Today’s retail technology links customer accounts, payment platforms, inventory tools and in-store systems to create faster, more seamless shopping experiences. But every new connection can also expand a retailer’s attack surface, creating security gaps that may be difficult to see when data, devices, applications and outside partners are constantly exchanging information.
That complexity can expose retailers to risks well beyond the payment systems that traditionally receive the most security attention, especially as businesses add more digital services, automation and connected technology. Below, members of Forbes Technology Council discuss cyber risks retailers may be overlooking and share practical steps they can take to reduce their exposure.
Secure Every Third-Party Connection
Retailers often underestimate third-party and system integration risk, where attackers enter through a vendor, API or store device and move into payments or customer systems. Reduce exposure through identity controls like phishing-resistant multifactor authentication and least-privilege access. Keep an inventory of APIs and integrations, limit permissions and monitor for abnormal usage. Strengthen vendor requirements, centralize logging and regularly test incident response. - Senthil Muthu, iCISO LLC






