Every major shopping event is a precision attack window. Threat actors know that retail infrastructure is under a change freeze, operations teams are stretched thin, and the cost of disruption is measured in real-time revenue loss. Bot volumes surge, API endpoints become primary targets, and fraud attempts spike exactly when security teams have the least room to maneuver.
In this interview on TFiR, Steve Winterfeld, Advisory CISO at Akamai, breaks down the end-to-end security preparation checklist retail security teams need to execute before peak shopping seasons arrive, covering customer journey protection, bot strategy, agentic identity management, DDoS readiness, and operational crisis protocols.
Guest: Steve Winterfeld, Advisory CISO at Akamai
Show: TFiR
Here is what every retail security practitioner and CISO needs to know before the next major shopping event.
Technical Deep Dive
Q: How should a retail CISO approach security preparation before a major shopping event?
Steve Winterfeld, Advisory CISO at Akamai, recommends starting by following the customer journey end-to-end. Every step from the product page through the database, inventory system, checkout, and purchase system represents an attack surface that must be mapped and protected. Winterfeld notes that a single purchase can involve 25 or more discrete steps, each requiring visibility and the ability to dynamically respond to threats.
“As a CISO, I want to follow the customer’s journey. I want to make sure I have visibility and the ability to dynamically protect that.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How should retail security teams handle fraud increases during peak events without degrading customer experience?
Winterfeld advocates for dynamic friction management. When fraud signals increase, security controls should introduce more friction into the transaction flow. When signals decrease, friction should be reduced. The goal is a proportional, responsive posture rather than a static rule set that either over-blocks legitimate customers or under-protects during surges.
“Fraud starts to increase, maybe I put a little bit more friction in there. If it decreases, I don’t.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Why is segmentation important for retail security during high-traffic shopping events?
Winterfeld treats segmentation as a containment mechanism, not a prevention mechanism. The assumption is that some attackers will get through, so the architecture must be designed to prevent an incident from becoming a major breach. Segmentation limits lateral movement and blast radius when a compromise occurs, preserving the integrity of surrounding systems.
“Someone is going to get through and I want to prevent it at the incident, not the major breach level. I want things like segmentation in there to minimize the impact.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How should retail teams prepare for DDoS attacks during peak shopping season?
Winterfeld emphasizes that DDoS readiness must be validated specifically for peak event traffic volumes. The capability to absorb and deflect DDoS traffic must be sized for the highest expected load, not average load. The objective is to move DDoS traffic aside so it does not degrade customer-facing performance at the moments when revenue impact is highest.
“I want to make sure my capabilities during this peak event are able to handle that volume and move the DDoS aside so it’s not impacting customer experience.” — Steve Winterfeld, Advisory CISO, Akamai
Q: Which retail systems should receive the highest level of security focus during peak events?
Winterfeld identifies APIs, checkout capability, loyalty programs, and inventory systems as the critical functions requiring prioritized protection. Applying stronger security controls to these systems creates a more dynamically survivable and resilient architecture. The logic is that protecting what directly touches revenue and customer data yields the highest return on security investment during constrained operational windows.
“By protecting those critical systems with more security than others, I’m guaranteeing a more dynamically survivable, resilient capability.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What is revenue chain mapping and why does it matter for retail security?
Winterfeld frames revenue chain mapping as identifying the Crown Jewels: which internal systems are essential, which third-party systems are critical dependencies, and how identities flow through and interact with all of them. This mapping exercise drives prioritization decisions for where to apply controls, where to invest in monitoring, and where a failure would produce the most severe business impact.
“I want to map the revenue chain. What are the Crown Jewels, what third party systems are critical.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How should retail security teams manage agentic AI identities during peak shopping events?
Winterfeld calls out agentic identities as a growing and underaddressed identity category. These are non-human actors, AI agents and automated systems, that make active decisions within retail environments. Security teams must extend their identity and access management visibility to cover these actors, ensuring they are tracked, governed, and included in situational awareness alongside human identities.
“All these agentic IDs, all these actors that are taking active part in making decisions within my systems. I need to have visibility and situational awareness around them.” — Steve Winterfeld, Advisory CISO, Akamai
Q: What does an effective retail bot strategy look like and why is blocking alone not sufficient?
Winterfeld describes bot management as a multi-dimensional challenge requiring credential review, bad bot mitigation, and the ability to distinguish API traffic from synthetic customers. Blocking is not sufficient because legitimate automation, partner integrations, and internal tooling are all part of the traffic mix. The strategy must manage the full bot spectrum without disrupting business-necessary automated activity.
“I need a good bot strategy. I can’t just block anymore. I need to manage this.” — Steve Winterfeld, Advisory CISO, Akamai
Q: How should security changes be handled during a retail peak event change freeze?
Winterfeld identifies the need for a clearly defined process covering the freeze itself, exceptions to the freeze, and escalation paths when a security change is required during the freeze window. This process must be documented and exercised before the event, not improvised under pressure. The absence of a clear exception and escalation protocol is a common operational gap that creates risk exactly when teams can least afford it.
“If I need to change something for security, do I have a clear process for freeze, exception, and escalation?” — Steve Winterfeld, Advisory CISO, Akamai
Q: What crisis readiness capabilities should retail security teams have in place before a major shopping event?
Winterfeld requires that crisis processes be exercised before the event window, not just documented. This includes executive alignment on a RACI model so that accountability for decisions, exceptions, and escalations is unambiguous when an incident begins. The goal is rapid mitigation at the earliest possible signal, before a contained incident can escalate into a business-impacting event.
“I need a crisis process that’s been exercised. So when something starts to go wrong, we quickly mitigate.” — Steve Winterfeld, Advisory CISO, Akamai
Resources and Documentation
- Akamai, enterprise security and content delivery platform covering DDoS protection, bot management, API security, and zero trust access
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: When you look at all these emerging threats, of course, nowadays every month or every other month, you see a big major shopping event. How should retail companies be preparing right now before the whole shopping season arrives here?
Steve Winterfeld: So, you know, I think the first is as a CISO, I want to follow the customer’s journey. And as I understand, you know, they come in here, they see this page, this page goes to this database, this database goes to this inventory system, this inventory systems, goes to this checkout, you know, to save that inventory, to hold it aside. This checkout goes to this purchase system. I want to make sure all those steps are protected. And there are 25 more steps in that one purchase I didn’t talk about. And so I want to make sure I have visibility and the ability to dynamically protect that. You know, fraud starts to increase. Maybe I put a little bit more friction in there. If it decreases, I don’t ultimately, you know, I also want to put some mitigations in there because someone is going to get through and I want to prevent it at the incident, not the major breach level. And so I want things like segmentation in there to minimize the impact. And finally, you know, got to go back to the basics, what we talked about earlier. DDoS. I want to make sure my capabilities during this peak event are able to handle that volume and move the DDoS aside so it’s not impacting customer experience. The next thing is I want to focus on critical functions. APIs, the checkout capability, loyalty programs, inventory systems. By protecting those critical systems with more security than others, then I’m guaranteeing a more dynamically survivable, resilient capability. I want to know, I want to map the revenue chain. What are the Crown Jewels, what third party systems are critical, how am I doing IDs and, and those IDs include now all these agentic IDs, all these, you know, actors that are taking, you know, active part in making decisions within my systems. I need to have visibility and situational awareness around them. We started with this and it’s probably, it’s deeper in the list, but it’s one of the most important things. I need a good bot strategy. I need to know, you know, how I’m reviewing credentials, bad bot mitigation, API versus, you know, synthetic customers. I need, I can’t just block anymore. I need to manage this. You know, obviously operations are big during these peak events. There’s a freeze. Nothing should change. So if I need to change something for security, do I have clear process for freeze, exception and escalation? Do I have a crisis process that’s been exercised. So when something starts to go wrong, we quickly mitigate. And, you know, that means executive alignment for a raci. You know, responsible, accountable, consultant and informed, making sure we know who can give these exceptions and who’s involved in that crisis. You know, it’s a more detailed list in the report, but at a high level, those are kind of those critical things that we should all have on our prep sheet for a major event.





