I read nine retail earnings calls from August and September.

Six of them do not contain the word shrink. Not shrinkage, not theft, not loss prevention, not asset protection. Home Depot, Lowe's, Target, TJX, Walmart, Dick's Sporting Goods — zero mentions across the set.

Two years ago this was the dominant theme in retail earnings. It is now absent from the largest retailers in the country.

It did not disappear because anyone stopped caring. Target explained the mechanism in March, and nobody noticed.

This edition is about defending a budget for a risk that no longer appears in the gross margin bridge.

Six of nine, and the three that kept it

The three exceptions matter more than the six.

  • Dollar General still quantifies it precisely. On the August call the CFO guided about 50 basis points of incremental gross margin from shrink and damages in 2026, while lapping a 108 basis point improvement from the prior year. Its 10-Q discloses shrink as an actual dollar line: $153.2 million in the quarter ended May 1, against $176.1 million a year earlier.

  • Ulta mentions it once, as one of three gross margin drivers, with no crime framing at all.

  • Kroger is the outlier, and it is moving the wrong way. Its September call reports shrink as a negative, concentrated in fresh. Its chief executive, describing what he had found in the business, listed unknown shrinkage alongside out-of-stocks and goods not for resale, and said all of them were "bigger than what I thought."

One retailer in nine is still publishing a shrink dollar figure. One is finding the problem larger than expected. The rest have stopped talking about it entirely.

Why it vanished

Target said it out loud on the March call: lower shrink delivered about 90 basis points of gross margin benefit last year and brought the shrink rate "all the way back down to pre-pandemic levels." Then the guidance: this year's shrink rate would be "in line with last year."

Flat year over year contributes zero basis points to the bridge.

A line item that does not move does not get discussed on an earnings call. Target announced its own disappearance five months before it happened, and the rest of the industry followed.

So the honest reading is not that executives lost interest. It is that your function succeeded, and success removed your agenda item. The variance that made shrink a topic was the same variance that made it a problem.

One fact sits awkwardly next to that. The Council on Criminal Justice's mid-year update describes 2026 as the peak year for reported shoplifting in its nine-year series. The exposure did not go anywhere. Only the disclosure did.

A perspective from the field

Every risk function eventually faces the same trap: you are funded because something is going wrong, and then you fix it. The reward for fixing it is that the thing you were funded for stops being visible.

I have never once walked into a budget conversation with a number showing what a company like mine should be spending on this. That number does not exist. I can tell a CFO what we lost, what we recovered, what we prevented — but I cannot tell him whether our spend is high, low or normal for our size, because nobody publishes it. That is not a research gap. It is a structural disadvantage, and every other risk function in the building has already solved it.

Gabriel Lerner

The number you do not have

I went looking for a loss prevention spend benchmark. Not a stale one, not a paywalled one. There isn't one.

  • NRF discontinued the National Retail Security Survey in October 2024, after 32 editions. Its replacement publishes neither a shrink rate nor a budget figure.

  • ECR Retail Loss published the best study of the LP function that exists in April — 58 retailers, 14 countries, €1.5 trillion in sales, 73,000-plus stores. It maps team structure and naming conventions in detail. It contains no budget data, no headcount data, and no spend-per-store ratio.

  • Everything circulating online as a "2026 shrink benchmark" is the 2022 NRSS number recycled by content farms.

Now the comparison that should bother you.

RH-ISAC surveyed 201 CISOs at retail and hospitality organizations in December and published the eighth edition of its benchmark in 2026. Security spend: 0.75% of revenue, up from 0.57%. Security as a share of IT budget: 5.8%. 54% of those CISOs expect budget increases in 2026, up from 44% in 2024.

And this line, which is the whole argument: RH-ISAC reports that "incident-driven funding remains relatively rare" — investment is "more planned and programmatic rather than reactive."

The cyber function inside your company has an annual sector benchmark, a rising trend line, and a doctrine that explicitly detaches funding from incident counts. Your function has none of the three, in the year your incident count stopped being quotable.

Three practical moves for the next 90 days

  1. Build the benchmark you were never given, internally. Spend per store, spend as a share of sales, coverage ratios by format and market — for your own company, trended over three years. You will not be able to compare it to peers. You will be able to show a direction and a rationale, which is more than a number you cannot produce at all.

  2. Move your ask from incidents to coverage. Cyber did this deliberately and published the doctrine. Frame next year around what percentage of stores, channels and categories your program actually covers to what standard — then price the gap. Incident counts are now arguing against you, because they are falling in your own reporting.

  3. Read the FY2027 bridge before you write the ask. This year's margins were flattered by one-time tariff refunds — roughly $2.9 billion at Walmart, $994 million at Target, $685 million at Home Depot — against fuel and freight inflation that is structural and getting worse. That windfall does not repeat. Every discretionary line is being re-justified in this cycle, and yours just reported a benefit of zero.

Closing note

There is a version of the next two years where shrink stays flat, the function keeps delivering, and the budget quietly erodes because nothing in the reporting argues for it.

The way out is not to hope for a bad quarter. It is to stop letting the incident count be the argument — which is the same conclusion the cyber function reached about five years ago, and wrote down.

If your organization has a defensible internal LP spend benchmark, I want to see how it is built. That is the rarest document in this discipline. Reply with anything you can share, anonymized always.

Forward this to one LP or AP leader who should be reading it.

— Gabriel

The LP Brief is a weekly intelligence read for senior loss prevention and asset protection leaders. Free. No vendor noise.

Not yet subscribed? thelpbrief.com