Retail security effort concentrates where the money changes hands: card readers, payment systems, the e-commerce platform. That is the right priority, and it is well covered.
Behind it sits everything that makes the transaction possible. Finance, logistics, HR, procurement and buying teams, many of them working from home, regional offices, leased warehouse space or the road. Those systems are reached across networks nobody in IT has assessed.
A regional manager working from home. A buyer connecting over airport Wi-Fi. A warehouse supervisor reviewing reports from a leased facility. Each is a point of connection outside your control, and the uncontrolled network edge is where attackers have been shifting their attention.
Core retail functions now run across distributed teams, hybrid patterns and temporary locations. That flexibility comes with exposure that rarely appears in a security review:
Those connections typically run through off-the-shelf routers that are poorly maintained and invisible to your IT team. For an attacker interested in the systems behind the till, that is the path of least resistance.
The uncontrolled network edge covers any device or network used to reach your systems that sits outside your control. The recurring weaknesses:
Default or out-of-date firmware with known vulnerabilities.
Unpatched routers, often running old software libraries.
Factory reset, quietly removing any hardening.
Shared Wi-Fi, with no separation between devices.
No audit trail, which makes both compliance evidence and post-incident work harder.
Both the NCSC and ENISA point to the same controls: firmware integrity, network separation and reliable automatic updates.
The economics have changed. Exploitation of edge-device and VPN vulnerabilities rose from 3% to 22% of vulnerability-related breaches in a single year, according to the Verizon 2025 Data Breach Investigations Report. Scanning for exposed routers is automated and cheap, tooling that once required expertise is packaged and resold, and the number of people running these attacks has grown accordingly.
Retail is a well-established target, and the disruption from an attack on back-office and logistics systems is not confined to data. It reaches stock, fulfilment and trading.
Securing endpoints and cloud accounts remains necessary. It does not address the network path between your people and your systems.
Loxada creates a controlled connection point wherever your teams are, replacing unmanaged home and shared routers with **Loxada secure routers**, and routing traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet.
Each device:
No training, no configuration. Deployment is fully auditable, with monthly security reports and device-status visibility.
Finance, HR and procurement teams working remotely.
Regional and franchise managers reaching central systems.
Supply chain and logistics partners working off-site.
Third-party vendors and auditors needing temporary access.
Hybrid and field teams in serviced offices and shared spaces.
Whether it is a payroll portal, a supply chain dashboard or an internal compliance tool, Loxada secures the route to it.
UK GDPR obligations for secure access to personal data.
NCSC guidance on firmware, segmentation and edge device management.
ENISA recommendations on securing distributed infrastructure.
PCI DSS, particularly around network segmentation and secure remote access.
Cyber Essentials, when firmware currency and secure configuration are in scope.
Cyber insurance and client due diligence, where remote access is a standard question.
Loxada supports one layer, the networks outside your control that your people connect from. It is a preventive control providing deployment coverage and configuration assurance, not monitoring, detection or containment.