{"id":14427,"date":"2025-07-08T06:35:00","date_gmt":"2025-07-08T05:35:00","guid":{"rendered":"https:\/\/citysecuritymagazine.com\/?p=14427"},"modified":"2025-07-08T10:06:19","modified_gmt":"2025-07-08T09:06:19","slug":"retail-reality-checks","status":"publish","type":"post","link":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/","title":{"rendered":"Retail Reality Checks"},"content":{"rendered":"<h1 style=\"font-weight: 400;\"><strong>Retail Reality Checks<\/strong><\/h1>\n<p style=\"font-weight: 400;\"><strong>\u00a0<\/strong><em>In early 2025, a series of cyber security incidents disrupted operations across some of the largest retail brands in the UK: Marks &amp; Spencer, Co-op, and Harrods. In mid-May, threat intelligence vendors claimed similar attacks in the US \u2013 though names are unconfirmed.<\/em><\/p>\n<p style=\"font-weight: 400;\">The attackers are a known group named, variously, Scattered Spider, Octo Tempest, and UNC3944, depending on the intelligence vendor. This native-English-speaking collective \u2013 believed to be a loose network of teenagers and young adults across the UK and US \u2013 was also behind high-profile attacks on MGM and Caesars casinos.<\/p>\n<p style=\"font-weight: 400;\">As usual, the incidents were labelled \u201csophisticated cyber security attacks\u201d. Yet UNC3944\u2019s methods are well-known, and the full attack narrative is unusually clear.<\/p>\n<p style=\"font-weight: 400;\">Scattered Spider act as access brokers for a Ransomware-as-a-Service (RaaS) group called DragonForce. Once access is gained, DragonForce affiliates deploy ransomware. But the breach relies more on psychology than technology: they target IT help desks, using social engineering techniques to bypass security controls.<\/p>\n<p style=\"font-weight: 400;\">While the follow-up is carefully planned, it\u2019s a stretch to call an attack that hinges on help desk impersonation \u201cadvanced\u201d. Attackers pose as staff, using publicly available information and social cues to trick help desk agents into resetting credentials \u2013 \u00a0a risk larger organisations, ironically, are more prone to. These attacks are preventable with the right processes, but few organisations implement them consistently.<\/p>\n<p style=\"font-weight: 400;\">Once inside, attackers aim for domain control. A primary target is NTDS.dit \u2013 Active Directory\u2019s core database, which stores all password hashes. Tools like Mimikatz, secretsdump.py, or Volume Shadow Copy manipulation are used to extract it. Weak or reused passwords fall quickly under offline cracking, giving attackers broad lateral movement.<\/p>\n<p style=\"font-weight: 400;\">Next: encrypt critical infrastructure. There\u2019s often a focus on virtualisation hosts \u2013 especially vulnerable if admin credentials or interfaces are exposed. Ransomware is deployed, virtual<\/p>\n<p style=\"font-weight: 400;\">machines are encrypted, and business operations halt.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Operation-specific impact<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Marks &amp; Spencer took the hardest operational hit. Online orders, mobile apps, customer services, and possibly logistics were all disrupted. The initial attack struck over the Easter bank holiday. By mid-May, online ordering remained unavailable. Financial losses were estimated at \u00a330 million, with ongoing revenue losses of up to \u00a315 million per week. M&amp;S brought in CrowdStrike, Microsoft, and Fenix24 to support recovery.<\/p>\n<p style=\"font-weight: 400;\">Co-op initially denied data loss, but later confirmed personal data had been leaked. Payment processing issues were widespread, and some areas \u2014 like the Scottish islands \u2013 reported product shortages. Co-op responded quickly, disconnecting systems to avoid ransomware spread, and recovered more rapidly as a result.<\/p>\n<p style=\"font-weight: 400;\">Harrods detected the attack early and cut off internet access as a precaution. So far, no significant operational or reputational damage has been confirmed.<\/p>\n<p style=\"font-weight: 400;\">Attribution in cyber incidents is always difficult, but UNC3944 were identified through technical indicators, leaked data, and their own communications. Selective data leaks \u2013 used to pressure victims into ransom payments \u2013 evidenced their claims.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Familiar script<\/strong><\/h3>\n<p style=\"font-weight: 400;\">This playbook \u2013 social engineering, credential reset, Active Directory compromise, ransomware on hypervisors \u2013 isn\u2019t new. It\u2019s well-documented. What\u2019s striking is how effective it remains.<\/p>\n<p style=\"font-weight: 400;\">Despite years of guidance and public awareness, the same structural flaws persist: help desks without layered verification, weak passwords, and enterprise networks with flat trust models offering all-or-nothing access. These weren\u2019t unprecedented attacks. They were predictable, preventable. What they reveal isn\u2019t attacker brilliance, but architectural fragility. Which leads to an important question: why are known weaknesses still built into critical systems?