Retail security training covers three problems at once: merchandise theft, violence against staff, and data breaches. Owners tend to handle them separately, though the cashier on shift deals with all three.
Shoplifting incidents climbed 18% in 2024, and California and New York now require covered retailers to deliver documented training programs.
Below you’ll find what to teach your team, where the law applies, how often to repeat it, and which resources cover the mandated material at no cost. What follows assumes a store with no loss prevention department.
Key Takeaways:
- Three threats, one program. Shoplifters, aggressive customers, and phishing emails all land on the same person behind the counter, so one curriculum has to answer for all of them.
- Two states mandate it. California and New York oblige covered stores to keep a written plan, train employees, and log each session.
- Report, don’t intervene. Staff note the details and alert a manager. Chasing, blocking, or restraining a suspect is off limits.
- The register is a training subject. Voids, refunds, and drawer opens account for much of what stores lose, so permissions and audit trails belong in the curriculum.
What Retail Security Training Covers
Retail security training teaches store employees to recognize and respond to three categories of threat: merchandise theft, physical violence, and data compromise. Owners tend to treat those as separate problems bought from separate vendors. The person behind the counter experiences all three as one job.
A working program answers four questions for anyone who wears a name badge:
- What does a threat look like before it becomes an incident?
- What am I authorized to do about it?
- What am I never authorized to do?
- Who do I tell, and how quickly?
The rest of this guide breaks the curriculum into four modules: theft and loss prevention awareness, de-escalation and violence response, register and cash controls, and data security. Before the curriculum, though, two things shape how you build it: the current threat picture and the laws that now govern your training obligations.
Why Retail Security Training Matters Now
Theft and violence against retail workers have both risen sharply, and the burden of preventing incidents has shifted onto frontline staff. Stores that once relied on a security presence or a camera system are leaning on cashiers and shift leads to spot problems early.
The Numbers Behind the Trend
The National Retail Federation’s Impact of Theft and Violence 2025 report, produced with the Loss Prevention Research Council, found an 18% rise in average shoplifting incidents in 2024 compared with 2023, alongside a 17% increase in threats or acts of violence during theft events. Transnational organized retail crime groups were involved in thefts at 67% of surveyed retailers, and their tactics have widened beyond the sales floor to take in phone scams (70% of retailers reported an increase), ecommerce fraud (55%), and cargo theft (50%).
One caveat on data: NRF discontinued its 32-year National Retail Security Survey in 2024 over methodology concerns, so older shrink estimates circulating online should be treated carefully. For context on how losses accumulate across a store, see our breakdown of what shrink means in retail.
Physical injury adds another layer. In its January 2026 release covering 2023 and 2024, the Bureau of Labor Statistics counted 78,340 private-industry cases of violent acts serious enough to require days away from work or restricted duty, with a median of 11 days lost per case. Retail’s overall injury and illness rate actually edged down in 2024, so the argument for training rests on how severe violent incidents have become, not on how frequently staff get hurt in general.
What Untrained Staff Cost You
Four costs follow directly from an untrained crew:
- Liability exposure. An improper detention, a false imprisonment claim, or an excessive-force incident can generate legal costs far larger than the merchandise involved.
- Regulatory penalties. Cal/OSHA penalties reach $25,000 for a serious violation and $162,851 for a willful or repeat one.
- Breach fallout. Compromised cardholder data brings fines, forensic audits, and card brand penalties.
- Turnover. Employees who feel unsafe leave, and replacing them costs more than the training would have.
Trained staff also change the store’s atmosphere. Attentive greeting and floor presence deter opportunistic theft before it starts, which is why customer engagement appears in nearly every loss prevention curriculum.
Where Security Training is Legally Required
In California and New York, documented security training is a statutory obligation for most store owners, not a recommended practice. Every other state falls back on OSHA’s General Duty Clause, which still requires employers to address recognized hazards.
| Jurisdiction | Requirement | Who is covered | Effective |
|---|---|---|---|
| California (SB 553) | Written Workplace Violence Prevention Plan, interactive annual training, violent incident log | Nearly all employers; exempts locations with fewer than 10 employees not open to the public | July 1, 2024 |
| New York (Retail Worker Safety Act) | Workplace violence prevention policy plus interactive training, delivered on hire and on a recurring cycle | Retail employers with 10 or more employees | June 2, 2025 |
| New York (silent response buttons) | Silent response buttons for retail workers | Employers with 500 or more retail employees statewide | January 1, 2027 |
| All other states | General Duty Clause obligation to address known hazards | All employers | Ongoing |
California SB 553
Senate Bill 553, codified as Labor Code section 6401.9, took effect July 1, 2024. Covered employers must maintain a written Workplace Violence Prevention Plan, either standalone or absorbed by an existing injury and illness prevention program. Training must be interactive, delivered by someone who knows the plan well enough to field questions, and repeated annually. Two separate retention clocks apply: training records are kept for one year, while the violent incident log, hazard inspections, and incident investigations are kept for five.
One thing to watch before you finalize a plan. Cal/OSHA is still writing a formal general industry workplace violence standard, and the Occupational Safety and Health Standards Board has until December 31, 2026 to adopt it. Revised draft language circulated during 2026. Until adoption, Cal/OSHA enforces the statute directly, and any plan you build today will need a review against the final rule.
New York’s Retail Worker Safety Act
Governor Hochul signed the act in September 2024 and amended it in February 2025, moving the compliance deadline to June 2, 2025. The threshold sits at 10 retail employees, and above it a store needs a workplace violence prevention policy plus a training program covering de-escalation tactics, emergency procedures, active shooter response, and the use of safety devices. Employers with fewer than 50 retail workers train every two years; larger operations train annually. The New York Department of Labor published a model policy and model training on May 29, 2025, which employers may adopt directly.
Module 1: Theft And Loss Prevention Awareness
Train employees to observe and report theft. Physical intervention is not their job. The distinction protects the worker, the customer, and the business, and it belongs in the opening session, not buried in a handbook.
Behavioral Indicators Worth Flagging
Staff should learn to read behavior, not appearance:
- Loitering without browsing, or repeated passes through the same aisle
- Frequent scanning of ceiling corners, mirrors, or staff positions
- Bulky outerwear or oversized bags inconsistent with the weather
- Groups that split up on entry, with one member engaging an employee in conversation
- Multiple trips to fitting rooms with varying item counts
Organized Retail Crime Patterns
Coordinated crews behave differently from opportunistic shoplifters. They survey a location first, identify coverage gaps, and return to execute at volume, sometimes hitting several stores in a day. Warning signs include vehicles idling near exits, a lookout posted at the entrance, and rapid clearing of an entire product category. Employees who recognize the pattern can alert a manager while the crew is still surveying, which is the only useful window.
What Employees Should Never Do
Four prohibitions belong in the first retail security training session:
- Never chase a suspect out of the store or into a parking lot
- Never block an exit or physically restrain anyone
- Never accuse a customer of theft on the sales floor
- Never handle an apprehension unless licensed and specifically authorized
Detention carries legal weight. California regulates the loss prevention role through the Bureau of Security and Investigative Services, and which registration applies depends on the job. An in-house officer who wears a uniform identifying them as security registers as a Proprietary Private Security Officer, while plain-clothes loss prevention work falls under security guard registration. Both routes require a state background check and Power to Arrest training. Assigning detentions to an unregistered cashier creates exposure well beyond the value of the goods. Store design and technology handle the rest of the problem, covered separately in our piece on asset security in retail.
Module 2: De-escalation And Violence Response
De-escalation training teaches employees to lower the temperature of a confrontation before it turns physical. Security Management research from ASIS International consistently identifies the same core techniques, and they take under an hour to teach.
De-escalation Basics
- Stay calm and keep your voice at a steady, moderate volume
- Maintain physical distance and avoid cornering the other person
- Treat the individual with dignity and avoid language that assigns blame
- Use short, clear sentences and repeat them if needed
- Signal a colleague discreetly, without announcing the problem aloud
Robbery And Active Threat Protocol
For armed robbery, the instruction is simple: comply, observe, and report afterward. Merchandise and cash are replaceable. Employees should note height, clothing, accent, direction of travel, and vehicle description once the person leaves, then call law enforcement.
Active threat response follows the run, hide, fight framework promoted by the Cybersecurity and Infrastructure Security Agency. CISA also offers an 85-minute Active Threat Recognition presentation built specifically for retail security personnel, available at no charge.
Silent Response Buttons And Alarms
New York’s January 2027 requirement makes emergency devices a training subject in their own right. Silent response buttons summon a manager or security officer internally, unlike panic buttons that dial 911 directly. Wearable and mobile options are permitted, though they must run on employer-provided devices and cannot track employees except when activated. Wherever your store sits on that timeline, all staff should know where the alarms sit and the precise condition that justifies pressing one.
Module 3: Register, Cash, And Back-Office Controls
Internal loss begins as a training gap before it becomes a technology gap. Employees who were shown no example of a legitimate void cannot flag an illegitimate one, and managers who leave the audit trail unmentioned have effectively told staff nobody is watching. Register conduct belongs in onboarding next to the scanner and the cash drawer, a point the cashier training guide works through in full.
