
Cybersecurity in transport: who attacks and how to protect against it
24 de September de 2026In today’s retail landscape, the distinction between digital and physical channels has effectively disappeared. The adoption of the omnichannel model has brought inventories, payment gateways, customer databases and order management systems together within a single technology ecosystem.
However, this operational convergence has a critical security consequence: the defensive perimeter in retail no longer ends at the e-commerce firewall; it now extends all the way to the point-of-sale (POS) terminal in the physical store.
A cyberattack targeting a retailer’s digital infrastructure is not limited to taking down its website or exposing online data; it can completely disrupt in-store operations, block the supply chain and cause irreversible damage to the brand’s reputation.
IT, OT and omnichannel interconnectivity
Traditionally, organisations have treated the security of corporate information technology (IT) environments and operational or physical systems (OT/IoT) as separate domains. In the retail sector, this approach is outdated and dangerous.
When a customer buys online and collects in store (Click & Collect), or when a sales assistant checks stock levels in real time from a tablet in the store, multiple interconnected systems come into play:
- Unified inventory management (ERP/WMS): An attacker who compromises the central database can alter actual stock levels, causing stockouts or the sale of unavailable products both online and at the checkout.
- Payment infrastructure (POS and gateways): A compromise of the corporate network can spread laterally to physical POS terminals across the store network, disabling card payments or exposing customers’ financial data in situ.
- IoT and building management: Public Wi-Fi networks for customers, connected barcode readers, inventory sensors or security cameras can become entry points into the internal network if they are not properly segmented and secured.
Impact: from the server to the checkout
The real risk of omnichannel retail lies in the domino effect. When the availability or integrity of data is compromised in the cloud or on central servers, the physical impact is immediate:
1. Operational disruption at the point of sale
A ransomware attack or denial-of-service (DDoS) attack against central systems does not only take the e-commerce store offline. If physical-store POS terminals depend on the central server to authenticate transactions, validate loyalty discounts or update inventories, the checkouts become inoperable. The direct consequence is temporary store closures, queues of frustrated customers and an immediate loss of daily revenue.
2. Disruption to logistics and the supply chain
Omnichannel retail requires seamless synchronisation between the distribution centre and the point of sale. If warehouse management or automated labelling systems become infected with malicious code, physical stores stop receiving goods. Empty shelves become the physical manifestation of a breach in the digital environment.
3. Data exposure across multiple fronts
A security breach affecting a unified loyalty programme exposes both the credentials of online users and customer records collected in physical stores. Regulatory non-compliance (GDPR) and the resulting financial penalties apply with the same severity, regardless of the channel through which the breach occurred.
Controlled workspaces and security by design
To protect business continuity in the retail sector, organisations need to move away from reactive or fragmented defensive solutions. Cyber protection in an omnichannel environment requires rigorous control and auditing of how users, employees and devices access the company’s critical assets.
At Cosmikal, we approach cybersecurity in the retail sector according to principles designed for highly demanding operational environments:
- Access control and asset isolation: Ensure that remote and local access to critical systems (ERP, POS management, database servers) always takes place through shielded workspaces governed by design. Solutions such as Endurance make it possible to manage, restrict and audit privileged access while preventing lateral threat movement.
- Protected local environments in stores: Minimise vulnerabilities at the physical point of sale through deployments using Ranger, ensuring that local terminals operate within restricted and monitored environments that are restored at every startup to prevent malware persistence.
- Certified security standards: Adopt protection standards endorsed by independent bodies (such as the CCN’s LINCE Certification or the specifications of NATO’s NIAPC catalogue), ensuring maximum resilience against incidents in complex infrastructures.
Conclusion
In modern retail, omnichannel operations are an essential competitive advantage, but they also create a unified attack domain. A cyber incident does not distinguish between a digital shopping basket and the checkout of a physical high-street store.
Protecting profitability, reputation and operational continuity in retail requires a comprehensive approach to cybersecurity. Workspace protection and strict control over access to information form the foundations supporting the entire customer experience.
Frequently asked questions
How can an attack on the corporate website affect my physical store if it has its own cash register?
Cash registers or POS terminals may appear to operate independently. However, in an omnichannel model they constantly communicate with central servers to synchronise inventory, verify prices, apply loyalty promotions and validate payments. If the network or central servers are attacked, physical-store terminals can lose critical connectivity or become blocked, preventing normal payment processing or the issuing of receipts.
What are the main attack vectors in physical retail stores?
The most common vectors include unsecured IoT devices (IP cameras, stock sensors, advertising displays), open or poorly segmented customer Wi-Fi networks, the use of USB drives on POS terminals, and insecure remote connections used by external technical maintenance providers.
What is “lateral movement” within a retail network and why is it so dangerous?
Lateral movement occurs when an attacker gains access to the corporate network through a weak point —such as a phishing email sent to an office employee or an IoT device in a store— and uses that initial foothold to move through the internal network until reaching high-value systems, such as the credit card database or the central ERP system.
How do solutions such as Endurance and Ranger help prevent these risks?
Endurance isolates and audits access to the company’s critical servers and systems, preventing an attacker from moving through the network or taking control of the ERP system. Ranger, meanwhile, protects workstations and local terminals (POS), ensuring that they operate in clean, restricted environments protected against unauthorised code execution or malware persistence.





