Skip to content

Third-Party Providers as Primary Risk in Retail Cybersecurity

In a nutshell: Third-party providers have become the biggest security challenge for German retailers – yet many prioritize compliance over technical vulnerability remediation.

Data breaches at German retailers show that even companies with strong security measures are compromised through trusted third-party providers. Every integration of a SaaS solution or logistics partner significantly expands the attack surface.

According to a ManageEngine study on operational resilience, 75 percent of surveyed retail companies reported at least one cybersecurity incident in the past year. Phishing and compromised access credentials remain the most common attack methods, followed by vulnerability exploitation and data breaches. The insight is critical: attackers do not primarily rely on novel techniques, but rather exploit known gaps that are difficult to close comprehensively across complex digital ecosystems.

In data breaches, personally identifiable information such as names, phone numbers, email addresses, dates of birth, addresses, passwords, and payment information are stolen. This information enables attackers to conduct more convincing phishing campaigns and identity fraud – the financial consequences often emerge only through subsequent waves of attacks. The central danger lies in the uncontrolled expansion of the ecosystem: every SaaS solution and every logistics partner increases the attack surface and thus the risk of compromise.

The study results reveal a significant discrepancy in the prioritization of countermeasures. Surveyed companies indicate that they prioritize rule-driven measures and policy adjustments more strongly than technical measures such as vulnerability remediation, patch management, and access rights reviews. While comprehensive compliance is necessary for corporate governance, it does not sufficiently reduce operational cyber risks without complementary technical measures.

IT security teams face considerable operational strain: too many manual processes, budget cuts, and a lack of continuous visibility into IT resources, digital identities, and third-party access hinder threat detection. Only 58 percent of surveyed retailers are confident they can manage cybersecurity-relevant incidents in the coming one to two years. With AI-driven attack automation and identity-based attacks, this loss of confidence will continue to grow as long as manual processes and reactive measures dominate.


Source: www.it-daily.net · Published July 21, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: