Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Father-son jewelers Faustino Alamo Dominguez and Luis Angel Alamo
CrimeNov 12, 2025
Father, Son Jewelers in Chicago Victims in Double Homicide

JSA and Cook County Crime Stoppers are both offering rewards for information leading to the arrest of the suspect or suspects involved.

Mellon Blue Diamond Christies
AuctionsNov 12, 2025
‘Mellon Blue’ Diamond Sells for $7M Less Than It Did a Decade Ago

A buyer paid $25.6 million for the diamond at Christie’s on Tuesday. In 2014, Sotheby’s sold the same stone for $32.6 million.

Mercedes Gleitze Companion Oyster
WatchesNov 12, 2025
Historic Rolex Oyster Fetches $1.7M at Sotheby’s

Mercedes Gleitze famously wore the watch in her 1927 swim across the English Channel, a pivotal credibility moment for the watchmaker.

roseco-catalog.png
Brought to you by
Roseco Releases New Full-Line Catalog

Roseco’s 704-page catalog showcases new lab-grown diamonds, findings, tools & more—available in print or interactive digital editions.

Gemological Institute of America logo
GradingNov 12, 2025
It’s Time: GIA’s Express Holiday Service Is Back

GIA is offering next-day services for natural, colorless diamonds submitted to its labs in New York and Carlsbad.

Weekly QuizNov 06, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Tiffany & Co. Love Is a Gift Campaign and David Yurman The Joy of Extraordinary Memories campaign
MajorsNov 10, 2025
Jewelers Focus on Love, Joy In 2025 Holiday Campaigns

Tiffany & Co., David Yurman, and Pandora have launched holiday campaigns depicting their jewelry as symbols of affection and happiness.

Hand holding holiday shopping bags
SurveysNov 10, 2025
5 Things Retailers Should Know About Holiday Shoppers This Year

The National Retail Federation is bullish on the holidays, forecasting retail sales to exceed $1 trillion this year.

20-Under-40-2025-LV.png
Brought to you by
Jewelers of America Aligns New Mission to Create Meaningful Impact for Members

From educational programs, advocacy, and recent MJSA affiliation, Jewelers of America drives progress that elevates businesses of all sizes.

The Rainbow Collection Christies
AuctionsNov 10, 2025
300+ Colored Diamonds Up for Auction at Christie’s

Late collector Eddy Elzas assembled “The Rainbow Collection,” which is offered as a single lot and estimated to fetch up to $3 million.

 Sapphire tennis necklace
EditorsNov 07, 2025
Piece of the Week: An MVP’s Sapphire Tennis Necklace

At the 2025 World Series, the Los Angeles Dodgers’ Yoshinobu Yamamoto sported a custom necklace made by California retailer Happy Jewelers.

Foundrae Palm Beach Location Exterior and Founder Beth Hutchens
IndependentsNov 07, 2025
Foundrae’s New Palm Beach Location Is a ‘Golden Solarium’

The brand’s seventh location combines Foundrae’s symbolic vocabulary with motifs from Florida’s natural surroundings.

Watches of Switzerland Mall of America store
FinancialsNov 07, 2025
Watches of Switzerland’s H1 Sales Up 8%

The retailer also shared an update on the impact of tariffs on watch customers.

AGTA Spectrum winners
SourcingNov 06, 2025
Pink Tourmaline Bracelet, Emerald Suite Take Top Spectrum Honors

Pink and purple stones were popular in the AGTA’s design competition this year, as were cameos and ocean themes.

G. St x Jewel Boxing Raffle for City Harvest Graphic
IndependentsNov 06, 2025
Greenwich St. Jewelers Hosts Raffle Supporting Food Rescue

All proceeds from the G. St x Jewel Boxing raffle will go to City Harvest, which works to end hunger in New York City.

Courtney Cornell
IndependentsNov 06, 2025
Cornell’s Jewelers Names New President

Courtney Cornell is part of the third generation to lead the Rochester, New York-based jeweler.

Trucks at Orapa diamond mine
SourcingNov 06, 2025
De Beers’ Production, Sales Increase in Q3

De Beers also announced more changes in its upper ranks ahead of parent company Anglo American’s pending sale of the company.

Ulrich Wohn
WatchesNov 05, 2025
Shinola President Steps Down Just as He Starts

Former Signet CEO Mark Light will remain president of Shinola until a replacement for Ulrich Wohn is found.

Artifex White Diamond, Fancy Dark Yellowish Brown Diamond, and Blue Sapphire Rings
AuctionsNov 05, 2025
Taylor Swift’s Engagement Ring Designer Makes Her Auction Debut

Kindred Lubeck of Artifex has three rings she designed with Anup Jogani in Sotheby’s upcoming Gem Drop sale.

Tyla Pandora Talisman collection
FinancialsNov 05, 2025
Pandora Posts Modest Q3 Sales Growth Amid ‘Weak’ Consumer Sentiment

The company focused on marketing in the third quarter and introduced two new charm collections, “Pandora Talisman” and “Pandora Minis.”

Brilliant Earth Jane Goodall Peace Medallion
FinancialsNov 05, 2025
Brilliant Earth’s Q3 Sales Climb 10%

The jewelry retailer raised its full-year guidance, with CFO Jeff Kuo describing the company as “very well positioned” for the holidays.

US Supreme Court
Policies & IssuesNov 04, 2025
Supreme Court to Hear Tariffs Case Wednesday

Ahead of the hearing, two industry organizations co-signed an amicus brief urging the court to declare Trump’s tariffs unlawful.

Stuller Inc.’s Danny Clark, Matt Stuller, and Belit Myers
MajorsNov 04, 2025
Danny Clark to Become Stuller CEO, Succeeding Matt Stuller

Stuller COO Belit Myers will take on the additional role of president, with all changes effective at the start of 2026.

Headshot of National Jeweler columnist Peter Smith
ColumnistsNov 04, 2025
Peter Smith: What Do Birds Have to Do With the Price of Gold?

Smith cautions retailers against expending too much energy on things they can’t control, like the rising price of gold.

Mellerio Jardin Pierreries Necklace
TrendsNov 04, 2025
Amanda’s Style File: Fall Colors for November Birthdays

Citrine and topaz are birthstones fit for fall as the leaves change color and the holiday season approaches.

Weston Jewelers Fort Lauderdale store rendering
IndependentsNov 04, 2025
Weston Jewelers Heads to Fort Lauderdale

The family-owned jeweler will open its fourth store in Florida in late 2027.

Two of the three suspects in burglary at Queens jeweler’s home
CrimeNov 03, 2025
Men Dressed as Construction Workers Burglarize Jeweler’s Home

The NYPD is looking for three men who stole a safe and jewelry valued at $3.2 million from the home of a jeweler in Jamaica Hills, Queens.

Matthew Rosenheim
MajorsNov 03, 2025
Matthew Rosenheim Takes Over as JA Board Chair

The trade organization also announced its executive committee and five new directors.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy