The threat surface is enormous. Kering operates a portfolio of high-profile luxury Houses - Gucci, Saint Laurent, Balenciaga, Bottega Veneta, McQueen, Boucheron, and more - spanning ready-to-wear, leather goods, jewelry, eyewear, and beauty. With 44,000 employees globally and €14.7 billion in revenue, the attack vectors multiply across retail operations, e-commerce platforms, supply chain logistics, and the intellectual property of some of the world's most counterfeited brands. The brand value alone makes these Houses persistent targets for credential harvesting, fraud, and data exfiltration.
Security teams here aren't just defending corporate infrastructure - they're protecting high-net-worth customer data, payment systems across global retail networks, and the creative IP that defines each House. The model likely spans identity and access management across a decentralized portfolio, securing e-commerce stacks at scale, third-party risk in complex supply chains, and threat intelligence tuned to the luxury sector's specific exposure profile: brand impersonation, counterfeiting networks, and targeted social engineering aimed at high-profile individuals.
The group is family-led and operates with a values framework - 'We care,' 'We dare,' 'We build' - alongside initiatives like the Kering Foundation (est. 2008), focused on combating gender-based violence. Security functions within Kering need to balance the distinct operational autonomy of each House against centralized governance, tooling consistency, and incident response at group scale. It's a federated model with all the complexity that implies.





