Direct Action Briefings
Leadership, decision-making, and operational execution under pressure.
Direct Action Briefings
DA Briefing 0042: Navigate Obstacles Rapidly in Retail, Restaurant, and Hospitality
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Capability Focus: Navigate Obstacles Rapidly
Industry Focus: Retail Operations
Tool Focus: Critical Intervention
Episode Focus: Taking a compromised online order channel offline before it creates more customer promises the operation cannot control.
The stores were open.
The website was live.
Customers were still shopping.
But the online order channel could no longer be trusted.
In this Direct Action Briefing, Mikey K breaks down what happens when a major retailer faces a cyber incident that disrupts online ordering, payment activity, inventory visibility, fulfillment, and customer communication.
Temporary controls may keep parts of the business moving.
Processes go offline.
Click and Collect is restricted.
Teams create manual workarounds.
Stores remain open.
But there is a point where stabilization stops protecting the objective.
Every new order becomes another promise involving payment, inventory, fulfillment, delivery, refunds, and customer trust.
The leadership question is no longer:
How do we keep the channel open?
It becomes:
How much damage are we creating by continuing to accept work through a channel we cannot control?
This episode examines the difference between Tactical Resolution and Critical Intervention, why activity is not the same as control, and how leaders identify the smallest point where direct action is required.
The stores did not need to close.
The affected channel did.
Read the companion article:
https://www.direct-action-system.io/blog/stores-stayed-open-online-channel-went-dark
Get the retail-specific Direct Action starter resource:
https://www.direct-action-system.io/retail-starter
Read practical leadership and operations articles on the Direct Action Blog:
https://www.direct-action-system.io/blog
This briefing is part of the Direct Action Briefings series, where Mikey K breaks down practical decision systems for leaders operating under pressure.
Hey, welcome to the briefing. What I'm going to cover with you today is this the stores stayed open. The online order channel had to go dark. The stores were still open. Customers were still shopping. Associates were receiving inventory, working the floor, processing transactions, answering questions, and trying to keep the operation moving. From the outside, the business looked operational, but one part of that retail operation could no longer make a promise, the rest of the company could reliably control. The online channel could still accept the customer's decision. What the organization could not confirm with enough confidence was what happened after that decision. Was the payment being controlled correctly? Was the inventory actually available? Was the product being allocated to the right customer? Could fulfillment see the order and release it? Could the store prepare it? Could customer service see the correct status? Could the retailer still meet the collection or delivery promise displayed on the screen? The website does not have to disappear for the operation behind it to become unreliable. The customer does not see the inventory allocation rule, the payment path, the fulfillment connection, the order cue, the store task, or the recovery burden forming behind that screen. The retailer accepted the order. Once the retailer accepts the order, it owns the promise. If the business can no longer control that promise, keeping the channel open is not automatically continuity. That is where critical intervention becomes relevant. Critical intervention is used when the problem is active, directly interfering with the objective, cannot be postponed, cannot be adequately stabilized through another temporary control, and can be acted on directly without creating unacceptable damage around it. The point is not to react broadly because the situation feels serious. The point is to act directly because containment is no longer protecting the objective. Marks and Spencer gave us a visible retail example of this in 2025. The company publicly reported a cyber incident affecting several connected retail services. Physical stores remained open. Customers could still browse the website and application. Selected processes moved offline. Click and collect activity was restricted. Contactless payment was affected. Online delivery delays were expected. Marks and Spencer paused new orders through its websites and applications while keeping its physical stores open. That distinction matters. The entire business did not have to stop. The affected channel did. Stores could keep trading. Customers could still shop in person. The wider organization could continue operating where confidence remained. But the online channel could not keep accepting new customer commitments as if the complete order path remained reliable. That was not just a technical decision, it was a retail operating decision. Let's put a leader inside that pressure. I am going to use a composite leader based on the publicly reported operating conditions. This is not a claim about the private discussions inside Marks and Spencer or any other retailer. Leah is the omnichannel operations director for a national retailer. The business is in a commercially important period. Seasonal products are active. Customer traffic is strong. Stores are busy. Online demand is feeding work into distribution centers and store fulfillment teams. Merchandising is watching sell-through. Finance is watching margin and revenue. Customer operations is watching service levels. Executives want the channels open. Store