which Security Risks Justify Action. Assess existing controls, estimate the likelihood and impact of each scenario, and compare severity scores against the organization's risk tolerance. Leaders can then prioritize treatment decisions, assign owners, and establish timelines for the most significant exposures.
"Just because two systems are in the same store doesn't mean they're equally important. A problem with the payment system could stop sales, while a problem with a digital sign might just be an inconvenience. Risk assessments help businesses separate the critical issues from the minor ones, so they can prioritize what really needs attention," explains MacDonald. "That discipline helps teams address the right risks instead of allowing the loudest or most visible issue to dictate priorities."
The Build Cyber Resilience in Connected Retail blueprint includes the Retail Security Threat and Risk Assessment Tool, which gives security and IT leaders a structured view of threats across stores, platforms, IoT devices, and customer data. The tool maps exposures to affected systems and owners, evaluates likelihood and impact, and produces a prioritized risk register to guide investment, segmentation, and response decisions.
By applying Info-Tech's approach, retail organizations can strengthen accountability across IT, store operations, and vendors, contain the potential spread of an incident, and direct security resources toward the exposures most likely to disrupt the business or damage customer trust.
For exclusive and timely commentary from Info-Tech's experts, including Donnafay MacDonald, and access to the complete Build Cyber Resilience in Connected Retail blueprint, please contact [email protected].
About Info-Tech Research Group
Info-Tech Research Group is the "get things done" partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.
To learn more about Info-Tech's HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm's SoftwareReviews platform.
Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm's Media Insiders program. To gain access, contact [email protected].
For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.
SOURCE Info-Tech Research Group
Share this article