Presenting to a small group in a meeting room

IT security for retail and logistics

Many sites, high staff turnover and an outage that costs revenue from the first minute. Where we start in retail and logistics.

Three people talking in an office

Retail & Logistics

Book a conversation

The situation

Swiss retail is only growing in part of the assortment. In the first half of 2026 total nominal turnover rose 1.2 percent according to the Swiss Retail Federation, and bricks-and-mortar retail 1.0 percent. Food grew 3.8 percent while bricks-and-mortar non-food shrank by 3.3 percent.

Price competition and margin pressure sit at the top of the industry's worry list accordingly. Where turnover stagnates or falls, every expense has to either reduce risk or replace another cost. Security that only adds cost does not get approved in that calculation.

At the same time revenue depends directly on IT: tills, warehouse, web shop and dispatch. An outage here does not stop a project, it stops the business. There is no grace period in which you calmly restore.

And the structure does not make it easier. Stores, warehouses and branch offices grew over the years, the cloud environment dates from a migration, and seasonal staff arrive and leave faster than accounts get closed.

What we find in this industry

  • Many sites, each one slightly differentStores, warehouses and branch offices grew over the years. What applies in one building does not apply in the next. That costs not only security but support time every single day.
  • High turnover and seasonal staffAccounts are opened quickly and rarely closed cleanly. After two seasons nobody knows who still has access. It is the most common open door in this industry.
  • The cloud environment grew, it was never set upThe baseline settings in Microsoft 365 date from the migration. Nobody has deliberately reviewed them since, even though both the defaults and the threat picture have changed several times.
  • An outage costs revenue from the first minuteTills, warehouse and web shop hang together. Recovery therefore has to be rehearsed, not just documented.
  • Security requirements spread across many teamsStore management, logistics, IT and procurement all have to pull. Without someone running the programme, delivery dissolves into individual measures.
  • The margin leaves no room for security that returns nothingWhere non-food turnover is shrinking, every expense has to either reduce risk or replace another cost. One standard across all sites does both.

Typical trigger

An outage in your own operation or at a logistics partner, or a major customer writing security requirements into the framework contract.

The ODCUS difference

No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.

Why these services fit

Security Management & Operations

Bring every site to the same standard

We harden Microsoft 365 and cloud, tidy up identities and set conditional access so that store operations and security work together. That includes a clean joiner and leaver process for seasonal staff.

One standard across all sites is also the cheaper operation: fewer special cases, less support effort, fewer licences that only one location needs.

Security Assessment with Implementation

Make visible what actually stops the business

We assess along the processes that carry revenue and prioritise by impact on operations rather than technical severity.

The result is an order of work a CFO can sign off on.

Interim & Fractional CISO

One target picture instead of many single measures

We run a security programme with a clear target picture and coordinate delivery across regions and teams.

Progress becomes measurable instead of disappearing into individual projects.

ISMS & ISO 27001

Evidence for framework contracts, without paperwork for its own sake

When large customers write security requirements into the contract, you need provable answers rather than assurances.

We build exactly as much structure as the contract calls for, and no more.

Who it is for

  • Retail and logistics companies with several sites
  • Operations with high turnover and many seasonal staff
  • Firms with a grown Microsoft 365 environment and no deliberate baseline
  • Suppliers whose large customers write security requirements into the framework contract

Related engagements

Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.

FAQ

We have twelve stores with different equipment. Where do you start?

With identities and access, not with hardware. Who can log in where is the bracket across all sites and can be tidied centrally, without replacing anything in any store.

Seasonal staff are our biggest issue. What actually helps?

A binding leaver step tied to the HR process rather than to an email to IT. As long as closing an account depends on someone remembering, the gap stays.

How quickly can we sell again after an outage?

That depends on whether recovery has ever been rehearsed. A backup that has never been restored is an assumption, not a safeguard. It is usually the first item on the roadmap.

Is ISO 27001 worth it in retail?

Only if customers or partners ask for it. Otherwise the better path is to build the evidence the framework contract actually requires and leave certification as a later decision.

Let us talk about your situation

Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.