How Walmart's Security Chief Stopped Saying No and Started Saying 'Yes, and…'
Walmart's global head of security operations explains why friction is the enemy, why trust is the currency, and what the rest of the retail sector can learn from running cybersecurity at a company this size.

Key points
- Verizon's 2026 Data Breach Investigations Report recorded 806 data breaches in the retail sector, a figure that covers only a sample of the worldwide total.
- Walmart employs more than two million people across 19 countries and generates over $700 billion in annual revenue.
- Jason O'Dell, Walmart's global vice-president of security operations, has spent seven years shifting his team away from blocking the business toward finding secure routes forward.
- The Information Security Forum warns that retail is now targeted by both organised criminal groups and nation-state actors.
The word Jason O'Dell has banned from his team's vocabulary is not a four-letter expletive. It is friction.
O'Dell is Walmart's global vice-president of security operations, responsible for defending the world's largest retailer against a threat environment that, by Verizon's own count, produced 806 data breaches across the retail sector in 2025 alone. His answer to that pressure is not to build higher walls. It is to stop making the walls so inconvenient that employees walk around them.
Why does any of this matter to ordinary shoppers?
A breach at a retailer the size of Walmart could expose payment card details, home addresses and purchase histories for hundreds of millions of customers. Retail has become a priority target because it sits at the junction of financial data and personal information, and because its supply chains, the networks of thousands of suppliers feeding products into stores, are riddled with entry points. Steve Durbin, chief executive of the Information Security Forum, a global security think tank, put it plainly in comments first reported by Dark Reading: retail is viewed by some state-sponsored hackers as "a soft underbelly for societal disruption."
That is not abstract. An attack on a major retailer's stock or payment systems could empty shelves or freeze checkouts at scale.
How does Walmart's security team actually work?
O'Dell's starting point is simple: security teams that constantly say no, or that bury the business in slow approval processes, push staff to find workarounds. Those workarounds usually create more risk than the original request ever would have.
His team maps every project on a two-axis grid: security value on one side, operational drag (meaning how much the process slows people down) on the other. High value, low drag is the target. The danger zone, as O'Dell puts it, is "high operational drag, low security value. That's where we as practitioners develop a bad reputation."
| Quadrant | Security value | Operational drag | Verdict |
|---|---|---|---|
| Target zone | High | Low | Aim for this |
| Acceptable | High | High | Tolerable |
| Acceptable | Low | Low | Sometimes fine |
| Danger zone | Low | High | Avoid at all costs |
The cultural shift runs deeper than a grid. Walmart holds what O'Dell calls a "Know Your Business Day," where security leaders sit down with colleagues from other parts of the company to understand what they are actually trying to achieve. "We walk away with a better understanding and empathy," he told Dark Reading.
Not everyone is fully sold on the enabler framing. Rik Turner, chief analyst at Omdia, told Dark Reading he is "extremely skeptical" about positioning security as a business enabler, arguing that security often should slow things down and that the tension between speed and control is genuine, not a problem to be dissolved.
What happens when a breach makes the news?
When a major attack hits the headlines, O'Dell's response to anxious executives is a single colour-coded page. Green shows controls already in place that would have blocked the reported attack method. Amber flags items already planned but not yet deployed. Red marks genuine gaps, stated plainly.
"Being transparent is one of the most important things that you can do," he told Dark Reading. "The day that you're not 100% honest and forthcoming, that is the day that you're going to have an issue sometime downstream."
That frankness is the part of this story worth watching. Plenty of security leaders talk about board communication; fewer build it around a document that names the gaps.
Should you worry about your data?
If you shop at any major retailer, a few habits reduce your exposure. Use a unique password for every retail account so a breach at one store can't compromise another. Check your bank statements weekly for small, unfamiliar charges, a common early sign of card fraud. If a retailer offers two-step verification (a second code sent to your phone when you log in), turn it on. A breach notification letter is worth taking seriously even when the company calls the risk low.
We covered the broader shift in how organisations think about security operations in our 12 August piece on AI adoption gaps in security teams. The O'Dell approach is the human side of the same problem.