leaders want clear instructions. Fulfillment teams need reliable work. Technology teams need room to investigate. Then the organization identifies a cyber incident affecting connected retail systems. At first, the exact operating boundary is not clear. Some functions appear normal, some are slow, some are unavailable, some are producing inconsistent information. Leah's first responsibility is not to close everything because the situation feels threatening. That would be easy to call decisive. It might also be careless. So the initial response is controlled stabilization. Selected work moves offline. Click and collect is paused or restricted. Some payment activity is limited, customer expectations are adjusted, delivery delays are communicated, store teams receive temporary instructions, customer service teams begin handling exceptions, cyber specialists investigate the affected environment. The objective at that stage is to reduce interference, protect the functions that remain trustworthy, and buy enough operating room to understand what comes next. Tactical resolution is a controlled temporary action used when an active problem is interfering with the objective, but the effect can still be stabilized enough for the operation to continue. It is not successful just because people are working hard. It is not successful just because transactions are moving. It is not successful just because the website is visible or senior leaders can say the channel is technically available. The control is successful only if the retailer can continue making and fulfilling customer commitments with an acceptable level of reliability. The longer the incident continues, the more the temporary controls begin creating their own work. One team creates a manual order record, another builds a spreadsheet to track exceptions. A store begins recording collection issues locally, a fulfillment point holds uncertain orders. Customer service creates a separate follow-up list. Finance tracks, unresolved payment activity, merchandising tries to determine what inventory is actually available. By noon, the spreadsheet has a larger jurisdiction than leadership. I respect that instinct. People are not sitting around waiting to be rescued. They are trying to keep the operation from falling apart, but that effort can create several different versions of the operation. One system says the order exists, another does not show it. The customer received a confirmation. Fulfillment cannot release the work. The item appears available online, the store cannot locate it, the payment appears to have moved, customer service cannot confirm the final status. The delivery date remains visible. The operating team no longer trusts it, and here is what that logic looks like once you stop pretending it is reasonable. The website is selling one sweater to three customers, while inventory, payment, fulfillment, and customer service hold a conference call to decide whether the sweater exists. The visual is ridiculous. The operating failure is not. The business is accepting promises faster than it can establish one shared truth. They mistake channel activity for channel control. The website is taking orders, so the channel appears to be working. Revenue is still being recorded, so keeping the channel open appears to protect the business. Customers can still complete checkouts, so shutting the channel down feels too aggressive. The channel does not succeed because the customer reached the confirmation page. It succeeds when the organization can control the full path from availability through delivery, collection, refund, or final resolution. The confirmation page is not the finish line. It is where the retailer becomes accountable for everything that follows. Leah now has competing voices around her. The commercial team says the organization cannot afford to shut down online sales. Merchandising says seasonal inventory may become stranded. Store operations warns that more customers may shift into physical locations. Customer service says call volume is increasing. Fulfillment leaders are losing confidence in which orders are real, delayed, or ready to release. Finance needs to understand payment exposure. The cyber team needs authority to protect the affected environment. Executives want a timeline. Suppliers want to know whether inventory will continue flowing. The leadership problem is deciding whether the current operating path is still protecting the customer and the wider retail objective. Every new order is more than a sale. The retailer accepts a customer payment or payment attempt. It reserves or appears to reserve inventory. It creates a fulfillment expectation, a delivery or collection promise, a customer service obligation, and a record that must eventually match the financial, inventory, and physical reality. If the path is reliable, that work becomes revenue. If the path is unreliable, that work becomes backlog, cancellation, refund complaint, manual investigation, stock distortion, or recovery? Can we confirm the inventory is available to promise? Can we confirm the order is entering the correct queue? Is the payment path controlled? Can fulfillment see and release the work? Can stores see the tasks assigned to them? Can customer service see the same status the customer sees? Can we identify which orders are complete, delayed, duplicated, uncertain, or unresolved? The website may still be visible. The path behind it is losing coherence. That is the deeper failure point. The operating failure forms when the retailer can no longer maintain one reliable connection between the customer promise, the order record, the inventory commitment, the payment status, the fulfillment work, and the final resolution. Once that connection weakens, local workarounds begin carrying partial truths. Customer service may know what the customer was told. The store may know what product is physically present. Fulfillment may know what work is visible in its queue. Finance may know what payment activity appears unresolved. Technology may know which systems are affected. Merchandising may know what inventory the commercial system is displaying. The problem is that those views no longer align well enough to control the whole commitment. The technology team can explain the system condition, it can advise what is affected, what remains uncertain, what needs to be isolated, and what must be protected. Leah owns the operating consequence. That responsibility cannot be outsourced to the cyber team. She has to decide whether the organization will accept the short-term loss created by stopping the channel or continue accepting the growing exposure created by leaving it open. The choice is between a contained consequence and an expanding one. Waiting does not preserve the option. It keeps adding customers, orders, and cleanup to the same unstable path. Delay is just exposure, wearing a tie. Pausing online orders creates lost sales, customer frustration, stranded inventory, increased store traffic, supplier pressure, markdown risk, and difficult questions from executives and customers. Continuing to accept orders creates commitments the retailer may not fulfill. It increases backlog, payment uncertainty, refund exposure, inaccurate inventory allocation, store pressure, customer service work, and the volume of manual correction waiting after the incident. Temporary controls have an expiration point. They expire when they stop protecting the objective. A workaround that buys time may be useful. A workaround that becomes the new operating system without common records, boundaries, ownership, or a return condition may become the second problem. The workaround has acquired its own org chart. I have learned to be careful when an operation starts celebrating movement before it has restored control. People work hard, teams improvise, managers create local solutions. The work starts moving again. Everybody feels some relief, and uh that relief can become dangerous because it lowers the pressure to keep inspecting the temporary process. The temporary process may be carrying more damage than the normal system did. It may just be carrying that damage more quietly. Are accepted orders becoming fulfilled orders? Are customer promises becoming controlled work? Are temporary records becoming reliable operating visibility? Are manual processes reducing uncertainty or spreading it? Are the teams protecting the objective, or are they simply preventing the disruption from looking worse? The online order channel has to stop accepting new orders, the stores can remain open, customers can still shop in person. The website may remain available for browsing if that function remains safe and reliable. Unaffected retail activity can continue. The problem cannot wait. Continuing to accept orders increases exposure. Temporary stabilization is no longer enough. The action point is clear enough. The intervention can be limited to the affected channel. Critical intervention does not mean the leader chooses the biggest available action. It does not mean shutting down everything because one connected system has failed. It does not mean acting dramatically so everybody can see the leader doing something. Leah does not close every physical store because the online channel is unreliable. She does not disable every payment method because one payment path is affected. She does not stop all inventory movement because online allocation has become uncertain. She protects what remains trustworthy. She tells customers what they can still do. She tells teams what they need to stop doing. She establishes who owns the operating decision. She keeps the technical response, an operating response connected. The organization still has to manage the orders already accepted. It has to determine which commitments remain valid, which orders can be fulfilled, which customers require communication, and how refunds, cancellations, delays, and exceptions will be controlled. It has to understand where inventory is physically located and where the systems believe it is located. It has to prevent manual processes from becoming uncontrolled. It has to keep stores from absorbing inconsistent instructions from several departments. It has to define the evidence required before the channel returns. Revenue is being lost. Customers want an answer, executives want a timeline, merchandising wants inventory moving, suppliers want predictability, teams want the incident to end. A screen comes back. A technical connection is restored. A small test order succeeds. One team says its function looks normal. One green check mark has been elected president. The complete customer promise has to be reliable enough again. Can the customer place the order? Can the organization confirm payment? Can inventory be allocated correctly? Can fulfillment see and complete the work? Can the customer receive an accurate status? Can customer service see what the customer sees? Can the organization sustain normal volume without recreating the failure? Can the teams reconcile the work already trapped inside the disruption? The intervention is not complete when the switch is turned off or when one technical issue is declared resolved. It is complete when the organization has reassessed the operating condition and can support the next decision with evidence. That may mean holding the channel offline longer. It may mean restoring one function before another. It may mean limiting volume during the initial return. It may mean keeping some manual controls in place. It may mean stopping the restoration if customer payment, inventory, or fulfillment signals begin separating again. The point is how leadership recognizes when an affected retail channel can no longer be stabilized through temporary controls, it must be stopped directly. That is why the consequence chain matters. Start with one customer. The customer sees a product online. The system displays availability, the customer places the order, the order is accepted, a confirmation is generated, the customer believes the item is committed to them. Behind the screen, the inventory status may be uncertain. The order may not enter the expected fulfillment queue. A store may not receive the task. A distribution point may not be able to release the work. The payment may remain unresolved. Customer service may not have the same view as the customer. The customer waits. The collection or delivery date approaches. The customer asks for an update. The service team searches across systems and manual records. The store receives a call about an order it cannot see. Fulfillment holds uncertain work. Finance tracks unresolved transactions. Inventory appears sold in one system and available in another. Another customer is allowed to order the same item. Now the organization has two customer promises attached to one uncertain unit of inventory. A cancellation follows. A refund may be required. The customer may travel to a store expecting collection. The store team absorbs frustration created by a channel it does not control. Customer service issues a concession. The inventory remains stranded until the systems reconcile. The product may miss its strongest selling period. Markdown and waste risk increase. That entire chain began with an order. The channel should not have accepted it. Scale that across thousands of customers, several fulfillment points, hundreds of stores, multiple payment states, seasonal inventory, and several days of disruption. Marks and Spencer later reported more than 100 million pounds in incident-related costs during the affected half year. It also reported effects on online sales, stock flow, product availability, logistics, markdown, waste, and profit. The failure reaches customer trust, labor, inventory, stores, distribution, suppliers, finance, the recovery plan, and the organization's ability to explain what happened. The better read is not online revenue matters, so the online channel must remain open. The better read is online revenue matters, so we cannot keep accepting orders through a channel we cannot reliably control. The better read is not the technology team should decide whether the business keeps taking orders. The better read is the technology team informs the condition, and leadership owns the customer revenue, inventory, fulfillment, and continuity decision. Tactical resolution reduces the interference enough for the operation to continue through a controlled temporary route. Critical intervention becomes necessary when that route no longer protects the objective and the problem itself has to be acted on directly. The loss sale is visible, the unavailable channel is visible, the customer notice is visible, the executive decision is visible, temporary workarounds can hide their consequences for a while. They spread damage across cues, spreadsheets, calls, refunds, stock positions, stores, and recovery work. Critical intervention forces the leader to recognize that hidden expanding damage may be worse than the controlled consequence of stopping the affected function. If Leah does not understand which channel, connection, account, system, or workflow is affected, direct action may be premature or misdirected. The organization may need deeper analysis before it can act responsibly. If a narrower technical or operational correction can restore control without stopping the channel, another response may fit better. If the obstacle can be redirected safely, the leader should not force a critical intervention because it sounds decisive. Critical intervention fits when the problem cannot wait, containment is not enough, the action point is known well enough, and the direct action can be limited. Turning off online ordering protects the organization from accepting more unreliable commitments. It may also transfer pressure into stores, increase contact center volume, disrupt supplier plans, create stock imbalances, affect customers who cannot easily shop in person, and increase the burden on employees already working the incident. A contained direct action is not consequence free. It is controlled because the leader has considered what the action will affect and establish limits around it. A contained intervention says this specific function stops because continuing it is directly damaging the objective. What stopped? What continues? Why did the decision change? Who owns the next update? What should teams tell customers? What work should no longer enter the affected path? What existing work still requires action? What evidence will support restoration? Stores may give different messages. Customer service may promise dates. The operating teams cannot support. Merchandising may continue promoting products the channel cannot sell. Fulfillment may prepare work that should be held. Teams may try to restart functions independently. The decision may be correct, and the execution may still fail. That is where the wider direct action system matters. CSA improves the read before the intervention. Leah needs to understand what is happening, what remains reliable, what has changed, what cannot be trusted, and where the disruption is interfering with the objective. Deepen helps the leader choose the correct problem navigation strategy. Some issues can be postponed, some can be stabilized, some can be redirected, some require deeper analysis. Critical intervention fits only when temporary stabilization is no longer enough and direct action can be contained. Pro strengthens the collateral read. The leader has to understand both the risk of acting and the risk of continuing the current condition. TMC protects the direction. A direct intervention requires one clear message across technology, stores, fulfillment, customer service, merchandising, finance, suppliers, and executive leadership. FLS supports controlled execution. The affected function has to stop at the intended point. Unaffected work has to continue where appropriate. Existing commitments need ownership. The status needs monitoring. ALC closes the loop after the operation stabilizes. The organization needs to capture what failed, which temporary controls worked, which created more risk, and what must change before the next incident. A weak read can create reckless intervention. A strong read followed by endless temporary controls can create dangerous delay. The same pattern can form when a loyalty platform accepts activity, stores cannot see correctly, a return system creates refunds that do not match, inventory movement, a delivery integration assigns promises to orders fulfillment, cannot release, or a promotion remains active while available, inventory cannot support the demand. What customer facing channel is still accepting work? What promise is it making? Can the operation behind it still Control that promise? What temporary controls are protecting the path? Are those controls reducing interference or distributing uncertainty across more people? Where is the smallest point at which the organization could act directly? Which function must stop? Which functions remain reliable enough to continue? What collateral pressure would the intervention create? What evidence would support restoration? They help you see when the situation may have crossed from a stabilization problem into a direct action problem. Choose one customer-facing or revenue-producing channel in your operation. It may be online ordering, click and collect, returns, loyalty, payment, delivery, store fulfillment, inventory availability, or customer status communication. Ask what temporary control you would use first if that channel became unreliable. Then ask what evidence would tell you the temporary control had stopped protecting the objective. Organizations build contingency plans around what they will do first. They do not always define the condition that tells them the first response is no longer enough. Then ask where you could act directly without stopping everything. The smallest effective boundary matters. A retailer should not close every store because one digital path failed if the stores remain safe and reliable. It should not preserve every digital function merely because physical stores are operating. Finally, ask what evidence would be required before the channel returns. Do not accept a restart date as evidence. Do not accept pressure from lost revenue as evidence. Do not accept one successful test as complete operating proof. The customer action, payment, inventory commitment, fulfillment release, status visibility, and final resolution need to align well enough for normal activity to resume. Watch the warning signs. Temporary controls keep multiplying. One workaround becomes three. Three become separate department processes. Each group creates a different record. Manual work starts hiding the failure. People are working hard enough that the organization still looks active, but nobody can say with confidence which order, inventory, payment, or customer record is correct. Then restoration pressure arrives before operating confidence. The channel has been down too long. The business wants movement. The calendar starts driving the decision. Apparently the calendar has assumed operational command. The action point may also be clear while nobody wants the commercial consequence. That is not a technical problem. That is decision ownership. The customer may see a website, an application, a store, a payment screen, a collection counter, a delivery message, a return process, or a customer service agent. Behind those experiences is one connected chain of commitments availability, allocation, order capture, payment, fulfillment, collection or delivery, return, refund, communication, and reconciliation. That is why critical intervention matters. It is not a cyber tool. It is not a technical shutdown procedure. It is a leadership strategy for the moment when the problem cannot wait, cannot be adequately stabilized, and must be acted on directly where it sits. The stores stayed open. The organization continued serving customers where it could. The online order channel went dark because continuing to accept customer commitments through that channel created more risk than the controlled consequence of stopping it. That was the boundary. That is the lesson. Do not act broadly because pressure is high. Do not keep adding temporary controls because direct action is uncomfortable. Inspect whether the temporary response is still protecting the objective. Identify the point that can no longer continue. Protect what remains reliable. Act directly when containment is no longer enough. Then reassess before normal operations return. When you are ready to go deeper with this tool, go to www.direct action system.io slash course dash directory. Open the course directory, find the course tied to critical intervention and deepen, and start there. That is where the deeper application belongs. Thanks for listening to the briefing.