Retail Cyber Security Checklist: Protecting Customer Data, Payments and Store Systems

 Retail Cyber Security Checklist: Protecting Customer Data, Payments and Store Systems

In April 2025, two of Britain’s best-known retailers found out just how quickly a cyber incident can turn into a trading crisis. Marks & Spencer and the Co-op were hit by co-ordinated ransomware attacks that the Cyber Monitoring Centre later assessed as a single event costing somewhere between £270 million and £440 million. M&S couldn’t take an online clothing order for 46 days. Co-op later confirmed that personal data belonging to all 6.5 million of its members had been compromised. And in stores, staff at both businesses were, at points, back to pen and paper.

Neither of these organisations was careless about security. Both had budgets, teams and tools that most retail businesses could only dream of. The attackers simply found the gaps, and in retail, there are always gaps to find.

If you run a retail business, the honest lesson from this isn’t “spend what M&S spends”. It’s that cyber security in retail is now an operational discipline, like health and safety or stock control. It needs a structure, an owner and a routine. This checklist gives you that structure: the essential areas to protect, why each one matters commercially, and what “good” looks like in practice.

Why cyber security is a growing operational risk for retailers

Before we get into the checklist itself, it’s worth being clear-eyed about why retail is such an attractive target. It isn’t bad luck, and it certainly isn’t personal. It’s economics.

Retail businesses manage valuable customer, employee and payment data

Think about what flows through your systems each day: customer names, addresses, email addresses and order histories; loyalty scheme records; employee payroll and HR data; and, of course, payment transactions. To you, it’s the plumbing of the business. To a criminal, it’s gold – it’s data that can be sold, used for fraud, or held to ransom.

There’s a common assumption among mid-sized retailers that attackers only bother with household names. The government’s Cyber Security Breaches Survey tells a different story: 43% of UK businesses identified a breach or attack in the last 12 months, and the figure rises to 65% for medium businesses and 69% for large ones. Attackers don’t browse your brand awareness figures before deciding whether you’re worth it. They scan for weaknesses at scale, and a regional retailer with 15 stores and a soft underbelly is a far easier payday than a FTSE 100 business with a robust security operations centre.

Multiple stores and endpoints increase the attack surface

A retail business like yours may span a head office, plus every store, plus warehouses, plus home workers, plus the ecommerce platform; each with its own tills, back-office PCs, tablets, handheld scanners, CCTV systems, guest Wi-Fi and, increasingly, smart devices.

Every one of those devices is a potential way in. And the further a device sits from head office, the more likely it is to be running old software, sharing a password taped to a corkboard or sitting on the same network as the public Wi-Fi. Attackers know this, which is why store-level technology is such a popular starting point. They don’t need to breach your strongest system; they need to breach your weakest one, then move sideways.

A cyber incident can quickly become a trading problem

This is the shift in thinking that matters most for directors. A cyber attack used to be framed as an IT problem or a data protection problem. In retail, it’s a trading problem.

When systems go down, tills stop, stock replenishment stops, click-and-collect stops, and the ecommerce site goes dark – often during your busiest trading period, because attackers time these things deliberately. The Cyber Monitoring Centre’s analysis of the M&S and Co-op attacks found that business disruption, not data theft or ransom payments, drove the vast majority of the financial cost. M&S alone was losing an estimated £1.3 million a day in online sales while its site was down.

Scale that thinking to your own business.

  • What does a day without tills cost you?
  • A week without your ecommerce platform?
  • A fortnight of manual stock ordering?

For most retailers, the answer is sobering, and it’s why cyber resilience belongs on the board agenda.

Retail employees are frequent targets for phishing and social engineering

Most successful attacks on retailers start with an email, a phone call or a text message.

Phishing remains far and away the most common attack type facing UK organisations, reported by 38% of businesses in the latest government survey. And retail is particularly exposed because of how the sector works. You may have dispersed teams with high turnover, seasonal staff who’ve had a limited induction, busy store managers who answer emails between customer queries, and helpdesks under pressure to fix things fast. The attackers who breached M&S reportedly did it by impersonating staff and talking their way past IT support, no malware required at the front door, just confidence and a plausible story.

None of this means your people are the problem. It means your people are the target, and they deserve defences designed around that reality.

Retail cyber security checklist: the essential areas to protect

Right, to the checklist itself. Eleven areas, each broken down into practical steps. You won’t fix all of this in a couple of weeks, and we wouldn’t recommend trying to. Work through it, identify your biggest gaps, and prioritise the fixes that reduce the most risk for the least disruption. (Spoiler: MFA and patching usually top that list.)

1. Protect customer and business data: Understand what sensitive data your retail business holds.

You can’t protect what you haven’t mapped. Start with a straightforward data audit: what personal and commercial data do you hold, where does it live, who can access it, and why do you still have it?

Retailers are notorious data hoarders (not criticising, we get it!). Old loyalty databases, CSV exports of customer lists sitting in shared drives, years of CVs in an HR inbox, spreadsheets of orders “just in case”. Every piece of data you keep is data you can lose and under UK GDPR, data you can be held accountable for losing. If a customer record from 2016 serves no purpose, deleting it is one of the cheapest security controls available.

Limit access to sensitive information

Apply the principle of least privilege: people get access to the data their role requires, and nothing more. A store colleague doesn’t need the full customer database. A merchandiser doesn’t need payroll. And nobody – genuinely nobody – should be doing day-to-day work from an administrator account.

This matters because attackers rarely stop where they land. If they compromise one set of credentials, they inherit everything that account can see. Tight access controls turn a potential catastrophe into a contained nuisance.

Use practical data protection strategies

Encryption for data at rest and in transit, secure disposal of old devices and paper records, sensible retention policies, and controls over how data leaves the business (email attachments, USB drives, personal cloud accounts) all belong in the mix. None of this is exotic. Most of it is configuration and policy rather than expensive new tooling.

Include data protection in wider IT compliance processes

Build data protection into your routine IT governance: reviews when systems change, checks when suppliers change, and clear ownership of who answers to the board on it. Remember, too, that a reportable breach triggers a 72-hour clock for notifying the ICO, which is a very short window if you’re working out your obligations for the first time mid-incident.

2. Strengthen endpoint protection across stores and offices: Identify and manage every device connected to the business

Every retailer we’ve ever worked with has discovered devices they didn’t know they had. Build and maintain an asset register covering tills, back-office PCs, laptops, tablets, handheld terminals, printers, CCTV and networked equipment across every site. If a device connects to your network, it’s your problem.

Use modern endpoint protection and monitoring

Traditional antivirus checks files against a list of known bad things. Modern endpoint detection and response (EDR) tools watch for suspicious behaviour, such as a till suddenly trying to talk to a server in another country, a back-office PC encrypting files at speed, and can isolate a device automatically. For a multi-site retailer, that behavioural monitoring is the difference between one infected machine and forty infected stores.

Remove or replace unsupported devices and software

Unsupported operating systems and legacy applications no longer receive security updates, which makes them permanently open doors. Retail is particularly prone to this because store hardware is often bought once and sweated for a decade. If a till PC is running an operating system that went out of support years ago, it doesn’t matter how good the rest of your security is, you’ve left a window open. Plan replacements; where replacement genuinely isn’t possible yet, isolate the device so a compromise can’t spread.

Standardise device security across multiple retail locations

Security that varies by store is security that fails at your weakest store. Use central management tools to enforce consistent configurations, encryption, screen locks and update policies across every location. The Basildon branch should be exactly as secure as head office and with modern device management, it can be, without anyone driving up the A127 with a USB stick.

3. Use MFA to protect business accounts: Why passwords alone are not enough

Passwords get phished, guessed, reused and bought in bulk on criminal marketplaces. If a password is the only thing standing between an attacker and your email, finance system or ecommerce admin panel, you’re one convincing phishing email away from a very bad month.

Multi-factor authentication (MFA) adds a second check, typically an app prompt or hardware key, so a stolen password alone isn’t enough. It is, without much competition, the highest-impact, lowest-cost security control available to a retail business. Microsoft’s long-standing estimate is that MFA blocks the overwhelming majority of automated account-compromise attacks. Few controls offer that return on ten minutes of setup per user.

Enable MFA for high-value and remote-access accounts

Prioritise email (the master key to everything else, thanks to password resets), remote access and VPN connections, cloud platforms like Microsoft 365, finance and banking systems, and your ecommerce and EPOS administration consoles. Anything reachable from the internet with a username and password should have MFA. No exceptions for directors, by the way – senior leaders are the most impersonated people in the business, which makes them the worst candidates for an opt-out.

Prioritise privileged and administrative users

Administrator accounts can create users, change permissions and switch off security tools, which makes them the crown jewels for an attacker. Protect them with the strongest MFA you can (phishing-resistant methods such as hardware keys, ideally), limit how many exist, and separate admin accounts from everyday user accounts so browsing and email never happen with elevated rights.

4. Strengthen email security and phishing protection: Email remains a common route into retail businesses

For all the talk of sophisticated threats, the humble inbox remains the front line. Phishing, invoice fraud, fake supplier payment-detail changes and gift card scams all arrive by email, and they’re getting harder to spot as attackers use AI to write fluent, personalised messages. The days of laughing at the typo-ridden scam email are, sadly, behind us.

Configure technical email security controls

A well-configured email platform catches most of the rubbish before a human ever sees it. That means anti-phishing and anti-spoofing protections (SPF, DKIM and DMARC — which also stop criminals sending emails pretending to be you), link and attachment scanning, and clear external-sender warnings. If your domain doesn’t have DMARC enforced, anyone on the internet can send email that appears to come from your brand. Customers and suppliers will thank you for closing that off.

Train employees to verify unusual requests

Technology filters most threats; judgement handles the rest. Give staff a simple rule: any unusual request involving money, credentials or data gets verified through a different channel.

An email from “the MD” asking for urgent gift card purchases? Call the MD.
A supplier “updating their bank details”? Phone the number you already hold, not the one in the email.

Make verification a normal, praised behaviour rather than something that feels like insubordination. The goal is a culture where checking is expected, not awkward.

5. Secure and segment retail networks: Separate business systems from guest and public Wi-Fi

Customer Wi-Fi is a lovely bit of service. Customer Wi-Fi that shares a network with your tills is a liability. Guest access should be completely isolated from business systems on a separate network, not just a separate password. The same goes for staff personal devices: welcome on the guest network, nowhere near the EPOS.

Protect store, office and warehouse networks

Each site needs properly configured business-grade firewalls, changed default passwords on all network equipment (routers still running “admin/admin” remain depressingly common), secured Wi-Fi with modern encryption, and disabled unused ports and services. Where sites connect to each other or to cloud systems, those connections should be encrypted and authenticated.

Use network segmentation to limit the impact of a compromise

Segmentation means dividing your network into zones such as payments, back office, CCTV, guest, so a compromise in one can’t wander into the others. Think of it as fire doors for your IT. It’s also one of the most effective ways to reduce the scope and cost of PCI DSS compliance, because properly isolating your payment environment shrinks the part of your network that the standard applies to. Fewer systems in scope, smaller blast radius, easier audits. Everyone wins except the attacker.

Maintain consistent network security management across multiple sites

Multi-site networks drift. Someone tweaks a firewall rule in one store to fix a printer issue and never mentions it again. Use centralised management so configurations, firmware updates and monitoring are handled consistently across the estate, and so you can actually see what’s happening on the network of a store 200 miles away.

6. Protect payment systems and transaction environments: Understand which systems are involved in processing payments

Payment security starts with scope: which devices, networks, applications and people touch cardholder data on its journey from tap to bank? That includes card terminals, EPOS software, the networks they use, your ecommerce checkout and payment gateway integrations.

This mapping underpins your PCI DSS obligations, the industry standard that every card-accepting retailer must meet, whose current version (4.0.1) brought a substantial set of additional requirements into force from March 2025, including stronger controls around ecommerce payment page scripts.

Keep payment devices and supporting systems secure

Card terminals and EPOS systems need updates and oversight like any other technology. Keep firmware and software current, restrict what payment devices can connect to, and physically check terminals periodically for tampering or skimming devices, a low-tech threat that still catches retailers out. Change any default passwords on payment equipment on day one.

Avoid storing payment information unnecessarily

The simplest way to protect card data is not to have it. Use point-to-point encryption and tokenisation through your payment provider so full card numbers never touch your systems, and never store card details in spreadsheets, email or notes fields (you’d be amazed). If a mail-order process involves writing card numbers down, redesign the process. Data you don’t hold can’t be stolen from you.

Include payment security within wider IT compliance and risk management

PCI DSS compliance isn’t a once-a-year form-filling ritual; the standard increasingly expects security to be demonstrably continuous. Fold payment security into your regular risk reviews, change management and supplier assessments, and make sure someone owns it by name. Non-compliance can mean fines, higher transaction fees and, after a breach, eye-watering remediation costs – quite apart from what it does to customer trust.

7. Keep software, devices and systems patched: Apply security updates promptly

Most successful attacks exploit vulnerabilities for which a fix already existed. Attackers reverse-engineer patches within days of release to find out exactly what they fixed, then scan the internet for organisations that haven’t applied them. Prompt patching, ideally within 14 days for critical security updates, which is also the Cyber Essentials benchmark, closes those doors before opportunists arrive.

Create a consistent patch management process

“We update things when we get a chance” is not a process. A real one defines what gets patched, on what schedule, who’s responsible, how updates are tested against critical systems like EPOS, and how exceptions are recorded. Automate wherever possible. In retail, scheduling matters too: nobody wants tills rebooting at peak, but “we’ll do it after peak” has a habit of becoming “we never did it”.

Do not overlook devices outside head office

Head office machines usually get patched. The back-office PC in your smallest store, the warehouse handhelds, the CCTV recorder, the self-service kiosk, these are the devices that quietly fall years behind, and they’re precisely where attackers look. Your patching process should cover every device on the asset register, wherever it lives. (You did build that asset register, didn’t you?)

8. Control third-party and supplier access: Retail technology depends on a wide supplier ecosystem

EPOS vendors, ecommerce agencies, logistics platforms, CCTV maintainers, HVAC contractors, marketing tools – modern retail runs on suppliers, and many of them have some form of access to your systems or data. Each connection is a potential route in. Some of the most damaging breaches in retail history began not with the retailer, but with a supplier whose credentials were compromised. Your security is only as strong as the least careful company with a login to your systems.

Give suppliers only the access they need

Least privilege applies to companies as much as people. Suppliers should have access only to the specific systems their work requires, through named accounts (never shared logins), protected by MFA, and time-limited where possible. When a contract ends, access ends the same day, dormant supplier accounts are a gift to attackers because nobody notices when they’re used.

Treat supplier access as part of your own cyber risk

Ask security questions before signing: how do they protect their own systems, do they hold certifications such as Cyber Essentials or ISO 27001, and how would they tell you about a breach affecting your data? Keep a register of who has access to what, review it regularly, and include key suppliers in your incident response thinking. If your EPOS provider gets breached on Black Friday eve, you want to already know who calls whom.

9. Back up critical retail data and systems: Identify what the business could not operate without

Work backwards from trading. Which systems and data would stop you selling, paying staff or fulfilling orders? Typically that’s EPOS and transaction data, stock and product information, the ecommerce platform, finance systems, and customer and supplier records. Those are your recovery priorities, and your backup strategy should reflect them explicitly – including how quickly each one needs to come back.

Protect backups from the same incident affecting production systems

Modern ransomware operators go hunting for backups first, precisely because destroying them forces you toward paying.

Follow the 3-2-1 principle:

Three copies of your data, on two different types of storage, with one held offsite or in the cloud – and make sure at least one copy is offline or immutable, meaning it cannot be altered or deleted even by an administrator account.

A backup that lives on the same network with the same credentials as everything else isn’t a backup; it’s a second copy for the attacker to encrypt.

Test recovery rather than assuming backups work

The only backup that counts is one you’ve restored. Test regularly: restore individual files, restore whole systems, and time it. Plenty of businesses discover mid-crisis that their backups were incomplete, corrupted, or would take three weeks to restore, which is a discovery best made during a quiet window, not during an incident. Know your realistic recovery time and check it against what the business can actually tolerate.

10. Train retail employees to recognise cyber threats: Make training relevant to real retail scenarios

Generic e-learning about “the dangers of cybercrime” washes over people. Effective retail training uses the scenarios your teams actually face: the fake head-office email about a refund, the caller claiming to be IT support asking someone to read out a code, the gift card scam, the “courier” text link, the customer trying to shoulder-surf a manager’s login. When training mirrors reality, people recognise the real thing.

Adapt training for different roles

A store colleague, a finance assistant and a systems administrator face different threats and need different depth. Finance teams need serious time on invoice fraud and payment verification. Store managers need to know how to respond when something looks wrong on a till. IT staff need to understand social engineering aimed at helpdesks, a technique used to devastating effect in the 2025 retail attacks, where attackers simply phoned up and impersonated employees to get passwords reset. And seasonal staff need the essentials on day one.

Make security awareness an ongoing process

One annual training session has roughly the shelf life of a January gym membership. Little and often works better: short regular refreshers, simulated phishing exercises treated as practice rather than punishment, and quick briefings when new scams appear. Above all, make it easy and safe to report mistakes. An employee who clicked a bad link and says so within five minutes has just given you a head start; an employee who’s too scared to admit it has given the attacker one.

11. Prepare a data breach and incident response plan: Define what employees should do when something looks wrong

The first minutes of an incident are usually in the hands of whoever spots it, often a store colleague, not an IT professional. Everyone should know the basics: don’t switch the machine off (evidence matters), disconnect it from the network if you can, report it immediately, and know exactly who to call, including out of hours. A laminated one-pager in the back office beats a beautiful 40-page PDF nobody has read.

Plan how the business will contain a cyber incident

Your plan should set out who leads the response, who has authority to make disruptive calls (taking systems offline, closing the website, pausing card payments), how you’ll isolate affected systems and sites, and how you’ll communicate when email itself might be compromised, phone trees and out-of-band messaging matter. Decide in advance who your external support is: incident response specialists, legal advice, your insurer’s requirements. Working this out after hours on the night of the breach is the most expensive way to do it.

Include operational recovery and communication

Containment is half the job; trading again is the other half. Plan how stores operate if systems are down (can you take payments offline? for how long?), the order in which systems are restored, and how you’ll communicate with staff, customers, suppliers, your bank and – where personal data is involved – the ICO within its 72-hour notification window. The retailers that came through 2025’s attacks with their reputations intact were, notably, the ones that communicated quickly and honestly.

Cyber security is not a one-off checklist exercise

Completing this checklist once doesn’t make you secure. It makes you secure today. Threats evolve, your business changes, new stores open, new suppliers plug in, and controls decay if nobody owns them. Treat this as a cycle of assess, improve, verify and repeat.

Review security controls regularly

Put reviews in the diary: access rights and supplier accounts quarterly, the asset register and patching status monthly, restore tests on a schedule, an annual look at the overall risk picture, and a proper review after any incident or near miss. Certifications like Cyber Essentials give you a useful annual forcing function and demonstrate to customers, partners and insurers that the fundamentals are in place.

Use managed security services where internal resources are limited

Very few retail businesses can justify a 24/7 in-house security team. Managed security services give you round-the-clock monitoring, threat detection, patching and response expertise at a fraction of the cost of building it yourself, and they free your internal IT resource (if you have one) to focus on projects that grow the business rather than firefighting. The question isn’t really whether you can afford support; it’s whether you can afford to face a serious incident without it.

Retail cyber security checklist at a glance

Key Actions Questions to Ask
Customer and business data Map the data you hold; apply least-privilege access;
encrypt; delete what you don’t need.
Do we know where all our sensitive data lives, and who can see it?
Endpoint protection Maintain an asset register; deploy EDR across all sites; retire unsupported devices; standardise configurations. Is every device in every store known, monitored and supported?
MFA Enable MFA on email, remote access, cloud, finance and admin accounts; use strongest methods for privileged users. Can any internet-facing account be accessed with just a password?
Email security Enforce SPF, DKIM and DMARC; scan links and attachments; train staff to verify unusual requests via another channel. Would a fake “supplier bank change” email reach and fool our finance team?
Network security Isolate guest Wi-Fi; segment payments, back office and CCTV; manage all sites centrally. If one store was compromised, could it spread to the rest of the business?
Payment systems Map the payment environment; patch terminals and EPOS; use P2PE/tokenisation; maintain PCI DSS compliance. Could card data be stolen from any system we control?
Patching Apply critical updates within 14 days; automate; cover store, warehouse and edge devices. What’s the oldest unpatched device on our network right now?
Supplier access Named, MFA-protected, least-privilege supplier accounts; remove access at contract end; assess supplier security. Who outside the business can log into our systems today?
Backups Follow 3-2-1 with an offline or immutable copy; test restores and time them. If ransomware hit tonight, how long until we’re trading again?
Employee training Retail-specific scenarios; role-based depth; regular refreshers; blame-free reporting. Would a new seasonal starter know how to spot and report a phishing attempt?
Incident response Written, tested plan; clear roles and out-of-hours contacts; recovery priorities; ICO 72-hour readiness. Does everyone know what to do in the first 30 minutes of an incident?

Building a more resilient retail business

If the events of the last couple of years have taught the retail sector anything, it’s that cyber security has moved from the IT department’s to-do list to the board’s risk register. The attacks on M&S and Co-op weren’t remarkable for their technical sophistication, much of it came down to social engineering and well-understood weaknesses.
They were remarkable for their commercial impact: hundreds of millions of pounds, months of disruption, and millions of customers’ data exposed.

The encouraging flip side is that the defences that matter most are neither exotic nor unaffordable. MFA, patching, segmentation, tested backups, trained people and a rehearsed plan would have blunted or prevented a large share of the incidents that made headlines. This is a game where doing the fundamentals consistently well puts you ahead of the vast majority of targets because attackers, like the rest of us, prefer the path of least resistance.

Work through this checklist honestly. Score yourself, find the gaps, and fix the highest-risk items first. And if your internal team doesn’t have the time or specialist depth to cover all of it – which is true for most retail businesses, and nothing to be embarrassed about – get support from a partner who lives and breathes this. You can start with our IT security audit.

At Utilize, we help retail businesses across Essex, London and the South East secure their stores, systems and data with managed IT and cyber security services built around how retailers actually operate. If you’d like a clear-eyed assessment of where your business stands against this checklist – and a practical plan to close the gaps – get in touch with our team. It’s a far better conversation to have now than during an incident.

Check out our Managed IT and Technology Solutions for Retail Businesses page to see a breakdown of all the ways we can support your retail business.

If you cannot say with confidence where your own estate stands, that is exactly where to start.

Book a retail IT audit and get a straight, practical read on what is working, what is exposed, and what to fix first. Or find out more about our retail IT offering.

Retail IT Support Book a Free Consultation