Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

2025 National Jeweler Retailer Hall of Fame inductees
Events & AwardsJun 06, 2025
Here Are the 2025 Retailer Hall of Fame Inductees

This year’s honorees include a Midwest retailer and two multi-store independents, one in New York and the other in New England.

Harwell Godfrey Granny Square Eleanor Necklace
CollectionsJun 06, 2025
Piece of the Week: Harwell Godfrey’s ‘Granny Squares Eleanor’ Necklace

As an homage to iconic crochet blankets, the necklace features the nostalgic motif through a kaleidoscope of cabochon-cut stones.

 Laura Gallon Joaillerie “Dynasty” ring, Bijules “Compass” bolo tie, Löf “The Orbitalis” ring
Events & AwardsJun 05, 2025
The 12 Fresh Faces in Couture’s Design Atelier

Discover the dozen up-and-coming brands exhibiting in the Design Atelier for the first time.

DCA-student-cert-NJ1872x1052-2.png
Brought to you by
The True Power Behind the Counter: Why Sales Associates Are the Heart of the Jewelry Business

When investing in your jewelry business, it's important not to overlook the most crucial element of success: the sales associates.

Jack Abraham The Royal Ruby Collection
SourcingJun 05, 2025
A Rare Suite of Rubies Has Arrived in Las Vegas

The “Royal Ruby” Collection is a quintet of untreated rubies curated by collector Jack Abraham.

Weekly QuizJun 05, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Daymond John
Events & AwardsJun 05, 2025
Daymond John to Give Keynote at JCK Las Vegas

The entrepreneur and “Shark Tank” star will share his top tips for success.

Vaishali Banerjee and Pallavi Sharma
MajorsJun 05, 2025
Platinum Guild International Updates Leadership Team

Two existing executives have been given new roles.

Article Image 1.png
Brought to you by
Clienteling Isn’t a Buzzword. It’s an Essential Business Model.

More shoppers are walking out without buying. Here’s how smart jewelers can bring them back—and the tool they need to do it right.

Meredith Tiderington
Events & AwardsJun 05, 2025
Zillion Announces 'Women in STEM' Scholarship Recipient

Meredith Tiderington, an electrical engineering student, was selected for the award.

The Gemological Institute of America’s logo
Lab-GrownJun 04, 2025
GIA Reverting to More General Terminology for Lab-Grown Diamonds

It will quit assigning the stones specific color and clarity grades in favor of applying “new descriptive terminology.”

Exterior of the Venetian and the Las Vegas Sphere
Events & AwardsJun 04, 2025
As JCK Talks Returns, Don’t Miss These 12 Sessions

From design trends to sustainability, here’s a roundup of can’t-miss education sessions at JCK Las Vegas.

JCK show
CrimeJun 04, 2025
10 Safety Tips for the Las Vegas Shows

The Jewelers’ Security Alliance offers advice for those attending the annual trade shows.

Amy Curran
MajorsJun 04, 2025
Amy Curran Promoted at Hill & Co.

Her new role is director of strategic initiatives.

The eight rings in Viviana Langhoff’s AU79 jewelry collection
CollectionsJun 03, 2025
In Her Latest Collection, Viviana Langhoff Is Leaning Into Gold

The designer is embracing bold pieces with weight to them in “AU79,” a collection she celebrated with a creative launch party.

Gold and diamond bangles on a pair of jeans
FinancialsJun 03, 2025
Signet Jewelers Sees Turnaround in Q1 With Sales Ticking Up 2%

On an earnings call, CEO J.K. Symancyk discussed what’s working for the company and how it’s preparing for the potential impact of tariffs.

Woman’s hand holding shopping bags
SurveysJun 03, 2025
Consumer Confidence Improves in May

The index partially rebounded after months of decline, due in part to the U.S.-China deal to temporarily reduce import tariffs.

Dakota Johnson as Roberto Coin Brand Ambassador
CollectionsJun 03, 2025
Dakota Johnson Is Roberto Coin’s New Brand Ambassador

The actress stars in the latest campaign set in Venice, Italy, and is set to participate in other creative initiatives for the jeweler.

Mason Kay Jade necklace
GradingJun 03, 2025
Mason-Kay Jade Adds ‘Fei Cui’ to Jade Reports

The company has joined other labs, including GIA and Lotus Gemology, in adopting the Chinese term for "jadeite jade."

Gemfields ruby
SourcingJun 02, 2025
Gemfields’ June Auction to Include 36-Carat Ruby

The large stone will be offered at its June sale along with a selection of secondary-type rubies from a new area of the Montepuez mine.

Adobe Stock image of skyline of Bangkok, Thailand
GradingJun 02, 2025
GSI Opens New Lab in Thailand

Located in Bangkok, the laboratory is Gemological Science International’s 14th location worldwide.

Seaman Schepps pearl earrings
TrendsJun 02, 2025
Amanda’s Style File: Three Gems for June

Those born in June have a myriad of options for their birthstone jewelry.

David Allouche
SourcingJun 02, 2025
David Allouche Joins Grandview Klein Diamonds

The diamond industry veteran has been named its senior sales executive.

Movado Connect 2.0 watches
FinancialsMay 30, 2025
Movado’s Q1 Sales Slip Amid ‘Challenging’ Retail Environment

The company plans to raise the prices of select watches to offset the impact of tariffs.

Zoë Chicco Bracelets
Policies & IssuesMay 30, 2025
Tariffs & Designers: Navigating Pricing in an Unstable Environment

Between tariffs and the sky-high cost of gold, designers enter this year’s Las Vegas shows with a lot of questions and few answers.

Renato Cipullo Hematite Blaze Necklace
CollectionsMay 30, 2025
Piece of the Week: Renato Cipullo’s ‘Hematite Blaze’ Necklace

Designed by founder Renato and his daughter Serena Cipullo, it showcases a flame motif representing unity and the power of gathering.

Stock image of shipping containers
Policies & IssuesMay 30, 2025
Trade Court Declares Trump’s Tariffs Invalid

However, the tariffs remain in effect in the short term, as an appeals court has stayed the U.S. Court of International Trade’s decision.

Britney Spears
CollectionsMay 29, 2025
Britney Spears Files Trademark for New Jewelry Line

The pop icon is one step closer to launching her “B Tiny” jewelry collection, a collection she first began posting about last fall.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy