Submind YouTube summaries
Thumbnail for Is Your Retail Stack Ready Before the Shopping Rush Hits? | Steve Winterfeld, Akamai

Is Your Retail Stack Ready Before the Shopping Rush Hits? | Steve Winterfeld, Akamai

Watch on YouTube

Video summary

Retail companies must proactively prepare their digital infrastructure ahead of major shopping events to navigate an increasingly complex threat landscape. A primary focus should be on mapping the entire customer journey, from initial browsing to final checkout, ensuring that every step interacts securely with databases and inventory systems. Security leaders need visibility into these processes to dynamically adjust protections based on real-time fraud levels; for instance, introducing additional friction when fraud spikes while maintaining a smooth experience when threats are low. Ultimately, the goal is to prevent incidents before they escalate into major breaches by implementing segmentation strategies that minimize potential impact. Beyond general protection, organizations must prioritize their critical functions and crown jewels, such as APIs, loyalty programs, and inventory management systems, with heightened security measures. This approach ensures a more resilient capability that can survive dynamic attacks without disrupting service. It is also essential to map the revenue chain to identify third-party systems that are vital to operations and to gain situational awareness around various digital identities, including agentic IDs that actively participate in decision-making within the ecosystem. Furthermore, a robust bot strategy is non-negotiable, requiring businesses to move beyond simple blocking toward managing synthetic customers, reviewing credentials, and mitigating bad bots effectively. Operational stability during peak events requires strict adherence to established processes, particularly when changes are needed for security reasons. Companies must have clear procedures for handling freeze exceptions and escalation paths so that nothing critical changes unexpectedly unless absolutely necessary. When issues do arise, a well-rehearsed crisis process is vital for quick mitigation, which relies heavily on executive alignment and a defined RACI matrix to clarify who is responsible, accountable, consulted, or informed during a crisis. By ensuring leadership knows exactly who can authorize exceptions and who must be involved in emergency responses, retailers can maintain order and protect the customer experience even when things go wrong.
Read the full video transcript
When we look at all these emerging threats, uh of course, now nowadays every month or every other month you see a big major shopping event. How should retail companies be preparing right now before the whole shopping season arrives here? >> So, you know, I think the first is as a CISO I want to follow the customer's journey. And as I understand, you know, they come in here, they see this page, this page goes to this database, this database goes to this inventory system, this inventory systems goes to this checkout. You know, to save that inventory, to hold it aside. This checkout goes to this purchase system. I want to make sure all those steps are protected. And there are 25 more steps in that one purchase I didn't talk about. And so I want to make sure I have visibility and the ability to dynamically protect that. You know, if fraud starts to increase, maybe I put a little bit more friction in there. If it decreases, I don't. Uh ultimately, you know, I also want to put some mitigations in there cuz someone is going to get through. And I want to prevent it at the incident, not the major breach level. And so I want things like segmentation in there to minimize impact. And finally, you know, got to go back to the basics what we talked about earlier, DDoS. I want to make sure my capabilities during this peak event are able to handle that volume and move the DDoS aside so it's not impacting customer experience. The next thing is I want to focus on critical functions. You know APIs the checkout capability, loyalty programs, you know, inventory systems. By protecting those critical systems with more security than others, then I'm I'm guaranteeing a a more dynamically survivable, resilient capability. Um I want to know I want to map the revenue chain. What are the crown jewels? What third-party systems are critical? How am I doing IDs? And And those IDs include now all these agentic IDs, all these, you know, actors that are taking, you know, active part in making decisions within my systems. I need to have visibility and situational awareness around them. We started with this and it's probably it's deeper in the list, but it's one of the most important things. I need a good bot strategy. I need to know, you know, how I'm reviewing credentials, bad bot mitigation, API versus, you know, syn synthetic customers. I need I can't just block anymore. I need to manage this. Um you know, obviously operations are big during these peak events. There's a freeze. Nothing should change. So, if I need to change something for security, do I have clear process for freeze exception and escalation? Do I have a crisis process that's been exercised? So, when those something starts to go wrong, we quickly mitigate. And you know that means executive alignment for a RACI, you know, responsible, accountable, consultant, [snorts] and informed, making sure we know who can give these exceptions and who's involved in that crisis. Uh you know, it it's a more detailed list in the report, but but at a high level, those are kind of those critical things that we should all have on our prep sheet for a major event.