42,849
Internet-facing assets discovered
Across 5 retail organisations
1,021
Supplier connections mapped
Script · cert · ASN · DNS · header
74
Fix Now priorities
Requiring immediate action
5/5
Common suppliers in every estate
Google · Cloudflare · Microsoft · AWS · DigiCert
Why retail attack surfaces demand a different approach
Retail organisations manage some of the most exposed digital estates in any sector. Loyalty portals, e-commerce platforms, click & collect apps, partner integrations, payment gateways, and seasonal microsites accumulate quietly — each adding suppliers, scripts, and connections that your existing tools never mapped. When a customer hands over their card details or personal data, every third-party asset that touched that journey is a link in your attack chain.
This report draws on ThingsRecon agentless scans of five retail organisations — physical and online retailers operating across the UK and Belgium. Everything below was discovered from public data only: DNS, TLS certificates, cloud metadata, internet-wide scanning, and API ecosystem mapping. No agents. No questionnaires. No internal access. It is the same outside-in view an attacker builds — except we go one step further by naming the suppliers, scoring proximity to your customer-facing assets, and surfacing the ones your TPRM programme never asked about.
All organisations in this report are anonymised. Technology suppliers, platforms, and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do retail organisations compare?
ThingsRecon scanned five retail organisations simultaneously. All five received an overall cyber resilience score of C or below — reflecting the sprawling, supplier-heavy nature of modern retail digital estates. The data below is anonymised.
Organisation
Assets
Suppliers
Fix Now
Fix Soon
Score
Weak indicators
Company AGeneral merchandise · NL
9,061
129
30
52
B
Headers C · Software C
Company BFootwear retailer · BE
7,078
59
16
49
C
Headers D · Software C · App C
Company CSpecialty retailer · UK
8,719
42
4
21
C
Headers D · App B
Company DFashion retailer · BE
13,216
56
18
62
C
Headers D · Cert C · Software C
Company ETrade & DIY retailer · UK
4,775
102
6
15
C
Headers F · Software C
Sector-wide Risk Patterns
What every retail estate has in common
Across all five organisations, ThingsRecon identified consistent risk patterns — structural weaknesses that emerge from how modern retail digital estates are built, not from isolated security failures.
HTTP Security Headers
Critical
All 5 retailers scored D or F on header hygiene. Missing Content-Security-Policy leaves every customer-facing page open to clickjacking, script injection, and downgrade attacks. This is the sector's single most consistent blind spot.
Software Supply Chain
High
4 of 5 organisations have C-rated software risk. Outdated and vulnerable JavaScript libraries, frontend frameworks, and server-side components are present across all estates — many with known CVEs actively exploited in the wild.
Cookie Security
High
Session and tracking cookies without Secure, HttpOnly, or SameSite flags appear across all five estates. These findings are ranked Fix Soon — they expose customer session tokens to theft via cross-site scripting or network interception.
Supplier Concentration
High
The same 5–8 technology suppliers are embedded in every retail estate scanned. Google, Cloudflare, Microsoft, Amazon, and DigiCert are universally present with high digital proximity scores. A compromise or outage at any creates simultaneous impact across the sector.
Certificate & TLS
Medium
Certificate risk is generally B-rated, but one organisation shows a C with Fix Now SSL findings. Misconfigured TLS on customer-facing services creates man-in-the-middle exposure on payment and account flows.
Application Controls
Medium
Application-level security scores vary between B and C across the sector. Access controls, authentication hygiene, and API exposure are inconsistently implemented — particularly on loyalty platforms and B2B partner portals.
Sector verdict: Retail security teams are managing large, fast-changing digital estates with supplier ecosystems that extend far beyond what their TPRM programmes cover. The universal header weakness and software supply chain exposure suggest these gaps are structural — driven by speed-to-market priorities and fragmented technology ownership — not individual security failures.
Why Retail Needs This
Discovery. Prioritisation. Monitoring.
Retail digital estates are among the most dynamic in any sector — driven by seasonal launches, platform migrations, third-party integrations, and omnichannel expansion. Static security tools built for known assets cannot keep pace.
01
Continuous Discovery
Seasonal microsites, click & collect portals, loyalty apps, and payment integrations appear and disappear faster than traditional asset management can track. ThingsRecon discovers your full external surface continuously — including assets your own teams don't know exist.
02
Risk Prioritisation
With 74 Fix Now items across five organisations and 199 Fix Soon, retail security teams need clear prioritisation — not a raw vulnerability list. ThingsRecon scores every finding by exploitability and proximity to customer data.
03
Supply Chain Monitoring
Tag management platforms, analytics providers, CDN configurations, and payment widgets change frequently. ThingsRecon detects these changes the moment they appear on your external surface — before they open a supply chain attack path.
Supply Chain Intelligence
The suppliers no TPRM questionnaire will find
Traditional TPRM focuses on suppliers you know about and chose deliberately. But retail digital estates are filled with implicit suppliers — analytics platforms, tag managers, CDN providers, certificate authorities, and JavaScript libraries that arrive embedded in platforms, themes, and third-party widgets. ThingsRecon maps all of them, scores their proximity to your most sensitive customer assets, and identifies the shared exposure across your sector.
Sector-wide supplier connections1,021
Across 5 retail estates — detected via script, cert, ASN, DNS, and header vectors. The majority were not declared in any TPRM programme.
Suppliers in every retail estate5
Google, Cloudflare, Microsoft, Amazon, and DigiCert appear in all 5 retail organisations — a shared, sector-wide supply chain risk profile.
Fix Now items linked to suppliers33
Fix Now software findings across the sector indicate actively exploitable vulnerabilities in supplier-provided components.
Avg digital proximity — top supplier67%
Google's average digital proximity score across all 5 retail estates — the highest of any supplier. Scripts load within reach of checkout and account flows.
Top 5 common suppliers across all 5 retail organisations:
Supplier
Avg proximity
Vector
In
Found in
Google LLCgoogle.com
67%
script · header · dns
5/5
Company A, B, C, D, E
Cloudflare, Inc.cloudflare.com
57%
cert · dns · ASN
5/5
Company A, B, C, D, E
Microsoft Corporationmicrosoft.com
57%
script · header · ASN
5/5
Company A, B, C, D, E
Amazon Technologies, Inc.amazon.com · aws.com
51%
ASN · cert · dns
5/5
Company A, B, C, D, E
DigiCert, Inc.digicert.com
33%
cert
5/5
Company A, B, C, D, E
Critical Supplier Spotlight
Google LLC
google.com | Tag Manager · Analytics · APIs | Avg proximity 67%
Found in
All 5 retail organisations
Digital proximity
67% avg — highest of any supplier sector-wide
Connection vectors
JavaScript scripts · response headers · DNS
Retail risk profile
Script injection · Data exfiltration
Google Tag Manager and Analytics scripts are active on virtually every retail page — including product pages, account portals, and checkout flows. With an average digital proximity of 67%, Google's scripts sit closer to customer-facing assets than almost any other supplier in the retail estate. Magecart and formjacking attacks operate by compromising or misconfiguring third-party scripts at exactly this proximity level — a single misconfigured Google Tag Manager container can silently exfiltrate payment card data and customer PII from every transaction, without triggering a single firewall alert.
Attack vector: GTM misconfiguration → malicious tag injection → script skims payment form inputs → customer card data exfiltrated at scale (Magecart)
Retail attack path — script-based supply chain intrusion
1
Entry point
Third-party analytics / tag manager script (high-proximity supplier)
Entry
Misconfiguration or account compromise
2
Pivot
Malicious payload injected into shared tag container — executes on checkout page
Pivot
Script loads silently on every customer session
3
Impact
Payment form skimmed — customer card data & PII exfiltrated at scale
Impact
Sector Findings
Aggregated risk signals across all 5 organisations
The following findings reflect aggregated patterns observed across all five retail estates. Individual organisation-level findings are available through a full ThingsRecon engagement.
- Fix Now
HTTP security headers absent or critically misconfigured across all 5 retail estates. Missing Content-Security-Policy leaves customer-facing pages exposed to cross-site scripting and third-party script injection — the primary Magecart attack vector. All scanned retailers scored D or F on header hygiene.
- Fix Now
Outdated software components with known CVEs detected in 4 of 5 retail estates. Fix Now software findings total 33 across the sector — publicly known vulnerabilities in JavaScript libraries, server-side frameworks, and platform components actively exploited in retail targeting campaigns.
- Fix Now
SSL/TLS service misconfigurations generating Fix Now findings in 3 organisations. Weak cipher suites and misconfigured TLS on externally accessible services create man-in-the-middle exposure on customer account and payment flows.
- Fix Soon
Session and authentication cookies missing security flags across all 5 estates. Cookies without Secure, HttpOnly, or SameSite attributes expose customer session tokens to theft — particularly acute during peak trading events when session volume is highest.
- Fix Soon
Application-level security controls inconsistently applied across loyalty portals, account management pages, and B2B partner interfaces. Gaps in authentication hygiene and input validation create pathways to customer account takeover at scale.
- Monitor
Supplier certificate and DNS changes not tracked — certificate rotations, DNS record changes, and supplier ASN migrations across the 1,021 mapped supplier connections occur continuously. Without monitoring, supply chain changes that introduce new risk go undetected until after exploitation.
Get the Full Picture
Your organisation's exposure — mapped in 48 hours
This sector report shows the patterns. A ThingsRecon scan of your organisation shows exactly which assets, suppliers, and attack paths apply to you — including the ones your current tools have never seen.
✦ Full asset inventory
✦ Every supplier scored
✦ Attack paths mapped
✦ Fix Now / Fix Soon list
✦ GDPR & NIS2 mapping
✦ Continuous monitoring
Request a PoC scan