Cybersecurity Is Now a Board Issue, Not Just a Technology Problem
Speaking to The Retail Podcast at NRF APAC 2026 in Singapore, DFI Retail Group Chief Executive Scott Price argued that cybersecurity has moved from the server room to the boardroom. With DFI running 23 e-commerce platforms and thousands of stores across Asia, Price makes the case for shared threat intelligence through RH-ISAC, warning that customer trust, not technology, is the strategic asset at risk.
- 1Scott Price says cybersecurity is no longer a tech issue but a board issue, with DFI's own annual report listing cyber risk among its principal threats to data, operations and customer trust.
- 2Research cited by Price found 73% of Asian consumers would stop using a platform after a cyber event, making security a direct commercial risk rather than an IT cost.
- 3Deepfakes of Price himself have already been used to target DFI finance staff, which is why he argues servant leadership cultures that empower employees to challenge instructions are now a security control.
Retail has spent years becoming more digital.
Every step has created new opportunities. E-commerce has expanded reach. Loyalty platforms have generated richer customer insight. Apps have made shopping more convenient. Rapid-delivery marketplaces have created new fulfilment channels. Artificial intelligence promises another major leap in productivity and personalisation.
Every connection also creates another potential vulnerability.
For Scott Price, Group Chief Executive of DFI Retail Group, that means cybersecurity can no longer be treated as an isolated technology problem.
Speaking to Alex Rezvan, Founder of The Retail Podcast, immediately after his keynote at NRF APAC in Singapore on 2 June 2026, Price argued that cyber risk increasingly needs to be understood at an industry and board level rather than left exclusively to individual IT teams.
His keynote at NRF APAC 2026 focused specifically on customer trust, cyber awareness and the case for collaborative security initiatives such as the Retail and Hospitality Information Sharing and Analysis Center, or RH-ISAC.
The underlying argument is straightforward.
When retailers share the same customers, technology providers, attack techniques and increasingly interconnected digital infrastructure, one company's cyber threat can contain intelligence that helps protect the rest of the sector.
Keeping that information isolated may no longer make sense.
Cybersecurity Has Moved From the Server Room to the Boardroom
Cyber incidents were once treated largely as technical failures.
Price described a culture in which being successfully attacked could carry a sense of embarrassment or organisational weakness, encouraging companies to reveal little beyond what regulation required.
His concern is that secrecy can weaken the wider industry.
Five Things Friday
Five useful signals from the people shaping global retail. Every Friday.
Threat actors learn from one another. Retailers need to do the same.
Price's central message during the interview was explicit: "It's no longer a tech issue. This is a board issue."
DFI's own corporate reporting supports the significance of that concern.
The group's 2025 Annual Report identifies IT systems, cybersecurity and data protection among its principal risks and states that cyber incidents could compromise data, disrupt inventory and customer-facing platforms, affect product availability and damage customer trust and experience.
DFI also states that its technology environment includes legacy systems, SaaS platforms, e-commerce and omnichannel services, loyalty programmes, in-store digital tools, distribution centres and employee systems.
Cybersecurity is therefore not sitting beside the retail operating model. It is embedded throughout it.
Digital Retail Has Dramatically Expanded the Attack Surface
DFI provides a useful illustration of the complexity.
At 31 December 2025, DFI Retail Group and its associates operated 7,580 outlets across 12 markets, spanning health and beauty, convenience, food, home furnishings and restaurants. The group reported US$8.9 billion in revenue for the year.
During the interview, Price gave a sense of DFI's own digital complexity: 23 e-commerce platforms and relationships with six or seven agentic rapid-delivery commerce platforms across its markets.
"The incremental surface area of attack for us has become so large," he said. "Going it alone to me makes little sense."
Each connection creates another point where systems, people and data interact.
The conventional response is for each company to build stronger individual defences. Price believes that is necessary but no longer sufficient.
For a multi-market retailer operating across a fragmented Asian retail landscape, he argued that trying to understand every threat entirely independently makes progressively less sense.
That is where collaboration enters the strategy.
Retailers Compete for Customers. They Do Not Need to Compete on Threat Intelligence.
Price's argument introduces an important distinction between competitive and non-competitive information.
Retailers compete aggressively on price, products, locations, loyalty, customer experience, delivery and market share.
Cyber threat intelligence is different.
One retailer learning how an attack is being attempted does not lose competitive advantage by helping another retailer recognise the same threat.
Price described this as a non-competitive layer of the industry, pointing to RH-ISAC as a mechanism through which retailers and other consumer-facing companies can share cybersecurity intelligence.
RH-ISAC describes itself as a trusted community for sharing sector-specific cybersecurity information and intelligence across retail, hospitality and other consumer-facing businesses.
The model is built on a simple premise: no single retailer can see every attack signal. A network can see more.
