Technology/Services

Convenience-store industry must be on guard for cyberattacks

Artificial intelligence is speeding up their scale and sophistication, says Juan Gomez-Sanchez of McLane Co. at Outlook Leadership event
Juan Gomez-Sanchez spoke Wednesday at CSP and Informa Connect’s Outlook Leadership event.
Juan Gomez-Sanchez spoke Wednesday at CSP and Informa Connect’s Outlook Leadership event. | CSP Staff

Artificial intelligence is accelerating the scale, speed and sophistication of cyberattacks, according to Juan Gomez-Sanchez, vice president of cyber resilience at McLane Co., Temple, Texas.

Gomez-Sanchez spoke about understanding cyber risk and resilience at CSP and Informa Connect’s Outlook Leadership event, held in Rancho Palos Verdes, California.

Emerging AI platforms can autonomously identify weaknesses, generate exploits and adapt attacks in near real time, he said.

In addition, traditional attack timelines measured in weeks can now occur in hours or minutes. Identity compromise remains the No. 1 attack vector, but AI amplifies phishing, credential theft and lateral-movement effectiveness, he said.

Organizations face increased risk from zero-day vulnerabilities and AI-enabled threat actors. Zero-day is an unknown security flaw in hardware or software.

Cyber risk is shifting

Modern cyber risk is shifting from human-scale attacks to machine-scale attacks, Gomez-Sanchez said.

Attackers can weaponize AI faster than most organizations can manually respond, Gomez-Sanchez said. AI increases the volume and believability of system vulnerability exploitation, phishing, impersonation and credential attacks. Detection and response capabilities must evolve beyond traditional rule-based security measures, he said.

In the past, it took weeks and sometimes years from the time a system identified a vulnerability to the vulnerability being exploited at scale, Gomez-Sanchez said, “the newest approximation into the time that it takes from understanding a vulnerability to it actually now being exploited is minutes."

Living in today’s world, in which vulnerabilities are bound to happen every day, means organizations must address the potential problems, he said. People should ask their organizations or even influence how their organizations are dealing with this problem.

“This is a problem, and it’s a problem that is coming to you real fast, and you need to be able to actually go and sustain that,” Gomez-Sanchez said. “If you’re thinking through resilience levels, you start thinking about what happens if a supplier cannot supply? Do I have second-level suppliers? What happens if the system is not there? Well, where are my backups? What happens if my POS system goes down? Can I have alternative methods of actually accepting payment?

“Those are all the things that you need to start thinking about,” he said. “The concept is not new. The way it’s impacting organizations today is different.”

Members help make our journalism possible. Become a CSP member today and unlock exclusive benefits, including unlimited access to all of our content. Sign up here.

Multimedia

Exclusive Content

Snacks & Candy

As GLP-1 use grows, consumers turn toward healthier offerings

Chestnut Market, CrossAmerica Partners and G&M Oil Co. leaders discuss effects of the rise of these weight-loss drugs

Technology/Services

Smarter targeting cuts wasted loyalty spend in convenience retail

‘Suppress your own members so every dollar buys a stranger,’ Convenience and Energy Advisors CEO Peter Rasmussen says at Outlook Leadership event

CBD/Hemp

Could hemp become a state-by-state market?

Why a marijuana-style marketplace may not be feasible for traditional wholesalers and retailers

Trending

More from our partners