Skip to main content

Cybersecurity statistics / Retail

In 2025, security spending increased from 0.57% to 0.75% of revenue in the retail and hospitality industry.

PublisherRetail & Hospitality Information Sharing and Analysis Center (RH-ISAC) and IANS
Report2026 CISO Benchmark Report
Published1 April 2026
TopicsRetail, Hospitality, IT Budgeting, Security Spending, Budget

Published by Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) and IANS in 2026 CISO Benchmark Report, 1 April 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Compare this across sources

12 sources answer what share of organisations have an ai governance policy in place. They report between 18% and 44%, with a median of 36.5%.

See all 12 sources

Related statistics

32% of retail organizations paid the ransom, the lowest payment rate of any sector.
Sophos, 18/07/2026
The three industries with the highest baseline PPP are Healthcare & Pharmaceuticals at 42.7%, Insurance at 38.1%, and Retail & Wholesale at 36%.
KnowBe4, 12/07/2026
Retail firms average 10 days to remediate exposures.
Intruder, 27/05/2026
83% of organizations in crypto and decentralized finance, 79% in retail, and 76% in manufacturing experienced cyber attacks.
Sygnia, 27/05/2026
The top three targeted sectors by ransomware victims were manufacturing (1,284), business services (824), and retail (682).
Fortinet, 27/05/2026
71% of retail and hospitality CISOs identify AI as a primary concern, citing risks such as data leakage, insider misuse, and insufficient governance controls.
Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) and IANS, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.