Events & Awards

Live from Conclave: Understanding Cybersecurity Risks

Events & AwardsApr 25, 2018

Live from Conclave: Understanding Cybersecurity Risks

Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?

Nashville, Tenn.—The hacks that make headlines are the ones that involve big companies and thousands, if not millions or billions, of files of customer data—Equifax, Yahoo and, most recently, Saks Fifth Avenue and Lord & Taylor. 

But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked. 

“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.” 

Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.

She started with social engineering and phishing. 

Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.

Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).

While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly. 

The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.

The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back. 

Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.

But that doesn’t always happen.

When a business owner or employee falls for a phish, Myers said options are somewhat limited. 

She said what business owners should not do is pay, as there is no guarantee they will get their data back. 
They should stop their system backup, wipe infected systems and devices, and restore using what was backed up before the malware was installed. (Systems need to be backed up regularly. Myers recommends having a set, repeating cycle; for example, it backs up every day at midnight.)

Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?

While not heavily attended, the Conclave session did generate multiple questions from attendees.

One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.

Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.

Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.

2. Keep an inventory of risks and threats, and use multiple layers of security.

3. Keep systems and devices patched.

All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
 
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”

4. Back up systems and, Myers added, test the back-up.

Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.

5. Establish separation in key systems.

Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.

Also, when someone leaves the company, take away their access to the company’s systems.

6. Train employees on cyber risks at least annually, if not quarterly.

In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.

The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.

Michelle Graffis the editor-in-chief at National Jeweler, directing the publication’s coverage both online and in print.

The Latest

202.18 carat fancy intense yellow diamond The Yellow Rose
AuctionsMay 16, 2024
Christie’s Holds 2 Sales Despite Cyberattack

Though its website has been down for a week, Christie’s proceeded with its jewelry and watch auctions on May 13-14, bringing in nearly $80 million.

The Allnatt yellow diamond
AuctionsMay 16, 2024
Sotheby’s Withdraws 101-Carat Yellow Diamond from Auction

Despite the absence of “The Allnatt,” Sotheby’s Geneva jewelry auction totaled $34 million, with 90 percent of lots sold.

National Jeweler columnist Lilian Raji
ColumnistsMay 16, 2024
The PR Adviser: What the Designer Should’ve Done

Lilian Raji gives advice to designers on how to make the most of great publicity opportunities.

Royal Chain gold chains
Brought to you by
Record Gold Prices Have Consumers Undeterred. Here’s Why.

Despite the rising prices, consumers continue to seek out the precious metal.

Mothae Diamond Mine Lesotho
SourcingMay 16, 2024
Lucapa to Shed Stake in Lesotho Diamond Mine

The mining company wants to divest its 70 percent holding in the Mothae Diamond Mine in an effort to streamline its portfolio.

Weekly QuizMay 16, 2024
This Week’s Quiz
Test your jewelry news knowledge by answering these seven questions.
Take the Quiz
National Jeweler columnist Peter Smith
ColumnistsMay 15, 2024
Squirrel Spotting: Why Retailers Struggle to Fire Brands

Why do so many jewelers keep lines that are not selling? Peter Smith thinks the answer lies in these two behavioral principles.

The Argyle Phoenix red diamond
AuctionsMay 15, 2024
Red Diamond Breaks Records at Phillips Geneva

The “Argyle Phoenix” sold for more than $4 million at the auction house’s second jewels sale.

Header image w logo.jpg
Brought to you by
From Registration to Return: 10 Tips to Protect You Before, During and After a Tradeshow

Tradeshow risks are real. Get tips to protect yourself before, during and after and gain safety and security awareness for your business.

David Mann jewelry store
IndependentsMay 15, 2024
David Mann Jewelers in Upstate NY to Close After 35 Years

Owner David Mann is heading into retirement.

Brilliant Earth Logan Hollowell jewelry collection
FinancialsMay 15, 2024
Brilliant Earth’s Sales Fall Flat in Q1

While overall sales were sluggish, the retailer said its non-bridal fine jewelry was a popular choice for Valentine’s Day.

Rough diamonds from De Beers
SourcingMay 14, 2024
Anglo American Confirms It Is Looking to Sell De Beers

The mining giant also wants to offload its platinum business as part of an overhaul designed to “unlock significant value.”

The Yellow Rose and the Allnatt yellow diamonds
AuctionsMay 14, 2024
2 Huge Yellow Diamonds Are Heading to Auction

Christie's is selling one of the diamonds, moving forward with its Geneva jewelry auction despite the cyberattack that took down its website.

Born Leaders Platinum Born campaign
MajorsMay 14, 2024
Platinum Born Taps ‘Born Leaders’ for New Campaign

The ad aims to position platinum jewelry as ideal for everyday wear.

Instappraise Trifold Brochure
GradingMay 14, 2024
Instappraise Adds Trifold Brochure to Appraisal Offerings

Retailers can customize and print the appraisal brochures from their store.

White, pink, and blue lab-grown diamonds from Lightbox
Lab-GrownMay 13, 2024
Lab-Grown Diamond Brand Lightbox Cuts Prices by 25 to 40%

The move follows a price-drop test run in Q4 and comes with the addition of a “quality assurance card” from GIA for some loose diamonds.

Christie’s New York
TechnologyMay 13, 2024
Christie’s Website Brought Down by Hackers, Watch Auction Postponed

The site has been down since Thursday evening, just ahead of its spring auctions.

Madeleine K. Albright’s Patriotic Leopard Brooch
AuctionsMay 13, 2024
Madeleine Albright’s Jewelry, Pins a White-Glove Sale at Freeman’s | Hindman

The late former U.S. Secretary’s collection went for quadruple the sale’s pre-sale estimate.

Zachary’s Jewelers Mother’s Day Jewelry Contest winners
IndependentsMay 13, 2024
Zachary’s Jewelers Names Mother’s Day Jewelry Contest Winners

Three fifth graders’ winning designs were turned into custom jewelry pieces in time for Mother’s Day.

Kimberly Adams Russell
IndependentsMay 10, 2024
Frank Adams Jewelers Names New CEO

Kimberly Adams Russell is taking over the role from her father, David Adams, marking the third generation to hold the title.

Birth of Venus necklace
CollectionsMay 10, 2024
Piece of the Week: Carina Hardy’s ‘Birth of Venus’ Necklace

As a token of womanhood, this necklace depicts when Venus was born from the sea.

Roberto Coin Fleur de Lis jewelry
MajorsMay 09, 2024
Watches of Switzerland Pays $130M for Roberto Coin Inc.

The deal gives the retailer control over the distribution of Roberto Coin jewelry in the U.S., Canada, Caribbean, and Central America.

Lauren K Mosaic necklace
TrendsMay 09, 2024
Amanda’s Style File: Shine Bright, Moms  

Show your mother some love with a piece of fine jewelry.

Kyle Edward Fine Jewelry
IndependentsMay 09, 2024
Kyle Edward Fine Jewelry to Close Salisbury Store

The company’s Easton location will remain open.

Jewelers Board of Trade logo
MajorsMay 09, 2024
JBT Elects New Chairman

Brian D. Fleming of Carla Corporation was elected to serve a one-year term in the role.

Las Vegas Antique Jewelry and Watch Show Bracelets
Supplier BulletinMay 08, 2024
Fusing Past and Present at the Las Vegas Antique Jewelry & Watch Show

Sponsored by the Las Vegas Antique Jewelry and Watch Show

Vikki Tobak
EditorsMay 07, 2024
Q&A: Author Vikki Tobak on the ‘Ice-Cold’ Exhibition

Tobak, author of “Ice Cold: A Hip-Hop Jewelry History,” shares how the exhibition came to be, and the pieces people may be surprised to see.

Cynthia Erivo, Zendaya, Lewis Hamilton at the Met Gala
EditorsMay 07, 2024
10 On-Theme Looks from the 2024 Met Gala

Stars adorned themselves in emeralds, platinum, and myriad bird motifs, writes Associate Editor Natalie Francisco.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy