Inside Walmart's Security Operations Frontline: Scale, Trust, and Defense Strategies
In Bentonville, Walmart's headquarters, a carefully orchestrated conversation lifted the veil on its security operations. From a security operations center processing six trillion data points daily, to a forensics laboratory equipped with cleanrooms and X-ray technology, to a defense system blocking 8.5 billion malicious bots monthly, Walmart is fulfilling its commitment to 'becoming the world's most trusted retailer' with rare scale and institutional investment. Based on on-site visits and interviews with multiple executives, this article analyzes the uniqueness of its security strategy.

BENTONVILLE, Ark. — Walmart legal executive Greg Schaffer told a small group of reporters seated in a mostly empty lobby at the company's headquarters that Walmart wants to be the "most trusted retailer." The reporters, including Cybersecurity Dive, ate a breakfast that could have fed 50 people while listening to a formal, choreographed fireside chat between Schaffer and Jerry Geisler, senior vice president and chief information security officer, about what trust means at Walmart.
The conversation would not have been out of place at any tech conference, and it was the first of several events held during Walmart's mid-January showcase of its security operations. Conversations with more than two dozen security personnel and tours of facilities demonstrated the scale of Walmart's network operations and why it takes security so seriously — even if customers may not notice.
"I may be biased — cybersecurity is always top of mind for me, but I know not everyone has that same perspective," Geisler said during the conversation with Schaffer. "If customers view security as a top priority, then I want them to be able to look at the work we do and have a high degree of confidence that we are delivering on our commitment — which is how we protect their information." If security is not a priority for customers, Walmart still wants them to trust that it will do the right thing, he said.
Many businesses do not prioritize security until it is too late. Cybersecurity Ventures projects that cybercrime will cost$8 trillionthis year, up from $6 trillion in 2022; the World Economic Forum warns of potential global instability following acatastrophic cyber event. Yet, amid a market downturn, there is no guarantee that companies can sustaininvestment in cybersecurity.
In an era where data breaches are commonplace and consumers are increasingly numb to privacy issues, the emphasis on security and trust is often undervalued. Fines from the Federal Trade Commission or EU data privacy regulators rarely change how companies handle data. Repeat offenders claim to be increasing cybersecurity investment, but additional spending does not prove that a security culture can truly change.

For Walmart, the seriousness of its approach to security is evident in its scale. Its network hub has a global footprint, leveraging shift schedules and time zone differences to achieve 24/7/365 security operations (for example, the security operations center in Bangalore, India, complements the working hours of US security personnel). Each year, these SOCs process an average of six trillion data points — data that Walmart digests internally and shares with the broader security community. The company also operates a fully accredited forensics lab for data recovery, equipped with a cleanroom, specialized X-ray technology, and hot-air rework stations. During a tour of its data center, employees enforcing rules followed curious visitors closely, demonstrating the redundancy of operations. There is little room for failure, only failover.
Walmart does not disclose its specific spending on cybersecurity, nor what percentage of its 20,000 Walmart Global Tech associates responsible for the retailer's foundational technology work in information security. Touring Walmart's facilities only offers a glimpse into the scale of its operations, but close observation suggests that few companies can independently run a system of this magnitude. Walmart's cybersecurity is not just an industry best practice; it may be an exception.
This is not to say Walmart's security approach is unattainable. Rather, its uniqueness lies in how the retailer finely tunes its security priorities. Facing a constant stream of threats, knowing exactly what to prioritize and what can be deferred is a skill other companies can emulate.

Behind the screens
From the outside, Walmart Global Tech's facilities have all the features of a world-class security operation, without the flash of Silicon Valley perks. There are no scooters on site, though a trampoline with safety netting stands in a corner of one room. Badge access and multiple layers of locked doors hint at the intersection of physical and digital security, even as remote or hybrid work options remain.
In terms of talent, Walmart faces the same obstacles as other companies: the demand for cyber workers far exceeds supply, a widening gap that currently covers3.4 million job openings. In terms of resources, Walmart is better positioned than many organizations. It generated$572.8 billion in revenuein fiscal 2022, with operating cash flow of $24.2 billion. But the tenure of its security organization adds substantial institutional knowledge.
The information security division has a history spanning more than two decades, with roots predating the high-profile attacks that marked industry upheaval — whether the 2014 hack of Sony or the 2015 attack on Ukraine's power grid. "Our experience is that because the company started investing in this area over 20 years ago, we have had the privilege of developing, evolving, and maturing our programs in step with the company's growth, evolution, and business expansion," Geisler said. "I think that has put us in an enviable position over time: having a seat at the table, being a trusted partner to the business, and helping to avoid missteps."
Walmart's security operations have earned it industry influence, which also allows it to attract experienced talent. Its roster of speakers includes resumes from Google, JPMorgan Chase, and other Fortune 100 companies. Beyond reputation, Walmart'sLive Better Uprogram pays 100% of college tuition and books for associates, aiming to build a pipeline of tech talent, supporting programs including cybersecurity and information technology. Retention is also part of its talent strategy. At Walmart's headquarters offices, it is not uncommon to see associate badges proudly displaying tenure in five-year increments. One specialist, Justin Simpson, joined Walmart straight out of college over a decade ago and now serves as director of data security, focusing on quantum and cryptography. His top priority is post-quantum cryptography, ensuring Walmart has the right security processes in place when quantum computers become a reality.
Like Simpson, some of the company's specialists and associates focus on the future, no matter how distant it may seem. Others handle identity and access management or cloud security. Bots are another specialty, supporting the company's defense-in-depth approach to ensure customers can purchase the items they need. On average, Walmart blocks 8.5 billion malicious bots in a month. Far from the tired, cookie-cutter infosec professional of internet memes, everyone here has a highly specialized role. Whether it's a corporate associate, a store employee, or a customer, every detail of each computer interaction is carefully considered, leaving nothing to chance or oversight.

Beyond the network
Walmart does not keep its security capabilities siloed. It partners with external Information Sharing and Analysis Centers, sharing intelligence involving threats inside and outside the network. Walmart works closely with its National Retail Federation (NRF) partners, "we win together," Rob Duhart, vice president and deputy CISO, said during a lunch roundtable. The NRF and the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) earlier this monthstrengthened their partnershipto better combat malicious cyberattacks and protect customer data. RH-ISAC found that a majority of CISOs, 70%, expect budget increases this year.
Walmart "does its best to continue working with regulators to ensure they learn from our experiences," Duhart said. In viewing external networks, Walmart takes a layered approach. Most organizations call it third-party risk, while Walmart's external party risk covers fourth, fifth, sixth tiers and deeper threats. For each tier, it provides empirical risk metrics.
"By working across security operations and partner teams, we are able to prioritize specific risks in the environment," Russ Buckley, senior director of risk and compliance, said during the roundtable. Beyond flagging something as a general risk, it can use internal numbers to help the business quantify where to invest in people or budget. "By doing that, our business leaders get an empirical number — not a guess, not 'my friend told me' — but something they can actually look at and say 'this is what we want to do, make the decision,'" Buckley said. "That decision in turn supports how we deliver services to all our customers."
The industry-standard Common Vulnerability Scoring System also goes through Walmart's empirical analysis, allowing the company to determine the risk a CVE could pose in its environment. This is where threat intelligence sharing comes into play. Walmart has mechanisms to determine the risk a threat actually poses. Even if a CVE does not affect its network, it can externally share how that threat might affect others in the industry. "We contribute a lot to make sure others understand the risk, and maybe also understand why we are not seeing that risk," Buckley said. "We can also influence other organizations that might change their security posture based on 'Hey, Walmart wasn't affected, but other companies were, maybe we should take a look.'"
This reflects Walmart's robust cyber intelligence program. It consumes information from commercial sources like many large organizations, but also procures threat intelligence on its own. "We have researchers doing things like looking at adversary backend infrastructure, understanding how threat actors pivot," Jason O'Dell, vice president of security operations, said during the roundtable. "Sometimes as a byproduct, we also see other organizations being targeted by a specific threat actor, and we quickly feed that back to the community."
A household-name brand company faces a different attack surface than an average organization, Gartner VP Analyst Chris Silva said last year when discussing Walmart'suse of automation in securitywith Cybersecurity Dive. "They are always a bigger target." Brands like Walmart may encounter threats never seen before, and sharing that intelligence gives other organizations the opportunity to respond.

Leading from the top
Walmart has its own security orbit, and its gravity extends into the regulatory arena, where the company hopes to help set the tone for customer expectations on privacy. State-level privacy legislation is steadily advancing, led by California, but a federal mandate has yet to materialize. These requirements "are pushing us in the direction we were already heading," Schaffer said during the keynote. When these laws come out, "sometimes it accelerates the roadmap we already had, which is a good thing." "Our goal, again, is to be the most trusted retailer — and frankly, because some of our businesses go beyond retail," he said. The goal is to be the "most trusted company."
It is a high bar, but Walmart has the resources to achieve it. In cybersecurity, a single misstep can damage a company's reputation, but Walmart has enough scale to absorb the impact. Defense is a proactive effort, and no part of its network is left to chance. "We don't necessarily focus too much on the size of Walmart because we are used to operating in a large environment," Geisler told Cybersecurity Dive in a final conversation of the day. "That is just our state of being."
Correction: This article has been updated to reflect revised information from the company, noting Walmart blocks 8.5 billion malicious bots in a month. Additionally, this article has been updated to clarify the original source of this year's cybercrime cost projection.