Security1 publisher3 min readPublished
VikingCloud survey links less attack spread across chain stores to a central policy mandate
VikingCloud's survey of 200 chain security leaders found attacks spread beyond the first site in 64% of cases under a policy mandate and 89% without one. None of the 13 tools it measured showed a link, and mandates did not change the 80% of chains that open stores before monitoring reaches them.
The Watch · Security desk

What happened
- VikingCloud surveyed 200 security and IT leaders at U.S. and European multi-site chains about attacks over the past year.
- Of respondents, 86% were attacked, and 77% of those saw the intrusion move into other locations, corporate systems or shared vendors.
- Where corporate mandated security policy at every site, 64% of attacks spread past their starting point, against 89% where it did not.
- None of the 13 security technologies measured was tied to less spread between sites, and real-time visibility was not either.
- Eighty percent of the chains open a new location before central monitoring and enforcement reach it.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Franchise and mixed operators weighing another tool purchase against a site-wide policy mandate have survey evidence on the mandate's side; fully owned chains gain little from writing one down.
- contradiction Self-rated confidence rises with tool count while tool count showed no link to spread, so a confident posture report tells a board about spending and little about containment.
- exposure New stores stay an unwatched entry point at the same rate whether or not a chain mandates policy, so solving spread with a mandate leaves the opening-day gap for someone else to own.
- cost Headquarters carries ransom decisions for sites whose controls it does not set, often without a full incident record reaching the board.
The mandate is a narrow measure. Only 51% of respondents said corporate sets security policy and requires every location to follow it [9]. A third let sites decide how to apply corporate guidelines, and 15% let each site write its own [9]. Among chains that own every location outright, 41% still do not mandate policy across all of them [10].
Counted as containment, the gap is wider. Under a mandate, 36% of attacks stayed at their starting point. Without one, 11% did [1]. Across the whole sample, roughly two in three respondents saw an attack spread in the past year [2].
The effect sits in one kind of chain. Among mixed and franchise operators, companies with a mandate were three times as likely to say an attack stayed put [12]. Among corporate-owned chains, the mandate made no measurable difference [12]. Help Net Security, which reported the survey, suggests a company that employs everyone at every site probably gets consistency without writing a mandate down [20].
This is a self-reported survey, and VikingCloud ran it [1]. It measures association. It cannot show that a mandate caused any attack to stay put. The write-up does not give subgroup sizes or a margin of error. "You cannot monitor your way out of blast radius. You have to govern," said Kevin Pierce, VikingCloud's President and COO [13].
Size makes spread worse. At attacked chains with 2,500 or more locations, 89% said the intrusion moved beyond its starting point, against 71% at smaller operators [5]. Confidence tracks tool count. Of all respondents, 83% call themselves confident or very confident [6]. That figure climbs from 73% among those running four or fewer of the 13 technologies to 100% among those running 10 or more [7]. Yet 48% lack real-time visibility across every location, and 40% say they would likely miss an active threat at their least-monitored sites [8].
Boards see part of the record. In all, 91% said at least one material incident in the past year never reached executive leadership or the board [14]. Forty-three percent said five or more went unreported, rising to 58% at chains with 2,500 or more locations [14]. The most common reason, cited by 47%, was fear of professional repercussions. Only 14% said they were unsure what counted as reportable [15]. Headquarters makes the ransom decision at 78% of chains [16], 27 points above the share that mandates policy everywhere [3].
Opening day is a separate gap. The 80% figure held whether or not a company mandated policy, and it did not improve at larger chains [17]. Only 7% of respondents named budget or staffing as their biggest risk [18]. Help Net Security's proposed fix is one named owner and a sign-off before the doors open [19].
What to watch
- Whether VikingCloud publishes respondent counts for franchise, mixed and corporate-owned chains, which would show how many answers the three-times figure rests on.
- Whether other chain surveys or incident data reproduce the finding that none of the 13 measured technologies tracked with cross-site spread.
- Whether any chain with 2,500 or more locations reports bringing new stores under central monitoring before opening day.