Connect with us

Technology

Connected Retail Is Widening the Cyber Attack Surface While Security Ownership Remains Fragmented, Info-Tech Research Group Warns

Published

on

Store systems, cloud platforms, IoT devices, vendor connections, and customer applications now operate as a connected ecosystem, while security accountability remains divided across technology domains and teams. Info-Tech Research Group’s Build Cyber Resilience in Connected Retail blueprint helps CIOs and security leaders set clear decision boundaries, align ownership, and prioritize threats according to operational and business impact.

ARLINGTON, Va., Sept. 3, 2026 /CNW/ — Retail technology environments are becoming more interconnected while the decisions that protect them remain fragmented. Legacy point-of-sale (POS) systems, IoT devices, cloud platforms, e-commerce applications, and third-party services are often owned and managed by different teams, leaving no single function with full visibility or end-to-end authority over cyber risk.

To help retail leaders address these gaps, Info-Tech Research Group, a global research and advisory firm, has published its Build Cyber Resilience in Connected Retail blueprint. The resource provides a three-phase methodology and supporting threat and risk assessment tool to help organizations identify assets, map threats and vulnerabilities, evaluate potential business impact, and establish clear priorities for action.

“Retail leaders understand the cyber risks in their environment. The breakdown happens when no one can make, enforce, and explain decisions across stores, platforms, and vendors,” says Donnafay MacDonald, research director at Info-Tech Research Group. “Cyber resilience is strengthened when organizations are able to clearly define decision-making responsibilities and assign accountable owners.”

Why Connected Retail Security Decisions Break Down

According to Info-Tech’s research, connected retail environments introduce structural constraints that prevent organizations from making consistent and defensible security decisions. The blueprint identifies three central challenges:

Fragmented systems limit decision authority: Legacy POS systems, IoT devices, cloud platforms, and customer-facing applications were often deployed by different teams at different times. No single owner has sufficient visibility or control to make and enforce decisions across the entire environment.Compliance complexity makes consistency harder: Retailers must account for overlapping requirements governing payment information, personal data, and customer privacy. Applying these requirements across shared systems, markets, and channels can create conflicting expectations and inconsistent controls.Attack speed outpaces traditional governance: Identity compromise, third-party access, and lateral movement can spread quickly through connected environments. Traditional escalation processes often move too slowly, increasing reliance on reactive and ad hoc decisions.

The firm advises retail CIOs and security leaders to build an operating model around five connected decision domains: visibility, control boundaries, decision ownership, risk prioritization, and response coordination. Together, these domains help organizations determine where exposure exists, how far a compromise could spread, who has authority to act, which threats matter most, and how teams and partners should respond.

Info-Tech’s Three-Phase Framework for Building Cyber Resilience in Connected Retail
The Build Cyber Resilience in Connected Retail blueprint moves organizations from defining their assessment criteria to producing a prioritized risk register ready for treatment decisions. The three phases include:

Phase 1: Define What Risk Matters in the Organization’s Environment. Establish data classifications, risk tolerance, and severity scales before identifying and documenting the assets under assessment. Assets are organized across four categories: software, hardware, networks, and physical sites.

Phase 2: Determine Where Exposure Exists. Identify vulnerabilities within each system component, evaluate applicable threats, and develop concise risk scenarios that connect technical weaknesses to credible operational and business consequences. Generative AI can assist with scenario development when its outputs are reviewed and validated by subject matter experts.

Phase 3: Decide Which Security Risks Justify Action. Assess existing controls, estimate the likelihood and impact of each scenario, and compare severity scores against the organization’s risk tolerance. Leaders can then prioritize treatment decisions, assign owners, and establish timelines for the most significant exposures.

“Just because two systems are in the same store doesn’t mean they’re equally important. A problem with the payment system could stop sales, while a problem with a digital sign might just be an inconvenience. Risk assessments help businesses separate the critical issues from the minor ones, so they can prioritize what really needs attention,” explains MacDonald. “That discipline helps teams address the right risks instead of allowing the loudest or most visible issue to dictate priorities.”

The Build Cyber Resilience in Connected Retail blueprint includes the Retail Security Threat and Risk Assessment Tool, which gives security and IT leaders a structured view of threats across stores, platforms, IoT devices, and customer data. The tool maps exposures to affected systems and owners, evaluates likelihood and impact, and produces a prioritized risk register to guide investment, segmentation, and response decisions.

By applying Info-Tech’s approach, retail organizations can strengthen accountability across IT, store operations, and vendors, contain the potential spread of an incident, and direct security resources toward the exposures most likely to disrupt the business or damage customer trust.

For exclusive and timely commentary from Info-Tech’s experts, including Donnafay MacDonald, and access to the complete Build Cyber Resilience in Connected Retail blueprint, please contact pr@infotech.com.

About Info-Tech Research Group
Info-Tech Research Group is the “get things done” partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.

To learn more about Info-Tech’s HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm’s SoftwareReviews platform.

Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm’s Media Insiders program. To gain access, contact pr@infotech.com.

For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.

View original content to download multimedia:https://www.prnewswire.com/news-releases/connected-retail-is-widening-the-cyber-attack-surface-while-security-ownership-remains-fragmented-info-tech-research-group-warns-302869497.html

SOURCE Info-Tech Research Group

Continue Reading

Technology

ISO 9001:2026 Release Is Approaching: What Organizations Need to Know and How Omnex Can Help

Published

on

By

ANN ARBOR, Mich., Sept. 4, 2026 /PRNewswire/ — Organizations around the world are preparing for the release of ISO 9001:2026, the next revision of the world’s most widely adopted Quality Management System (QMS) standard. According to information discussed during Omnex’s recent webinar on the upcoming revision, the new standard is expected to be published by the end of September 2026.

While organizations should wait for the officially published standard before making final implementation decisions, quality professionals are already evaluating the anticipated updates and planning their transition strategies.

Key Themes Expected in ISO 9001:2026

Based on the Final Draft International Standard (FDIS) and industry discussions, organizations can expect increased emphasis in several areas, including:

Quality culture and ethical behaviorRisk and opportunity managementEnhanced change managementOrganizational knowledge sharingClimate change considerations within organizational contextGreater alignment with ISO’s Harmonized Structure used across management system standards

These updates are intended to help organizations strengthen the effectiveness of their quality management systems while improving alignment with modern business practices.

What Organizations Should Do Now

Organizations currently certified to ISO 9001 should begin preparing for the transition by:

Conducting a GAP assessment against the new requirements.Reviewing existing quality management processes and documentation.Evaluating leadership responsibilities, quality culture initiatives, and risk and opportunity management practices.Training key personnel on the expected changes.Planning internal audits and implementation activities well ahead of certification body transition deadlines.

Industry experts generally encourage organizations to start planning early rather than waiting until the end of the transition period.

Omnex ISO 9001:2026 Transition Training

To help organizations understand and prepare for the upcoming revision, Omnex offers ISO 9001:2026 Transition Training, providing practical guidance for quality professionals, management teams, auditors, and implementation leaders. Participants who have already completed Internal Auditor or Lead Auditor training can efficiently upgrade their certification through this 1-day transition course, eliminating the need to repeat the full training.

Participants will learn:

1. Overview of the New Standard

Structure and intent of ISO 9001:2026Key themes and focus areasAlignment with other ISO management system standards

2. Understanding the Changes

Significant revisions compared to ISO 9001:2015New expectations regarding risk and opportunity managementUpdates related to leadership, quality culture, organizational knowledge, and change managementClimate change considerations and stakeholder expectations

3. What Organizations Need to Do

Conducting a GAP analysisUpdating processes and documented informationTraining employees and leadership teamsPreparing for internal and certification auditsBuilding an effective implementation roadmap

How Omnex Can Help Your Organization Transition to the ISO 9001:2026 Standard

Omnex supports organizations throughout the transition process through:

ISO 9001:2026 Transition TrainingExecutive awareness sessionsGAP analysis servicesQMS implementation and improvement consultingInternal auditor and lead auditor trainingIntegrated management system expertiseDigital quality and quality management solutions

With more than four decades of experience in consulting, training, and management systems, Omnex has helped organizations across industries improve operational performance and quality management capabilities worldwide.

Learn More

Organizations interested in preparing for ISO 9001:2026 can learn more about Omnex training and transition support services at:

Transitioning to ISO 9001:2026

About Omnex
Omnex is an international consulting, training, and software solutions organization specializing in quality, environmental, health and safety, and operational excellence systems. Founded in 1985 and headquartered in Ann Arbor, Michigan, Omnex supports organizations worldwide through training, consulting, auditing, and digital solutions.

View original content to download multimedia:https://www.prnewswire.com/news-releases/iso-90012026-release-is-approaching-what-organizations-need-to-know-and-how-omnex-can-help-302870336.html

SOURCE Omnex

Continue Reading

Technology

CME Group Inc. Announces Third-Quarter 2026 Earnings Release, Conference Call

Published

on

By

CHICAGO, Sept. 4, 2026 /PRNewswire/ — CME Group Inc. will announce earnings for the third quarter of 2026 before the markets open on Wednesday, October 21, 2026. Written highlights for the quarter will be posted on the company’s website at 6:00 a.m. Central Time, the same time it provides its earnings press release. The company will also hold an investor conference call that day at 7:30 a.m. Central Time, at which time company executives will take analysts’ questions.  

A live audio Webcast of the conference call will be available on the Investor Relations section of the company’s website. Following the conference call, an archived recording will be available at the same site. Those wishing to listen to the live conference via telephone should dial 877-918-3040 if calling from within the United States, or +1 312-470-7282 if calling from outside the United States, at least 10 minutes before the call begins. The participant passcode for both telephone numbers is 1944793.

As the world’s leading derivatives marketplace, CME Group (www.cmegroup.com) enables clients to trade futures, options, cash and OTC markets, optimize portfolios, and analyze data – empowering market participants worldwide to efficiently manage risk and capture opportunities. CME Group exchanges offer the widest range of global benchmark products across all major asset classes based on interest ratesequity indexesforeign exchangecryptocurrencies, energy, agricultural products and metals.  The company offers futures and options on futures trading through the CME Globex platform, fixed income trading via BrokerTec and foreign exchange trading on the EBS platform.  In addition, it operates one of the world’s leading central counterparty clearing providers, CME Clearing. 

CME Group, the Globe logo, CME, Chicago Mercantile Exchange, Globex, and E-mini are trademarks of Chicago Mercantile Exchange Inc.  CBOT and Chicago Board of Trade are trademarks of Board of Trade of the City of Chicago, Inc.  NYMEX, New York Mercantile Exchange and ClearPort are trademarks of New York Mercantile Exchange, Inc.  COMEX is a trademark of Commodity Exchange, Inc. BrokerTec is a trademark of BrokerTec Americas LLC and EBS is a trademark of EBS Group LTD. The S&P 500 Index is a product of S&P Dow Jones Indices LLC (“S&P DJI”). “S&P®”, “S&P 500®”, “SPY®”, “SPX®”, US 500 and The 500 are trademarks of Standard & Poor’s Financial Services LLC; Dow Jones®, DJIA® and Dow Jones Industrial Average are service and/or trademarks of Dow Jones Trademark Holdings LLC. These trademarks have been licensed for use by Chicago Mercantile Exchange Inc. Futures contracts based on the S&P 500 Index are not sponsored, endorsed, marketed, or promoted by S&P DJI, and S&P DJI makes no representation regarding the advisability of investing in such products. All other trademarks are the property of their respective owners. 

CME-G

View original content:https://www.prnewswire.com/news-releases/cme-group-inc-announces-third-quarter-2026-earnings-release-conference-call-302870343.html

SOURCE CME Group

Continue Reading

Technology

ISO 14001:2026 Is Here: What Organizations Need to Know and How Omnex Can Help with the Transition

Published

on

By

ANN ARBOR, Mich., Sept. 4, 2026 /PRNewswire/ — The release of ISO 14001:2026 marks an important milestone for organizations seeking to strengthen their Environmental Management Systems (EMS) and address evolving environmental, sustainability, and stakeholder expectations. The new standard was officially released on April 15, 2026, replacing ISO 14001:2015 and incorporating the climate change amendment issued in 2024. Organizations have until April 15, 2029, to complete their transition.

As organizations begin evaluating the impact of the revision, early planning and training can help ensure a smooth transition while also identifying opportunities to improve environmental performance and business resilience.

Key Themes in ISO 14001:2026

The revised standard includes several notable areas of focus, including:

Greater alignment with ISO’s Harmonized Structure to support integrated management systems.Climate change considerations incorporated directly into the standard.Expanded requirements around planning and managing change.Increased emphasis on environmental context, interested parties, and life cycle considerations.Additional guidance throughout the standard and a revised Annex A designed to improve understanding and implementation.

These updates are intended to help organizations integrate environmental management more effectively into business strategy and operational decision-making.

What Organizations Should Do Now

Organizations certified to ISO 14001:2015 should begin preparing for the transition by:

Conducting a GAP analysis of their current EMS against ISO 14001:2026 requirements.Reviewing environmental aspects, risks, opportunities, and life cycle considerations.Assessing how climate change may impact organizational context and stakeholder expectations.Updating procedures, processes, and documented information where needed.Training leadership, EMS professionals, and internal auditors on the new requirements.Planning internal audits and transition activities well ahead of certification deadlines.

Organizations that begin their transition early are often better positioned to manage resources, implement changes effectively, and avoid last-minute scheduling challenges.

Omnex ISO 14001:2026 Transition Training

To help environmental professionals, management teams, and auditors understand and prepare for the upcoming revision, Omnex offers ISO 14001:2026 Transition Training and related learning programs. This 1-day transition course enables currently certified Internal Auditors and Lead Auditors to upgrade their training certification to the new standard without retaking the full auditor training program.

1. Understand the New Standard

Participants gain an overview of:

The structure and intent of ISO 14001:2026The evolution of the standard from ISO 14001:2015Climate change considerations within environmental management systemsThe role of Annex A guidance in supporting implementation

2. Learn the Key Changes

Training covers:

New and revised requirements across major clausesPlanning of changes within the EMSExpanded life cycle considerationsUpdates related to interested parties and environmental contextInternal audit and management review changesClimate-related considerations and environmental performance expectations

3. Develop a Practical Transition Plan

Organizations learn how to:

Conduct an EMS gap analysisPrioritize implementation activitiesUpdate documentation and processesTrain relevant personnelPrepare for transition auditsIntegrate changes into existing management systems

How Omnex Can Help Your Organization Transition to the ISO 14001:2026 Standard

Omnex supports organizations through:

ISO 14001:2026 Transition TrainingUnderstanding Requirements CoursesInternal Auditor TrainingLead Auditor TrainingExecutive Overview WorkshopsGAP Analysis ServicesEMS Consulting and Implementation SupportIntegrated Management System Solutions

With more than 40 years of experience in management systems consulting and training, Omnex helps organizations navigate evolving standards while improving operational and environmental performance.

Learn More

Organizations interested in preparing for ISO 14001:2026 can learn more about Omnex environmental management training and transition support at:

Transitioning to ISO 14001:2026

About Omnex

Omnex is an international consulting, training, and software solutions organization specializing in quality, environmental, health and safety, cybersecurity, sustainability, and operational excellence systems. Headquartered in Ann Arbor, Michigan, Omnex has supported organizations worldwide since 1985 through consulting, training, audits, and digital solutions.  

View original content to download multimedia:https://www.prnewswire.com/news-releases/iso-140012026-is-here-what-organizations-need-to-know-and-how-omnex-can-help-with-the-transition-302870353.html

SOURCE Omnex

Continue Reading

Trending