Loyalty programs now hold assets cybercriminals treat as financial instruments, yet most retail security teams still classify that data as low-sensitivity. At the same time, bot traffic is growing more complex, splitting across malicious actors, AI training crawlers, and legitimate fetcher bots, while most retailers manage all of it with a single binary decision: block or allow. Neither problem has a tooling fix. Both require a strategy.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, breaks down findings from Akamai’s retail and hospitality security research and explains why retailers must reclassify loyalty data and build a joint CIO-CISO bot strategy to stay ahead of emerging threats.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every retail security practitioner and CISO needs to know.
Technical Deep Dive
Q: Why are loyalty points now considered high-value targets for cybercriminals?
Steve Winterfeld, Advisory CISO at Akamai, explains that cybercriminals increasingly treat loyalty points as a shadow currency with real monetary value, comparable to credit card data. Retailers that operate loyalty programs must reclassify that data and apply the same security controls they apply to financial data, because attackers already have. Winterfeld draws this insight from a guest column by the Retail and Hospitality ISAC included in Akamai’s retail security research.
“Loyalty points are the new shadow currency.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What types of bots are retailers dealing with and why does the distinction matter?
Winterfeld identifies three distinct bot categories retailers encounter: AI training bots that consume server resources to train third-party models, fetcher bots that retrieve product and pricing data for legitimate purchasing workflows, and malicious bots acting with fraudulent intent. Treating all three categories identically with a block decision wastes legitimate traffic, inflates infrastructure costs, and still fails to stop targeted attacks. Retailers need a classification layer before any enforcement decision is made.
“There are training bots out there that are using my resources to train their AI. There are fetcher bots that are coming to get the information to buy shoes. There are malicious bots out there.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is wrong with the binary block-or-allow approach to bot management?
The binary human-or-bot decision model collapses when bots are operating as synthetic customers or legitimate data fetchers. Winterfeld acknowledges falling into this trap himself: the instinct is to ask whether traffic is human, then block everything that is not. That framing misses the entire category of wanted bot traffic and creates a false sense of control. The right question is not whether traffic is a bot, but what that bot is doing and whether that activity serves the business.
“Is this bot part of a synthetic customer? Is it somebody fetching something that I want? Is it somebody training on my site that I want to minimize because I don’t want to pay for those cycles?” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is the difference between having bot tools and having a bot strategy?
Winterfeld draws a direct line between tool adoption and strategic failure: most retailers have deployed bot detection tools but have not defined what they want those tools to achieve across different bot types. Tools without strategy produce inconsistent enforcement, blocked legitimate traffic, and undetected malicious activity. A bot strategy requires the organization to define acceptable bot behavior, set thresholds for AI training crawlers, and align enforcement rules to business outcomes rather than defaulting to block-all.
“They don’t have a bot strategy. They have bot tools.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Why does bot strategy require CIO and CISO alignment rather than sitting with security alone?
Winterfeld argues that bot decisions are not purely security decisions: they carry operational and revenue implications that require CIO input. Blocking AI training bots affects infrastructure cost but may also affect partner and vendor relationships. Allowing fetcher bots supports legitimate purchasing pipelines. These are business trade-offs that cannot be made unilaterally by the security team. A joint CIO-CISO bot strategy ensures enforcement decisions are grounded in business context, not just threat posture.
“It’s going to be more and more important to have a working with the CIO and the CISO to have a joint bot strategy.” — Steve Winterfeld, Advisory CISO, Akamai
Resources & Documentation
- Akamai, security research, bot management, and application protection platform referenced throughout this interview
- Retail and Hospitality ISAC, information sharing organization for retail sector cybersecurity intelligence
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: Can you talk about what other insights were there in terms of retail hospitality?
Steve Winterfeld: So, you know, this first year we had a guest column by the retail and hospitality isac, the information sharing organization that all the revenue, all the retailers belong to. And so essentially, I loved the CISO’s comment that loyalty points are the new shadow currency. So for those companies that have loyalty programs, I really think you need to change your attitude, if you haven’t already, and treat those just like you would credit card data or other financial data, because we’re seeing more and more cybercriminals go after this.
Swapnil Bhartiya: Can you also talk about what are some of the biggest mistakes that you see retailers are making right now when it comes to managing all this bot traffic and, and why they should go and read this report?
Steve Winterfeld: I think part of the problem is they, they hear bots and traditionally are thinking as bots as negative things. You know, going back to, you know, all these different types of bots out there. There are training bots out there that are using my resources to train their AI. There are fetcher bots that are coming to get the information to buy shoes. There are malicious bots out there. And so a lot of us are still stuck because I find myself falling into the trap of. When I think about bots, bots are something that I try to say, is it human, yes or no? And then binary decision, block them. And now I need to say, you know, is this bot part of a synthetic customer? Is it somebody fetching something that I want? Is it somebody training on my site that I want to minimize because I don’t want to pay for those cycles? So I think it’s. They don’t have a bot strategy. They have bot tools, but they don’t, you know. And as we go forward, it’s going to be more and more important to have kind of a working with the CIO and the CISO to have a joint bot strategy.