<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Why the fix isn\u2019t more cyber security<\/strong><\/h3>\n<p style=\"font-weight: 400;\">If we judge security by how well we respond to breaches, we\u2019ve already failed. These incidents make it clear: we don\u2019t need more expensive cyber solutions \u2013 we need less insecure design.<\/p>\n<p style=\"font-weight: 400;\">Too many organisations are pouring money into layered technologies in a desperate attempt to hold broken systems together. Detection, response, and managed services aren\u2019t bad \u2013 but they\u2019re compensating for deeper flaws. They\u2019re papering over cracks, and every breach makes those cracks more visible.<\/p>\n<p style=\"font-weight: 400;\">At the root of these failures is a simple truth: our systems weren\u2019t designed to be secure. They were built for convenience, speed, and scale \u2013 then retrofitted with security once the need could no longer be denied.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>The identity illusion<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Take identity. The bedrock of modern access control, and often the weakest link. For all the talk of zero trust, many organisations are still vulnerable to anyone who knows a few employee names, the help desk number, and how to sound confident.<\/p>\n<p style=\"font-weight: 400;\">Help desk impersonation was the first step in these attacks. It shouldn\u2019t have worked \u2013 but it did, across multiple large retailers. That\u2019s not a training failure, it\u2019s a process design flaw.<\/p>\n<p style=\"font-weight: 400;\">A reset process that accepts scraped LinkedIn details as proof of identity isn\u2019t secure \u2013 it\u2019s theatre.<\/p>\n<p style=\"font-weight: 400;\">Muti-factor authentication helps, but less so when it\u2019s reset by the same help desk agent who\u2019s just been manipulated. Tying brittle directories into SSO systems only amplifies the fracture radius when something inevitably breaks.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Active Directory: predictable catastrophe<\/strong><\/h3>\n<p style=\"font-weight: 400;\">The next failure is just as familiar: Active Directory. Still the foundational pillar of enterprise identity, AD is a single point of total failure and every attacker knows it.<\/p>\n<p style=\"font-weight: 400;\">Once inside, attackers extract NTDS.dit \u2013 the skeleton key to the kingdom. A few cracked hashes later, they\u2019re logged in as privileged users, forgotten service accounts, or administrators. The fact that this vital file is so often accessible is a damning indictment. Domain controllers shouldn\u2019t be this exposed. Service accounts shouldn\u2019t have excessive rights. A single cracked password should not allow a pivot across half the organisation.<\/p>\n<p style=\"font-weight: 400;\">Legacy assumptions kick in: implicit trust, flat networks, privileges handed out \u201cjust in case\u201d and never revoked. We\u2019ve known better for years. We just haven\u2019t done better.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Virtualisation: the jackpot<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Admin access in hand, attackers target the real crown jewels: virtualisation infrastructure.<\/p>\n<p style=\"font-weight: 400;\">Hypervisors like VMWare ESXi consolidate the organisation\u2019s digital estate. Compromise one host, and you\u2019ve effectively compromised everything it runs.<\/p>\n<p style=\"font-weight: 400;\">Ransomware on a desktop disrupts a user. Ransomware on ESXi shuts down the business. That\u2019s what happened at M&amp;S: encrypted VMs, compromised backups, and recovery plans not designed for this scale of impact.<\/p>\n<p style=\"font-weight: 400;\">The mistake isn\u2019t just poor patching or weak credentials. It\u2019s assuming these systems are secure by default. They\u2019re often reachable from the network, managed with domain credentials, and administered using outdated tools.<\/p>\n<p style=\"font-weight: 400;\">They\u2019re rarely segmented, infrequently audited, and almost never treated with the level of sensitivity they deserve. That makes them perfect ransomware targets \u2013 and leaves defenders improvising under pressure.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Security tooling isn\u2019t a fix<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Faced with this kind of failure, the instinct is to buy another solution: EDR, XDR, SIEM, SOAR, NGAV, and another dashboard to plug them all together.<\/p>\n<p style=\"font-weight: 400;\">But these are compensating controls, not cures. You can\u2019t fix bad architecture by stacking more products on top of it.<\/p>\n<p style=\"font-weight: 400;\">Each new tool adds complexity. Another agent to deploy. Another system to monitor. Another failure point. And as Crowdstrike\u2019s recent outage showed, even the best tools can become critical liabilities.