Retail feels like a low-tech business. You sell things, you take payment, you order stock. Cyber security sounds like a problem for banks and big chains, not a Sydney shop with a counter, a stockroom, and a handful of casuals on the roster.
That is exactly why retailers get caught. A shop runs payment terminals, holds customer details, processes supplier invoices, and turns over staff constantly. Every one of those is a door, and most of them are left unlocked because nobody thinks of a retail business as a target. If you want the wider picture of running IT in retail, start with our guide to IT for retailers. Here are the seven gaps we find most often, and the practical fix for each.
Gap 1: The Point of Sale and Back-Office Machines Are Unpatched
The till runs all day, the back-office PC handles ordering and accounts, and neither gets touched as long as they keep working. We routinely find point of sale machines and back-office computers months behind on updates, or running a version of Windows that stopped getting security fixes a long time ago.
A machine that processes payments and sits on the same network as everything else is a serious target. Most break-ins use a flaw that already had a fix available. The gap is the time between the patch existing and it being applied. The fix is to actively manage and report on updates for every machine in the shop, including the till and the back office, not to assume they are fine because they still ring up sales.
Gap 2: Customer Data Is Spread Everywhere
Loyalty lists, layby records, special orders, repair tickets, email marketing exports. Retail collects customer details in more places than anyone realises, and over the years it sprawls into spreadsheets, old email threads, a former staff member’s login, and three different apps.
Every copy of that data is something you are responsible for under the Privacy Act, and every copy is something an attacker can take. The fix is to know where customer data actually lives, cut it back to the systems that genuinely need it, and protect those systems properly rather than leaving copies scattered across the business.

Gap 3: Supplier Invoice Fraud
Retail runs on a steady stream of supplier invoices, and that is what attackers count on. They get into one mailbox in the chain, watch how invoices flow, and then send a message that looks like it came from a real supplier asking you to update their bank details before the next payment.
Because the request looks genuine, it passes the usual checks, and the money is often gone before anyone notices. The defence is part technical and part process: multi-factor authentication on every mailbox to make the break-in harder, and a firm rule that any change to bank details is confirmed by a phone call to a known number, never by replying to the email.
Gap 4: Casual and Seasonal Staff Keep Their Access
Retail turns over staff faster than almost any other trade. Casuals come on for a busy season, students move on, someone covers a shift and never comes back. Each departure is a small security event, and the common gap is access that never gets removed.
A former casual who still has a login to the point of sale, the roster app, or a shared email is a quiet way in long after they have gone. The fix is unglamorous but effective: access is granted by role, reviewed regularly, and switched off promptly the day someone stops working for you.
Gap 5: Guest Wi-Fi Shares the Business Network
Plenty of shops offer customers Wi-Fi, or let the network the public uses sit on the same connection as the till and the back office. That means a customer device, or anyone sitting outside, is on the same network as the systems that handle payments and data.
Public and business traffic should never mix. The fix is straightforward: keep customer Wi-Fi completely separate from the network your point of sale and business machines use, so a problem on the guest side cannot reach anything that matters. It is a one-off setup change that closes a path most retailers do not know is open.
Gap 6: No Multi-Factor Authentication
Almost every shop has a password on its email and its key systems. Far fewer have a second lock. We regularly find multi-factor authentication switched on for nothing, or for the owner’s email but not the point of sale login, the supplier portal, or the accounting system.
Attackers look for the one account protected by a password alone, because passwords leak constantly. The fix is to inventory every system that holds money or customer data and confirm a second verification step is enforced on all of them. It is the single control that blocks most account takeovers, and in retail it is usually missing.
Gap 7: No Tested Backup, So Downtime Stops Sales
If the point of sale goes down on a Saturday, you are not just inconvenienced, you are not trading. Ransomware that locks up your systems hits sales directly, and the only thing that gets you back quickly is a backup you can actually restore from.
The gap we see most is backups that are “running” but have never been tested, or that an attacker could encrypt along with everything else. A backup nobody has restored from is a guess. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete, so a bad day costs you hours rather than a week of lost takings.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a quiet Tuesday into a closed shop and a privacy headache. Most of them are settings you can tighten or protections you are already paying for in tools you own, not a major rebuild.
The hard part is knowing which gaps apply to your shop, because most are invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your business in more than one of these, you are normal, and you are in a good position, because every gap here has a clear fix. The starting point is the same for everyone: get a clear picture, then close the biggest gaps in order.
Our IT maturity assessment takes a few minutes and shows you which controls need attention first. For the structured version of the basics, it is worth reading what Essential Eight is, the baseline published by the Australian Cyber Security Centre.
We are a Sydney-based team in Bella Vista, and we look after retail businesses across the metro area. We secure the till, the customer list, and everything behind the counter without getting in the way of trading. Talk to our team when you are ready.