How Walmart's Security Chief Stopped Saying No and Started Saying 'Yes, and…'
Walmart's global head of security operations explains why friction is the enemy, why trust is the currency, and what the rest of the retail sector can learn from running cybersecurity at a $700 billion company.

Key points
- Verizon's 2026 Data Breach Investigations Report recorded 806 data breaches in the retail sector alone, and that figure covers only a sample of the worldwide total.
- Walmart employs more than two million people across 19 countries and generates over $700 billion in annual revenue, making its security operation one of the largest of any private company.
- Jason O'Dell, Walmart's global vice-president of security operations, has spent seven years shifting his team away from blocking the business toward finding secure routes forward.
- The Information Security Forum warns that retail is now targeted by both organised criminal groups and nation-state attackers, meaning governments that use hacking as a tool of policy.
The word Jason O'Dell has banned from his team's vocabulary is not a four-letter expletive. It is friction.
O'Dell is Walmart's global vice-president of security operations, responsible for defending the world's largest retailer against a threat landscape that, by Verizon's own count, produced 806 data breaches across the retail sector in 2025 alone. His answer to that pressure is not to build higher walls. It is to stop making the walls so inconvenient that employees walk around them.
Why does any of this matter to ordinary shoppers?
A breach at a retailer the size of Walmart could expose payment card details, home addresses, purchase histories, and account credentials for hundreds of millions of customers. Retail has become a priority target because it sits at the junction of financial data and personal information, and because its supply chains, the networks of thousands of suppliers that feed products into stores, are riddled with entry points. Steve Durbin, chief executive of the Information Security Forum, a global security think tank, put it plainly in comments first reported by Dark Reading: retail is viewed by some state-sponsored hackers as "a soft underbelly for societal disruption."
That is not abstract. It means an attack on a major retailer's stock or payment systems could empty shelves or freeze checkouts at scale.
How does Walmart's security team actually work?
O'Dell's starting point is simple: security teams that constantly say no, or that bury the business in slow approval processes, push staff to find workarounds. Those workarounds usually create more risk than the original request ever would have.
His team maps every project on a two-axis grid: security value on one side, operational drag (meaning how much the process slows people down) on the other. High value, low drag is the target. High drag, low value is where, as O'Dell puts it, "practitioners develop a bad reputation."
| Quadrant | Security value | Operational drag | Verdict |
|---|---|---|---|
| Target zone | High | Low | Aim for this |
| Acceptable | High | High | Tolerable |
| Acceptable | Low | Low | Sometimes fine |
| Danger zone | Low | High | Avoid at all costs |
The cultural shift runs deeper than a grid. Walmart holds what O'Dell calls a "Know Your Business Day," where security leaders sit down with colleagues from other parts of the company to understand what they are actually trying to achieve. The goal is empathy, not interrogation.
What happens when a breach makes the news?
Every time a major hack hits the headlines, executives ask their security chiefs the same question: are we OK? O'Dell's answer is a single colour-coded page. Green shows controls already in place that would have blocked the reported attack method. Amber flags items on the roadmap, already planned but not yet deployed. Red marks genuine gaps, stated plainly so nothing is hidden.
Transparency is non-negotiable for him. "The day that you're not 100% honest and forthcoming," he told Dark Reading, "is the day that you're going to have an issue sometime downstream."
What should customers do?
If you shop at any major retailer, online or in-store, a few straightforward habits reduce your exposure. Use a unique password for every retail account so a breach at one store cannot unlock another. Check your bank statements weekly for small, unfamiliar charges, which are a common first sign of card fraud. If a retailer offers two-step verification (a second code sent to your phone when you log in), turn it on. And if you receive a breach notification letter, take it at face value and change your password immediately, even if the company says the risk is low.