The Strategic Asset at Risk Is Customer Trust
The strongest part of Price's argument is not really about technology. It is about trust.
Historically, retail trust was relatively tangible. Was the advertised price the price charged at checkout? Was the product available? Would the retailer honour the return?
Digital commerce has expanded that definition.
Retailers now hold names, addresses, purchase histories, loyalty information, payment details, preferences and increasingly sophisticated behavioural data.
Customers are being asked to exchange more information for better personalisation and convenience. That exchange depends on confidence.
Price argued that if customers stop trusting retailers to protect their information, they may become less willing to share the data retailers increasingly rely on to personalise experiences, improve operations and lower costs.
Price cited research conducted in Asia that he described as particularly striking.
"Asians are probably the most tech-enabled and tech-agile," he said. "They are also the most unforgiving." According to that research, 73% of consumers in Asia said they would stop interacting with a platform if they saw that a cyber event had put their data at risk.
That makes cybersecurity a commercial issue.
A breach is not only an IT recovery project. It can affect the relationship on which digital retail increasingly depends.
AI Makes the Trust Equation More Urgent
Artificial intelligence intensifies the challenge.
Retailers want AI to improve forecasting, personalisation, customer service, productivity and decision-making.
But many of those applications depend on data. The more useful retailers want AI to become, the more important the quality, accessibility and security of that data becomes.
Price's concern is that attackers are gaining access to powerful technologies too.
AI can improve the sophistication and scale of defensive security. It can also improve phishing, impersonation, automation and other attack techniques.
The resulting problem is asymmetric. A retailer may need thousands of employees to behave securely every day. An attacker needs one successful opening.
This is RetailNews.ai's analysis: AI governance and cybersecurity governance increasingly need to be considered together. Retailers cannot responsibly accelerate AI adoption while treating the security of the information feeding those systems as a separate conversation.
Asia's Fragmented Retail Landscape Makes Collaboration More Important
Price also placed the issue in a specifically Asian context.
Retail across the region is highly diverse. Different countries have different market leaders, consumer behaviours, regulations and levels of digital maturity.
Price described the industry as moving towards a more regionalised form of omnichannel retail, with strong country-level players operating inside highly varied markets.
That fragmentation can make regional collaboration harder. But it can also make it more valuable.
DFI's multi-country footprint gives Price exposure to retail executives operating in very different environments. He argued that forums such as NRF can help bring those leaders into the same conversation around shared cyber risk.
Security becomes one of the rare areas where a competitor's resilience can indirectly strengthen the wider ecosystem.
If customers begin losing confidence in digital retail platforms generally, the consequences are not confined neatly to whichever retailer was attacked first.
The CEO's Job Is to Enable the Security Team
Price does not argue that chief executives should suddenly become cybersecurity engineers.
He argues that they need to create the conditions in which their security teams can operate effectively.
That begins with the Chief Information Security Officer.
Price said he would expect CISOs to communicate with peers and participate in wider professional networks.
"If you talk to your CISO and they say 'No, I don't talk to other CISOs,' you probably have the wrong CISO," he said.
CEOs, in turn, should understand which collaborative platforms their cybersecurity teams can access and what organisational support or permissions they need to participate effectively.
RH-ISAC membership provides member companies with access to threat intelligence, peer collaboration, working groups, benchmarking, training and incident-related insights.
The CEO's responsibility is therefore not to replace the specialist. It is to remove the barriers preventing the specialist from doing the job. And then make sure the board understands what is being done.
Information Sharing Is Becoming Part of Cyber Defence
The cultural shift Price is advocating is significant.
Companies have historically protected sensitive security information carefully, and for good reason. Effective collaboration does not mean publicly revealing vulnerabilities or publishing confidential incident details.
RH-ISAC itself operates under information-handling rules including the Traffic Light Protocol, designed to control how threat information can be shared within trusted communities.
That distinction matters. The choice is not between secrecy and publishing everything. It is between isolation and trusted information exchange.
Retailers can share useful intelligence inside controlled environments without giving attackers a roadmap to their systems.
That allows one organisation's warning signal to potentially become another organisation's early defence.
Cybersecurity Is Becoming an Economic Risk
There is another reason boards are paying attention.
Cyber risk increasingly connects directly to business performance.
DFI's own risk disclosures state that cyber incidents could interrupt operations, compromise customer information, reduce product availability and adversely affect trust.
Those are not abstract technical outcomes. They affect revenue, stores, inventory, employees, customers, reputation and regulation.
RetailNews.ai's interpretation is that this changes how investment in cybersecurity should be framed internally. Security spending can easily appear to be a cost because success often means something does not happen: no ransomware event, no major outage, no customer data breach, no operational shutdown. But that absence is exactly what the investment is buying.
Cybersecurity is increasingly a form of commercial resilience.
The Human Layer May Be Retail's Hardest Vulnerability
Technology is only one side of the problem.
Price ended the discussion by focusing on what he sees as one of the most difficult areas of information security: people.
He emphasised that insider risk does not necessarily involve malicious employees. Mistakes can originate from trust, inexperience, urgency or a failure to question a convincing instruction.
AI-generated impersonation makes that problem more complicated. Deepfake audio and video can make fraudulent instructions appear to come from a senior executive.
Price made this personal. He revealed that deepfakes of himself had already been used to approach a mid-level finance person at DFI with instructions to wire money to an account immediately.
"In that world, if you don't have a servant leadership culture where everyone is empowered to question and challenge, you're going to end up at risk because they're just simply going to comply," he said.
The security response cannot therefore rely solely on teaching employees to identify badly written phishing emails. Businesses also need cultures in which people feel authorised to challenge an instruction that looks wrong.
Hierarchy Can Become a Cybersecurity Weakness
Price believes this issue deserves particular attention in parts of Asia, where workplace cultures can sometimes be more hierarchical.
His concern is straightforward. If an employee is culturally conditioned not to question a senior leader, a highly convincing impersonation of that leader becomes more dangerous.
Price argued that organisations need to empower employees to question and escalate unusual instructions, particularly as deepfake technology improves.
This moves cybersecurity into an unexpected area: leadership culture.
A company can buy stronger detection software. It can introduce multi-factor authentication. It can improve access controls. But it also needs employees who feel safe raising a concern when something about a request does not look right.
That behaviour cannot be installed through software. It has to be built into the organisation.
The Best Cyber Defence May Be Collective
Price's longer-term vision is for cybersecurity collaboration to become as normal as other shared layers of retail technology.
Retailers already depend on many of the same types of merchant systems, accounting platforms, workforce technologies and technology architectures. Over time, best practices develop around them.
Price wants cybersecurity to reach a similar level of collective maturity.
The concept challenges one of business's strongest instincts: protect your information, do not show weakness, solve your own problems.
Cybersecurity may increasingly require a different mindset. Protect sensitive information, certainly. But share the signals that help an industry recognise the same adversary.
Retail's Digital Future Depends on Trust
The broader implication extends beyond cybersecurity.
Retailers want customers to embrace increasingly connected shopping: loyalty ecosystems, personalisation, AI assistants, digital wallets, marketplace integrations, rapid delivery and connected stores.
Each relies on consumers trusting the infrastructure underneath it. If that trust weakens, the technology becomes less valuable.
That is why Price's argument deserves attention beyond the CISO community.
Cybersecurity is not simply about keeping hackers outside a network. It is about preserving the confidence that allows digital retail to function.
The board owns that problem because the board ultimately owns the consequences.
And as AI makes both retail technology and cyber threats more sophisticated, the industry may need to abandon the idea that defending each company separately is enough.
Retailers will continue competing fiercely for customers. On cybersecurity, they may increasingly be stronger protecting them together.
Frequently Asked Questions
What is the key point of "Cybersecurity Is Now a Board Issue, Not Just a Technology..."?
- Speaking to The Retail Podcast at NRF APAC 2026 in Singapore, DFI Retail Group Chief Executive Scott Price argued that cybersecurity has moved from the server room to the boardroom.
Cybersecurity Has Moved From the Server Room to the Boardroom - what does it mean?
- Cyber incidents were once treated largely as technical failures. Price described a culture in which being successfully attacked could carry a sense of embarrassment or organisational weakness, encouraging companies to reveal little beyond what regulation required.
Digital Retail Has Dramatically Expanded the Attack Surface - what does it mean?
- DFI provides a useful illustration of the complexity. At 31 December 2025, DFI Retail Group and its associates operated 7,580 outlets across 12 markets, spanning health and beauty, convenience, food, home furnishings and restaurants. The group reported US$8.9 billion in revenue for the year.
Retailers Compete for Customers. They Do Not Need to Compete on Threat Intelligence - what does it mean?
- Price's argument introduces an important distinction between competitive and non-competitive information. Retailers compete aggressively on price, products, locations, loyalty, customer experience, delivery and market share. Cyber threat intelligence is different.
The Strategic Asset at Risk Is Customer Trust - what does it mean?
- The strongest part of Price's argument is not really about technology. It is about trust. Historically, retail trust was relatively tangible. Was the advertised price the price charged at checkout? Was the product available? Would the retailer honour the return? Digital commerce has expanded that definition.
Related coverage
Technology
Jabra Bets on Voice as the Gateway to AI for Retail's Frontline Workers
Aug 17, 2026Technology
From Products to Ecosystems: Nagarro's Vision for the AI-Powered Future of Retail
Aug 13, 2026Technology
NVIDIA's Vision for AI in Retail: Shopping Assistants, Digital Twins and the Rise of Physical AI
Aug 7, 2026technology

