With the upward trend in threats, vulnerabilities, compliance requirements, and digital innovation, it is important for businesses to understand the emerging risks, implement essential cyber hygiene controls, train the workforce to mitigate those risks, and ensure that their cyber insurance policy is designed to properly respond when a cyberattack does occur.
Organizations can start by identifying their vulnerabilities, which continue to evolve as cyber criminals become increasingly organized and savvy. Some of the top cyber threats to retail establishments include:
1. Ransomware
According to the State of Ransomware in Retail report published by Sophos, 69% of retail businesses were the victim of ransomware attacks in 2023. Ransomware is can be a short term event with long term consequences. Short-term expenses to hire a forensic investigator and pay a ransom but meaningful business interruption and long-term liability issues involving class action lawsuits and regulatory actions are a growing concern.
The U.S. Treasury Department’s Office of Foreign Assets Control maintains a list of banned threat actors called the Specially Designated Nationals and Blocked Persons List. An organization or individuals could face federal civil penalties, sanctions or jail time by paying someone on this list. A breach coach, provided as a resource through many cyber policies, can help determine if the ransom can be paid.
2. Third-Party Exposure
According to several studies, data breaches that include a third-party vendor are among the most expensive breaches reported. Organizations should be aware of all vendor usage, including what they are doing to protect against cyber crime and how they report an incident should one occur. Vendor access should be limited, especially if your business is handling personal identification information (PII). Data breaches commonly start from within a company, so it is critical for your reputation and customers’ security that businesses have a thorough vendor management program that thoroughly assesses vendor system security and protocols.
3. Pixel-Tracking Technology
Many large organizations are grappling with this, particularly those using public-facing websites with embedded pixel-tracking technologies to retarget ads to potential customers. In order to serve these personalized ads, this technology passes on customers’ info across the web. Some businesses are fully aware that this technology is embedded in their website to enable the retargeting, however, some may not be aware that their customers’ data is being shared with technology companies like Meta. As this becomes more of a common practice, it is important for all businesses to disclose these practices in the privacy policy. Failure to do so could result in privacy liability lawsuits.
4. Deep Fakes
With the use of artificial intelligence (AI), this risk is evolving quickly. Threats now go beyond reputational risk related to spoofing corporate executive in videos. Retailers now face the threat of engaging with a social media post that, unbeknownst to them, can be a deep fake. For instance, it would not be uncommon for a clothing retailer to repost or engage with a celebrity’s post on social media where they wear something from the brand. If this is a deep fake, the celebrity can claim that they have been financially harmed as a result of sharing that post and sue for reputational damages. It is important for every business to address social media approvals in their policies specific to address AI and deep fakes.
5. Security-Related Technology
There are several exposures related to measures clients are taking to prevent theft at their retail locations. Many have implemented video surveillance, tracking, and facial recognition tools to assist with theft prevention. There are risks related to a leak of the biometric data that some of this technology collects, which could open up an organization to liability and regulatory exposures.
What a Great Cyber Policy Should Include
Reputational damage is not the only aspect of an organization’s risk anymore when it falls victim to a cybercriminal. Regulatory fines, penalties, lawsuits, and paying a ransom to retrieve your data from a bad actor are all potential incurred expenses related to a cyber event.
A cyber-attack can debilitate any organization, exposing protected customer data, and putting the company at risk for law suits, regulatory actions and reputational damage.
• Security and Privacy Liability – This includes the resulting liability and legal expenses that occur from a security or privacy breach.
• Incident Response Expenses – This protection will cover costs related to IT forensics, legal assistance, crisis communications, notifications, and monitoring.
• Non-Physical Business Interruption – This will cover loss of profit, extra expenses, and fixed operating expenses following a total or partial computer outage, disruption caused by a security breach, or administrative error.
• Contingent Business Interruption – Aside from some business interruption that will occur regardless, this coverage can safeguard against any loss of profit and extra expense resulting from total or partial interruption or service degradation from a third-party service provider’s computer system caused by a security breach.
• Reputational Harm – This protection will cover loss of profits and crisis communication expenses resulting from brand damage following a security or privacy breach.
• Multimedia Liability – This coverage will address liability and defense costs incurred from multimedia activities where third parties allege damage from the dissemination of media material.
• Regulatory Defense – Penalties for non-compliance can be crippling. A great policy covers fines, penalties, and defense costs resulting from regulatory investigations and formal actions following a security or privacy breach.
• Card Industry Fines, Penalties, and Assessments – Cardholder data often includes PII, and consumers expect it to be handled appropriately. The associated costs can be hefty when this trust is put at risk. This protection will cover costs following the improper disclosure of payment card data.
• Cyber Extortion – Many threat actors will demand money from an organization in return for remediating or ending an attack. This safeguards against expenses incurred from a cyber extortion payment.
• Data Restoration – This will cover costs to repair or restore damaged or destroyed digital assets to restore operational networks and systems.
Aside from costs, an effective cyber insurance carrier will also offer solutions that assist clients with their cyber incident preparedness and response. These resources could include access to a network of established privacy breach vendors and a panel of cyber risk law firms.


