Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Macy’s New York City Herald Square flagship
FinancialsMar 20, 2026
Macy’s Turnaround Plans Shows Promise, Boosted by Bloomingdale’s

Plus, why Saks Global’s bankruptcy may have given Bloomingdale’s an edge.

Jwaneng Diamond
AuctionsMar 20, 2026
Sotheby's, De Beers Unveil ‘Jwaneng 28.88’ Diamond

The flawless, Type IIa stone is estimated to achieve up to $2.8 million at the auction house’s high jewelry sale in April.

Tiffany & Co.’s Three Jean Schlumberger for Tiffany & Co. Archives Brooches
TrendsMar 20, 2026
‘Frankenstein’ Costume Designer Is Bejeweled In Brooches for Oscars Win

Costume designer Kate Hawley wore three archival Tiffany & Co. brooches, our Pieces of the Week, while accepting her first Oscar.

GIA iD100®
Brought to you by
Protect Your Customers and Your Business

You deserve to know what you are selling–to protect your customers as well as your business and your reputation.

Women wearing Zales jewelry
FinancialsMar 19, 2026
Signet Jewelers to Close 100 Stores, Shutter James Allen Banner

The jewelry retailer announced changes to its store network and brand portfolio during its fourth-quarter earnings call.

Weekly QuizMar 19, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Hand holding shopping bags
SurveysMar 19, 2026
NRF Forecasts 4% Retail Sales Growth in 2026

From a weaker labor market to inflation, NRF Chief Economist Mark Mathews gave insight on what retailers can expect this year.

26.36 carat round brilliant cut white diamond
AuctionsMar 19, 2026
26-Carat Diamond Tops $1M at Auction

The historic stone, which sold at Elmwood’s in London, is the largest white diamond to be offered on the U.K. market in more than a decade.

TopImageCrop.jpg
Brought to you by
Is This You? Every Jeweler Has This Problem; We Have the Solution.

Every jeweler faces the same challenge: helping customers protect what they love. Here’s the solution designed for today’s jewelry business.

JCK Rocks Nelly Graphic
Events & AwardsMar 19, 2026
JCK Rocks To Ride With Nelly

Three-time Grammy award-winning artist Nelly is set to perform at the annual event at Tao Beach in Las Vegas on May 31.

Lady Wardington and diamond-clip brooch
AuctionsMar 18, 2026
Collection of the ‘Severely Beautiful’ Lady Wardington Fetches $161K

The model and fashion editor’s gold evening bags were the top lots at the London sale, going for more than $25,000 each.

My Next Question Episode 3 guest Johnny Nelson
PodcastsMar 18, 2026
Episode 3: An Interview With Jewelry Designer Johnny Nelson

Fresh off winning the David Yurman Gem Awards Grant, Nelson discusses the ring that launched his career and his plans for the future.

Lucara blue diamond
SourcingMar 18, 2026
Lucara Recovers Nearly 37-Carat Blue Diamond

The “stunning” Type IIb stone was found via x-ray technology at its Karowe mine in Botswana.

Stuller The Basics of Jewelry
MajorsMar 18, 2026
Stuller Releases New Edition of Jewelry Education Book

“The Basics of Jewelry” has been updated to include modern topics and visuals.

Mark and Candy Udell on stage at the 2026 Gem Awards
Events & AwardsMar 17, 2026
The Best Moments From the 2026 Gem Awards

Held just before the Oscars, the jewelry industry’s big awards show had its share of standout jewelry, gowns, and acceptance speeches.

Winter Tourmaline
SourcingMar 17, 2026
Cruzeiro Mine Debuts ‘Winter Tourmaline’

The Brazilian mine’s new collection features cabochons in soft, muted shades like silver and lilac.

Natalie Portman in Tiffany & Co. Jewelry
TrendsMar 17, 2026
Natalie Portman Is Tiffany & Co.’s New Ambassador

The Academy Award-winning actress stars in Tiffany & Co.’s latest commercial, which debuted Sunday night during the Oscars.

Jean-Marc Duplaix
MajorsMar 17, 2026
Kering Establishes Jewelry Division, Appoints CEO

The organizational change follows Kering’s promise of a transformation after declining sales in 2025.

Anne Hathaway and Rose Byrne
EditorsMar 16, 2026
2026 Oscars Jewelry: One Necklace After Another

Natalie Francisco rounds up the top Oscars jewels, including Rose Byrne’s Taffin necklace with a more than 20-carat yellow-brown diamond.

Tag Heuer CEO Béatrice Goasglas
WatchesMar 16, 2026
TAG Heuer Has a New CEO

Béatrice Goasglas has been with TAG Heuer since 2018. She is the first woman to head the 166-year-old, LVMH-owned watch brand.

Ben Bridge Jeweler Honolulu boutique
IndependentsMar 16, 2026
Ben Bridge Debuts New Honolulu Boutique

The store features the first in-store build for the jeweler’s in-house “Bella Ponte” bridal brand.

Bonhams fine jewelry Paris
AuctionsMar 16, 2026
Bonhams Paris To Offer Antique, Signed Jewels

The live fine jewelry auction will take place later this week, showcasing antique pieces, rare gemstones, and signed jewels.

Silvia Furmanovich Horse Mane Earrings, Cece Jewellery Underworld Triptych Necklace, Almasika Invictus Flower Brooch
CollectionsMar 13, 2026
A Trio of Jewels from the 3 Gem Award Nominees for Jewelry Design

Our Pieces of the Week honor the 2026 nominees for the Gem Award for Jewelry Design, Silvia Furmanovich, Cece Fein-Hughes, and Catherine Sarr.

Vera Wang
WatchesMar 13, 2026
Citizen, Vera Wang to Launch Watch Collection

The 24-piece watch collection is set to debut in spring 2027.

Andrea Pooler
SourcingMar 13, 2026
Andrea Pooler Joins Third-Generation Diamond Company as COO

Pooler, who has more than 25 years’ experience in jewelry, is now chief operating officer of Modani Jewels, Soham Diamonds, and SNJ Creations.

24 Karat Club banquet
MajorsMar 13, 2026
24 Karat Club of New York’s Banquet to Return to Waldorf Astoria

The reopening of the Waldorf Astoria means a homecoming for the industry group’s annual event, which will take place Saturday.

Zoë Kravitz in Jessica McCormack’s Planetary Necklace
CollectionsMar 12, 2026
Jessica McCormack Sends Gold, Gemstones Into ‘Orbit’

McCormack looked to the 19th century’s “golden age” of astronomy when designing her new celestial-themed collection.

Johnny Nelson Wins David Yurman Gem Award Grant Graphic
Events & AwardsMar 12, 2026
Johnny Nelson Wins David Yurman Gem Awards Grant

Nelson will be honored as the inaugural grant winner at the Gem Awards gala on Friday.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy