Is Your Retail Stack Ready Before the Shopping Rush Hits? | Steve Winterfeld, Akamai
Watch on YouTubeVideo summary
Retail companies must proactively prepare their digital infrastructure ahead of major shopping events to navigate an increasingly complex threat landscape. A primary focus should be on mapping the entire customer journey, from initial browsing to final checkout, ensuring that every step interacts securely with databases and inventory systems. Security leaders need visibility into these processes to dynamically adjust protections based on real-time fraud levels; for instance, introducing additional friction when fraud spikes while maintaining a smooth experience when threats are low. Ultimately, the goal is to prevent incidents before they escalate into major breaches by implementing segmentation strategies that minimize potential impact.
Beyond general protection, organizations must prioritize their critical functions and crown jewels, such as APIs, loyalty programs, and inventory management systems, with heightened security measures. This approach ensures a more resilient capability that can survive dynamic attacks without disrupting service. It is also essential to map the revenue chain to identify third-party systems that are vital to operations and to gain situational awareness around various digital identities, including agentic IDs that actively participate in decision-making within the ecosystem. Furthermore, a robust bot strategy is non-negotiable, requiring businesses to move beyond simple blocking toward managing synthetic customers, reviewing credentials, and mitigating bad bots effectively.
Operational stability during peak events requires strict adherence to established processes, particularly when changes are needed for security reasons. Companies must have clear procedures for handling freeze exceptions and escalation paths so that nothing critical changes unexpectedly unless absolutely necessary. When issues do arise, a well-rehearsed crisis process is vital for quick mitigation, which relies heavily on executive alignment and a defined RACI matrix to clarify who is responsible, accountable, consulted, or informed during a crisis. By ensuring leadership knows exactly who can authorize exceptions and who must be involved in emergency responses, retailers can maintain order and protect the customer experience even when things go wrong.
Read the full video transcript
When we look at all these emerging
threats, uh
of course, now nowadays every month or
every other month you see a big major
shopping event.
How should retail companies be preparing
right now before the whole shopping
season arrives here?
>> So, you know, I think the first is
as a CISO
I want to follow the customer's journey.
And as I understand, you know, they come
in here, they see this page, this page
goes to this database, this database
goes to this inventory system, this
inventory systems goes to this checkout.
You know, to save that inventory, to
hold it aside.
This checkout goes to this purchase
system.
I want to make sure all those steps are
protected. And there are 25 more steps
in that one purchase I didn't talk
about.
And so
I want to make sure I have visibility
and the ability to dynamically protect
that. You know, if fraud starts to
increase, maybe I put a little bit more
friction in there. If it decreases, I
don't.
Uh ultimately, you know, I also want to
put some mitigations in there cuz
someone is going to get through.
And I want to prevent it at the
incident, not the major breach level.
And so I want things like segmentation
in there to minimize impact.
And finally, you know, got to go back to
the basics what we talked about earlier,
DDoS.
I want to make sure my capabilities
during this peak event
are able to handle that volume and move
the DDoS aside so it's not impacting
customer experience.
The next thing is I want to focus on
critical functions.
You know
APIs
the checkout capability, loyalty
programs,
you know, inventory systems.
By protecting those critical systems
with more security than others,
then I'm I'm guaranteeing a a more
dynamically survivable, resilient
capability.
Um I want to know I want to map the
revenue chain. What are the crown
jewels? What third-party systems are
critical?
How am I doing IDs? And And those IDs
include now all these
agentic IDs, all these, you know, actors
that are taking, you know, active part
in making decisions within my systems. I
need to have visibility and situational
awareness around them.
We started with this and it's probably
it's deeper in the list, but it's one of
the most important things.
I need a good bot strategy.
I need to know, you know,
how I'm reviewing credentials, bad bot
mitigation, API versus, you know, syn
synthetic customers. I need I can't just
block anymore. I need to manage this.
Um
you know, obviously operations are big
during these peak events. There's a
freeze. Nothing should change. So, if I
need to change something for security,
do I have clear process for freeze
exception and escalation?
Do I have a crisis process that's been
exercised? So, when those something
starts to go wrong, we quickly mitigate.
And you know that means executive
alignment for a RACI, you know,
responsible, accountable, consultant,
[snorts] and informed, making sure we
know who can give these exceptions and
who's involved in that crisis.
Uh you know, it it's a more detailed
list in the report, but but at a high
level, those are kind of those critical
things
that we should all have on our prep
sheet for a major event.