In FY2024-25, the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) responded to 138 ransomware incidents across Australia. In 39% of them, the organisation found out simply because ASD rang to tell them.
That means nearly four in 10 learned about their own incident from a phone call. For a retailer, what if that call lands at 2am, when the person answering didn't design the environment and can't yet tell whether the message is merely noise or the start of a bad day?
This question can hit retailers hardest because they run distributed environments. Point-of-sale (POS) systems, ecommerce platforms, Microsoft 365, warehouses, stores, support tools and third-party providers all connect to the business. Plus, seasonal staff, contractors and suppliers keep adding access, often while the internal teams are already stretched thin.
When retail environments get hit, that exposure can go downstream. Credentials get traded, combined with information from other leaks, and used to build surprisingly complete pictures of real people. That translates into more convincing phishing attempts, account takeover on any site where the same email and password was reused and, in some cases, targeted fraud. The breach notification is the visible moment. The damage keeps compounding after it.
To avoid that, the goal is to understand which systems keep you trading, and how fast someone can act when one of them is in trouble, especially outside office hours. Here's how that breaks down.
1. Map the systems that keep revenue moving
Build a simple map of the critical path: payments, POS, online orders, inventory, fulfilment, identity, email and store operations. Record the dependencies between them and the people or suppliers who can access each one.
And don't stop at the head office. The map has to cover stores, distribution centres, cloud services, remote-access tools and any devices managed by someone else. For each system, answer three questions:
Who can reach it?
What would happen if it went offline?
How would I know if something was wrong?
The ASD's Annual Cyber Threat Report recorded more than 84,700 cybercrime reports in 2024–25. That's roughly one every six minutes! And the average self-reported cost of cybercrime for a small business rose 14% to $56,600. Though neither figure is retail-specific, both are useful when you need to explain to leadership why the map is worth the time it takes to build. After all, cyber risk is now part of keeping stores, fulfilment and digital channels available.
2. Secure identities and support the people who use them
Anyone with access to your systems can be targeted. Employees, seasonal staff, contractors and trusted suppliers may receive phishing messages, fake supplier requests, payment-redirection attempts and convincing login prompts.
People need clear processes and an easy way to report something that looks wrong. Verify changes to payment details through a second channel, using a number you already have rather than one supplied in the email. Always challenge unusual requests for access. And make sure staff know how to confirm that a login prompt is genuine, and that reports receive a timely response.
Back those processes with phishing-resistant MFA where possible, least-privilege access and prompt onboarding and offboarding. Review administrator access, stale accounts, mail forwarding rules, unfamiliar applications and logins that don't fit the person or role. Separate administrator accounts from everyday accounts, and make privileged access temporary wherever possible.
One Australian IT leader described what that kind of visibility looked like during a Huntress deployment:
3. Shorten the path from discovery to verified action
Retail environments change constantly. New stores open, POS systems are updated, suppliers are replaced and staff leave or change roles. But older systems can remain online longer than planned because replacing them is expensive or disruptive.
Create a repeatable path from discovery to verified action:
Discover: Keep an accurate view of assets, identities, suppliers and security controls. Know which systems support payments, stores, online orders, inventory and fulfillment.
Prioritise: Assess exploitability and business impact together. An issue on a POS server or payment-related system may deserve attention before the same issue occurs on a lower-impact office laptop.
Act: Assign an owner, set an expected response time and take the right action: patch, isolate, disable access, rotate credentials, increase monitoring or involve a supplier.
Verify: Confirm that the fix worked and the risk has been reduced. But don't just close the task simply because a patch was applied or a security tool reports that it's installed.
Start with internet-facing systems, VPNs, remote-management tools, POS devices and servers. Set clear service expectations for high- and critical-impact issues. Automate low-risk, repeatable actions where it's safe to do so, while routing decisions with operational consequences to people who understand the business.
If you want a framework your team already recognises, the Essential Eight maps well to this. Patch applications, patch operating systems, restricting admin privileges and MFA are four of the highest-value strategies for retail environments, and the maturity levels give you a way to implement controls and describe progress without reducing it to vendor tool sprawl.
4. Make suppliers and dependencies part of the plan
Payment providers, logistics partners, software vendors, contractors and franchisees may all be able to reach into your operations. That access should be limited to what they need, logged and reviewed.
Ask suppliers if their staff complete security awareness training, how they notify you about a suspected compromise. And learn how they'll contain access and support recovery. Make sure you have an escalation contact who'll answer during a peak trading period or 10pm on Boxing Day. An annual questionnaire is useful, but it can't replace a tested contact path or clear ownership when something goes wrong.
Also, plan for a critical supplier, cloud service or internet connection becoming unavailable. Ask:
Which stores could continue using manual procedures?
What alternative payment arrangements exist?
How will fulfilment operate?
How will teams communicate?
What must be restored first?
Keep the plan proportionate to the business, but test it before an incident exposes the gaps.
5. Practise the plan before you need it
An incident response plan is only useful if people know who owns the decision and what happens next. Be sure to document:
Who can declare an incident?
Who can isolate a system?
Who can approve a recovery action?
Who communicates with staff, customers and partners?
Write the notification decision into the same document. Under Australia's Notifiable Data Breaches scheme, organisations must conduct a reasonable and expeditious assessment when they have reasonable grounds to suspect an eligible data breach, taking all reasonable steps to complete it within 30 calendar days. If the breach is likely to result in serious harm and remedial action hasn't prevented that risk, the organisation must provide a statement to the OAIC and notify individuals at risk of serious harm as soon as practicable.
In New Zealand, the Privacy Act 2020 requires an agency to notify the Office of the Privacy Commissioner and affected individuals as soon as practicable when it has reasonable grounds to believe a notifiable privacy breach has caused, or is likely to cause, serious harm. The OPC expects notification within 72 hours of the organisation becoming aware that the breach is notifiable, but treats 72 hours as a guide rather than a fixed statutory deadline.
Whoever isolates a POS server at 2am should already know who owns the escalation, the assessment, and—if required—the notification decision.
Test scenarios that reflect how a retailer actually operates. For instance, a POS outage on a Saturday, a compromised Microsoft 365 account, ransomware affecting fulfillment, a payment provider becoming unavailable or a supplier asking for an urgent change to payment details. For each scenario, ask how long the business can operate, which stores can continue manually and what must be restored first.
And test the restoration itself. Restore critical data, configurations and business systems in a controlled exercise. Confirm how long it takes to return those systems to a usable state, and record the decisions that would need to be made during a real outage.
For good measure, include an overnight scenario where the first alert reaches someone who didn't design the environment. The handoffs between IT, security, operations, legal, communications and key suppliers should be clear before the pressure is real.
A note from the Huntress Security Operations Center
The following data is pulled specifically from partners in the APAC retail vertical, predominantly in Australia and New Zealand. Across those partners, we saw two genuinely different attack paths being worked at the same time. Our EDR telemetry generated more than a thousand reports. The overwhelming majority were low severity, and that is the point rather than a caveat: adware, unwanted programs and blocked scripts were intercepted at the earliest possible stage, before any of it matured into something worse.
But 60 of those endpoint incidents reached critical or high severity, including 62 reports of established footholds and persistence. A smaller category of multi-host activity was critical or high more than 95% of the time.
On the identity side, more than five in six critical incidents involved a compromised Microsoft 365 account rather than malware at all. That means no malicious binary, no process to block, just a valid credential in the wrong hands. Identity monitoring was active across roughly four in five of these retail partner accounts. That gives us confidence that this finding reflects real attacker behaviour rather than simply where monitoring happened to be in place.
The reason both paths matter is that they lead to different, equally damaging outcomes. The identity path leads to business email compromise (BEC), and retail is an unusually rich target for it. An attacker inside a mailbox can read supplier and customer correspondence, intercept an invoice and alter the BSB and account number so payment lands in their account instead of yours. The problem is your customer believes they have paid you; you believe you are owed.
The fraud often surfaces weeks later, and the reputational damage runs in both directions. The same access exposes financial records, payment data and customer information, with the regulatory consequences that follow. The endpoint path leads somewhere different: persistence, lateral movement and ultimately extortion, whether by encrypting systems or stealing data and threatening to publish it. For a retailer, that is not merely an IT problem. When POS, e-commerce or warehouse dispatch stops, trading stops, and losses accrue by the hour, whether or not a ransom is ever paid.
This is why response speed is the metric that matters, and it is worth being precise about what we measure. From the first detected event on the customer's own estate, the median time to contain a compromised identity was around eight minutes, including the telemetry lag before we had anything to act on. Measured from the moment our platform generated the signal, the median was two minutes and twenty seconds.
Once an incident report was raised, containment executed in a median of 23 seconds because the containment action was issued with the report rather than waiting on anyone to approve it, a practical benefit of agentic solutions. Every host isolation and every identity containment was completed successfully. Session revocation is part of that containment. An attacker holding a valid session token does not need the password again, so resetting credentials without terminating sessions leaves them logged in and working.
What the data also shows is that attackers rarely settle for one attempt. In 14 organisations, we saw multiple critical incidents inside a single 24-hour window: an attacker working several identities, several hosts, or both, in the same environment rather than quietly sitting on one. We contained every one of them. When that pattern appears, we assess the environment more broadly and dig deeper to understand the full breadth of the activity, rather than treating each alert in isolation.
The pattern is clear from this data: users and endpoints were the primary targets. A critical server incident was the trigger for escalation in only three organisations. More often, the issue was activity against a user or endpoint, enabled by another reused credential, an account with more privilege than the role required, an unpatched application or a server alongside the one we had just contained. Detection and response address the activity once it is found. Reducing the number of viable attack paths before an incident occurs is where the business has the greatest opportunity to reduce risk.
If you want a framework your team already recognises, the ACSC's Essential Eight maps onto this almost line for line, and its maturity model makes it useful rather than just a checklist. Different organisations will need to apply different controls to different depths, based on their environment, current capability and the adversary they expect to face. For some, MFA and restricting administrative privileges will close the most immediate gaps. Others will need phishing-resistant MFA, tighter privilege management, defined patching timeframes, better logging and monitoring and tested processes for identifying and containing persistence.
The point is to choose the controls that reduce the risk you actually face, then measure whether they made a difference. That is where the Huntress SOC adds value: human experts using judgement to lead agentic solutions operating at machine speed, contain the threat, protect your business and help your organisation make the next control improvement with confidence.
Where managed security fits
Most retailers aren't in the business of becoming security operations specialists. Lean IT teams still need to understand what's happening across endpoints, identities, email and critical systems, but they may not have the time or specialised coverage to interpret a high volume of signals around the clock.
Managed security extends the team by monitoring the environment, adding context to suspicious activity, helping validate whether an alert represents a real threat and supporting practical next steps. The important question isn't simply whether a provider offers 24/7 coverage. Ask who owns the escalation, what access the provider needs, how decisions are handed back to your team and whether the response process fits your operating model.
Huntress can address the concerns mentioned above. We protect your endpoints and identities with Managed EDR and Managed ITDR, while Managed ISPM closes the misconfigurations attackers go looking for. Managed SAT coaches your people to spot the threats that reach them first. Managed SIEM pulls logs from across the environment into one place, so activity can be investigated thoroughly and produced for an auditor when the time comes. And a 24/7 SOC detects all of it, with AI augmenting our analysts, so they can move with speed and agility to remediate problems—with a mean-time-to-respond of eight minutes on endpoints and under three for identity threats. With Huntress behind your retail environment, your team stays in control.
Four in 10 of those Australian ransomware victims found out the hard way when someone else rang them. The distance between a random phone call and an instant alert can make all the difference in how you trade.
Book a Huntress demo or start a free trial to see how Huntress can support your retail environment across Australia and New Zealand.