Cyber attacks can cause major damage for independent retailers. Some small businesses may even not be able to survive a succesful instance of phishing, ransomware, fraud or account compromise. This guide covers practical steps retailers can take to strengthen cyber security, protect customer information and reduce the risk of attack.

 
Cyber Attack Fraud Retail

In this article:

‣  How badly cyber attacks and fraud can hurt independent retailers
‣  How to secure business email and important online accounts
‣  Protecting staff, devices, websites and online payments
‣  Backing up data, reviewing security and preparing for an incident
 

> Updated as of 28th September 2026

Cyber attacks against businesses have been making headlines, including a recent attack involving services at Manchester, Stansted and East Midlands Airports, but the threat is not limited to large organisations and can be far more brutal on small high street businesses and independent retailers.

One in two small businesses experiences a cyber incident each year, while phishing, ransomware, account compromise and other attacks can cause significant disruption, financial loss and reputational damage.

Independent retailers can be particularly exposed because they rely on email, online accounts, websites, payment systems and customer data to operate. Criminals are also using increasingly convincing AI-generated content to impersonate businesses, target staff and customers, and make fraudulent requests harder to identify.

Good cyber security helps protect your business, customers, staff and suppliers from attacks and fraud, while helping you respond quickly when incidents occur. Here are the steps you can take.


1. Secure your business email

Email is one of the most important accounts to protect because criminals who gain access can potentially view sensitive information, impersonate the business and use password-reset links to access other accounts.

Make sure business email accounts are protected with:

  • Multi-factor authentication or two-step verification, wherever available.
  • Strong, unique passwords that are not reused elsewhere.
  • Passkeys (sign-in methods that use biometrics like Face-ID), where supported, as these provide a more phishing-resistant way to sign in.
  • A process for removing access when employees leave or change roles.
  • Appropriate controls over who can access shared inboxes and sensitive information.

Consider using a password manager to help staff create and manage unique passwords.


2. Protect your most important online accounts

Email is only one potential route into a business. Retailers should identify their most important online accounts and make sure they are appropriately protected.

This could include:

  • Online banking and finance systems.
  • Payment and point-of-sale systems.
  • Your website and domain.
  • E-commerce platforms.
  • Cloud storage.
  • Accounting and payroll software.
  • Social media accounts.
  • Customer relationship systems.

Use MFA or two-step verification where available, and consider passkeys for business-critical accounts. Regularly review who has access and remove accounts and permissions that are no longer required.


3. Make your staff your first line of defence

Many cyber attacks begin with a convincing message designed to make someone click a link, open an attachment, reveal information or transfer money. AI can make phishing emails, scam messages, cloned voices and other fraudulent communications more convincing and harder to identify.

Phishing can arrive by email, text message, phone call or social media, so do not rely solely on spelling, branding or tone to identify a scam.

Make sure employees know to:

  • Treat unexpected requests for payments or sensitive information with caution.
  • Check the sender and destination of links before clicking.
  • Avoid opening unexpected attachments.
  • Verify changes to supplier bank details using a trusted contact method.
  • Never provide passwords, banking information or security codes in response to an unsolicited request.
  • Report suspicious messages quickly, even if they have already been opened.

Regularly remind staff about these risks rather than relying on one-off training.


4. Keep devices and software secure

Devices Cyber
 

Computers, phones, tablets, tills and other connected devices can all provide a route into your business.

Keep operating systems, applications, browsers and security software up to date, and make sure devices are protected with appropriate security measures.

Where possible, avoid giving everyday users administrator privileges on their devices. Using standard user accounts for routine work can reduce the ability of a compromised account to make damaging changes to a device.

If you use third-party IT or software providers, understand what security measures they have in place and who is responsible for applying updates and dealing with incidents.


5. Protect your website and online payments

An e-commerce website can be targeted directly, including through malicious code or compromised third-party scripts that capture payment information from customers.

Retailers accepting card payments online should understand their responsibilities under PCI DSS v4.0.1, the current payment card security standard. Requirements covering e-commerce payment-page security and protection against e-skimming became effective from 31 March 2025.

Check that:

  • Your e-commerce platform and plugins are kept up to date.
  • Your payment provider is appropriately PCI DSS compliant.
  • You understand which parts of payment security are your responsibility.
  • Third-party scripts on your website are reviewed and controlled.
  • Your payment pages are protected against unauthorised changes and malicious scripts.
  • Access to your website administration is restricted and protected with MFA where available.

If your payment page uses an embedded payment form or iframe, make sure you understand the relevant PCI DSS requirements and your payment provider's responsibilities.

You can read our simple steps on what PCI DSS compliance is and simple steps to achieve it here.


6. Limit the information you hold

Customer information can be valuable to criminals even when it does not include payment details.

Review the information your business collects and stores, and only retain what you need for legitimate business purposes. Make sure access to customer information is limited to people who need it and review whether old data can be securely deleted in line with your data-protection obligations.

Remember that information exposed during a breach could subsequently be used to make phishing emails, texts and phone calls appear more convincing.


7. Back up your essential data

Cloud Cyber
 

Ransomware and other attacks can prevent a business from accessing its systems and information.

Identify the data and systems your business needs to continue trading and make regular backups. This could include financial records, customer information, business documents, website data and other essential files.

Do not assume that having a cloud copy automatically means you are protected. Backups should be protected from unauthorised access or deletion, and you should regularly check that they can actually be restored. Where possible, keep backups separate from the main network or use a cloud service with appropriate protection against ransomware.


8. Review your security regularly

Cyber threats and the systems businesses use are constantly changing, so security measures should be reviewed regularly.

Check that:

  • Important accounts still have MFA or two-step verification enabled.
  • Staff access remains appropriate and former employees' accounts have been removed.
  • Devices, software and e-commerce platforms are up to date.
  • Backups are working and can be restored.
  • Your website, payment systems and third-party services remain secure.
  • Staff understand current phishing, impersonation and AI-enabled fraud risks.



9. Know what to do if an attack happens

Good preparation can limit the impact of an incident. Keep a simple plan covering who is responsible, who to contact for IT support, how to contact your bank or payment provider, how to secure compromised accounts and what to do if customer information may have been exposed.

If a personal data breach is likely to result in a risk to people's rights and freedoms, it must be reported to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it. Businesses must also keep a record of personal data breaches, including those that do not need to be reported, and may need to tell affected individuals if the breach is likely to result in a high risk to them.

A simple cyber security checklist

Independent retailers should regularly check that they:

•  Have MFA or two-step verification enabled on important accounts.

•  Use unique passwords and consider passkeys where available.

•  Keep devices, software and e-commerce platforms updated.

•  Train staff to identify phishing, AI-generated scams and other fraud.

•  Review who can access important systems and remove unnecessary accounts.
•  Protect customer information and avoid retaining data unnecessarily.

•  Understand their PCI DSS responsibilities if they accept card payments.

•  Maintain secure, tested backups.

•  Review their cyber security measures regularly.

•  Know what to do and who to contact if an incident occurs.
 

Listen to our podcast special on cyber security and how there's no business too small to be targeted...

A subject that many independent retailers think doesn't apply to them is cyber security. The harsh reality is that small businesses are increasingly being targeted by cyber criminals, and the "it won't happen to me" mentality can be dangerously costly.

 

Photo credit: Shutter2U/stock.adobe.com; vegefox.com/stock.adobe.com; Koto Amatsukami/stock.adobe.com

 

Related Resources