
IT security for retail and logistics
Many sites, high staff turnover and an outage that costs revenue from the first minute. Where we start in retail and logistics.
The situation
Swiss retail is only growing in part of the assortment. In the first half of 2026 total nominal turnover rose 1.2 percent according to the Swiss Retail Federation, and bricks-and-mortar retail 1.0 percent. Food grew 3.8 percent while bricks-and-mortar non-food shrank by 3.3 percent.
Price competition and margin pressure sit at the top of the industry's worry list accordingly. Where turnover stagnates or falls, every expense has to either reduce risk or replace another cost. Security that only adds cost does not get approved in that calculation.
At the same time revenue depends directly on IT: tills, warehouse, web shop and dispatch. An outage here does not stop a project, it stops the business. There is no grace period in which you calmly restore.
And the structure does not make it easier. Stores, warehouses and branch offices grew over the years, the cloud environment dates from a migration, and seasonal staff arrive and leave faster than accounts get closed.
What we find in this industry
- Many sites, each one slightly differentStores, warehouses and branch offices grew over the years. What applies in one building does not apply in the next. That costs not only security but support time every single day.
- High turnover and seasonal staffAccounts are opened quickly and rarely closed cleanly. After two seasons nobody knows who still has access. It is the most common open door in this industry.
- The cloud environment grew, it was never set upThe baseline settings in Microsoft 365 date from the migration. Nobody has deliberately reviewed them since, even though both the defaults and the threat picture have changed several times.
- An outage costs revenue from the first minuteTills, warehouse and web shop hang together. Recovery therefore has to be rehearsed, not just documented.
- Security requirements spread across many teamsStore management, logistics, IT and procurement all have to pull. Without someone running the programme, delivery dissolves into individual measures.
- The margin leaves no room for security that returns nothingWhere non-food turnover is shrinking, every expense has to either reduce risk or replace another cost. One standard across all sites does both.
Typical trigger
An outage in your own operation or at a logistics partner, or a major customer writing security requirements into the framework contract.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
Bring every site to the same standard
We harden Microsoft 365 and cloud, tidy up identities and set conditional access so that store operations and security work together. That includes a clean joiner and leaver process for seasonal staff.
One standard across all sites is also the cheaper operation: fewer special cases, less support effort, fewer licences that only one location needs.
Make visible what actually stops the business
We assess along the processes that carry revenue and prioritise by impact on operations rather than technical severity.
The result is an order of work a CFO can sign off on.
One target picture instead of many single measures
We run a security programme with a clear target picture and coordinate delivery across regions and teams.
Progress becomes measurable instead of disappearing into individual projects.
Evidence for framework contracts, without paperwork for its own sake
When large customers write security requirements into the contract, you need provable answers rather than assurances.
We build exactly as much structure as the contract calls for, and no more.
Who it is for
- Retail and logistics companies with several sites
- Operations with high turnover and many seasonal staff
- Firms with a grown Microsoft 365 environment and no deliberate baseline
- Suppliers whose large customers write security requirements into the framework contract
Related engagements
- Hardening a Microsoft 365 tenant including MacOS device management
- Coordinating a group-wide IT security programme
- Ransomware recovery after full encryption
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
We have twelve stores with different equipment. Where do you start?
With identities and access, not with hardware. Who can log in where is the bracket across all sites and can be tidied centrally, without replacing anything in any store.
Seasonal staff are our biggest issue. What actually helps?
A binding leaver step tied to the HR process rather than to an email to IT. As long as closing an account depends on someone remembering, the gap stays.
How quickly can we sell again after an outage?
That depends on whether recovery has ever been rehearsed. A backup that has never been restored is an assumption, not a safeguard. It is usually the first item on the roadmap.
Is ISO 27001 worth it in retail?
Only if customers or partners ask for it. Otherwise the better path is to build the evidence the framework contract actually requires and leave certification as a later decision.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

