He adds that most recently, they’ve used AI to correlate alerts from multiple products and control points, ultimately giving end users a singular and more coherent picture of an attack in progress.
“For the average retailer, that means it reduces the pressure on their security teams, making the workload a lot more manageable, which is huge in an era where the number of threats just continues to grow.”
Here’s how AI solutions are helping retailers keep up with cyberthreats and physical shrink.
Unified Endpoint Management Isn’t One-Size-Fits-All
A specific challenge retailers face, O’Brien says, is a diverse array of systems and number of sites, more than other sectors have to secure. So, unified endpoint management becomes more important for retail. But it doesn’t mean one size fits all across retailers or even across device types.
“Unified doesn’t mean identical policy. A self-checkout terminal should be locked down far harder than a mobile worker’s laptop. It means you have a single authoritative list of what exists and you can express and enforce policy per device class from one place,” he says.
READ MORE: How to improve visibility throughout your ecosystem.
The diversity of the tools the industry uses “strengthens the argument” for unified endpoint management, he adds.
Unifying systems is a great time to also analyze the whole potential attack chain, he says. “What’s the one capability retailers are underinvesting in right now that would make the biggest difference? It’s probably correlation across the whole attack chain: endpoint, network, cloud and data in one picture rather than four.”
O’Brien says individual tools are no longer a strong solution, calling them “insufficient.”
“Having the individual tools is no longer sufficient. Having them produce a single, high-fidelity incident instead of four disconnected alerts is what’s needed. Based on our experience investigating breaches, that level of visibility is now the bare minimum, not an aspiration.”
