Sep 25 / Latest News

Security Mandates — Not Tools — Determine Whether Retail Chain Cyberattacks Spread Across Locations

A new VikingCloud survey of 200 U.S. and European retail and restaurant chains found that security tools had no measurable impact on whether cyberattacks stayed contained to a single location. Only one factor mattered: whether corporate mandated a single security policy across every site.

Eighty‑six percent of chains experienced a cyberattack in the past year, and 77% of those saw the intrusion move beyond its starting point — into other stores, corporate systems, or shared vendors. Spread was worst among the largest operators: 89% of companies with 2,500 or more locations reported multi‑site impact, compared with 71% of smaller chains.

Despite this, 83% of leaders described themselves as confident in their security posture. Confidence rose with the number of tools deployed, even though none of the 13 measured technologies reduced spread. Nearly half of respondents lack real‑time visibility across all locations, and 40% say they would likely miss an active threat at their least‑monitored sites.

Only 51% of chains require every location to follow a corporate security policy. A third allow sites to interpret guidelines as they wish, and 15% let each location write its own rules. Even among companies that own every store outright, 41% still do not mandate a unified policy.

Where a mandate existed, 64% of attacks spread beyond the first site. Without one, spread jumped to 89%. Among franchise and mixed‑ownership brands, a mandate made attacks three times more likely to stay contained. Corporate‑owned chains saw no measurable difference, likely because consistency is built into their operating model.

Ninety‑one percent of respondents said at least one material incident never reached executive leadership or the board. Fear of professional repercussions was the most common reason. The survey also found that 80% of chains open new locations before central monitoring and enforcement are in place — a gap that persists regardless of size or policy maturity.

Kevin Pierce, VikingCloud’s President and COO, summarized the findings: “You cannot monitor your way out of blast radius. You have to govern.”