Back Masslive Cyber attacks cited at 80% of reporting restaurants, new report says
A new report from a cybersecurity and compliance company says that 80% of quick service and fast-casual restaurants surveyed experienced at least one “cyber incident” in the last 12 months and 76% had sensitive data leaked. That’s despite 94% of the restaurants leaders expressing confidence in their ability to prevent or detect an attack.
The data was gathered by VikingCloud , which questioned security and IT leaders, along with franchise owners, as they looked into restaurants in the United States and Canada.
The leaked data ranges from payment card information to personal information of customers to internal system credentials and payroll records. The report also found that many of the restaurants did not have consistent systems in place to handle a centralized approach to cybersecurity, and that 78% of those surveyed “delay security patches to avoid disrupting service.” On top of that, more than a third of those questioned “mistook a real cyberattack for a routine technical glitch, meaning many incidents go unrecognized.”
A report by VikingCloud last year found that almost half of the cybersecurity leaders in that survey failed to report a “material incident” up the chain of command. And in this year’s report, almost half of the respondents said they took a revenue hit thanks to an operational disruption, with 30% saying they lost a costumer and suffered brand damage.
Additionally, 36% of respondents say they are either “not at all” or “somewhat” prepared for socially engineered deep fake videos or voice attacks, even though 80% were victims of some type of social engineering attack, such as fake refund requests and phishing attempts to get staff credentials.
“A 500-location chain could have hundreds of different digital environments, connected by shared vendors, systems, and credentials,” VikingCloud president and COO Kevin Pierce said in a statement. “One weak location is all it takes to open a door into the entire enterprise. Most chains are lacking the visibility needed for true protection and resilience.”
Another potential issue for these restaurants is third-party vendors, with a little more than a quarter of those surveyed saying they had third-party platform data leaked.
A little more than a third of these restaurants reported using around-the-clock monitoring, with standardized controls and vetted response plans for all the locations, meaning there is room for growth in the security approaches across the industry. The report says 30% of those questioned plan to bring in outside cybersecurity to more closely monitor their systems.
“Cybersecurity has moved from a back-office cost to a competitive differentiator,” Pierce said in the statement. “The chains that treat it that way will protect their revenue and deepen the trust that keeps customers coming back.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
