Mitigating The Security Risks Of Black Friday 

One of the biggest shopping events of the year is looming where busy retailers and eager shoppers are gearing up for Black Friday. Limited time offers encourage higher purchase numbers and rising sales, but businesses must also be aware of the increased risk of cyber attacks during this period.

Website traffic, online transactions and data transfers significantly rise during Black Friday as consumers take advantage of the unmissable deals and discounts on offer, and with more shoppers expected to shop online rather than in-store, retailers are a tempting target for cybercriminals looking to disrupt their operations. Businesses focus on allowing customers to conduct online transactions but they often fail to implement adequate cybersecurity measures, leaving them vulnerable to attacks. 

Protecting Data & Information

It’s paramount for retailers to ensure the security of their customer's data and personal information. Dominik Birgelen, CEO of oneclick AG explains that retailers' success during the Black Friday period depends on performance and security. He explains that “The right solutions, infrastructure and technical setup will support retailers during this time by ensuring lightning-fast and responsive e-commerce websites as well as uninterrupted service during peak demand.” He also adds that to effectively mitigate internal and external cybersecurity risks “Retailers need robust solutions that not only allow them to secure their assets but also to consistently monitor and spot malicious activities.”

The consequences of a cyberattack not only negatively impact sales, but are also extremely damaging to a retailer’s reputation, putting them at risk of losing their customers’ trust and loyalty. Some of the most common cyber security threats facing retailers include credential threats, phishing and bot scams, and insider threats

The majority of online users think that retailers are personally responsible for tackling these problems. Michael Jenkins, CTO at ThreatLocker agrees, stating “Organisations are responsible for protecting the data of their stakeholders, employees and customers, making them liable for implementing data breach prevention methods.”

Human error remains one of the largest contributors to cyber attacks, with 9 out of 10 of all data breaches being caused by employee mistakes. Michael also adds that “While operating on a tight schedule, an employee opening an inappropriate link, mistakenly giving users access to private information, or downloading compromised data can cause significant downtime, severely limiting businesses' ability to capitalise on Black Friday opportunities, loss of profit and damage to reputation.

“Businesses should prepare for the surge in cyberattacks during Black Friday by first educating their employees about potential threats and behaviours that make them vulnerable to ransomware and other potential threats.”

A Zero Trust Strategy

To effectively mitigate internal and external cybersecurity risks over the festive period, retailers need robust solutions that not only allow them to secure their assets but also to consistently monitor and spot malicious activities. Michael recommends zero trust, explaining that “The concept of ‘Zero Trust’ seeks to eliminate the idea of default access and trust. Just because a device is within a trusted firewall, network, or software, it does not mean that it should be trusted automatically. Zero Trust means that internal or external access is independently verified.

“Zero Trust is a comprehensive cybersecurity strategy that addresses both software and network vulnerabilities. Allowlisting and Ringfencing are examples of tools that, respectively, limit a single person's access to software and applications, as well as create firewall-like restrictions that limit application access to files, registry, the internet, and interaction with other applications."

Dominik also agrees that this strategy allows retailers to mitigate cyberattacks explaining “A Zero Trust Approach is a security framework that assumes no inherent trust within a network. It focuses on verifying every user and device attempting to access resources, regardless of their location or network. Retailers can adopt ZTA principles by implementing multifactor authentication, granular access controls, and continuous monitoring to ensure that only authorised entities can access sensitive data or systems.” 

Being Vigilant For An Attack

Fraudsters stole £580 million from British consumers and businesses in the first six months of 2023. Black Friday offers bad actors the chance to capitalise even further on these fraudulent attacks. Despite the technological advancements that have empowered businesses to bolster their cybersecurity, hackers continue to leverage the latest innovations to make their attacks more sophisticated.

This should act as a wake-up call for retailers to adopt a cybersecurity strategy and educate employees on the relevant tactics that can help them fend off a cyber attack this Black Friday.

Image: Unsplash+    thumbnail:  ElisaRiva

You Might Also Read:

Why Is Retail Cyber Security So Weak?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


« Australian Ports Recovering After Large-Scale Attack 
Surging Attacks On Israeli Websites »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

RIVA Solutions

RIVA Solutions

RIVA provides innovative best practices in IT and management consulting, program support services and emerging technologies.

IP Performance

IP Performance

IP Performance Limited is a leading supplier of customised network infrastructure and security solutions.

Atomicorp

Atomicorp

Atomicorp, the leader in Secure Linux, is a developer of solutions for the protection and support of cloud, virtual, shared, and dedicated web hosting environments.

Semperis

Semperis

Semperis is an enterprise identity protection company that enables organizations to quickly recover from accidental or malicious changes and disasters that compromise Active Directory.

Idaptive

Idaptive

Idaptive delivers Next-Gen Access through a zero trust approach. Idaptive secures access everywhere with single sign-on, adaptive MFA, EMM and analytics.

IoT Defense

IoT Defense

IoT Defense (IOTD) is a cybersecurity and networking company building solutions that enable the protection of networks and the ever-increasing prevalence of IoT devices.

AimBrain

AimBrain

AimBrain tools detect and prevent fraud, faster and more accurately than ever before.

Curricula

Curricula

Curricula's cyber security awareness training delivers short relatable security stories to your employees. We make learning cyber security simple and fun.

Field Effect Software

Field Effect Software

Field Effect Software build sophisticated and integrated IT security, threat surface reduction, training and simulation capabilities for enterprises and small businesses.

Secure Digital Solutions (SDS)

Secure Digital Solutions (SDS)

Secure Digital Solutions is a leading consulting firm in the business of information security providing cyber security program strategy, enterprise risk and compliance, and data privacy.

TriagingX

TriagingX

TriagingX successfully created the first generation malware sandbox that is being used by many Fortune 500 companies for daily malware analysis.

Aurora Systems Consulting

Aurora Systems Consulting

Aurora is a Cybersecurity solutions provider with a portfolio consisting of security consulting, products and services that proactively prevent, secure and manage advanced threats and malware.

Hubify

Hubify

Hubify is an experienced, service-driven technology company specialising in business connectivity across mobile, data, voice, cloud, & cyber security solutions.

Mercury Systems

Mercury Systems

Mercury Systems is the leader in making trusted, secure mission-critical technologies profoundly more accessible to aerospace and defense.

Rapifuzz

Rapifuzz

At Rapifuzz, our goal is to help organizations test and secure their APIs enabling trust, innovation and Seamless Secured Digital Experiences.

Softanics

Softanics

Softanics’ ArmDot protects .NET apps with advanced obfuscation, control flow protection, and virtualization, securing code against reverse engineering without requiring agents or environment changes.