Skip to main content
Anthrasec

Customers expect to browse, pay and collect without a hitch, on every channel, every day. We build and protect the platforms, payments and store systems behind that experience, so your busiest days are your best ones.

  • Peak-ready platforms
  • Payments and customer data protected
  • AI that improves margin
A shopper carrying a basket down a supermarket aisle

£440m

upper estimate of the cost of the 2025 cyber attacks on M&S and the Co-op, from a low of £270m (Cyber Monitoring Centre)

The sector today

Every channel is now a digital channel

Stores, websites, apps and warehouses are one connected system. When any part fails, customers notice within minutes.

A person holding a payment card while shopping online on a laptop

Retail has become one of the most technology-dependent sectors in the UK. More than a quarter of all retail spending now happens online, and even in-store sales rely on cloud-hosted tills, payment terminals, stock systems and loyalty apps talking to each other in real time. Peak events such as Black Friday, Christmas and a successful product launch can multiply traffic many times over within an hour. A platform that copes on an ordinary Tuesday can fail at exactly the moment it matters most, and sales lost at peak are rarely recovered.

The 2025 attacks on major UK retailers showed how quickly a cyber incident becomes a trading problem: online orders suspended, shelves empty and customer data stolen. Attackers reportedly got in by impersonating staff to help desks and suppliers, not through a sophisticated technical flaw. Retailers also carry responsibility for card data under PCI DSS and for customer data under UK GDPR, while fraudsters test every checkout. Anthrasec helps retailers and consumer brands build platforms that scale, protect payments and identities, connect stores and fulfilment, and use AI where it improves margin.

Online is now more than a quarter of retail

The share of retail sales made online jumped during the pandemic and has settled well above its earlier level. Every point of that share depends on platforms, payments and delivery systems staying available.

Internet sales as a percentage of total retail sales, Great Britain

Source: ONS, Internet sales as a percentage of total retail sales

YearShare
201512.5%
201614.7%
201716.3%
201818%
201919.2%
202028.1%
202130.7%
202226.6%
202326.7%
202427.1%
202527.5%

Who we help

From single stores to national chains

Retail covers very different businesses. We shape our services to how you sell.

  • High-street and multi-site retailers

    Reliable store networks, tills and Wi-Fi, managed centrally and secured consistently across every site.

  • E-commerce and direct-to-consumer brands

    Fast, scalable storefronts and checkouts, with the monitoring to catch problems before customers do.

  • Grocery and convenience

    Always-on systems for high-volume, low-margin trading, where minutes of downtime mean empty shelves.

  • Wholesale and distribution

    Connected ordering, stock and warehouse systems, with supplier and partner access kept under control.

  • Hospitality and leisure

    Booking, ordering and payment systems that hold up through the busiest service.

  • Marketplaces and retail technology companies

    Secure development, testing and the assurance evidence larger retail customers ask for.

The pressures

Six risks retail leaders ask us about

Each one is manageable with the right controls. Here is what's at stake, and how we respond.

  • Failure at peak

    The risk
    Traffic can rise many times over within minutes. Sites and tills that slow or fail lose sales that don't come back.
    Our response
    Load testing, architecture that scales automatically and a change-freeze plan agreed before peak.
  • Help-desk social engineering

    The risk
    Attackers impersonate staff to have passwords and multi-factor authentication reset, then move through the network.
    Our response
    Verified reset procedures, phishing-resistant authentication and alerts on unusual account changes.
  • Payment fraud and card data

    The risk
    Stolen card details are tested at your checkout, and any system that touches card data falls under PCI DSS.
    Our response
    Reduced PCI scope, tokenised payments, script monitoring on payment pages and bot defences.
  • Ransomware

    The risk
    Encrypted stock, ordering or warehouse systems can stop trading across every channel at once.
    Our response
    24/7 detection, segmented networks and immutable backups with rehearsed recovery.
  • Supplier and third-party access

    The risk
    Logistics partners, agencies and software suppliers often hold access to your systems and data.
    Our response
    Least-privilege access, supplier risk reviews and monitoring of third-party connections.
  • Disconnected systems

    The risk
    Stock, orders and customer records that disagree across channels lead to overselling and poor service.
    Our response
    Integrations that give you one reliable view of stock, orders and customers.

What we deliver

Our services, applied to retail

One team covers platforms, security, stores, software and AI, so nothing falls between suppliers.

Two colleagues talking as they walk through a warehouse aisle, one holding a clipboard

AI in retail

Where AI earns its place in retail

The best retail AI projects start with a number you want to move: waste, availability, conversion or cost to serve.

1 in 5

wholesale and retail businesses reported using at least one AI technology in June 2026, compared with almost three in five in information and communication

Source: ONS, Artificial intelligence in UK businesses, 2023 to 2026

  • Demand forecasting

    Predicting sales by product, store and channel from your own history, the weather and promotions, to cut waste and stock-outs.

    Safeguard: Buyers can see why a forecast changed, and override it.

  • Search and recommendations

    Helping customers find the right product faster, on your site and in your app.

    Safeguard: Personalisation respects consent and marketing preferences under UK GDPR and PECR.

  • Customer service assistants

    Answering order, delivery and returns questions at any hour, and handing over to staff when needed.

    Safeguard: A clear hand-off to a person, and no invented answers on refunds or policy.

  • Fraud and loss detection

    Spotting unusual orders, refunds and account activity before goods leave the warehouse.

    Safeguard: People review flagged cases, and decisions can be explained to the customer.

When it matters most

Black Friday, 8pm: how a prepared retailer stays online

Peak trading combines record traffic with heightened attack activity. This is how preparation and our monitoring service are designed to carry you through it.

Illustrative scenario showing how our service is designed to work. Response times are agreed with each client and set out in their service agreement.

  1. Weeks before

    Rehearse

    Load tests at several times last year's peak find the checkout's limits. Fixes go in before the change freeze.

  2. 20:00

    Scale

    Traffic climbs sharply as a promotion lands. Capacity scales automatically, and dashboards show response times holding.

  3. 20:20

    Detect

    Monitoring spots a burst of failed sign-ins: bots testing stolen passwords against customer accounts.

  4. 20:25

    Defend

    Bot traffic is rate-limited and challenged at the network edge. Genuine customers keep shopping without interruption.

  5. 20:40

    Protect the checkout

    A third-party recommendations service slows down. It is switched off automatically, so pages and checkout stay fast.

  6. Next morning

    Review

    You receive a summary of traffic, incidents and actions, and capacity scales back down to control cost.

Regulation and standards

The frameworks retail is measured by

We help you prepare the controls and evidence each one asks for. Certification and assessment decisions rest with the relevant accredited body or assessor.

  • PCI DSS v4.0.1

    What it asks forSecurity requirements for any business that stores, processes or transmits card data, including controls on scripts running on payment pages.

    How we helpScope reduction, gap analysis and remediation ahead of your assessment or self-assessment questionnaire.

  • UK GDPR and the Data Protection Act 2018

    What it asks forLawful, secure handling of customer and employee data, with breach reporting within 72 hours.

    How we helpData mapping, access controls, encryption and incident response support.

  • Privacy and Electronic Communications Regulations (PECR)

    What it asks forConsent for marketing emails and texts, and for non-essential cookies and tracking.

    How we helpConsent-aware tracking and marketing integrations, built correctly from the start.

  • Cyber Essentials

    What it asks forThe government-backed baseline of five technical control areas that stops the most common attacks.

    How we helpReadiness assessment and remediation before your certification body's assessment.

  • ISO/IEC 27001

    What it asks forAn independently audited information security management system, often requested by enterprise partners and marketplaces.

    How we helpRisk assessment, policies and control implementation ahead of your certification audit.

  • WCAG 2.2 AA and the Equality Act 2010

    What it asks forOnline services that disabled customers can use, with reasonable adjustments made for them.

    How we helpAccessibility audits, fixes and testing built into delivery.

Our approach

Your first 90 days with Anthrasec

A typical first engagement for a retailer. You see progress every fortnight, and you own everything we produce.

Jackets and knitwear hanging on rails in a clothing store
  1. Weeks 1–2

    Discover

    We map your platforms, payment flows, store systems and suppliers, and review the incidents from your last peak.

    You get: A clear picture of your estate and risks

  2. Weeks 3–6

    Secure the basics

    Identity and help-desk procedures, patching, backups and monitoring are tightened, starting with what protects trading.

    You get: Urgent gaps closed and monitoring live

  3. Weeks 7–10

    Build

    We deliver the first agreed improvement, such as load testing, a checkout fix or a forecasting pilot.

    You get: A measurable improvement in production

  4. Weeks 11–13

    Prepare for peak

    We run a peak rehearsal, test recovery and agree a 12-month roadmap with costs.

    You get: A tested peak plan and a costed roadmap

For your team

What each leader gets from working with us

Retail technology touches every part of the business. We make sure each team has what it needs.

Common questions

Retail IT and security, answered

Can you help us prepare for peak trading?

Yes. We load test your platform against realistic peak traffic, fix the bottlenecks, agree a change freeze and put monitoring and an on-call plan in place. Ideally this starts at least three months before your busiest period.

Do you help with PCI DSS compliance?

We help you reduce the number of systems in scope, close gaps in your controls and prepare evidence. Formal assessment is carried out by a Qualified Security Assessor, or through your acquirer's self-assessment process.

How can we defend against attacks like those on UK retailers in 2025?

Start with identity. Tighten how your help desk verifies people before resetting passwords or multi-factor authentication, use phishing-resistant sign-in for administrators, limit privileged access and segment your network. Then make sure backups are immutable and that you have rehearsed recovering from them.

Can you work with our existing e-commerce platform?

Yes. We work with hosted platforms, open-source platforms and custom builds, and we'll tell you honestly whether improving what you have or moving to something new gives the better return.

We're a smaller retailer. Is this relevant to us?

Yes. Smaller retailers take card payments, hold customer data and depend on a few critical systems, just like larger ones. We scale the service to your size, starting with the basics that prevent most attacks and outages.

How do you use AI in retail without risking customer trust?

We start with a measurable goal, use only the data customers have agreed to share, keep people in charge of decisions that affect customers, and test for errors before anything goes live.

More sectors

Explore our other sectors

Compare all sectors

Work with us

Ready to work with Anthrasec?

Let's schedule a meeting.

Pick a time that suits you and tell us a little about what you need. We'll come prepared, with the right people in the room.

Step 1 of 4

Choose a date and time

October 2026

Checking availability…

Times are shown in UK time (London). Meetings are held on Microsoft Teams.

Available times

Choose a date to see available times.