Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Sylvie Jewelry Auranova Collection Campaign Imagery
CollectionsApr 25, 2025
Sylvie Looks to Water in New Sculptural Bridal Collection

“Shell Auranova” is the next generation of the brand’s bridal line, featuring half-bezel engagement rings with bold and fluid designs.

Pomellato Nudo toi et moi ring
FinancialsApr 25, 2025
Kering’s Jewelry Brands Persevere as Q1 Sales Sink 14%

Boucheron and Pomellato performed well in an otherwise bleak quarter for Kering amid struggles at Gucci.

Deborah Meyers Experience The Birds Earrings
EditorsApr 25, 2025
Piece of the Week: Deborah Meyers Experience’s ‘The Birds’ Earrings

Designer Deborah Meyers created her birds from oxidized sterling silver, rose-cut diamond eyes, and Akoya Keshi pearl feathers.

ejap cohort 1872x1052.png
Brought to you by
Emerging Jewelers Accelerator Program Announces Second Cohort of Aspiring Jewelry Entrepreneurs

Six new retail businesses were selected for the 2025 program, which began in January.

Melee diamonds from De Beers
SourcingApr 25, 2025
De Beers Sales, Production Fall in Q1 Amid Uncertainty

The company said it expects sightholders to remain “cautious” with their purchasing due to all the unknowns around the U.S. tariffs.

Weekly QuizApr 24, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
LIM-401 2024 National Jeweler Supplier Bulletin- iD100 Web and Eblast FINAL (1).jpg
Supplier BulletinApr 24, 2025
Protect Your Customers and Your Business

Sponsored by the Gemological Institute of America

Wolf CEO Simon Wolf
EditorsApr 24, 2025
Q&A: Wolf’s CEO Talks U.S. Expansion

Simon Wolf shares why the time was right to open a new office here, what he looks for in a retail partner, and why he loves U.S. consumers.

gia1d100 btyb.jpg
Brought to you by
Protect Your Customers and Your Business

The risk of laboratory-grown diamonds being falsely presented as natural diamonds presents a very significant danger to consumer trust.

Iowa jeweler Herman Ginsberg
IndependentsApr 24, 2025
Longtime Iowa Jeweler Herman Ginsberg Dies at 99

A third-generation jeweler, Ginsberg worked at his family’s store, Ginsberg Jewelers, from 1948 until his retirement in 2019.

Charles & Colvard moissanite ring
FinancialsApr 24, 2025
Charles & Colvard Delisted From Nasdaq Due to Noncompliance

The company failed to file its quarterly reports in a timely manner.

Young Diamantaires
SourcingApr 24, 2025
Young Diamantaires Transition to Nonprofit

The organization also announced its board of directors.

Mined + Found "Hope" Matchbox Locket
TrendsApr 24, 2025
Amanda’s Style File: So Charming

Charms may be tiny but with their small size comes endless layering possibilities, from bracelets to necklaces and earrings.

Bulgari’s expanded factory in Valenza, Italy
MajorsApr 23, 2025
Bulgari Doubles Size of Jewelry Factory in Italy

Located in Valenza, the now 355,000-square-foot facility includes a new jewelry school that’s open to the public, Scuola Bulgari.

Jason McNary accepting FGI Fine Jewelry Rising Star award for Paola Sasplugas
Events & AwardsApr 23, 2025
PDPaola Creative Director Wins FGI’s ‘Rising Star’ Award

Paola Sasplugas, co-founder of the Barcelona-based jewelry brand, received the Fine Jewelry Award.

1999 Cosmograph Daytona, Ref.16516
AuctionsApr 23, 2025
Rare Custom Rolex Daytona Heads to Auction

A platinum Zenith-powered Daytona commissioned in the late ‘90s will headline Sotheby’s Important Watches sale in Geneva next month.

Carmelo Anthony and Jaylen Brown David Yurman campaign
MajorsApr 23, 2025
David Yurman’s New Campaign Stars Carmelo Anthony, Jaylen Brown

The basketball stars wear men’s jewelry from the “Curb Chain” collection.

Woman wearing Zales jewelry
MajorsApr 22, 2025
Zales’ Rebrand Takes Playful Approach to Fine Jewelry

The Signet Jewelers-owned retailer wants to encourage younger shoppers to wear fine jewelry every day, not just on special occasions.

JAR Apricot Blossom bracelet
AuctionsApr 22, 2025
Christie’s to Auction JAR Jewelry Collection

The 21 pieces, all from a private collector, will be offered at its Magnificent Jewels auction next month.

National Jeweler columnist Lilian Raji
ColumnistsApr 22, 2025
The PR Adviser: Building Buzz Through Word of Mouth

Lilian Raji answers a question from a reader who is looking to grow her jewelry business but has a limited marketing budget.

Avi Levy
GradingApr 22, 2025
Avi Levy Is GCAL By Sarine’s New Chief Growth Officer

GCAL by Sarine created the new role to sharpen the company’s focus on strategic partnerships and scalable expansion.

Scottsdale Fine Jewelers store exterior
IndependentsApr 22, 2025
Brinker’s Jewelers Acquires Fellow Independent

The Indiana jeweler has acquired Scottsdale Fine Jewelers in Scottsdale, Arizona.

Cartier Exhibition Installation at Victoria & Albert Museum
Events & AwardsApr 21, 2025
An Exhibition Exploring the History of Cartier Is Now on Display

“Cartier: Design, Craft, and Legacy” opened earlier this month at the Victoria and Albert Museum in London.

Bill and Birdie Levine of Van Cott Jewelers
IndependentsApr 21, 2025
New York Jeweler to Close After 111 Years

Van Cott Jewelers in Vestal, New York, is hosting a going-out-of-business sale.

IJO Director Samantha Larson
IndependentsApr 21, 2025
IJO Names New Director of Vendor Relations, Merchandise Strategy

Industry veteran Samantha Larson has held leadership roles at Borsheims, McTeigue & McClelland, Stuller, and Long’s Jewelers.

Events & AwardsApr 21, 2025
Jewelers of Louisiana, Mississippi Jewelers Association to Co-Host Convention

The two organizations will hold the educational event together this fall in Mississippi.

Daymond John
Events & AwardsApr 18, 2025
Daymond John to Give Keynote at JCK Las Vegas

The entrepreneur and “Shark Tank” star will share his top tips for success.

Dukachi Easter Bread Pendant
CollectionsApr 18, 2025
Piece of the Week: Dukachi’s ‘Easter Bread’ Pendant

The Ukrainian brand’s new pendant is modeled after a traditional paska, a pastry often baked for Easter in Eastern European cultures.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy