Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Watches on a table next to a coffee cup
WatchesApr 10, 2026
These Watches Have Increased in Value the Most Since 2018, Says Chrono24

The top-performing watch models may be surprising, with Rolex and several popular pandemic-era picks notably absent from the top 20.

Ophelia Eve Scroll Toggle Pendant
CollectionsApr 10, 2026
Ophelia Eve’s Toggle Pendant Holds Your Secrets

The “Scroll” toggle pendant, our Piece of the Week, opens to reveal a hidden message, mantra, or love letter written on washi paper.

National Jeweler columnist Sherry Smith, partner at The Retail Smiths
ColumnistsApr 09, 2026
Jewelry Demand Isn’t Stronger, Prices Are Just Higher

Jewelers who misinterpret the state of the jewelry market risk employing the wrong retail strategy, cautions columnist Sherry Smith.

GIA iD100®
Brought to you by
Protect Your Customers and Your Business

You deserve to know what you are selling–to protect your customers as well as your business and your reputation.

Tiffany & Co. Nathalie Verdeille
MajorsApr 09, 2026
Tiffany & Co. Promotes Nathalie Verdeille to SVP, Chief Artistic Officer

In her newly expanded role, she will continue to oversee the jewelry category, as well as watches, home, and accessories.

Weekly QuizApr 09, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Jacob & Co. The Godfather II Musical Watch
WatchesApr 09, 2026
Jacob & Co. Rolls Out Its Sequel to ‘The Godfather’ Musical Watch

“The Godfather II” watch plays two melodies from the mob film’s score, “The Godfather’s Waltz” and “The Godfather Love Theme.”

Jesse Itzler
Events & AwardsApr 09, 2026
JCK Announces Jesse Itzler as 2026 Keynote Speaker

Organizers have also introduced the new JCK Talks Signature Series, as well as an offering of watch-focused workshops and lectures.

TopImageCrop.jpg
Brought to you by
Is This You? Every Jeweler Has This Problem; We Have the Solution.

Every jeweler faces the same challenge: helping customers protect what they love. Here’s the solution designed for today’s jewelry business.

Alan Hodgkinson
SourcingApr 09, 2026
AGA To Honor ‘Quiet Leadership’ With New Award

The Alan Hodgkinson Medal recognizes gemologists who are consistently generous with their time and expertise.

Oris CEO Rolf Studer and Oris CFO Claudine Gertiser
WatchesApr 09, 2026
Oris Names New CEO, CFO

The Swiss watchmaker is changing up its executive leadership team as part of a restructuring.

Hearts On Fire What’s Your Signature Campaign Imagery
CollectionsApr 08, 2026
Hearts On Fire Celebrates 30 Years By Asking a Question

The “What’s Your Signature?” campaign invites women to think about how they see themselves.

41.82-carat Type IIb blue diamond recovered from Cullinan in January 2026
SourcingApr 08, 2026
Sale of 42-Carat Blue Diamond Gives Petra a Boost in Q3

The big diamond’s sale added to the company’s revenue though the market remains “challenging” overall, particularly for smaller goods.

American Gem Society Confluence Logo
Events & AwardsApr 08, 2026
AGS Confluence Returns with AI, Sustainability Sessions

Rob Bates of The Jewelry Wire will also moderate a panel on the state of the jewelry industry during the virtual event.

Dennis Buzz Busby and Randy Welch
Events & AwardsApr 08, 2026
TJS to Honor 2 Longtime Former Stuller Employees

The Jewelry Symposium will honor two industry veterans with lifetime achievement awards at its upcoming May event.

Isabel Delgado A necklace
TrendsApr 08, 2026
Amanda’s Style File: April’s Brilliant Birthstone

With their durability, brilliance, and beauty, diamonds are the perfect stone for everyday birthstone jewelry.

QVC Group logo
MajorsApr 07, 2026
QVC Group’s Latest Filing Calls Its Future Into Question

The retailer failed to file its annual report on time and said it may issue a going concern warning.

Headshot of National Jeweler columnist Peter Smith
ColumnistsApr 07, 2026
Peter Smith: A Tip to the Post Office on Workplace Culture

Smith recounts a recent trip to the post office that included an uncomfortable, embarrassing, and public exchange between two employees.

Retiring GIA CFO David Tearle and new GIA CFO John Cowley
GradingApr 07, 2026
GIA CFO David Tearle to Retire in June

John Cowley, who has more than 30 years of experience, is succeeding Tearle as the lab’s chief financial officer.

Gemology Geek Ignite collection tourmaline ring
CollectionsApr 07, 2026
Nerd Out Over Gemology Geek’s First Jewelry Collection

Founder Erica Silverglide has designed 35 colorful pieces set with fluorescing gemstones for the brand's first finished jewelry offering.

Ukrainian Jewelry | Contemporary Jewelry and Art Jewelry from Ukraine
CollectionsApr 07, 2026
Ukrainian Jewelers Highlighted In New Book

“Ukrainian Jewelry | Contemporary Jewelry and Art Jewelry from Ukraine” features 33 contemporary Ukrainian designers and studios.

Fope Golden Now Campaign Imagery
CollectionsApr 06, 2026
Fope’s New Jewelry Debuts Are Golden

“The Golden Now” campaign celebrates the here and now with the brand’s signature styles and a selection of its new pieces.

Former Signet executive Kecia Caffie
MajorsApr 06, 2026
Kecia Caffie, Corinne Bentzen No Longer With Signet Jewelers

Signet confirmed that Caffie, president of Zales and Banter, and Bentzen, who headed Blue Nile, have left the company.

Author Tanzy Ward and her book Precious Black Jewels The Bijou Material Culture of Black Victorians & Edwardians
CollectionsApr 06, 2026
Historian Tanzy Ward Pens Book on Black Victorians’ Jewelry

The antique jewelry dealer talks about the importance of including Black Americans in jewelry history and preserving their stories.

Gemfields emeralds
SourcingApr 06, 2026
Gemfields Reports $51M Loss in 2025

Both its mines faced challenges last year, from operational issues to disruptions in the market.

Screenshot of Taylor Swift's "Elizabeth Taylor" music video
CollectionsApr 03, 2026
Taylor Swift’s ‘Elizabeth Taylor’ Video Puts Jewelry Front and Center

Iconic pieces, like the Mike Todd Diamond Tiara, appear in the superstar’s new music video for her song inspired by the actress.

Neiman Marcus store in Fort Worth, Texas
MajorsApr 03, 2026
Saks Global Says It Will Emerge From Bankruptcy This Summer

The luxury retailer, which went Chapter 11 in January, announced Thursday that it has secured $500 million in exit financing.

NouvelleBox logo
Events & AwardsApr 03, 2026
JCK Luxury, NouvelleBox Partner on New Designer Ballroom

The NouvelleBox ballroom will feature independent jewelry designers, including Lene Vibe, Wyld Box Jewelry, and Kiaia Limited.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy