Retail Cyber Resilience: Risks, Response and Readiness

This event is for retail leaders responsible for cyber security, risk, technology, compliance and business resilience. BRC Retail Members only.


This in-person BRC Technology Community event will bring retail security leaders and those in retail businesses who need to make decisions about cyber security together for a practical afternoon of discussion on the issues shaping cyber resilience across retail.

Together with the BRC, National Cyber Security Centre (NCSC), and industry experts, we will hear: 

  • An update on the threat landscape from RH-ISAC (USA) 
  • An update on expectations from Government for retailers, including the Pledge from Department for Digital, Culture, Media and Sport (DCMS) 
  • A deep dive on AI, including hearing how retailers are approaching AI governance, identity and access management, and broader resilience planning.  

This event is designed to encourage honest discussion and will provide members with useful insights, examples and actions they can take back to their organisations.

In Partnership with

KEY BENEFITS FOR RETAIL MEMBERS

  • Gain practical insight into how peers are responding to emerging cyber risks and opportunities
  • Understand the implications of AI for governance, security teams and business decision-making
  • Learn from real-world perspectives on identity, access and authentication challenges
  • Hear actionable ideas on strengthening resilience, continuity planning and incident preparedness
  • Take away relevant examples, expert input and peer discussion tailored to the retail sector
  • Build connections with fellow retail cyber leaders and trusted expert contributors

 

Agenda

12:00–12:05 Chair's Welcome

  • Graham Wynn, Assistant Director, BRC

12.05–12:45 | Threat landscape update
Opening discussion on the latest cyber threats facing retail, with insight from RH-ISAC, and opportunities for member discussion.

  • Luke Vander Linden, Vice President, Membership & Marketing, Retail & Hospitality ISAC
  • Lee Clark, Manager, Cyber Threat Intelligence Production, Retail & Hospitality ISAC
  • Samuel B, Retail Resilience Lead, NCSC

12:45–13:30 | Networking lunch
A chance to connect with peers and expert contributors.

13:30–14:15 | Government approach and governance
Hear from DCMS on the Government’s approach to cyber resilience and governance, including an update on the cyber pledge, supply chain considerations, and what further requests Government may have for businesses.

  • John Maguire, Head of Securing Organisations Cyber at Department for Digital, Culture, Media and Sport (DCMS)

14:15–16:00 | AI governance, security and practical considerations
A practical session led by NCSC exploring the cyber risks and opportunities linked to AI adoption, including governance, supplier assurance, data protection, vulnerability management and building resilience across the AI supply chain.

  • Samuel B- Retail Resilience Lead, NCSC
  • Major Retailer CISO
  • Duncan Bradley, Director of Customer Enablement and Country Practice Leader for UKI, Kyndryl

16:00–16:15 | Break

16:15–16:45 | Passkeys and identity access management
Explore practical approaches to strengthening identity and access management, including passkeys and implementation considerations for retail organisations.

  • Carla V, Economy & Society Passkeys Lead, NCSC

16:45–17:00 | Closing reflections and next steps
Key takeaways from the afternoon and closing points for members.

  • Graham Wynn, Assistant Director, BRC

17.00-18.00 | Networking Drinks

Meet the Speakers

  • Graham Wynn

    Assistant Director for Consumer, E-Commerce and Regulatory Affairs | BRC

    Graham joined the BRC in 2001 and has built up an extensive network in departments and agencies which he can call on for information, advice and to make submissions on policy proposals. He was Chairman of the EuroCommerce Internal Market and Consumer Affairs Committee for 10 years, having first lobbied in the EU in 1979. Prior to the BRC he worked on BBC local radio; was Secretary General of an international political organisation; and Head of Policy and the Shadow Cabinet Secretariat of the Liberal Party of Australia. 

  • Lee Clark

    Cyber Threat Intelligence Production Manager, Retail & Hospitality ISAC

    Lee Clark is the RH-ISAC Cyber Threat Intelligence Production Manager. He joined the ISAC in February 2022 and leads the intelligence team’s collection and production operations.

    His prior experience includes working as a cyber policy and intelligence advisor for Booz Allen in the defense, commercial, and Middle East markets.

    He has published numerous writings on cyber issues through the ISAC and various security focused publications. He has an MA in Intelligence and International Security from the University of Kentucky.

  • Luke Vander Linden

    Vice President, Membership & Marketing, Retail & Hospitality ISAC

    The Retail & Hospitality ISAC is the cybersecurity sharing and collaboration community for the global consumer-facing business sector. As the RH-ISAC’s vice president of membership, Luke Vander Linden is responsible for member growth and engagement and, as part of the leadership team, overall organizational strategy.

    The RH-ISAC is a dynamic community with nearly 350 member companies, representing over 5,000 cybersecurity professionals. Prior to joining the RH-ISAC, Luke held similar positions at the Society for Corporate Governance and the Academy of Management.

    For two decades, he also had a long career in nonprofit fundraising and operations. Luke lives in Connecticut with his wife and two sons. He volunteers with multiple community organizations and serves on several nonprofit boards.

  • John Maguire

    Head of Securing Organisations Cyber, Department for Culture, Media and Sport (DCMS)

    John Maguire is the Head of Securing Organisation at the Department for Digital, Culture, Media and Sport, with a focus on raising the baseline of cyber resilience across the economy by ensuring the right support and guidance is in place for businesses to better manage their cyber risk and developing incentives for them to do so.

    He is an experienced government official, with a diverse background that includes central government, devolved government, and regulatory experience. Prior to his current role, he led work on UK digital trade policy and negotiations, which included delivery of the UK-Singapore Digital Economy Agreement and a range of digital FTA chapters.

  • Duncan Bradley

    Director of Customer Enablement and Country Practice Leader for UKI, Kyndryl

    Duncan is a senior cyber resilience and protection advisor at Kyndryl, with deep experience helping global enterprises strengthen their ability to protect, detect, respond and recover from cyber events.

    With over 29 years’ experience across managed outsourced services and critical enterprise systems, he works with strategic customers to assess current recovery capabilities, define target-state resilience requirements, and develop practical roadmaps aligned to business-critical processes and outage tolerances.

    As Kyndryl’s Director of Customer Enablement and Country Practice Leader for UKI, Duncan is a strong advocate for real-world cyber attack & recovery testing, ensuring teams are rehearsed and gaps are identified before a live incident occurs. He regularly advises customers on modern AI agentic security defence, cyber tolerant recovery solutions, data recoverability and the importance of building resilience into enterprise system design.

Register for this event

If you have issues completing this form, contact events@brc.org.uk

Free for BRC members

Join Communities for invites to events like this

Our Communities are the mechanism to unlock the value of BRC membership. They’re free to join for all employees of BRC members - whether a retailer, trade association or associate member.