2025 Global Digital Trust Insights Survey

Building cybersecurity through C-suite collaboration: insights for Retail

2025 Global Digital Trust Insights Survey: insights for Retail
  • Industry
  • March 11, 2025
only 2%

have implemented cyber resilience actions across their organisation in all areas surveyed

< 50%

of CISOs are involved to a large extent in key business activities

13%

point gap in confidence between CISOs/CSOs and CEOs in their AI and resilience compliance

The necessity for stronger digital resilience and cybersecurity is growing against a rapidly-changing European threat landscape. As technology becomes more complex with the artificial intelligence (AI) boom at the forefront, businesses are prioritising strengthening cybersecurity and modernising to be better prepared to face threats. Chief Information Security Officers (CISOs) are also getting more involved in strategic planning.

PwC's report "2025 Global Digital Trust Insights" highlights crucial gaps that companies should address to attain cyber resilience.

2025 Global Digital Trust Insights Survey Insights for Retail

Key findings from the retail sector include:

  • Mitigation Priorities: Retailers prioritize mitigating cyber risks and inflation more than other sectors, with 60% focusing on cyber threats compared to 57% of all respondents, and 57% addressing inflation versus 48% overall.

  • Cyber Risk Concerns: Retailers are particularly concerned about third-party data breaches and cloud-related threats, each cited by 38% of respondents, as well as attacks on connected products (33%).

  • Preparedness Gaps: Retailers report feeling least prepared for certain cyber threats, including attacks on connected products (40% versus 31% of all respondents), cloud-related threats (32% versus 34%), and zero-day vulnerability exploits (27% versus 20%).

  • CEO Involvement: Retail CEOs are significantly involved in discussions regarding the cyber and privacy implications of future strategies (42%) and major operational changes (38%). They also engage with regulators on cyber incident reporting and enforcement actions.

  • Challenges in Risk Quantification: Retailers encounter difficulties in quantifying the financial impact of cyber risks, including challenges with the reliability and trustworthiness of risk quantification outputs (47%), legal or regulatory concerns about potential legal exposure (45%), and uncertainty about the scope of risk quantification, such as whether it applies to assets, business processes, or core business units (39%).

CEE findings from the 2025 Global Digital Trust Insights Survey

Boardroom priority and cyber budgets up

Businesses are planning to increase their cyber budgets next year—in EMEA (73%) and globally (77%). We see a similar, growing trend in CEE—65% of companies in our region also plan to increase their cyber budgets. 

There is also a clear cybersecurity imperative. More organisations see cyber as a means to generate competitive advantage. Cybersecurity resilience must be a key priority, not just for tech leaders, but for the business as a whole. Prioritising cybersecurity is essential if businesses are to:

  • Safeguard their data and systems

  • Retain trust with their consumers and stakeholders

  • Mitigate the financial, operational and reputational costs of unpreparedness.

However, there is a disconnect between CISOs and CEOs about their organisations’ readiness, including its ability to comply with cyber regulations, the need for faster incident response times and progress in implementing technology for cyber defence. Less than half of CISOs in CEE are involved to a large extent in strategic planning on cyber investments and in oversight of tech deployments. 

“For many years, cybersecurity was often perceived as more of a governance and cost function. However, it is now transforming into a clear business value-add function for the customer. Our clients, particularly in financial services, are demanding stability, operational continuity and robust data protection. This shift elevates cybersecurity to a critical board-level discussion. ”

Marek Chlebicki, PwC Partner and CEE Technology Risk Assurance Leader

About the survey

The 2025 Global Digital Trust Insights is a survey of 4,042 business and technology leaders conducted from May to July 2024.

Respondents operate in a range of industries, including industrials and services (21%), tech, media, telecom (20%), financial services (19%), retail and consumer markets (17%), energy, utilities and resources (11%), health (7%), and government and public services (4%).

Respondents are based in 77 countries globally. There were 230 survey participants in Central and Eastern Europe from countries such as the Czech Republic, Poland, Hungary, Slovakia, Bulgaria, Romania, Serbia, Ukraine, Estonia, Latvia and other countries.

The Global Digital Trust Insights Survey was previously known as the Global State of Information Security Survey (GSISS). Now in its 27th year, it’s the longest-running annual survey on cybersecurity trends. It’s also the largest survey in the cybersecurity industry and the only one that draws participation from senior business executives, not just security and technology executives.

PwC Research, PwC’s global Centre of Excellence for market research and insight, conducted this survey.

Bridging the gaps to cyber resilience: The C-suite playbook

Sign up to get the full playbook and access more of the latest findings for 2025

Contact us

Olena Volkova

Olena Volkova

Partner, Retail & Agro Industry Leader, PwC in Ukraine

Tel: +380 44 354 0404

Anton Tseshnatii

Anton Tseshnatii

Director, Risk Assurance, PwC in Ukraine

Tel: +380 44 354 0404

Follow us on social media