Retail chains with hundreds or thousands of locations are buying security tools and still seeing attacks jump from one store to another. A VikingCloud survey of 200 U.S. and European security and IT leaders found that none of the 13 technologies measured, nor real-time visibility, made a measurable difference in whether an intrusion stayed put. What did matter was governance: where headquarters mandated a single security policy for every location, 64% of attacks spread, versus 89% where no such mandate existed.
The gap is starkest at the largest chains. Among companies with 2,500 or more locations, 89% of attacked firms saw the intrusion move beyond its starting point, compared with 71% at smaller operators. Still, 83% of all respondents called themselves confident or very confident in their security posture, even though 48% lack real-time visibility across every location and 40% say they would likely miss an active threat at their least-monitored sites. Confidence rises with spending, but the survey suggests that spending alone does not shrink the blast radius.
A more troubling finding: 80% of chains open a new location before central monitoring and enforcement reach it, a figure that did not improve with size or with a policy mandate. And 91% of respondents said at least one material incident in the past year never reached executive leadership or the board; 43% said five or more went unreported, rising to 58% at the largest chains. The top reason, cited by 47%, was fear of professional repercussions.
The survey's practical takeaway is simple: monitoring cannot substitute for rules. VikingCloud's president and COO, Kevin Pierce, put it bluntly: "You cannot monitor your way out of blast radius. You have to govern." For chains, especially those with franchisees, the fix is a named owner and a sign-off before the doors open — not another security product. The data shows that mixed and franchise operators with a mandate were three times as likely to say an attack stayed put, while corporate-owned chains saw no measurable difference, likely because consistency already exists when the same employer runs every site. However, even among wholly owned chains, 41% still do not mandate policy across all locations, leaving the gap open. The survey highlights that the money follows the same pattern: 78% of headquarters make the ransom decision, but only 51% mandate the security policy that could prevent the ransom from being needed. Bridging that mismatch is the clearest opportunity for security leaders.}}]} Note: The response must be valid JSON, so we need to escape any double quotes in the body? Actually the body contains quotes around the Kevin Pierce quote, we need to escape them with backslash. Also the keyPoints have double quotes? No, they are strings, but the quotes inside the body need escaping. I'll fix the body string to have escaped quotes. Also the body has a period after the quote? We'll adjust. Let's produce clean JSON. I'll rewrite the body to avoid double quotes inside the string by using single quotes or rephrasing. Better to escape: "You cannot monitor..." etc. Also ensure the keyPoints don't have double quotes. The body is a single string, so we need to escape any double quotes. I'll use backslash. Also note the body has a period inside the quote. Let me rewrite the body to be concise. The instructions say 2-4 short paragraphs. I'll do 3 paragraphs. Also the body ends with a sentence about the mismatch. Let me produce the final JSON.```json{