Skip to content

Security1 publisher3 min readPublished

VikingCloud survey links less attack spread across chain stores to a central policy mandate

VikingCloud's survey of 200 chain security leaders found attacks spread beyond the first site in 64% of cases under a policy mandate and 89% without one. None of the 13 tools it measured showed a link, and mandates did not change the 80% of chains that open stores before monitoring reaches them.

The Watch · Security desk

Illustration accompanying VikingCloud survey links less attack spread across chain stores to a central policy mandate

What happened

  • VikingCloud surveyed 200 security and IT leaders at U.S. and European multi-site chains about attacks over the past year.
  • Of respondents, 86% were attacked, and 77% of those saw the intrusion move into other locations, corporate systems or shared vendors.
  • Where corporate mandated security policy at every site, 64% of attacks spread past their starting point, against 89% where it did not.
  • None of the 13 security technologies measured was tied to less spread between sites, and real-time visibility was not either.
  • Eighty percent of the chains open a new location before central monitoring and enforcement reach it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Franchise and mixed operators weighing another tool purchase against a site-wide policy mandate have survey evidence on the mandate's side; fully owned chains gain little from writing one down.
  • contradiction Self-rated confidence rises with tool count while tool count showed no link to spread, so a confident posture report tells a board about spending and little about containment.
  • exposure New stores stay an unwatched entry point at the same rate whether or not a chain mandates policy, so solving spread with a mandate leaves the opening-day gap for someone else to own.
  • cost Headquarters carries ransom decisions for sites whose controls it does not set, often without a full incident record reaching the board.

The mandate is a narrow measure. Only 51% of respondents said corporate sets security policy and requires every location to follow it [9]. A third let sites decide how to apply corporate guidelines, and 15% let each site write its own [9]. Among chains that own every location outright, 41% still do not mandate policy across all of them [10].

Counted as containment, the gap is wider. Under a mandate, 36% of attacks stayed at their starting point. Without one, 11% did [1]. Across the whole sample, roughly two in three respondents saw an attack spread in the past year [2].

The effect sits in one kind of chain. Among mixed and franchise operators, companies with a mandate were three times as likely to say an attack stayed put [12]. Among corporate-owned chains, the mandate made no measurable difference [12]. Help Net Security, which reported the survey, suggests a company that employs everyone at every site probably gets consistency without writing a mandate down [20].

This is a self-reported survey, and VikingCloud ran it [1]. It measures association. It cannot show that a mandate caused any attack to stay put. The write-up does not give subgroup sizes or a margin of error. "You cannot monitor your way out of blast radius. You have to govern," said Kevin Pierce, VikingCloud's President and COO [13].

Size makes spread worse. At attacked chains with 2,500 or more locations, 89% said the intrusion moved beyond its starting point, against 71% at smaller operators [5]. Confidence tracks tool count. Of all respondents, 83% call themselves confident or very confident [6]. That figure climbs from 73% among those running four or fewer of the 13 technologies to 100% among those running 10 or more [7]. Yet 48% lack real-time visibility across every location, and 40% say they would likely miss an active threat at their least-monitored sites [8].

Boards see part of the record. In all, 91% said at least one material incident in the past year never reached executive leadership or the board [14]. Forty-three percent said five or more went unreported, rising to 58% at chains with 2,500 or more locations [14]. The most common reason, cited by 47%, was fear of professional repercussions. Only 14% said they were unsure what counted as reportable [15]. Headquarters makes the ransom decision at 78% of chains [16], 27 points above the share that mandates policy everywhere [3].

Opening day is a separate gap. The 80% figure held whether or not a company mandated policy, and it did not improve at larger chains [17]. Only 7% of respondents named budget or staffing as their biggest risk [18]. Help Net Security's proposed fix is one named owner and a sign-off before the doors open [19].

What to watch

  • Whether VikingCloud publishes respondent counts for franchise, mixed and corporate-owned chains, which would show how many answers the three-times figure rests on.
  • Whether other chain surveys or incident data reproduce the finding that none of the 13 measured technologies tracked with cross-site spread.
  • Whether any chain with 2,500 or more locations reports bringing new stores under central monitoring before opening day.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories