Preparing for the Inevitable: Cyber Pandemic Resilience Strategies for Retail & Restaurant Brands
What if payments went dark on Black Friday? How retail and restaurant brands can keep trading through a cyber pandemic.
Imagine your payment systems go dark on Black Friday. No payments, no sales, and your support team can’t help because their tools are down too. This isn’t sci-fi. It’s a realistic scenario in the event of a cyber pandemic.
In an era where connectivity is the lifeblood of commerce, the threat of a cyber pandemic looms large over the retail and restaurant industries. According to the JPMorgan Chase Institute, which polled 600,000 businesses, restaurants can survive on average only 16 days without sales, while retail businesses can last about 19 days. Adding to the urgency is the startling statistic from the 2023 WEF Global Cybersecurity Outlook: 93 percent of respondents expect a catastrophic cybersecurity event within the next two years.
2023 WEF Global Cybersecurity Outlook: 93 percent of respondents expect a catastrophic cybersecurity event within the next two years.
The retail sector’s increased dependency on technology, especially with the rise of cashless transactions and digital kiosks, magnifies the risk. This guide aims to arm technology stakeholders within retail brands with strategies to bolster their defences and ensure operational continuity during cyber crises and everyday disruptions.
Some sobering statistics to consider outside of a cyber pandemic:
- 75% of Shopwave support tickets result from inadequate internet, network infrastructure or network security. Skimping on this critical aspect to allocate funds to aesthetic or marketing improvements can leave your business vulnerable.
- In 2023, 36.5% of retailers face one or more instances of downtime per week, while 57.2% deal with downtime 2–3 times per month (Newrelic). This is more than any other industry polled.
- The average cost of a technology outage is $9.95 million.
Consider the following measures to fortify your retail technology
Network Segregation & Security:
- Isolate your POS and payment hardware on a private network, out of reach from customer usage, music systems, or third-party apps.
- Establish a firewall, conceal your SSIDs, and restrict connections to a whitelist of known URLs and hardware MAC addresses.
- Regularly monitor and control your network to prevent unauthorised access. Use an active threat detection and endpoint security product, e.g. SentinelOne.
- Maintain physical security for your network ports, network cabinet and access points.
- Don’t run legacy software, operating systems or firmware. Upgrade to the latest versions as soon as you have tested them using your store blueprint setup at HQ.
Ditch Reliance on Wi-Fi where it isn’t needed:
- Outside of mobile terminals, opt for wired connections over wireless. Keep Wi-Fi as a contingency plan, and invest in ethernet to USB-C or Lightning adapters for flexibility and an easy life.
Internet & Connectivity Redundancy:
- Prioritise fibre optic connections for their reliability and speed.
- Implement cellular networks like 4/5G as a backup, and consider satellite options such as Starlink for an extra layer of assurance at rural sites.
Resilient POS & Supporting Apps:
- Ensure your POS, self-serve kiosks, digital displays and printers can function without an internet connection. All Shopwave Apps have this capability.
Bulletproof payments:
- Have robust payment methods that include offline processing capabilities.
- Train staff to revert to non-integrated or traditional cash transactions if necessary. Many businesses close unnecessarily if card payments fail.
- Consider backup digital payment solutions.
Ops, Staff Training & Chaos Testing:
- Prepare your team to maintain operations with minimal tech or third-party assistance.
- Simulate tech-failure scenarios to test and improve response strategies.
- Hard mode: Attempt to maintain service during a simulated power cut and/or internet failure. If you can handle comms, most tablets and payment terminals can revert to battery power.
- See it. Say it. Sorted. Ensure comms and training are in place for HQ and store teams. - Report unexpected changes to hardware or networking. Have protocols around maintenance and unexpected access requests. - Eliminate password resuse & ensure staff do not distribute sensitive information via social media. - Simulating a phishing attack to see who within your company is susceptible.
A cyber pandemic may not be a question of “if” but “when,” and the level of preparedness will dictate a retail brand’s ability to withstand and quickly recover from such an event. By implementing robust and redundant network infrastructures, prioritising offline functionalities, and maintaining a trained adaptable workforce, retailers can create a resilient environment that not only prepares them for the worst-case scenarios but also enhances their day-to-day operational stability.
Investing in these precautions is not merely a defensive measure. It’s a strategic business decision that can mean the difference between continuity and closure in the face of cyber threats. When the inevitable disruptions occur, your brand could stand as a bastion of resilience, a testament to foresight and preparation in an unpredictable digital landscape.
Upgrade your retail and payment infrastructure for resilience:
Let’s talk retail tech. Your offices, our London HQ, or over a stiff drink (our treat) at a venue of your choice with the Shopwave CEO and CTO. No pitches, no sales talk. Book your spot at medium@getshopwave.com.
https://www.youtube.com/watch?v=kU0SmxKucCw
Pain: The average cost of a technology outage is $9.95 million.
Disclaimers:
- You don’t need it until you need it. Despite what a salesperson may tell you, no service can guarantee 100% uptime at the best of times. You will struggle to get 4 or 5 nines with an unlimited budget. Add a cyber pandemic or warfare to the mix, and things could get spicy fast. You can make a considerable difference prepping operationally before spending a penny/cent on new products.
- This piece is not intended to be a comprehensive checklist or guide to IT security, nor is it scaremongering. The scale of some retail and restaurant hacks is eye-watering:
- TJ Maxx: 45.7 million credit and debit card details.
- Panera Bread: Reports of up to 37 million customer records.
- Sonic Drive-In: 5m card numbers.
- Door Dash: 5m customer records.
- Dunkin’ Donuts: 300,000 customer records.
https://www.youtube.com/watch?v=H_tJNVc07Jc
Zen: Resilient and secure infrastructure.