Marks & Spencer
After a cyberattack, the retailer had to suspend online orders for weeks; product availability and logistics were affected. The company later put the impact on operating profit at around 300 million pounds.
According to an analysis by the security provider Yarix, 12.2% of recorded cyberattacks in Germany in 2024 targeted retail and e-commerce, second only to manufacturing. Unlike hospitals or utilities, retail has no KRITIS sector of its own and no statutory testing duty. The pressure comes from contracts: anyone accepting card payments falls under PCI DSS, and Requirement 11 demands a penetration test every year and after every significant change. Add GDPR for customer accounts and loyalty programmes, plus the NIS2 pressure that large groups pass down to franchise partners and service providers through supplier audits.
Sources: Yarix analysis 2024, cited via security-insider.de; PCI DSS v4, Requirement 11.
Network sockets under the counter, card terminals nobody checks for tampering, a guest Wi-Fi on the same segment as the merchandise system. Someone in a hi-vis vest with a clipboard saying they are swapping the card reader rarely gets stopped.
POS infrastructure and card terminals for tampering, network segmentation between checkout, Wi-Fi and store IT, and the fake service technician scenario as an agreed social engineering test.
The transition from shop floor to back office is often a curtain or an unlocked door. Behind it: the store PC with someone logged in, shift plans, sometimes the safe. Temporary staff do not know all their colleagues after two weeks.
Tailgating and pretext scenarios during off-peak hours, screen locks and accounts on the store PC, and a phishing simulation built for seasonal and store staff rather than head office.
Unlocked network cabinet, access points within reach, suppliers coming and going through the loading bay without anyone signing them in. The cabinet is rarely the target, but often the route.
Physical access to network and server components, open ports and default passwords on store devices, the connection to merchandise management and head office.
Customer accounts, loyalty programmes, vouchers and returns logic form their own attack space: account takeovers, points fraud, interfaces to payment and logistics, franchise partners with remote access to central systems.
Web application pentest of shop and loyalty programme, permissions at the interfaces to payment providers and stores, third-party access from partners and service providers.
Two publicly documented cases from recent years, deliberately far apart in size.
After a cyberattack, the retailer had to suspend online orders for weeks; product availability and logistics were affected. The company later put the impact on operating profit at around 300 million pounds.
An employee opened an email containing a supposed job application. Malware installed itself in the background and the store's operations came to a halt. It took neither a corporate group nor a head office, one email was enough.
The attack scales. The defence has to as well.
Based on public reporting. accessgranted was not involved in these incidents.
Requirement 11 of PCI DSS calls for regular testing of the security of systems and networks. For the pentest, that means:
| Requirement | What it means | How we cover it |
|---|---|---|
| At least annually | One penetration test per year, plus another after every significant change to infrastructure or applications. | Fixed test cadence, re-test after changes |
| External and internal | Attacks from outside against reachable systems and from inside the cardholder data environment. | Infrastructure pentest, store network included |
| Application layer | Web applications and interfaces carrying card or customer data, tested against the common vulnerability classes. | Web application pentest of shop and portals |
| Segmentation | Proof that the cardholder data environment is genuinely separated from the rest of the network, for example from the guest Wi-Fi in a store. | Segmentation test on site and from head office |
The report maps every finding to the matching requirement, so you can hand it to your PCI assessor as it is. That retail needs more political attention was recently raised by the CDU Economic Council, as reported by Handelsblatt: many stores, networked checkouts, sensitive payment data.
In many retail businesses, physical security and IT security sit in two departments that rarely meet. The break-in happens exactly in the gap between them.
Knows shrinkage, cameras, locking schedules and behaviour at the gate. Sees the network cabinet in the stockroom as an IT topic.
Knows firewalls, POS software and the shop. Sees the back office door as the store manager's problem.
A combined assessment gives both the same report. Who fixes which item then sits as a line in the action list instead of getting stuck as a question of principle between two departments.
One location, one visit, four angles. Spot checks at further stores on request.
Access to back office, stockroom and network cabinet, tampering with card terminals, how staff respond to supposed technicians and suppliers.
Phishing and pretext scenarios for store and seasonal staff, evaluated per location rather than per company.
Online shop, customer accounts, loyalty programme and the interfaces to payment and logistics, following OWASP and mapped to PCI DSS.
Store network, segmentation towards the cardholder data environment, remote access by franchise partners and service providers.
For chains with high staff turnover, we also run the phishing simulation on its own, evaluated per store, with a report within 48 hours.