
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

A field engineer arrives to fix a self-checkout terminal.
Summary
A digital signage supplier needs to update content across several stores. A warehouse technician transfers a configuration file to equipment that cannot be reached through the corporate network. These are ordinary retail scenarios.
They are also examples of something that can sit outside many retailers’ usual cybersecurity controls: physical data transfer. As retail estates become more connected, security teams naturally focus on cloud platforms, networks, credentials and software vulnerabilities. But not every file, update or diagnostic tool reaches a retail system through those channels.
USB drives and other removable media can still play a practical role across stores, warehouses and fulfilment environments. The challenge is to ensure its use is controlled, visible and proportionate to the risk. Photo credit: iMin Technology/Pexels.
Why Physical Data Transfer Still Exists in Modern Retail Retail technology has moved quickly towards cloud-based systems, but most estates remain a mixture of old and new. An EPoS platform may sit alongside self-service kiosks, handheld stock devices, digital signage, warehouse scanners, smart shelving and specialist fulfilment equipment. Some systems can be updated remotely.
Others may require local maintenance, diagnostic files or offline configuration. This becomes particularly important during store openings, refurbishments and equipment roll-outs, when external engineers may be installing or configuring multiple devices in a short period of time. The security question is not whether a USB drive should ever be used.
It is whether the retailer knows which devices are being used, what they contain, where they have been and what checks take place before they connect to operational systems. The Gap Between Head Office Policy and Store Level Reality A retailer may have strong central cybersecurity policies while still facing inconsistent practices across hundreds of stores and operational sites. Controls designed at head office have to work in very different environments.
A flagship store, regional warehouse, temporary pop-up and small high-street branch may all operate different combinations of hardware, connectivity and local support. That creates the possibility of a gap between formal policy and operational reality. If a self-checkout terminal is offline, a digital display needs an urgent update or an engineer needs to retrieve diagnostic logs, staff may prioritise restoring service quickly.
In those situations, portable media can become the easiest route between systems. The UK National Cyber Security Centre notes that removable media can provide an additional route for malicious software to reach devices outside normal software installation processes. For retailers, the important point is that data can move into a system without following the same path as ordinary network traffic.
That makes removable media a separate security boundary that needs its own controls. Third-Party Engineers Create an Additional Trust Question Retailers depend heavily on external technology providers. EPoS vendors, kiosk manufacturers, facilities contractors, signage suppliers and warehouse automation specialists may all need physical access to equipment.
These providers often work across many customer environments and may use portable storage as part of maintenance or diagnostics. A retailer can tightly manage company-owned laptops and storage devices while having far less visibility over a drive brought in by an external engineer. This does not mean third-party devices should automatically be treated as unsafe.
It does mean the retailer should decide in advance what happens before external media connects to sensitive equipment. That might include limiting access to approved devices, requiring files to be checked before use, or establishing a defined process for contractor media. The key is consistency.
Security should not depend on an individual store manager deciding whether a device looks trustworthy in the middle of an operational problem. Connected Retail Is Increasing the Number of Physical Touchpoints Retail innovation is creating more distributed technology, not less. Edge computing, smart stores, IoT devices, electronic shelf labels, automated fulfilment systems and connected customer-facing hardware all increase the number of endpoints operating away from a retailer’s central IT environment.
Many of these technologies improve efficiency and customer experience, but they also create more places where maintenance, updates and configuration may need to happen locally. The more distributed the estate becomes, the more important it is to understand how data moves between those systems. This is particularly relevant where systems are deliberately isolated or restricted from the internet.
Reduced connectivity can lower exposure to some forms of attack, but it does not remove the need to manage files and devices that are physically introduced to the system. Treat Removable Media as a Controlled Gateway For many retailers, banning portable media entirely is unlikely to be practical. A stronger approach is to define where it is necessary and treat those points as controlled gateways.
The first step is understanding where removable devices are actually being used. This might include EPoS maintenance, digital signage, warehouse equipment, self-checkout systems or legacy hardware. Once those workflows are mapped, retailers can establish clearer rules around approved devices, ownership, storage and permitted systems.
Unknown devices can be restricted from connecting directly to sensitive equipment, while staff and contractors can be given a defined process for transferring files. Where portable media remains operationally necessary, dedicated removable media security measures can create a controlled checkpoint for files and devices before they reach business-critical systems. That separation matters because it reduces reliance on the destination system identifying a problem after a device has already been connected.
Retailers should also think beyond the individual scan. A broader USB cybersecurity policy can define who is authorised to use portable media, what systems it can connect to, how devices are checked and whether transfers need to be recorded. For larger retail estates, visibility can be as important as prevention.
Understanding when and where physical data transfer is taking place gives central security teams a clearer picture of activity across stores and operational sites. Security Controls Have to Work in the Store The strongest retail cybersecurity policies are not simply the most restrictive. They are the ones that work under real operational pressure.
If a security process makes routine maintenance too difficult, staff and suppliers may look for faster alternatives. Controls therefore need to reflect how stores, warehouses and field engineers actually work. As retail technology becomes more connected and distributed, that means looking beyond the network.
Cloud security, identity controls and endpoint protection remain fundamental, but physical data transfer still plays a role in many retail environments. For retailers, the challenge is to make those physical touchpoints as visible and controlled as their digital ones. That means understanding where removable media is still needed, setting clear rules around its use and making sure files are checked before they reach critical systems.
The aim is not to remove every convenient tool from the store or warehouse. It is to make sure that the same level of scrutiny applied to network activity also extends to the physical routes through which data can enter retail systems.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.