Aug 18 2026
Security

Retailers Are Rebuilding Endpoint Security To Combat Cyberthreats and Physical Shrink

Retailers are vulnerable to attack from multiple angles, which makes endpoint management a complex challenge.

“If you’re vulnerable, they will come.” That was the finding of the Verizon 2025 Data Breach Investigations Report: Retail Snapshot. And experts confirm that’s the case for retailers’ IT leadership, who are striving to rise to the challenge of keeping pace with evolving cyberattacks targeting them. Verizon also reported a 15 percentage point increase in retail cyber incidents involving third parties, with attackers increasingly pursuing credentials and internal business information rather than only payment card data.

Endpoint detection and response, device management, and network segmentation strategies are helping retailers strengthen both cybersecurity and traditional loss prevention efforts. artificial intelligence for cybersecurity is not a new concept in retail, but its sophistication is increasing as cybercriminals increase theirs.

“Our peers have been using AI for nearly 20 years to improve detection. What we’re seeing now is an evolution, and maybe the pace of evolution is accelerating,” says Dick O’Brien, principal intelligence analyst for the Symantec + Carbon Black Threat Hunter Team at Broadcom. “From our perspective, we began using AI to identify malicious files, then moved to identifying malicious behavior, even malicious behavior involving legitimate applications. Now, AI-powered detection can learn what constitutes typical activity on your network, then lock down unused functionality and alert you to outliers.”

Click the banner below to read the recent CDW Cybersecurity Research Report.

 

He adds that most recently, they’ve used AI to correlate alerts from multiple products and control points, ultimately giving end users a singular and more coherent picture of an attack in progress. 

“For the average retailer, that means it reduces the pressure on their security teams, making the workload a lot more manageable, which is huge in an era where the number of threats just continues to grow.”

Here’s how AI solutions are helping retailers keep up with cyberthreats and physical shrink.

Unified Endpoint Management Isn’t One-Size-Fits-All

A specific challenge retailers face, O’Brien says, is a diverse array of systems and number of sites, more than other sectors have to secure. So, unified endpoint management becomes more important for retail. But it doesn’t mean one size fits all across retailers or even across device types.

“Unified doesn’t mean identical policy. A self-checkout terminal should be locked down far harder than a mobile worker’s laptop. It means you have a single authoritative list of what exists and you can express and enforce policy per device class from one place,” he says.

READ MORE: How to improve visibility throughout your ecosystem.

The diversity of the tools the industry uses “strengthens the argument” for unified endpoint management, he adds.

Unifying systems is a great time to also analyze the whole potential attack chain, he says. “What’s the one capability retailers are underinvesting in right now that would make the biggest difference? It’s probably correlation across the whole attack chain: endpoint, network, cloud and data in one picture rather than four.”

O’Brien says individual tools are no longer a strong solution, calling them “insufficient.”

“Having the individual tools is no longer sufficient. Having them produce a single, high-fidelity incident instead of four disconnected alerts is what’s needed. Based on our experience investigating breaches, that level of visibility is now the bare minimum, not an aspiration.”

Dick O’Brien
What’s the one capability retailers are underinvesting in right now that would make the biggest difference? It’s probably correlation across the whole attack chain: endpoint, network, cloud and data in one picture rather than four.”

Dick O’Brien Principal Intelligence Analyst, Symantec + Carbon Black Threat Hunter Team, Broadcom

Keeping Up With Evolving Types of Attacks

AI-based advancements are “coming into their own,” O’Brien says, in detecting malware-free intrusions.

In a recent attack he investigated, attackers didn’t use malware at all until they were attempting to deploy ransomware. They got in through an unpatched, internet-facing collaboration server, ran PowerShell, and established command and control through three commercial remote monitoring tools before moving laterally to standard Windows file sharing via a remote desktop, he says.

“Then they used a well-known open-source sync utility to exfiltrate data to the victim’s own cloud storage account, flipped the sharing permissions to ‘anyone with the link,’ and pulled it down from outside the network,” he explains. “Not one element of that chain is catchable by traditional file scanning. What catches something like this is driven by AI: behavioral analysis in context, parsing what’s actually in a command, de-obfuscating and emulating a script end-to-end before it runs, analytics trained on attack patterns that can flag activity that’s similar to known intrusions rather than identical, and baselining that notices a remote access tool nobody in your business has ever used.”

Prediction Is Essential in an Industry With Seasonal Fluctuations

In addition, prediction tools are helping retailers safeguard their systems.

“We trained a model on around 500,000 documented attack chains, treating each event in a breach the way a language model treats a word in a sentence,” O’Brien says. “It predicts the attacker’s next three or four moves. That moves you from cleaning up what already happened to closing doors in front of the attackers.”

Retailers have to navigate unique challenges in peak seasons as well, a time when a system already familiar with what’s typical and what is an outlier can make the difference between a security decision and a board-level one, O’Brien notes. “Predictive detection changes the containment decision itself. If you know the attacker’s likely next moves, you can block those specific behaviors instead of shutting down the network and reimaging the estate.”

The cost of doing nothing is immeasurable in retail, beyond dollars. “They now go looking for a small number of high-value assets that give them enough leverage to extort you. In retail, that's payment data, customer records, supplier terms,” O’Brien says. “Losses aren’t just financial. You can lose reputation, lose trust.”

benedek/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.