HORNBACH Baumarkt AG is one of Europe's largest DIY-store chains, operating 171 megastores with garden centers across nine countries. The company moves roughly EUR 5.1 billion in annual sales (2020/2021) across a catalog of approximately 50,000 articles - hardware, electrical, paint, flooring, construction materials, sanitary, tiles, garden supplies - alongside online retail operations. More than 22,000 employees keep the physical and digital infrastructure running.
The threat surface here is broad and unglamorous: a sprawling retail footprint with point-of-sale systems, warehouse logistics, e-commerce platforms, and customer data flowing across borders. The attack model for a retailer of this scale includes payment card fraud, supply chain compromise, ransomware targeting operational continuity across 171 physical locations, and the regulatory complexity of handling customer data across nine European jurisdictions. None of this is theoretical for any organization running this many endpoints and this much transactional volume.
Cybersecurity roles at HORNBACH sit at the intersection of protecting both legacy retail infrastructure and the growing online shop operation. The company's family-business roots stretch back to 1877, with the modern Baumarkt chain founded in 1977 - a long operational history that often correlates with deeply embedded legacy systems alongside newer digital commerce platforms. Security engineering here means defending a hybrid environment where physical logistics and digital retail converge.





