Store systems, cloud platforms, IoT devices, vendor connections, and customer applications now operate as a connected ecosystem, while security accountability remains divided across technology domains and teams. Info-Tech Research Group’sBuild Cyber Resilience in Connected Retailblueprint helps CIOs and security leaders set clear decision boundaries, align ownership, and prioritize threats according to operational and business impact.
ARLINGTON, Va., Sept. 3, 2026 /PRNewswire/ — Retail technology environments are becoming more interconnected while the decisions that protect them remain fragmented. Legacy point-of-sale (POS) systems, IoT devices, cloud platforms, e-commerce applications, and third-party services are often owned and managed by different teams, leaving no single function with full visibility or end-to-end authority over cyber risk.
To help retail leaders address these gaps, Info-Tech Research Group, a global research and advisory firm, has published its Build Cyber Resilience in Connected Retail blueprint. The resource provides a three-phase methodology and supporting threat and risk assessment tool to help organizations identify assets, map threats and vulnerabilities, evaluate potential business impact, and establish clear priorities for action.
“Retail leaders understand the cyber risks in their environment. The breakdown happens when no one can make, enforce, and explain decisions across stores, platforms, and vendors,”says Donnafay MacDonald, research director at Info-Tech Research Group.“Cyber resilience is strengthened when organizations are able to clearly define decision-making responsibilities and assign accountable owners.”
Why Connected Retail Security Decisions Break Down
According to Info-Tech’s research, connected retail environments introduce structural constraints that prevent organizations from making consistent and defensible security decisions. The blueprint identifies three central challenges:
- Fragmented systems limit decision authority: Legacy POS systems, IoT devices, cloud platforms, and customer-facing applications were often deployed by different teams at different times. No single owner has sufficient visibility or control to make and enforce decisions across the entire environment.
- Compliance complexity makes consistency harder: Retailers must account for overlapping requirements governing payment information, personal data, and customer privacy. Applying these requirements across shared systems, markets, and channels can create conflicting expectations and inconsistent controls.
- Attack speed outpaces traditional governance: Identity compromise, third-party access, and lateral movement can spread quickly through connected environments. Traditional escalation processes often move too slowly, increasing reliance on reactive and ad hoc decisions.
The firm advises retail CIOs and security leaders to build an operating model around five connected decision domains: visibility, control boundaries, decision ownership, risk prioritization, and response coordination. Together, these domains help organizations determine where exposure exists, how far a compromise could spread, who has authority to act, which threats matter most, and how teams and partners should respond.
Info-Tech’s Three-Phase Framework for Building Cyber Resilience in Connected Retail
The Build Cyber Resilience in Connected Retail blueprint moves organizations from defining their assessment criteria to producing a prioritized risk register ready for treatment decisions. The three phases include:
Phase 1: Define What Risk Matters in the Organization’s Environment.Establish data classifications, risk tolerance, and severity scales before identifying and documenting the assets under assessment. Assets are organized across four categories: software, hardware, networks, and physical sites.
Phase 2: Determine Where Exposure Exists. Identify vulnerabilities within each system component, evaluate applicable threats, and develop concise risk scenarios that connect technical weaknesses to credible operational and business consequences. Generative AI can assist with scenario development when its outputs are reviewed and validated by subject matter experts.
Phase 3: Decide Which Security Risks Justify Action. Assess existing controls, estimate the likelihood and impact of each scenario, and compare severity scores against the organization’s risk tolerance. Leaders can then prioritize treatment decisions, assign owners, and establish timelines for the most significant exposures.
“Just because two systems are in the same store doesn’t mean they’re equally important. A problem with the payment system could stop sales, while a problem with a digital sign might just be an inconvenience. Risk assessments help businesses separate the critical issues from the minor ones, so they can prioritize what really needs attention,”explains MacDonald.“That discipline helps teams address the right risks instead of allowing the loudest or most visible issue to dictate priorities.”
The Build Cyber Resilience in Connected Retail blueprint includes the Retail Security Threat and Risk Assessment Tool, which gives security and IT leaders a structured view of threats across stores, platforms, IoT devices, and customer data. The tool maps exposures to affected systems and owners, evaluates likelihood and impact, and produces a prioritized risk register to guide investment, segmentation, and response decisions.
For exclusive and timely commentary from Info-Tech’s experts, including Donnafay MacDonald, and access to the complete Build Cyber Resilience in Connected Retail blueprint, please contact pr@infotech.com.
About Info-Tech Research Group
Info-Tech Research Group is the “get things done” partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.
To learn more about Info-Tech’s HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm’s SoftwareReviews platform.
Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm’s Media Insiders program. To gain access, contact pr@infotech.com.
For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect
View original content to download multimedia:https://www.prnewswire.com/news-releases/connected-retail-is-widening-the-cyber-attack-surface-while-security-ownership-remains-fragmented-info-tech-research-group-warns-302869497.html
The articles, information, and content displayed on this webpage may
include materials prepared and provided by third parties. Such
third-party content is offered for informational purposes only and
is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the
accuracy, completeness, timeliness, or reliability of any third-party
content displayed on this site. The views and opinions expressed in
third-party content are those of the respective authors and do not
necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays
in this content, nor for any actions taken in reliance thereon.
Users are advised to exercise their own judgment and seek independent
financial advice before making any decisions based on such content.
The third-party providers of this content are not affiliated with
Morningstar, and their inclusion on this site does not imply any
form of partnership, agency, or endorsement.
Plus, whether Nvidia, Marvell Technology, or Salesforce looks attractive after earnings.
David Sekera, CFA and Susan DziubinskiAug 31, 2026
We’re more optimistic about this stock now than we’ve been in a long time.
David Whiston, CFA, CPA, CFEAug 27, 2026Why a fan of ‘good enough’ investing isn’t losing sleep over these often-criticized financial moves.
Christine BenzAug 31, 2026Treasury Inflation-Protected Securities are sporting some of the highest yields ever, but there are a few caveats for investors to consider before making a purchase.
Jeffrey Ptak, CFASep 2, 2026Here’s how concerned investors can participate in the US stock market while managing its risks.
Dan LefkovitzSep 2, 2026
