Aug 10 2026
Security

How Retail IT Leaders Are Using Identity and Access Management to Reduce Loss Prevention Risks

With attackers adding new weapons to their arsenals, retailers are turning to other cybersecurity solutions to ward off attacks and build resilience.

For years, the focus for retail loss prevention has centered primarily on physical prevention technologies such as surveillance cameras and point-of-sale monitoring. But with the risk of cyberattacks, the focus is shifting to loss prevention in retail digital landscapes. Now, identity and access management (IAM), multifactor authentication (MFA) and privileged access controls are becoming essential components of modern loss prevention strategies.

“Historically, retail loss prevention was about securing physical doors, lockboxes and cash registers. Today, high-value inventory, financial records, and discount authorizations are all software-defined,” says Sandeep Kumbhat, vice president and global field CTO at Okta, where he supports product strategy and solution design for global customers, focusing on AI security, identity and cybersecurity. 

The Verizon Data Breach Investigations Report found that 31% of breaches begin with software weaknesses, with ransomware specifically growing in retail, accounting for up to 48% of breaches within the industry.

Here’s how retailers are using the newest tools to prevent loss in an increasingly vulnerable digital environment.

Click the banner below to lay the data governance foundation needed for artificial intelligence.

 

Trends Are Shifting for Cyberattacks Targeting Retailers

Okta’s 2025 Customer Identity Trends Report shows nearly half (46%) of all digital registration attempts across the globe are classified as malicious identity attacks. “For retail and e-commerce, this battlefield is exponentially worse. Bad actors are not just trying to log in to existing accounts; they are deploying massive, automated botnets to create fraudulent new accounts at scale,” Kumbhat says. He explains that these accounts and compromised credentials act as the basis for multiple types of attacks, including:

Loyalty and promo abuse. 

Fraudsters use automated credentials to mass-register and drain signup bonuses, gift card balances and promo rewards.

Inventory hoarding.

Attackers deploy shopping bots to buy up high-demand, limited-run inventory instantly using fake credentials, forcing physical retail shrinkage and massive digital cart abandonment losses.

Refund fraud.

Using credential stuffing to take over trusted customer accounts, bad actors fabricate virtual receipts and process fraudulent returns directly to clean bank cards or untraceable gift cards.

There’s also a disconnect between customer trust and perceived customer trust, further exacerbated when cyberattacks derail the trust that does exist. PwC’s 2024 Trust Survey reports that the majority (90%) of business executives think customers trust their companies, when only 30% of consumers actually do.

DIVE DEEPER: Read more about how retailers are modernizing their loss prevention strategies.

Zero-Trust Security Is Changing How Retail IT Leaders Combat Loss

IAM addresses a leading gap in security, helping with “systemic overprovisioning and fragmented, unmanaged nonhuman identities, which are the two most common gaps retailers are facing,” Kumbhat says. Overprovisioning often occurs as retailers hire seasonal employees, who may account for up to 50% of their staff, and as they deal with generally high employee turnover rates in the industry. This creates a “massive lingering attack surface,” Kumbhat says, as old accounts aren’t deprovisioned right away.

“And, when you factor in the nonhuman identities or AI agents, that attack surface multiplies. Nonhuman identities, such as API keys, third-party vendor integrations and emerging AI shopping or inventory agents, vastly outnumber humans,” he adds. “These are often overprovisioned with permanent, high-privilege service accounts that lack human oversight, creating massive backdoor vulnerabilities.”

Faster Solutions Must Maintain Security Without Holding Up Sales

There isn’t much a potential customer will tolerate by way of delays in the buying process, either in person or digitally. The entire session must be secured whether at a physical kiosk in a retail setting or online. IT leaders must consider the fastest and least prohibitive solutions to maintain security without slowing down the buyer. 

“It requires a shift toward low-friction, passwordless, continuous trust models. Forcing a frontline retail worker to type in passwords or wait for SMS one-time passcodes every time they step away from a terminal completely stalls checkout lines,” says Kumbhat. To replace such high-friction MFA, biometrics and passwordless standards can help.

“This involves using secure physical badges paired with biometrics, such as FastPass or passkeys, to verify identity in milliseconds, combined with continuous session evaluation that automatically locks the terminal the second anomalies like geographic or behavioral mismatches are detected,” he says.

30%

The percentage of customers who trust the companies with whom they do business

Source: pcw.com, “PCW’s 2024 Trust Survey: 8 key findings,” March 12, 2024

What Experts Recommend IT Leaders in Retail Do Right Now

Security initiatives can be overwhelming and expensive. The most effective move to make right now, Kumbhat says, is to centralize your workforce and partner directories to automate provisioning and deprovisioning, the area with the greatest potential for cybersecurity activity.

“When seasonal or frontline staff leave, their access to POS, stockroom systems and inventory application programming interfaces must be instantly killed,” he says. “Backing this up with a passwordless, biometric-first authentication experience eliminates the threat of shared PINs, written-down passwords and simple credential phishing — the easiest ways bad actors slip through the front door.”

Closing this gap is just one step in a broader strategy that should be an ongoing conversation within retail IT leadership teams to ultimately secure entire sessions regardless of identity, physical location or intent. The future of retail companies depends on it in an industry rife with bad actors.

visualspace/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.