The ‘Plain English’ guide written with input from the NCSC advises retailers on what they should do to keep their business – and their customers – safe from cyberattacks.
Retailers face potential threats from ransomware, malware, phishing attacks and many more, and a new guide developed with the help of the National Cyber Security Centre (NCSC) aims to prevent retailers from falling victim to these attacks.
The “Cyber Resilience Toolkit for Retail” has been developed by the British Retail Consortium (BRC) and the NCSC and attempts to provide a “Plain English” guide to cybersecurity for management and boards.

The nature of retailers and the way they handle not only financial data but also personal data , always makes them a tempting target for cybercriminals . During 2020, the BRC reports that there has been an increase in the number of online marketplaces, potentially providing cybercriminals with more loot if they carry out a successful cyberattack on an e-commerce website .
“We want to keep shoppers’ data , identity and privacy safe and ensure the retail sector is well-equipped to address the cyber challenges associated with an increasingly digital world ,” said Dr Ian Levy, technical director of the NCSC.
“Cybersecurity doesn’t have to be scary. There are many best practice measures you can implement to ensure you protect yourself and customers ,” he added.
These best practice measures include using strong passwords, training staff well, and backing up data, so if a successful ransomware attack occurs, the organization will be able to restore data from backups.
It is also recommended that management knows what procedures are in place and knows what to do if a cyberattack occurs – and who to call if help is needed.
“Last year, retailers spent over £186 million on cyber security, but the rise in online sales means there is a growing threat of new cyber breaches and sophisticated hacking techniques . As a result, retailers need to ensure their systems are up to date,” said Helen Dickinson, chief executive of the British Retail Consortium.
The toolkit also contains advice on areas where potential threats to retailers may come from. These include people working from home, malicious actors, the supply chain, and legacy systems that are not being updated.
The guide also urges retailers to take advantage of the NCSC’s Exercise in a Box – a free tool that allows organizations to test their cyber defenses based on some common hacking scenarios and real-world cyber incidents.
