Shoprite identifies cybersecurity as its top risk, noting rise in data breaches
Read more
TechCentral
techcentral.co.za

Shoprite identifies cybersecurity as its top risk, noting rise in data breaches

In Shoprite's integrated report for 2026, the retailer identified cybersecurity as its primary risk among six key business risks. The company assessed cyberattack and data breach protection systems as 'partially effective,' which is the lowest rating it assigns to any of its key risks. According to internal data, the number of data breaches has increased for the second consecutive year.

The retailer rated the inherent risk in this area as critical. Even after considering control measures, the residual risk remains at an average level. Unlike cyber risks, the other five main risks are rated no worse than 'substantially effective' in controls, and all have a low residual risk. These risks include unavailability of key technological systems, disruptions in distribution centers and logistics, non-compliance with laws and regulations, inventory losses, and weak internal financial reporting controls.

For the 2026 fiscal year, the company registered four data breaches, compared to three in 2025 and one in 2024. In all four cases, personally identifiable information was compromised, affecting 44 customers. Only one customer was affected in 2025, while one breach in 2024 affected 1,437 customers. The report does not provide details on these incidents.

This figure significantly exceeds the stated zero tolerance threshold. Shoprite's risk register sets 'zero tolerance for security breaches and unaddressed critical vulnerabilities' as the criterion for this risk. The report indicates that the growth of artificial intelligence tools and the increasing sophistication of cybercrime make more frequent and serious incidents likely, and a breach could lead to the disclosure of confidential data or intellectual property and a significant disruption of operations. The risk trend remains unchanged compared to the previous year.

Volume of data requiring protection

The volume of information at risk is considerable. Shoprite's Xtra Savings loyalty program records over 2,500 card scans per minute and accounts for over 88.7% of sales. The group also reports storing over 5,000 data points per program member. Furthermore, Shoprite manages a banking account: its money market account serves over 4.3 million customers. The Sixty60 on-demand delivery service generated R25.5 billion in revenue for the 2026 fiscal year.

Technology ranks next in the risk register. Unavailability of critical technological systems, whether due to service provider failures, internet outages and cloud services, server malfunctions, or telecommunications interruptions, is recognized as a critical inherent risk. Shoprite's tolerance is 99% availability during working hours and 95% outside of them, and the company assesses the relevant controls as substantially effective.

Shoprite has reorganized the management of these risks. It merged its teams for risk, compliance, insurance, information security, occupational health and safety, technical safety, and fire safety into a single Corporate Risk and Compliance department led by the Chief Risk and Compliance Officer. In its 2025 report, the risk management function was carried out by the Group Risk Manager, with information security listed separately.

The report names 'strengthening the cybersecurity posture' as one of the main goals of the year in the section on corporate governance of information and technology. It also emphasizes that AI simultaneously enhances cyber threats and provides tools for their faster detection and mitigation. The Audit and Risk Committee of the Board of Directors, chaired by Linda de Beer, included information security and cyber defense in its priorities for the 2027 fiscal year, alongside creating protective mechanisms for the use of AI within the group, including data and intellectual capital protection.

The report names Shoprite's Chief Technology Officer as the custodian of all group information and technology assets, which is done under the board-approved charter and under committee oversight. This is Chris Shortt, who stated on the TechCentral Meet the CIO podcast last month that cybersecurity is the area that keeps him awake at night.

Major shift to SAP

The report also sets a deadline for Shoprite's next major project. Group CEO Peter Engelbrecht announced that the group is implementing an update to SAP S/4Hana across its finance, data analytics, and human resources functions, utilizing 'leading global resources,' with project completion scheduled for 2029. Oversight of the project implementation is on the agenda of the Audit and Risk Committee for the 2027 fiscal year.

Shortt told TechCentral that modernizing the core retail platform SAP Shoprite, which contains the group's real-time inventory data, is the largest technology project currently underway.

Popular