Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Lisa Bridge and Alexis Padis at AGS Conclave 2024
Events & AwardsApr 25, 2024
Alexis Padis Takes Over as AGS Board President

Padis succeeds Lisa Bridge, marking the first time the organization has had two women board presidents in a row.

Jesse Cole Savannah Bananas
EditorsApr 25, 2024
5 Tips for Creating Fans from the Top (Savannah) Banana

Jesse Cole, founder of Fans First Entertainment, shared the “five Es” of building a fan base during his AGS Conclave keynote.

John Mayer Audemars Piguet
WatchesApr 25, 2024
Audemars Piguet and John Mayer Partner on Limited Edition Watch

The Royal Oak Perpetual Calendar "John Mayer" was celebrated at a star-studded party in LA last week.

1-(3.18).JPG
Brought to you by
The Blueprint for Success in Scalable, Personalized Jewelry Retail

With Ho Brothers, you can unlock your brand's true potential and offer customers the personalized jewelry experiences they desire.

Stock image of rough diamonds mined by De Beers
SourcingApr 25, 2024
De Beers Lowers Production Guidance for 2024

The announcement came as the company reported a 23 percent drop in production in Q1.

Weekly QuizApr 26, 2024
This Week’s Quiz
Test your jewelry news knowledge by answering these seven questions.
Take the Quiz
Jared Goff Presents Jared Jewelers’ Donation to Give Merit
MajorsApr 25, 2024
Detroit Lions’ QB Jared Goff Keeps Going to Jared

The three-time Pro Bowler continues to partner with the retailer, donating to a Detroit nonprofit and giving watches to fans.

Stock image of police crime scene tape
CrimeApr 24, 2024
Jewelry Crime Declines Significantly, But Dollar Losses Remain High

A double-digit drop in the number of in-store crimes was offset by a jump in off-premises attacks, JSA’s 2023 crime report shows.

Jewelers of America Fly In Washington, D.C.
Brought to you by
How Jewelers of America Represents Your Business

For over 30 years, JA has advocated for the industry, fought against harmful legislation and backed measures that help jewelry businesses.

Kirsty Hume models Pippa Small Venus collection
CollectionsApr 24, 2024
Pippa Small Announces ‘Venus’ Collection

Inspired by the Roman goddess of love, the designer looked to the sea for her new collection.

Pomellato Pom Pom Dot necklaces
FinancialsApr 24, 2024
Kering’s Jewelry Brands a Bright Spot in Tough Q1

The luxury titan posted declining sales, weighed down by Gucci’s poor performance.

JCK Industry Fund Logo
Events & AwardsApr 24, 2024
JCK Industry Fund Announces 2024 Grant Recipients

The selected nine organizations have outlined their plans for the funds.

Aerial shot of the Diavik Diamond Mine in Canada’s Northwest Territories
SourcingApr 24, 2024
Rio Tinto’s Q1 Production Drops Amid Pause to Honor Lost Colleagues

The mining company’s Diavik Diamond Mine lost four employees in a plane crash in January.

Rolex Oyster Perpetual Deepsea in 18-karat yellow gold
WatchesApr 24, 2024
These Are Rolex’s New Watches for 2024

The crown introduced a dozen timepieces in Geneva, including a heavy metal version of its deep-sea divers’ watch.

National Jeweler columnist Emmanuel Raheb
ColumnistsApr 23, 2024
The Smart Lab: Advanced Email Marketing Strategies for Mother’s Day

Emmanuel Raheb recommends digging into demographic data, customizing your store’s communications, and retargeting ahead of May 12.

Hannoush Jewelers Queensbury NY location
IndependentsApr 23, 2024
Hannoush Jewelers Opens New Store in New York

Located in the town of Queensbury, it features a dedicated bridal section and a Gabriel & Co. store-in-store.

203-carat, 116-carat, and 42-carat diamond
SourcingApr 23, 2024
Lucapa Sells 3 Diamonds for $10.5M in First Lulo Tender of 2024

A 203-carat diamond from the alluvial mine in Angola achieved the highest price.

William Ruser: The Jeweler Who Charmed Hollywood book cover
GradingApr 23, 2024
GIA Has a New Book About William Ruser

Ruser was known for his figural jewelry with freshwater pearls and for his celebrity clientele.

Adam Levine and Behati Prinsloo modeling Jacquie Aiche’s Rebel Heart collection
CollectionsApr 22, 2024
Jacquie Aiche’s New Campaign Stars Adam Levine, Behati Prinsloo

The “Rebel Heart” campaign embodies rebellion, romance, and sensuality, the brand said.

American Gem Society Conclave logo 2024
EditorsApr 22, 2024
The 22 Best Quotes from AGS Conclave 2024

Editor-in-Chief Michelle Graff shares the standout moments from the education sessions she attended in Austin last week.

Virtual Diamond Boutique
SourcingApr 22, 2024
Virtual Diamond Boutique Rebrands as ‘VDB’

The overhaul includes a new logo and enhanced digital marketplace.

Signet Jewelers employees and St. Jude Children’s Research Hospital
MajorsApr 22, 2024
Signet Raises Nearly $9M for St. Jude Children’s Research Hospital

The money will go toward supporting ongoing research and aftercare programs for childhood cancer survivors.

Retrouvaí’s Treasure Necklace
CollectionsApr 19, 2024
Piece of the Week: Retrouvaí’s Treasure Necklace

A new addition to the “Heirloom” collection, this one-of-a-kind piece features 32 custom-cut gemstones.

Stock image crime handcuffs
CrimeApr 19, 2024
Grand Jury to Hear Case Against Jeweler Charged in Fatal Shove Following IJO Show

Last month in Dallas, David Walton pushed another jeweler, David Ettinger, who later died.

China Pearl collage
MajorsApr 19, 2024
Unique Designs Acquires China Pearl

The move will allow the manufacturing company to offer a more “diverse and comprehensive” range of products.

Printed and digital AGS Ideal grading reports
GradingApr 19, 2024
AGS Ideal Report Now Available in Printed Form

From now through mid-May, GIA will be offering the reports at a 50 percent discount.

Stock image of a polished diamond in tweezers
SourcingApr 18, 2024
Diamond Trade Remains Cautious Amid Economic Uncertainty

De Beers’ rough diamond sales were down 18 percent year-over-year in its latest round of sales.

LVAJWS24_carousel_images_1872x1052_1.jpg
Supplier BulletinApr 18, 2024
Discover History’s Hidden Gems at the Las Vegas Antique Jewelry & Watch Show

Sponsored by the Las Vegas Antique Jewelry & Watch Show

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy