Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

Gretchen Koback Pursel
MajorsSep 08, 2026
Former Tiffany & Co. Exec Joins Exemplar Luxury Group

Gretchen Koback Pursel is the new chief people officer at the company formerly known as Saks Global.

Frederick (Ricky) Wilkinson Bromberg
IndependentsSep 08, 2026
Ricky Bromberg, Longtime President of Bromberg & Co., Dies at 67

Bromberg is remembered as a Southern gentleman who always wore a suit and tie and treated others with kindness.

Zahn Z Zaha rainbow sapphire ring
TrendsSep 08, 2026
Amanda’s Style File: A Hot Take on September’s Birthstone

With high durability and a wide range of colors to choose from, sapphires may be the ultimate birthstone, Gizzi claims.

Cover.jpg
Brought to you by
Your Piece Could Be the One Editors Talk About

Submit your pieces for a chance to win in this year's competition.

The Retail Smiths principal and National Jeweler columnist Peter Smith
ColumnistsSep 08, 2026
Peter Smith: Humor Is No Laughing Matter

Laughter is often considered a distraction in the workplace, but it has benefits for both staff and management, Peter Smith writes.

Weekly QuizSep 03, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Rendering of renovated Orloff Jewelers store
IndependentsSep 04, 2026
Orloff Jewelers Will Soon Unveil a Bigger, Better Location

The California jeweler is renovating its store in Fresno, with plans to show off the new space in December.

Chelsea Gabrielle Momentum Infinite Ring
CollectionsSep 04, 2026
Chelsea Gabrielle Transforms Pilates Reformer Springs Into Ring

A lifelong practitioner of Pilates, Gabrielle looked to the springs’ tension and suspension when creating this ring, our Piece of the Week.

1872-x-1052-July-ad (1).png
Brought to you by
Why More Jewelry Retailers Are Hosting Turnkey Estate Buying Events

Retailers are seeking new ways to attract customers, increase traffic, and create revenue – Estate buying events are a popular solution.

JCK Industry Fund logo
Events & AwardsSep 04, 2026
JCK Industry Fund Accepting 2027 Applications

The deadline to apply is Nov. 13.

Remi Guillemin
AuctionsSep 04, 2026
Christie's Names New Global Head of Watches

The auction house has promoted Remi Guillemin, formerly its head of watches for the Americas and EMEA, to the role.

Simon G CEO Zaven Ghanimian
EditorsSep 03, 2026
Q&A: Simon G.’s CEO on Why He Won’t Use AI for Jewelry Design

Zaven Ghanimian discussed the value of human craftsmanship and where the implementation of artificial intelligence does work.

Jewelers of America logo
Events & AwardsSep 03, 2026
Here Are the First Recipients of Nina Pugliese Memorial Scholarship

Jewelers of America also revealed the recipients of the Seymour & Evelyn Holtzman Bench Scholarship and its own scholarship programs.

Robert Pattinson Jaeger-LeCoultre
WatchesSep 03, 2026
Robert Pattinson Joins Jaeger-LeCoultre as Brand Ambassador

The British actor, known for his roles in “Twilight” and “The Odyssey,” will star in a campaign for the Master Control Chronometre.

Sydney Evan Little Love Open Coin Fixed Necklace
CollectionsSep 03, 2026
Sydney Evan Celebrates 25 Years With 4 New Collections

The “Confetti Disco,” “Champagne Cheers,” “Tuxedo,” and “Classic Punk” jewelry collections each capture a distinct spirit of celebration.

Stock image of a gavel
CrimeSep 02, 2026
CA Jeweler Gets 5 Years in ‘Phantom Rolex’ Ponzi Scheme

Nelson Holdo of Newport Beach pleaded guilty to multiple counts of felony grand theft and writing bad checks and was sentenced Monday.

Sandy Lerner’s 18-karat gold and diamond cat brooch
AuctionsSep 02, 2026
If You Love Cats, This Jewelry Auction Is for You

Cat ladies of the jewelry world, unite. Sandy Lerner’s “significant” collection of cat jewelry and other objects is going up for auction.

Arnaud Michon
MajorsSep 02, 2026
Messika Names Former Omega Exec as New President, CEO of Americas

Arnaud Michon, the former Omega USA President, will now lead Messika’s Americas region during its international development.

Glitter in the Grove Logo
Events & AwardsSep 02, 2026
Emerald’s New Owner Introduces ‘Glitter in the Grove’

The branding references the back-to-back jewelry shows that new parent company Forge will host in Miami's Coconut Grove this November.

Stainless steel Patek Philippe Calatrava watch
AuctionsSep 01, 2026
UK Woman Uncovers Rare Patek Philippe Watch in Mom’s Jewelry Box

The stainless steel Patek Philippe “Calatrava” watch from the 1930s sold for nearly $80,000 at a recent Hansons Cornwall auction.

Smart Age Solutions founder and CEO Emmanuel Raheb
ColumnistsSep 01, 2026
Your Jewelry Marketing Has a Bridal Problem

Engagement rings are important but don’t ignore the customers who are buying jewelry “just because,” Emmanuel Raheb writes.

Charlotte Fournet and Krizia Cucurachi
MajorsSep 01, 2026
Kering Names New Pomellato, DoDo CEOs

Former Pomellato CEO Sabina Belli has been named president of Kering Italia amid a shakeup of Kering's new Jewelry division.

Anne Marie Shulman
MajorsSep 01, 2026
Anne Marie Shulman Joins GPA Global

The veteran luxury packaging executive was appointed to help the company grow its North American business.

Photo of one of the suspects in theft of Queen Nazli’s necklace from MAK museum
CrimeAug 31, 2026
$4M Van Cleef & Arpels Diamond Necklace Snatched From Vienna Museum

Once the property of an Egyptian queen, the necklace was part of a larger exhibition of VCA jewelry at the Museum of Applied Arts (MAK).

Ethiopian paraiba tourmaline
GradingAug 31, 2026
GIA, Gübelin Gem Lab Confirm New Paraíba Tourmaline Deposit in Ethiopia

The labs’ separate investigations each determined that the East African country is producing copper-bearing tourmaline.

Levinger & Bissenger silver floral pendant
Events & AwardsAug 31, 2026
Wisconsin Museum to Host Jewelry Exhibition

“Chicago Collects: Jewelry in Perspective” at the Oshkosh Public Museum will feature works by Fabergé, Lalique, and Louis Comfort Tiffany.

Catbird First Men’s Collection Worn Well
CollectionsAug 31, 2026
Catbird Launches First Men’s Jewelry Collection

The “Worn Well” collection is Catbird's take on classic men's jewelry.

Buddha Mama Butterfly Necklace
CollectionsAug 28, 2026
Dolly Parton Would Have Loved This Butterfly Necklace

This Buddha Mama butterfly is our Piece of the Week honoring the legend, who embraced the beautiful insect as her symbol.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy