Dr. Martens’ boots have been walking the sidewalks since 1960. Predominantly made for workwear, the leather footwear brand has evolved from factory floors to punk rock festivals and now, a popular choice for an everyday boot.
In that time, shopping habits have also evolved — and today’s shopping experience is plagued less by sore feet than by cyber threats.
Over the past year and a half, brands such as The North Face, Pandora and Adidas have had significant cyberattacks that breached customer data and disrupted operations.
Cybersecurity firm VikingCloud’s Retail Cyber Threat Survey, published in April 2025, found that 80% of retailers had experienced cyberattacks in the previous year, with understaffed teams and inadequate cybersecurity training among the key risks. And the pressure hasn’t eased: Verizon’s 2026 Data Breach Investigations Report found retail breaches doubled year over year, with 68% involving a third party.
And commerce is now the favorite target of AI bots: Akamai’s latest State of the Internet report revealed that nearly half of all AI bot traffic across its network from July to December 2025 was aimed at commerce sites.
On the ground at Dr. Martens
The stats are one thing, but they don’t capture the daily reality of being a prime target.
Speaking alongside one of the brand’s cybersecurity vendors, Cloudflare, at Tech Show London in March, Theo Botha, global CISO at Dr. Martens, acknowledged on stage that Dr. Martens is battling impersonators, bots and increasingly sophisticated fraudsters. Meanwhile, his team is preparing for a future in which some of its most valuable “customers” are software.
Six years into the role, Botha has steered the consumer brand through an IPO, a pandemic-driven e-commerce surge and a threat landscape that has grown more complex with every passing year. Dr. Martens has more than 200 stores in cities around the world, and its digital channels expanded along with its growth.
“As our digital footprint grew, so did the number of attacks,” Botha said. “Being a well-known brand makes you a target.”
Even with its cyber defenses secure, the firm can’t stop bad actors from creating fake websites to deceive its customers. “At one point during the pandemic, we were taking down around 34 fake websites a day,” he said. The company worked with legal and intellectual property teams to combat the problem while expanding bot management and web application firewalls across its digital estate.
Because Dr. Martens runs a lean internal team, it relies on outsourced partnerships. “Our MXDR [managed extended detection and response] provider handles 24/7 monitoring and escalates issues to us,” he said. “Threat intelligence is especially important — many attacks start with conversations about our brand online.”
But not all attacks are online. “Some recent threats have been very old-school, people physically turning up at stores pretending to be IT staff to gain access,” he said. “So security isn’t just digital; it’s physical too.”
Botha described what he calls a “coffee shop model” for its stores: minimal infrastructure, centrally managed, with clear separation between systems.
“Digital signage isn’t connected to the corporate network. Everything is segmented,” he said. “Simplicity makes security easier to manage.”
The customer is an agent
As he splits his attention across both physical and online security, Botha acknowledged the need to build for an age when an AI agent may find products, make purchases and complete transactions on behalf of a consumer.
“It’s a major topic right now,” he said. “Operationally, it’s another channel we need to support. Products need to be discoverable by AI, and transactions must work seamlessly.”
From a security perspective, he said it raises three big questions: How do you authenticate an agent? How do you detect fraud? What happens if an agent is compromised?
“We don’t have all the answers yet, but governance, compliance and fundamentals still apply. It’s an area we’re actively exploring.”
In the months that have elapsed since Botha’s on-stage comments in London, companies have been hard at work on defining the answers.
Dr. Martens’ vendor Cloudflare’s Web Bot Auth uses cryptographic signatures so a merchant can verify that an agent is registered and authorized. Visa’s Trusted Agent Protocol and Mastercard’s Agent Pay are both built on top of it, according to the company, extending that verification through to the payment itself.
Fraud detection is also a problem because the “attacker” may be a legitimate agent that’s been manipulated. For example, researchers at Palo Alto Networks’ Unit 42 have shown how prompt injection hidden in a deals page or in product metadata could reprogram a shopping agent to slip gift cards into a cart or trigger mass refunds at machine speed.
A channel still under construction
What is yet to be delivered is a universal, interoperable standard for authenticated delegation and fraud handling across merchants, platforms and agents. Stripe said its Agentic Commerce Protocol, codeveloped with OpenAI, had attracted more than 25 ecosystem partners by January’s NRF Big Show — where Google announced a competing Universal Commerce Protocol of its own.
The consumer side is still finding its feet too. OpenAI’s Instant Checkout, launched in September 2025 with Etsy and the promise of “over a million Shopify merchants,” was wound down by the company in March. “It struggled to onboard merchants, show accurate data about products and introduce multi-item carts or connect loyalty memberships,” CNBC reported.
Dr. Martens is approaching the new channel fundamentals-first: governance, compliance and segmentation before scale. More than 60 years after the first pair of 1460s rolled off the line, the bootmaker’s agentic customers may not have feet, but Botha and others like him are working hard to figure out how to outfit them all the same.