The winners and losers in the retail industry are often separated by the thinnest of lines. Margins are tight, competition tough and consumer preferences constantly shift in unpredictable ways. In a hyper-connected, social-media-obsessed world, a single security incident that hits a retailer can be the difference between profit and loss.
According to IBM’s Cost of a Data Breach Report 2023, the global average cost of a breach rose to $4.45 million last year, a 15% increase over three years. That figure is almost certainly low, since certain costs are difficult to measure, such as an erosion of public trust.
Yet, when researchers attempt to measure things like trust and fear, the findings show that the impact of a breach affects many consumers’ states of mind. According to research from the Binghamton University School of Management, data breaches can trigger fear in consumers, and if the breach is large enough, fear and loss of trust tend to correspond with drops in the breached company's stock price.
But it’s not just security problems that can sink a retail business, of course.
Retailers face a slew of other threats. Slow transaction times, supply chain issues, and even the failure to move swiftly to capitalize on new product/service opportunities can put retailers at a competitive disadvantage against more nimble competition.
These challenges have triggered digital transformation initiatives across the retail sector.
Why digital transformation efforts often fail to deliver on expectations The rise of e-commerce has sparked transformation efforts throughout retail organizations, from warehouses to offices to retail sites, but the harsh reality is that many of those initiatives fail. According to a 2022 study by McKinsey, which surveyed more than 600 businesses that have embarked on digital transformation journeys, only 20% managed to attain three-quarters or more of the revenue gains they had anticipated going into the transformation project. At the same time, only 17% managed to drive down costs by three-quarters or more of what they had expected.
According to McKinsey, one of the main reasons digital transformation projects fail is because they are not embedded throughout the organization. Digital transformation tends to be isolated in departments, with efforts uncoordinated, often duplicated, and even worse, often at cross-purposes with other projects siloed somewhere else in the organization.
To keep up with competitors in the digital era, retailers must synchronize their digital transformation efforts so they can deliver on three essential characteristics that must be maintained to succeed in an economy where even the smallest brick-and-mortar business relies on maintaining a positive reputation in the digital economy.
Those three key essential characteristics are value, convenience, and trust.
How legacy systems undermine value, convenience, and trust during digital transformation To compete today, retailers must provide their products/services at the right price point (value) at the right time, usually “right now” (convenience), in a secure manner that doesn’t expose consumers’ personal information to thieves, scammers, and other bad actors (trust). To continue to provide consumers with an experience that delivers value, convenience, and trust, retailers are investing heavily in modern IT tools, moving systems to the cloud, containerizing applications, and interconnecting every part of the value chain from warehouses to websites to brick-and-mortar retail sites. But legacy constraints threaten to undermine the benefits of transformation.
Digital transformation may provide a competitive advantage against more technophobic competitors, but only when value, convenience, and trust are maintained during the transformation process. If, on the other hand, retailers move too many sensitive assets into poorly secured systems, their attack surface expands, and a single security failure could cause significant damage.
This is why legacy technologies can be especially dangerous in retail environments. Attackers exploit known vulnerabilities, i.e. vulnerabilities that should have been patched or closed with updated tools, so often that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintains a catalog of known vulnerabilities that attackers can exploit or have already exploited. Legacy tools and legacy devices often leave known vulnerabilities exposed.
Security vulnerabilities are just one part of the equation, though, since retailers must also deliver fast transaction times and a seamless retail experience, whether in person or online. To maintain value, convenience, and trust, retailers must pull off the balancing act of migrating to better systems without impacting customers’ experiences. Otherwise, the result will be a drop in traffic to online stores, abandoned shopping carts, and less foot traffic to physical retail stores.
Retail organizations that want to successfully transform into digital- and data-powered businesses must modernize in a way that migrates key systems to the cloud and blankets their organizations with connectivity, while at the same time cutting costs and maintaining top-notch retail experiences. In other words, retailers need to redesign their IT stack so adding mission-critical features like updated security and better connectivity is as easy and reliable as flipping on a light switch.
Additionally, retailers face a range of other challenges that impact their ability to consistently deliver value, convenience, and trust to their customers. These challenges include:
● Geographical complexity: Any business larger than a mom-and-pop store must deal with geographical complexity, needing to deliver secure connectivity to multiple locations and multiple types of locations (i.e., headquarters, branch offices, warehouses, retail sites, etc.).
Retailers also require high-performing and secure connectivity for multiple geo-diverse locations. They need to connect retail locations to each other and to a central data center. However, using legacy MPLS or VPNs, as has been common so far, is expensive, complicated, unreliable, and insecure.
● Climbing costs: Over time, the cost of legacy technologies climbs sharply. Newer technologies deliver new features that better match current business conditions and also tend to be cheaper to maintain and manage while also offering a lower total cost of ownership (TCO).
For instance, retailers need to minimize their costs while increasing their employee productivity. But MPLS links are costly and VPN tunneling is complex. Alternatively, relying on the public internet is inefficient and unreliable because ISPs prefer cost-savings over performance, which could result in packet loss, jitter, or latency, any of which can torpedo real-time, mission-critical applications. Providing secure connectivity alone can be a huge cost center.
● Administrative overhead: Legacy, non-cloud-native technologies have sky-high administrative overhead. Whether delivering complimentary guest Wi-Fi or connecting to cloud-based, mission-critical business systems, retailers’ IT teams need to ensure high performance and security, otherwise the business will lose revenue. Procuring, managing, and updating a tech stack that answers those needs is a huge hassle. In addition, the transition of data center services, like voice-over-IP (voice over internet protocol (VOIP)) and point of sale (PoS), to the cloud requires IT to learn and manage a completely new set of tools.
● Evolving threats: Cybersecurity is a constant arms race between legitimate businesses and online crooks. Today, the threat landscape is more dangerous and difficult to manage than ever before, with ransomware groups, state-sponsored malware, and artificial intelligence (AI)-generated targeted malware representing just a few of the emerging threats that legacy tools can’t counter.
● Compliance requirements: Various regulations mandate that retailers protect personal and Payment Card Industry (PCI) (Payment Card Industry (payment card industry (payment card industry (payment card industry (PCI))))) information related to retail memberships and loyalty programs via a strict set of security requirements.
Why SASE is the key to secure, speedy, growth-oriented digital transformation To be successful over the long haul, digital transformation projects should be integrated across organizations and constructed on a secure foundation that was designed to face today’s retail challenges. One technology has differentiated itself as the key technology that enables retailers to consistently deliver value, convenience, and trust while navigating the choppy waters of digital transformation: secure access service edge (SASE).
SASE consolidates networking and security features into a single platform, so adopting SASE as the foundation of unified digital transformation enhances your chances of success.
But not all SASE is created equal.
Many providers force you to stitch together disparate tools from multiple vendors. If every single one of these tools were best-in-class, perhaps this approach would make sense. It would still be a management nightmare and costs would certainly escalate, but at least you could make the case that you were getting the best across the boards.
In the real world, even if each tool is best in its class, will it remain so when integrated with other tools? In the real world, partnerships are rarely driven by the desire to stitch together the best of the best, but rather are often linked to cover gaps in a portfolio. In the real world, what one vendor calls best in class in one sector may not live up to that billing when facing different challenges in a different market sector.
One approach is to seek a vendor that has proven with each successive product rollout and service upgrade that they know how to architect best-in-class tools from the ground up that can be layered on top of a common, security-first, cloud-native platform.
Deploying platform-based, single-vendor SASE as the foundation for digital transformation allows retailers to shift their focus away from IT management back to their own core business, strengthening competitive advantages and innovating for growth.
Single-vendor SASE supports site setups in hours or days – rather than weeks or months for competing technologies – and single-vendor SASE platforms help retailers future-proof IT, serving as a simple, scalable, and secure architecture on which to build.
What to look for in a SASE platform When Gartner outlined the concept of SASE in 2019, the research firm noted that enterprises need a simple service that consolidates key networking and security features into a single solution. Since that time, the market has rapidly expanded, and Gartner predicts it will expand at a 29% compound annual growth rate (CAGR) through 2026, to reach $25 billion in 2027.
When evaluating SASE platforms, retailers must assess how any SASE solution will help them meet the challenges of the modern retail environment.
What retailers need from SASE networking Retailers need to achieve several capabilities to compete in today’s digital retail world. Retailers need blazing-fast transaction speeds for both in-store and online transactions; they need to blanket all of their locations around the globe with reliable bandwidth; and they must accommodate remote and mobile employees, as well as partners and suppliers, all of which SASE enables through cloud-native WAN connectivity, WAN optimization, SaaS acceleration, and other features.
Key questions to ask SASE providers about networking: ● Does the SASE platform deliver reliable, stable SD-WAN connectivity to geo-diverse store locations and facilities, while improving efficiencies and reducing costs? ● Does the SD-WAN network connect to a private backbone that will deliver connectivity to your region and also connect any of your sites to any other of your sites, partner sites, or service-provider clouds located anywhere around the world through a global footprint of points of presence (PoPs)? ● Does the SASE solution have the ability to route traffic based on quality-of-service (QOS) bandwidth prioritization policies that the retailer sets? ● Does the SASE solution accelerate applications, such as PoS, so that they function as truly real-time apps? ● Are features such as transmission control protocol (TCP) acceleration, packet-loss mitigation, and route optimization standard?
What retailers require from SASE security Speed cannot come at the expense of privacy and security, especially in heavily regulated sectors like retail. The following questions will help you balance your networking and security needs.
Key questions to ask SASE providers about security: ● Are connections private, encrypted, and reliable? ● Does the solution include advanced data protection to safeguard sensitive information such as PoS transactions, membership data, inventory management, guest/customer Wi-Fi, and compliance? ● Does the solution streamline compliance through policy enforcement and automated reporting? ● Does the solution deliver next-generation security features, such as zero-trust access, secure web gateway (SWG) filtering for guest Wi-Fi, next-generation anti-malware (NGAM) threat protection, firewall-as-a-service (FWaaS), threat prevention, cloud access security broker (CASB), data loss prevention (DLP), remote browser isolation (RBI), endpoint protection platform (EPP), and extended detection and response (XDR)? ● Do these converged security features provide a holistic approach to protecting users and data, ensuring compliance and detecting attacks, or are they provided by a lightly integrated patchwork of providers?
Comments