Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

The Retail Smiths partner and National Jeweler columnist Peter Smith 
ColumnistsJul 28, 2026
Peter Smith: Why Your Job Postings May Be Working Against You

Smith reveals the method The Retail Smiths use to help retailers and vendors write better job postings.

Tiffany & Co butterfly necklace
FinancialsJul 28, 2026
Tiffany & Co., Bulgari Lead the Way for LVMH in H1

LVMH’s jewelry and watch brands outperformed the company’s other divisions in an environment the company described as “disrupted.”

Lionheart Sacred Heart Charm Necklace
CollectionsJul 28, 2026
Lionheart’s New Collection Unites Spiritual Iconography

“Sacred Heart” features symbols like crosses, angel wings, the Star of David, and the evil eye as a representation of coexistence.

1872-x-1052-July-ad (1).png
Brought to you by
Why More Jewelry Retailers Are Hosting Turnkey Estate Buying Events

Retailers are seeking new ways to attract customers, increase traffic, and create revenue – Estate buying events are a popular solution.

Events & AwardsJul 28, 2026
The Edge Funding 2 Scholarships Via 24 Karat Club SEUS

The scholarships will go to early-career professionals looking to study gemology, bench work and jewelry design, or store operations.

Weekly QuizJul 23, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Mikimoto L'éclat high jewelry brooch
SurveysJul 27, 2026
Jewelry Leads Luxury Market Amid Stabilization, Bain Says

Bain & Company delved into the trends shaping the luxury market, the impact of AI, and more in its recent study.

Harvard Rubies Exhibit The Soul of Flame II Brooch by Austy Lee
SourcingJul 27, 2026
‘Rubies’ Goes on Display at Harvard Museum

The exhibition reveals the gemology, geology, and cultural history of the iconic red gemstone.

Brought-To-By-Article-Top-Image.jpg
Brought to you by
Wedding Band Trends 2026: Personalization Takes Center Stage

Colored gemstones, artisan finishes, mixed metals, and meaningful details are shaping demand in bridal jewelry.

Stock image of shipping containers in port
Policies & IssuesJul 24, 2026
New Trump Tariffs: What They Mean for Jewelry

The new sweeping slate of tariffs impacts 60 countries, including India, China, Thailand, Hong Kong, and the United Arab Emirates.

Jorge Adeler Gods & Heroes coin pendant
TrendsJul 24, 2026
Amanda’s Style File: Ode to ‘The Odyssey’

From coin pendants to diamond shields, these old world-inspired jewels are the perfect accessory for an epic journey.

Courtney Leidy Amethyst Silk Cord Pendant
TrendsJul 24, 2026
Courtney Leidy’s Silk Cord Pendants Center Unexpected Pairings

Our Piece of the Week pairs a checkerboard-cut amethyst with an ivy green silk cord.

NJ Article image.png
PodcastsJul 23, 2026
Episode 7: Reinhold Jewelers on the Power of Relationships

Mildred Marcano Abrams and Yael Reinhold join the podcast to talk community connections, holiday plans, and preserving Reinhold’s legacy.

Trucks at De Beers’ Orapa mine in Botswana
SourcingJul 23, 2026
De Beers’ Production Jumps 88 Percent in Q2

Production also was up in the first half of 2026 but is expected to “substantially” decrease in H2 as two key mines undergo maintenance.

Silvia Furmanovich Enchapado en Tamo Wooden Wheat Straw Sun Earrings
CollectionsJul 23, 2026
Silvia Furmanovich’s New Collection Travels Back to the 1920s

“Art Deco” fuses ancestral techniques, rare materials, and modern perspectives as a tribute to the optimism and curiosity of the movement.

Sissy’s Log Cabin Saracen Casino
IndependentsJul 23, 2026
Sissy's Log Cabin Opens Casino Store

The jeweler’s newest store is inside Arkansas’ Saracen Casino Resort.

Kate Spade New York watches
WatchesJul 23, 2026
Movado Inks Licensing Deal With Kate Spade New York

The watch company will design, manufacture, and distribute Kate Spade New York watches.

Stock photo of loose polished diamonds
Policies & IssuesJul 22, 2026
Trump to Put 50% Tariff on Canadian Goods

The higher tax is set to go into effect in August and will apply to loose polished diamonds as well as precious and base metals jewelry.

Monica Rich Kosann Enchanted Garden Cherry Necklace
CollectionsJul 22, 2026
Monica Rich Kosann’s High Jewelry Is Fruitful

The “Enchanted Garden” series features a cherry, lemon, and pear that each hold a little secret inside.

Liljenquist new Rolex boutique McLean Virginia
IndependentsJul 22, 2026
Liljenquist Beckstead Opens Rolex New Boutique

It’s located in Tysons Galleria, an upscale shopping center in the Washington, D.C., metro area.

NY Now exhibitor booth
Events & AwardsJul 22, 2026
NY Now Returns in August Under New Ownership

The show, recently acquired by Rockview Management Group, will be held at New York City’s Javits Center from Aug. 2-4.

The Retail Smith Principal Partner and National Jeweler columnist Sherry Smith
ColumnistsJul 21, 2026
Sherry Smith: Shattering the Illusion of the ‘Either/Or’ Diamond Market

Smith offers retailers guidance on creating an environment where natural and lab-grown diamonds can both thrive.

Emerald logo
Events & AwardsJul 21, 2026
Apollo Funds Completes Emerald Acquisition

Former Emerald President and CEO Hervé Sedky has transitioned to the role of senior advisor.

Graff Seraphina Brooch and Lina Pendant
CollectionsJul 21, 2026
Graff’s New Butterfly High Jewelry Brooches Metamorphosize

The 12-piece capsule collection transforms from brooches to pendants.

Rough diamonds from De Beers’ Gahcho Kue mine in Canada
SourcingJul 21, 2026
Anglo Reportedly Selects Gareth Penny’s Consortium as Top Bidder for De Beers

A Botswana government official told lawmakers Anglo has selected The Global Diamond Consortium, an entity chaired by Penny, to buy De Beers.

Stock image of shipping containers
Policies & IssuesJul 20, 2026
Tariffs on Brazil to Increase But Rough Gemstones Exempt

The new tariff, imposed after a Trump administration study, is 25 percent and will stack on top of existing tariffs.

Vhernier Freccia High Jewelry Necklace
CollectionsJul 20, 2026
Vhernier Transforms ‘Freccia’ Collection Into High Jewelry

The collection from 2014 has been reinterpreted into high jewelry with its signature triangular-shaped elements.

Krista Collins Walters
MajorsJul 20, 2026
Krista Collins Walters Promoted to Publisher of Instore

She will also take on the role of vice president of jewelry for SmartWork Media, a newly created position.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy