

The retail sector is operating under extreme pressure as the threat landscape rapidly intensifies. Across all industries analysed in Security Navigator 2026, Retail experienced the single largest year‐on‐year surge in cyber extortion (Cy‐X) victims: + 84% rising to 311 confirmed victims between October 2024 and September 2025 - the highest relative increase of any sector.
Retailers face a dual-front threat. While 40% of incidents originate externally, the majority of detections now stem from internal sources (57%), driven by endpoint misuse, misconfigurations, and identity‐related incidents. End‐user devices illustrate this perfectly: they now represent 52% of all impacted assets, more than any other category. This report distils the most relevant retail insights from Security Navigator 2026, exploring the intersection of external criminal pressure, internal weaknesses, and systemic supply‐chain dependencies that uniquely heighten risk for the retail sector.
Download the Retail in Focus Report


In the event of a cyber attack that compromises a store-front technology, such as self service tills and scanners, a retailer is faced with an immense task. Where computers might have a standardised reboot process, these specialised devices often require complex rebooting procedures. So, if they are taken out by an attack or compromised and forced to be taken offline, the process of getting them safely back up and running is a manual one – and it can be painfully slow.
Birgitte Skorge Steen - Head of Microsoft Strategy and Sales UK at Orange Cyberdefense

