惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Engineering at Meta
Engineering at Meta
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence
IT之家
IT之家
博客园 - 【当耐特】
U
Unit 42
云风的 BLOG
云风的 BLOG
L
LangChain Blog
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
B
Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
宝玉的分享
宝玉的分享
N
Netflix TechBlog - Medium

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… NIST is cataloging so many vulnerabilities it can only assign severity scores to the highest priority threats How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Solving the shadow IT crisis in travel Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure The war in Iran is reaching cyberspace - here’s how to prepare Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros
What 2025 taught us about the importance of resilience in...
2026-04-14 · via Latest from TechRadar in Security

When it rains, it pours.

That phrase defined retail cybersecurity in 2025. What began as isolated incidents quickly became prolonged, intense disruptions, exposing just how interconnected — and fragile — modern retail operations really are.

CTO and Co-Founder at Armis.

Over the year, high-profile retailers around the world were hit. Luxury global brands like Gucci and Balenciaga suffered data breaches; Victoria’s Secret was forced to temporarily shut down parts of its digital operations. While Marks & Spencer, Co-Op and Harrods in the UK all faced incidents, with disruption for M&S lasting for 15 weeks.

Article continues below

Different triggers, same outcome: major disruption and financial loss.

But when disruption spreads this quickly and lingers this long, it stops being about individual attacks and starts raising a more uncomfortable question: why was retail such fertile ground for them in the first place?

Why disruption spread so easily

While the volume of retailers hit in 2025 might have felt anomalous, it makes sense when viewed through this lens: retail is one of the most effective sectors for causing maximum disruption at scale. The cyberattack on United Natural Foods, a key supplier to tens of thousands of grocery stores across North America, showed how a single compromise can ripple outward – emptying shelves, disrupting lives, and triggering wider economic impact.

But it wasn’t simply a lack of security investment that caught out countless retailers last year, it was the sheer scale of cyber exposure retailers are now dealing with. The most disruptive incidents of the year weren’t driven by sophisticated zero-day exploits, but by attackers exploiting complexity and that lack of contextual understanding around how systems, assets and users interact.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Retailers operate sprawling digital ecosystems that combine ecommerce platforms, cloud infrastructure, in-store operational technology, identity systems, and third-party services. Each connection improves efficiency and scale — but also introduces new exposure and risk. A weakness in one area, whether a supplier, a trusted integration or an unmanaged asset, can quickly cascade into widespread disruption.

Attackers are increasingly adept at exploiting these conditions, too. Rather than targeting a single critical vulnerability, they chain together lower-risk weaknesses, move laterally across environments or providers and take advantage of fragmented visibility between IT, cloud storage and operational systems. The Adidas breach is a clear example: attackers gained access via a third-party supplier, stole customer data and demonstrated how interconnected environments can amplify impact.

And every incident that occurred last year was enabled by the realities of modern retail operations. New systems are deployed quickly, integrations are prioritized over security hygiene, and legacy infrastructure often sits alongside modern cloud services.

This creates blind spots that attackers can exploit long before an incident becomes visible. Security teams are left defending environments that are constantly changing, often without the visibility or intelligence needed to anticipate where risk is building. Many are under-resourced, fighting the growing threat of generative AI, all while trying to embed a culture of collaborative risk management.

After a tumultuous year, one thing is clear; this wasn’t a brief surge in activity or a single bad quarter. It was a sustained pattern of exposure playing out across the retail ecosystem. And as long as that exposure remains fragmented and poorly understood, disruption will continue to outpace response.

Cyber exposure becomes the foundation for resilience

What the past year made clear is that resilience in retail can no longer be built by reacting faster to incidents after they occur. With AI, as well as other emerging technologies becoming more mainstream, the problem is only going to get worse. The scale and persistence of disruption showed that retailers need to rethink how they understand risk in the first place.

That starts with recognizing that many of the most damaging weaknesses don’t sit in a single system or vulnerability, but in the relationships between software assets, platforms, and partners that underpin modern retail operations. This is where cyber exposure management becomes key. Rather than treating risk as a series of isolated alerts or vulnerabilities to be patched, exposure management focuses on understanding how risk originates and accumulates across an organization’s entire digital footprint.

For retailers, that footprint is uniquely complex: ecommerce platforms connect directly to inventory systems, in-store operational technology links back to central networks, identity management systems span employees, and third-party suppliers or contractors are embedded into day-to-day operations. Without a clear understanding of how these elements interact, it becomes impossible to anticipate how a seemingly minor weakness can escalate into widespread disruption.

Cyber exposure management offers a strategic approach to identifying, assessing, prioritizing and reducing cyber risk across an organization’s entire digital footprint. It’s about developing a living, contextual understanding of what assets exist, what role they play within retail operations, how critical they are during peak trading periods, and what other systems or partners they depend on – whether assets are managed or unmanaged, IT or OT, cloud-based or on-premises. This context is what separates manageable risk from systemic failure.

With attackers consistently exploiting gaps, exposure management allows organizations to assess risk in terms of real-world impact – not just technical severity – helping retailers prioritize the exposures most likely to affect operations, customer trust and revenue continuity.

This shift is ultimately about resilience, not just security maturity. By grounding risk decisions in how retail operations actually function, exposure-led approaches help teams anticipate where disruption is most likely to emerge, rather than responding after it has already taken hold. The result is more informed decision-making across IT, security and the wider business, with risk reduction aligned to operational continuity, customer experience and revenue protection.

Resilience starts before the next incident

There’s little room left for complacency. Retailers have learned the hard way that disruption doesn’t arrive in isolation, but through complex, interconnected environments – and once it begins, the impact can escalate quickly and spread far beyond the initial point of failure.

Last year was a wake-up call for the entire retail sector, not just for those that made the headlines. The challenge now is to ask harder questions about how environments are designed, how risk accumulates across systems, and whether businesses truly understand where their most critical points of exposure lie.

Because after all, when it rains, it pours. And the cost of inaction could now very well mean the difference between profit and sustained financial damage.

We've ranked the best patch management software.

CTO and Co-Founder at Armis.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.