Cybersecurity requires collective resilience

Articles & Reports
 |  
Feb 2026
 |  
Harvard Business Review
Save to favorites
Your item is now saved. It can take a few minutes to sync into your saved list.

What: Retailers are facing escalating cyber threats, prompting a shift toward collective resilience and industry-wide collaboration.

Why it is important: This development reflects the urgent need for coordinated defense strategies in retail, as highlighted by recent sector-wide cyber incidents.

Retailers are increasingly targeted by sophisticated cyberattacks, with recent high-profile breaches at major brands underscoring the sector’s vulnerability. The rapid pace of digital transformation and the growing reliance on third-party providers have expanded the attack surface, making traditional, isolated security measures insufficient. As a result, the industry is witnessing a strategic pivot from prevention alone to a broader focus on resilience, rapid recovery, and collective action. Regulatory pressures and the direct impact of breaches on customer trust and brand reputation have further accelerated this shift. Retailers are now prioritising industry-wide collaboration, intelligence sharing, and integrated risk management to safeguard their operations and maintain consumer confidence. This evolution marks a significant change in how the sector approaches cybersecurity, recognising that only through coordinated efforts can retailers effectively counter increasingly complex threats and ensure long-term business continuity.

IADS Notes: The urgency for collective resilience in retail cybersecurity is underscored by a series of sector-wide incidents and analyses over the past year. In August 2025, The Retail Bulletin reported that only 18% of retailers had mature digital core security, with ransomware accounting for 30% of attacks and average losses reaching $1.4 million per incident. The same month, Retail Week highlighted the escalation of cyberattacks on major UK retailers and the acute vulnerabilities introduced by third-party providers, prompting a sector-wide shift toward rapid recovery and coordinated responses. In May 2025, Inside Retail examined how breaches at M&S, Harrods, and Co-op evolved into core business risks, directly impacting market value and customer trust. By June 2025, Inside Retail emphasised that cyber resilience had become a competitive differentiator, with incidents like the M&S attack driving a 10% increase in cyber insurance premiums. Finally, RH-ISAC’s April 2025 analysis stressed the importance of industry collaboration and intelligence-driven solutions as cyber threats continue to evolve, reinforcing the need for integrated, proactive risk management across the retail sector.

Cybersecurity requires collective resilience