<\/p>\n<p style=\"font-weight: 400;\">Complexity doesn\u2019t create resilience \u2013 it erodes it. Systems become harder to manage, harder to recover, and easier to break. Worse, layers of tooling create a false sense of safety. Alerting isn\u2019t understanding. Correlating logs doesn\u2019t equal insight (even if you plug AI into the picture). If your architecture allows one cracked password to collapse everything, no EDR in the world is going to save you.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Fixing the foundation<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Secure by design isn\u2019t a buzzword \u2013 it\u2019s a mindset. It means building systems to resist compromise by default, not reacting to compromise after the fact.<\/p>\n<p style=\"font-weight: 400;\">It means removing implicit trust. Designing for failure. Segmenting access. Reducing privilege. Treating administrative operations as high-risk, high-scrutiny actions every time \u2013 not just at initial login.<\/p>\n<p style=\"font-weight: 400;\">We\u2019ve known these principles since the 1970s. We still rarely see them taken seriously.<\/p>\n<p style=\"font-weight: 400;\">CHERI, a UK-supported hardware architecture, reworks how memory is managed at the chip level \u2013 removing entire categories of exploit. But we don\u2019t need to wait for future hardware.<\/p>\n<p style=\"font-weight: 400;\">Secure architecture \u2013 zero trust, least privilege, or just good engineering \u2013 is achievable today. It includes redesigning help desk flows to verify identity properly. These aren\u2019t costly changes, they just require thought, discipline, and the will to build better.<\/p>\n<p style=\"font-weight: 400;\">James Bore CSyP.\u00a0 www.bores.com<\/p>\n<p style=\"font-weight: 400;\">Security Institute \u2013 Cyber Security Special Interest Group<\/p>\n<p style=\"font-weight: 400;\"><a href=\"http:\/\/www.security-institute.org\/\">www.security-institute.org<\/a><\/p>\n<p style=\"font-weight: 400;\">\n","protected":false},"excerpt":{"rendered":"<p>Retail Reality Checks \u00a0In early 2025, a series of cyber security incidents disrupted operations&hellip;<\/p>\n","protected":false},"author":19,"featured_media":14489,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"footnotes":""},"categories":[36,2],"tags":[],"class_list":["post-14427","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","category-editors-choice"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.0 (Yoast SEO v25.2) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Retail Reality Checks - City Security Magazine<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Retail Reality Checks\" \/>\n<meta property=\"og:description\" content=\"Retail Reality Checks \u00a0In early 2025, a series of cyber security incidents disrupted operations across some of the largest retail brands in the UK:\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\" \/>\n<meta property=\"og:site_name\" content=\"City Security Magazine\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-08T05:35:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-08T09:06:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"750\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Contributor CSM\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CitySecuritymag\" \/>\n<meta name=\"twitter:site\" content=\"@CitySecuritymag\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Contributor CSM\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\"},\"author\":{\"name\":\"Contributor CSM\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2\"},\"headline\":\"Retail Reality Checks\",\"datePublished\":\"2025-07-08T05:35:00+00:00\",\"dateModified\":\"2025-07-08T09:06:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\"},\"wordCount\":1399,\"publisher\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg\",\"articleSection\":[\"Cyber Security\",\"Editor's Choice\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\",\"url\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\",\"name\":\"Retail Reality Checks - City Security Magazine\",\"isPartOf\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg\",\"datePublished\":\"2025-07-08T05:35:00+00:00\",\"dateModified\":\"2025-07-08T09:06:19+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage\",\"url\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg\",\"contentUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg\",\"width\":750,\"height\":500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citysecuritymagazine.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Retail Reality Checks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#website\",\"url\":\"https:\/\/citysecuritymagazine.com\/\",\"name\":\"City Security Magazine\",\"description\":\"News and advice for security professionals\",\"publisher\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citysecuritymagazine.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\",\"name\":\"City Security Magazine\",\"url\":\"https:\/\/citysecuritymagazine.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg\",\"contentUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg\",\"width\":2048,\"height\":573,\"caption\":\"City Security Magazine\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/CitySecuritymag\",\"https:\/\/www.linkedin.com\/company\/city-security-magazine\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2\",\"name\":\"Contributor CSM\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g\",\"caption\":\"Contributor CSM\"},\"description\":\"City Security magazine is proud to work with contributors from across the security sector and beyond, including police forces, security associations, security providers, consultants and specialists who produce a range of varied and interesting content.\",\"url\":\"https:\/\/citysecuritymagazine.com\/author\/contributor-csm\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Retail Reality Checks - City Security Magazine","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/","og_locale":"en_GB","og_type":"article","og_title":"Retail Reality Checks","og_description":"Retail Reality Checks \u00a0In early 2025, a series of cyber security incidents disrupted operations across some of the largest retail brands in the UK:","og_url":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/","og_site_name":"City Security Magazine","article_published_time":"2025-07-08T05:35:00+00:00","article_modified_time":"2025-07-08T09:06:19+00:00","og_image":[{"width":750,"height":500,"url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg","type":"image\/jpeg"}],"author":"Contributor CSM","twitter_card":"summary_large_image","twitter_creator":"@CitySecuritymag","twitter_site":"@CitySecuritymag","twitter_misc":{"Written by":"Contributor CSM","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#article","isPartOf":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/"},"author":{"name":"Contributor CSM","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2"},"headline":"Retail Reality Checks","datePublished":"2025-07-08T05:35:00+00:00","dateModified":"2025-07-08T09:06:19+00:00","mainEntityOfPage":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/"},"wordCount":1399,"publisher":{"@id":"https:\/\/citysecuritymagazine.com\/#organization"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage"},"thumbnailUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg","articleSection":["Cyber Security","Editor's Choice"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/","url":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/","name":"Retail Reality Checks - City Security Magazine","isPartOf":{"@id":"https:\/\/citysecuritymagazine.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage"},"thumbnailUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg","datePublished":"2025-07-08T05:35:00+00:00","dateModified":"2025-07-08T09:06:19+00:00","breadcrumb":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#primaryimage","url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg","contentUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2025\/06\/p3.-Harrods-Retail.jpg","width":750,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/retail-reality-checks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citysecuritymagazine.com\/"},{"@type":"ListItem","position":2,"name":"Retail Reality Checks"}]},{"@type":"WebSite","@id":"https:\/\/citysecuritymagazine.com\/#website","url":"https:\/\/citysecuritymagazine.com\/","name":"City Security Magazine","description":"News and advice for security professionals","publisher":{"@id":"https:\/\/citysecuritymagazine.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citysecuritymagazine.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/citysecuritymagazine.com\/#organization","name":"City Security Magazine","url":"https:\/\/citysecuritymagazine.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/","url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg","contentUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg","width":2048,"height":573,"caption":"City Security Magazine"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/CitySecuritymag","https:\/\/www.linkedin.com\/company\/city-security-magazine"]},{"@type":"Person","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2","name":"Contributor CSM","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g","caption":"Contributor CSM"},"description":"City Security magazine is proud to work with contributors from across the security sector and beyond, including police forces, security associations, security providers, consultants and specialists who produce a range of varied and interesting content.","url":"https:\/\/citysecuritymagazine.com\/author\/contributor-csm\/"}]}},"_links":{"self":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/14427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/comments?post=14427"}],"version-history":[{"count":2,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/14427\/revisions"}],"predecessor-version":[{"id":14508,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/14427\/revisions\/14508"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/media\/14489"}],"wp:attachment":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/media?parent=14427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/categories?post=14427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/tags?post=14427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}