Transaction Types That Hide Loss
Four transaction types account for most register-level shrink:
- Voids and cancellations performed after the customer has already left
- Refunds processed without a receipt or against a fabricated order
- Discounts and price overrides applied to personal purchases
- No-sale drawer opens with no corresponding transaction
Teach staff the legitimate use case for each, then explain that all four are logged by cashier and timestamp. Our overview of retail fraud and its impact goes deeper on how these schemes develop.
Cash Handling And Shift Reconciliation
Cash procedures work when they are boring and identical from one day to the next. Count the drawer at open with a second person present, drop excess cash into a safe at set intervals, reconcile at close against the shift report, and document variances of any size. A store that only investigates large discrepancies signals to staff how much can go missing unnoticed. Put the sequence in writing so it survives new hires and schedule changes, since our guide to cash handling procedures sets out drop schedules, dual-custody counts, and variance thresholds you can lift straight into a policy.
Permissions And Audit Trails
Every cashier should hold the narrowest set of permissions their role requires. Refund authority, price override authority, and report access belong to supervisors unless there is a specific operational reason otherwise.
KORONA POS supports role-based cashier permissions and detailed activity reporting, so managers can trace each void, return, discount, and cancellation back to the person who rang it. As a processor-agnostic platform, it applies those controls consistently whichever payment processor you choose to work with. More detail sits on our retail loss prevention page.
Module 4: Data And Cybersecurity Awareness
Retail employees are the entry point for most successful cyberattacks, because attackers target people before systems. The terminal they log in to when they clock on belongs to the same attack surface, and the POS security guide covers the configuration side that instruction alone cannot reach. Six threat types cover the majority of incidents, and each takes only a few minutes to explain.
Email Scams And Phishing
Phishing remains the most common route into a retail network. Attackers trick a staff member into surrendering credentials or opening a malicious file.
- Be wary of unexpected messages from unfamiliar senders
- Watch for pressure tactics involving urgency or secrecy
- Avoid unverified attachments and links
- Withhold system access from anyone who asks for it by email
Password Theft
Weak and reused credentials give attackers a straightforward path in.
- Use a unique, autogenerated password on each account
- Enable two-factor authentication everywhere it is offered
- Adopt a password manager across the team
- Set written company standards that all staff follow
Personal Devices
Allowing managers to use their own laptops or phones reduces hardware spend and increases risk. Issue company devices, provide VPN access to avoid untrusted WiFi, and keep antivirus protection current on everything that touches the store network.
Social Engineering
Attackers mine social media for details that make their approach convincing, then reference a real colleague, a real vendor, or a genuine recent event. Staff should verify any unusual request through a second channel before acting on it.
Malware And Ransomware
Malware harvests financial data and personal information. Ransomware locks operations until payment is made. Both arrive through infected attachments, downloads, and links. Employees should install nothing themselves and report anything that behaves unexpectedly.
Removable Media
USB drives and external hard drives can carry payloads that execute on connection. Some attackers leave drives in parking lots or hand out branded devices at trade events. The rule is absolute: nothing unknown gets plugged into a store computer.
Two related guides go further on the technical side: improving retail data security and PCI compliance for retailers.
How to Run a Retail Security Training Program
Deliver retail security training at onboarding, refresh it annually, and keep a dated record of what you covered. Most small retailers overcomplicate the format and underinvest in the record keeping, when regulators care about the second far more than the first.
Cadence And Session Length
Budget 60 to 90 minutes for a new hire and 30 to 45 minutes for the annual refresher. Between formal sessions, run 10-minute huddles on one topic at a time. Short, frequent reinforcement holds up better than an annual marathon, and it lets you respond to whatever happened that month.
Trigger additional training whenever you identify a new hazard, change the plan, or work through an incident.
Who Delivers It
An in-house manager can run the program as long as they can field questions on the spot with no binder in hand. California explicitly requires that the interaction be back-and-forth, so a recorded video played in a silent room does not satisfy the standard. Outsourcing makes sense for specialized content, such as active threat response or certified de-escalation, less so for store-specific procedures that only your team knows. System walkthroughs sit on the in-house side as well, and our breakdown of point of sale training shows how to structure those sessions so the lesson holds.
What to Document
Keep a training log recording date, topics covered, attendees, and the name of whoever delivered the session. Add signed acknowledgments of the written policy, distributed on hire and at each subsequent training. In California, training records are kept one year and the violent incident log five, so do not file them on the same schedule. Store the plan somewhere staff can reach it without asking, whether that is a break room binder or an intranet page.
Training Providers And Resources
Start with free government and industry material before paying for a platform, because the mandated content is already published at no cost.
A note on cost. Government material below costs nothing. Among the commercial platforms, only ESET publishes a free tier; the rest price per user per month and quote on request, so expect a sales conversation, not a number on a pricing page. Treat any per-seat figure you find on a third-party review site as unverified.
Free And Official Resources
- CISA Commercial Facilities Training. Active Threat Recognition for Retail Security Officers, an 85-minute session, plus active shooter planning webinars.
- New York Department of Labor. Model Retail Workplace Violence Prevention Policy and an interactive online training, published May 2025 and adoptable as written.
- Cal/OSHA. Workplace violence prevention guidance, FAQs, and fillable written plan templates.
- ICSC and the Loss Prevention Research Council. Shopping center security programs and active shooter preparation resources.
Cybersecurity Awareness Platforms
- KnowBe4. The largest content library of the group, with thousands of assets in its ModStore, more than 200 modules added during 2026 alone, and material in over 47 languages. AI personalization matches training to a user’s role and risk. Best suited to larger teams.
- Hoxhunt. Now positioned as a human risk management platform, pairing AI with behavioral science to build individualized learning paths in place of one course assigned to the whole team. Phishing simulation remains the core.
- ESET. Runs a free Basic course alongside a paid 90-minute Premium version built around a storyline, with phishing simulation, completion certificates, and admin dashboards. The free tier makes it the easiest starting point for a small store.
- Jericho Security. A newer entrant, founded in 2023, focused on AI-generated attack simulation across email, SMS, and voice, including deepfake scenarios. A useful option if voice and text scams worry you more than email alone.
Physical Security And De-escalation Providers
- ALICE Training, part of Navigate360. Options-based active shooter response, widely adopted across retail.
- ASIS International and the Loss Prevention Foundation. The Essentials of Retail Asset Protection certificate, a self-paced online course ending in a 35-question proficiency test. Aimed at staff moving into loss prevention roles.
- Force Training Institute. Retail-specific modules for managers who carry security responsibility without a security background.
How Your POS System Supports Retail Security Training
Training gives your team the judgment to spot problems. Your software gives you the record to prove what happened. Retail point of sale software from KORONA POS brings retailers tighter permissions, deeper reporting, and a clearer view of each transaction, so running a business is just a little bit easier.
Role-based cashier permissions make the register rules from Module 3 something the system enforces on its own, not a policy riding on everyone’s memory. Refund and override authority stays with the people you assigned it to. Reporting and analytics cover the other half, breaking those same transaction types out by operator and time of day, so a variance narrows to one shift.
Documentation carries as much weight as the controls themselves. Cal/OSHA can ask to see your training records, and insurers will ask what you did after an incident. A store able to produce a training log alongside a matching transaction history sits in a much stronger position than one working from memory.
Click below to learn more with a free trial or product demo.
Speak with a product specialist and learn how KORONA POS can power your business.
Frequently Asked Questions
Is Retail Security Training Required by Law?
In California and New York, yes. Covered retailers there owe employees a written policy plus a documented program. No other state names retail specifically, yet the federal General Duty Clause leaves employers on the hook for hazards they already know about.
How Often Should Retail Security Training Happen?
On hire, then yearly. California expects an interactive session annually with no exceptions. Smaller New York retailers get a longer gap, once per two years below the 50-worker mark. Any new hazard or plan revision resets the clock.
What Should Employees Do if They See Someone Stealing?
Watch, memorize, escalate. A quiet word to the manager beats any attempt at intervention. Chasing someone down or laying hands on them puts the worker in danger of injury and hands the business a lawsuit it will probably lose.
Can Small Retailers Run Security Training in House?
Yes, and most do. Both states hand out ready-made templates at no charge, so a manager who has read the plan closely is qualified to lead it. What the law asks for is a knowledgeable presenter and a paper trail, not a purchased course.
How Long Should a Security Training Session Take?
New hires need 60 to 90 minutes. After that, 30 to 45 minutes once a year will do. Brief 10-minute huddles on a single topic beat one long annual sitting, because attention falls away sharply past the hour mark.
Does Security Training Cover Cybersecurity Too?
It should. Your people handle payment card details, open back-office tools, and get targeted by scam emails hunting for store logins. Teaching the digital and physical halves as unrelated programs opens a gap precisely where attackers work across both.








