Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

International Gemological Institute logo
GradingFeb 02, 2026
IGI to Acquire American Gemological Laboratories

IGI is buying the colored gemstone grading laboratory through IGI USA, and AGL will continue to operate as its own brand.

Ylang 23 store burglary
CrimeFeb 02, 2026
Ylang 23’s Dallas Store Burglarized

The Texas jeweler said its team is “incredibly resilient” and thanked its community for showing support.

Tyla at 68th annual Grammy Awards
EditorsFeb 02, 2026
Stars Choose Chokers, Elongated Earrings at 2026 Grammys

From cool-toned metal to ring stacks, Associate Editor Natalie Francisco highlights the jewelry trends she spotted at the Grammy Awards.

MJSA Apprenticeship Guide
Brought to you by
The MJSA Mentor & Apprenticeship Program: Attracting & Training the Next Generation of Bench Jewelers

Launched in 2023, the program will help the passing of knowledge between generations and alleviate the shortage of bench jewelers.

Silver, Gold, and Bronze Medals for 2026 Winter Olympics
CollectionsFeb 02, 2026
2026 Winter Olympic Medal Design Symbolizes Unity

The medals feature a split-texture design highlighting the fact that the 2026 Olympics are taking place in two different cities.

Weekly QuizJan 29, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Dawn dish soap, Dove soap, M&M candy, Tylenol
SurveysJan 30, 2026
These Are the Top Brands of 2026, Says YouGov

From tech platforms to candy companies, here’s how some of the highest-ranking brands earned their spot on the list.

Etiq Khol Ring
CollectionsJan 30, 2026
Follow the Beat With Etiq’s ‘Khol’ Ring

The “Khol” ring, our Piece of the Week, transforms the traditional Indian Khol drum into playful jewelry through hand-carved lapis.

JamAlert 1872x1052.png
Brought to you by
How Jewelers Can Fight Back Against Cell Jammers

Criminals are using cell jammers to disable alarms, but new technology like JamAlert™ can stop them.

Arch Crown Tag & Label 2026 Catalog
MajorsJan 30, 2026
Arch Crown’s 2026 ‘Tag & Label’ Catalog Is Here

The catalog includes more than 100 styles of stock, pre-printed, and custom tags and labels, as well as bar code technology products.

Ghirardelli Chocolocket
CollectionsJan 29, 2026
Ghirardelli’s ‘Chocolocket’ Returns for Valentine’s Day

The chocolatier is bringing back its chocolate-inspired locket, offering sets of two to celebrate “perfect pairs.”

Step-cut Colombian emerald ring London Jewels Bonhams
AuctionsJan 29, 2026
These Were Bonhams’ Top 10 Jewelry Lots in 2025

The top lot of the year was a 1930s Cartier tiara owned by Nancy, Viscountess Astor, which sold for $1.2 million in London last summer.

Red Rubies AGTA
SourcingJan 29, 2026
Stuller Website to Mark AGTA-Sourced Gemstones

Any gemstones on Stuller.com that were sourced by an AGTA vendor member will now bear the association’s logo.

Audemars Piguet Atlanta Store Artwork
WatchesJan 29, 2026
Audemars Piguet Opens AP House in Atlanta

The Swiss watchmaker has brought its latest immersive boutique to Atlanta, a city it described as “an epicenter of music and storytelling.”

Anza Gems gemstones
SourcingJan 28, 2026
Ethical Gem Fair to Debut Designer Showcase in Tucson

The new addition will feature finished jewelry created using “consciously sourced” gemstones.

National Jeweler columnist and jewelry sales expert Peter Smith
ColumnistsJan 28, 2026
Peter Smith: Setting the Next Generation Up for Success

In his new column, Smith advises playing to your successor's strengths and resisting the urge to become a backseat driver.

Hand holding shopping bags
SurveysJan 28, 2026
Consumer Confidence Falls Below Pandemic Lows in January

The index fell to its lowest level since May 2014 amid concerns about the present and the future.

Foundrae Aspen Store
IndependentsJan 28, 2026
Foundrae Heads to Aspen for Latest Store Opening

The new store in Aspen, Colorado, takes inspiration from a stately library for its intimate yet elevated interior design.

Bulgari Gioco di Forme e Colori watch and brooch
FinancialsJan 28, 2026
Tiffany & Co., Bulgari Sales Resilient as LVMH’s 2025 Sales Slip

The brands’ high jewelry collections performed especially well last year despite a challenging environment.

GemFair x DBL Toi et Moi Ring
CollectionsJan 27, 2026
De Beers London, GemFair Debut New Collection Highlighting Artisanal Diamonds

The collection marks the first time GemFair’s artisanal diamonds will be brought directly to consumers.

Montana sapphire
SourcingJan 27, 2026
GemGuide Launches Pricing for Montana Sapphires

The initial charts are for blue, teal, and green material, each grouped into three charts categorized as good, fine, and extra fine.

Columbia Gem House celestial shapes
SourcingJan 26, 2026
Tucson Preview 2026: Earthy Tones and Innovative Shapes

Buyers are expected to gravitate toward gemstones that have a little something special, just like last year.

Diamond center in Saurimo, Angola
SourcingJan 26, 2026
Angolan Diamond Cos. Join NDC as Rio Tinto, Murowa Exit

Endiama and Sodiam will contribute money to the marketing of natural diamonds as new members of the Natural Diamond Council.

Francesca’s boutique
MajorsJan 26, 2026
Francesca’s To Close All Stores

The retailer operates more than 450 boutiques across 45 states, according to its website.

Thomas Davis, Monalisa DePina, Jamie Batiste, Namwezi Nicole Batumike, Lavina Hunt-Lewis
MajorsJan 26, 2026
BIJC Names 5 New Board Members

The new members’ skills span communications, business development, advocacy, and industry leadership.

Tiffany & Co. Celebrating Love Stories Since 1837 Campaign
CollectionsJan 26, 2026
Tiffany & Co. Celebrates 189 Years of Love Stories

The jeweler’s 2026 Valentine’s Day campaign, “Celebrating Love Stories Since 1837,” includes a short firm starring actress Adria Arjona.

DCA colored gemstone course
GradingJan 26, 2026
DCA Updates Colored Gemstone Course

The new features include interactive flashcards and scenario-based roleplay with AI tools.

Deutsch & Deutsch jewelers team
MajorsJan 23, 2026
Watches of Switzerland Acquires 4-Store Jewelry Chain in Texas

Family-owned jewelry and watch retailer Deutsch & Deutsch has stores in El Paso, Laredo, McAllen, and Victoria.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy