Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Stock image of money
Policies & IssuesApr 28, 2026
Tariff Refunds: How to File, What to Expect

Importers can submit claims now to receive money back for the IEEPA tariffs they’ve paid, with refunds expected to take up to 90 days.

Gregory's Jewelers storefront
IndependentsApr 28, 2026
This North Carolina Jeweler Is Passing the Torch

The owners of Gregory Jewelers in Morganton, North Carolina, are heading into retirement.

Doug Hucker
SourcingApr 28, 2026
Doug Hucker Retires From ICA

The colored gemstone industry leader is heading into retirement after four years as the association’s CEO.

Antique Jewelry & Watch Show
Brought to you by
Discover Timeless Treasures: A Showcase of Antique Jewelry & Timepieces in Las Vegas

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

Natural Diamond Council Chief Marketing Officer Susie Dewey
SourcingApr 28, 2026
NDC Hires Tapestry Exec to Head Global Marketing

Susie Dewey joins the Natural Diamond Council as its new chief marketing officer.

Weekly QuizApr 23, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
The Ocean Dream diamond
AuctionsApr 27, 2026
12 Years Later, the ‘Ocean Dream’ Diamond Resurfaces at Christie’s

The largest known fancy vivid blue-green diamond could fetch more than $12 million at its second auction appearance.

Smart Age Solutions CEO and National Jeweler columnist Emmanuel Raheb
ColumnistsApr 27, 2026
Stop Treating Mother’s Day Like an Afterthought

Emmanuel Raheb says jewelers need to start marketing early and make it easy for customers to pick a gift for mom.

lvajws image 1.jpg
Brought to you by
Las Vegas Antique Jewelry & Watch Show: Showcasing the Most Collectible Merchandise from Across the Globe

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

Longnecker Jewelry storefront
IndependentsApr 27, 2026
Longnecker Jewelry Celebrates 30 Years

In honor of the milestone, the Nebraska jeweler has debuted Leslie & Co., its new in-house jewelry brand.

Jeff Corey
MajorsApr 27, 2026
JBT Re-Elects Jeff Corey as Board Chair

The trade organization, which held its annual elections earlier this year, also added five new board members.

Fourteen August Irene mom ring
SurveysApr 24, 2026
Mother’s Day 2026 Jewelry Spending to Top $7B, NRF Says

NRF’s annual survey found that 45 percent of consumers plan to purchase jewelry for a loved one this Mother’s Day.

Hamptons Jewelry Show exhibitors Maison Mèrenor, Jochen Leën, Studio Javo
Events & AwardsApr 24, 2026
Hamptons Jewelry Show to Return in July

The open-to-the-public luxury jewelry and timepiece show, in its second year, is slated for July 23-26.

Photos from Day’s Jewelers 2025 Mother’s Day campaign
IndependentsApr 23, 2026
Meet the Real Moms of Day’s Jewelers

The jeweler’s Mother’s Day campaign highlights the women who work there—mothers, grandmothers, women who want to be mothers, and dog moms.

National Jeweler - Supplier Bulletin - April 2026 - JMSS Graphic.jpg
Supplier BulletinApr 23, 2026
JM® Shipping Solution: Smarter Shipping for High-Value Goods

Sponsored by Jewelers Mutual

Woman wearing Charles & Colvard lab grown diamond jewelry
Lab-GrownApr 23, 2026
Charles & Colvard May Sell Assets for $1.5M

The proposed agreement follows the moissanite maker’s Chapter 11 bankruptcy protection filing last month.

John Jacob Astor IV’s Titanic pocket watch and a gold pencil case
AuctionsApr 23, 2026
John Jacob Astor IV’s Titanic Pocket Watch Fetches $1M

The Patek Philippe for Tiffany & Co. timepiece Astor brought aboard the ill-fated ship sold for double its estimate at a Freeman’s auction.

Adam Neeley Dali Garden Collection Eyris Ring
CollectionsApr 23, 2026
Adam Neeley’s High Jewelry Collection Steps Into Salvador Dalí’s Garden

The “Dalí’s Garden” collection was inspired by a surreal dream Neeley had after cooking a recipe from Salvador Dalí’s 1973 cookbook.

Natalie Feanny
IndependentsApr 23, 2026
Windsor Jewelers Names New Buying Director

Natalie Feanny has been appointed to the role.

Stock image of a gavel and books
CrimeApr 22, 2026
New Mexico Couple Pleads Guilty to Selling Fake Native American Jewelry

The pair falsely claimed their jewelry was made by Navajo artists, but it was imported from Vietnam.

Roberta Flack: Style, Art, & Music Auction Bulgari Collar
AuctionsApr 22, 2026
Roberta Flack’s Jewelry Is Going Up for Auction

Julien’s Auctions is selling the musician’s fine and fashion jewelry alongside her clothing, gold records, and other memorabilia.

Rachel King and The Tudor Heart book cover
CollectionsApr 22, 2026
British Museum Curator Pens Book on ‘The Tudor Heart’

Rachel King’s book dives into the history of the pendant believed to have belonged to Henry VIII and his first wife, Katherine of Aragon.

Henry Kessler, Vance Kessler, Alex Kessler, and Daniel Kessler of Sy Kessler Sales Inc.
Events & AwardsApr 22, 2026
Here’s What Sy Kessler Has on Tap for Las Vegas

The company will have deals on precious metals testers as well as the latest in lab-grown diamond detection technology and security.

Chanel Coco Game Haute Horlogerie Chessboard
WatchesApr 21, 2026
Coco Chanel Enters the Game with New Watch Collection

Gabrielle “Coco” Chanel is a character in the “Coco Game” collection of watches and the queen in its first haute horlogerie chessboard.

Jewelers of America 20 Under 40 winners collage
IndependentsApr 21, 2026
Meet Jewelers of America’s 2026 ‘20 Under 40’ Class

The annual list honors rising professionals on the retail and supply sides of the jewelry industry.

Fake Fendi bangle
CrimeApr 21, 2026
Customs Nabs 1,500 Pieces of Counterfeit Jewelry Bound for NYC

Seized in Kentucky, the packages include fake Cartier, Tiffany & Co., Chanel, and Fendi jewelry.

Stock image of a judge’s gavel
CrimeApr 20, 2026
Queens Man Convicted in Bludgeoning Death of Pawn Shop Owner

Rodolfo Lopez-Portillo faces 25 years to life in prison after being found guilty in the March 2022 beating death of Arasb Shoughi.

Jewelry Creators: Dynamic Duos and Generational Gems Book Cover
TrendsApr 20, 2026
Beth Bernstein, Sonia Esther Soltani Pen New Jewelry Book

“Jewelry Creators: Dynamic Duos and Generational Gems” highlights the relationships among 22 influential designers, brands, and gem dealers.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy