One is the driver who allegedly crashed a car into a Sacramento jewelry store in April, striking a 71-year-old employee who later died.
21 digital security tips for retailers
With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers.

New York--The past six months have been rough for the security of private consumer information.
Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.
Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge.
Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.
National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.
1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates
Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.
RELATED CONTENT: Target hires new CIO, announces security updates
These breaches can have numerous negative effects for a retailer.
“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.
The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.
There are a number of steps that jewelers can take to prevent a data breach.
1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date. Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.
If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:
9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.
The Latest

In a new column, Peter Smith posits that people actually enjoy putting together IKEA furniture, and the same is true for engagement rings.

9lakha Jewelers in Iselin, New Jersey, was the target of a smash-and-grab robbery on Aug. 8.

Retailers are seeking new ways to attract customers, increase traffic, and create revenue – Estate buying events are a popular solution.

The jeweler has partnered with Jenner’s 818 Tequila brand to gift lab-grown diamond studs to a bride-to-be and their bridal party.


The exhibition will feature more than 100 drawings of stained-glass lampshades, windows, and more, many created by women and émigrés.

Marquise-cut diamonds in drop charms are the center of the new collection, reflecting the movement of a dancer in modular styles.

Colored gemstones, artisan finishes, mixed metals, and meaningful details are shaping demand in bridal jewelry.

The inaugural Fort Lauderdale Jewelry, Antique, & Object Show will be held from Jan. 28 through Feb. 1, 2027.

The family-owned jeweler will open a new showroom in Bel Air, Maryland, this fall.

Amanda Ileana Hernandez is married to Carlos Hernandez, one of two men in prison for the 2024 murder of Michigan jeweler Hussein Murray.

The reimagined jewel, our Piece of the Week, trades the diamonds in the original 1998 design for blue, pink, yellow, and green sapphires.

Sponsored by American Gem Trade Association

In the United States, second-quarter sales were flat amid soft consumer sentiment and lower in-store traffic.

The 22-karat gold egg, sold at Batemans Auctioneers in the U.K., was part of a 1980s treasure hunt ad campaign for Cadbury Creme Eggs.

Lucara Diamond Corp., which recovered the “Motswedi” diamond from the Karowe mine, sold the stone for an undisclosed amount.

The expanded collections now feature hand-cut gemstones like topaz, tanzanite, chrysoprase, chalcedony, smoky quartz, and fire opal.

The lab-grown diamond jewelry brand’s newest boutique is in Westfield Valley Fair in Santa Clara, California.

The gemstone supplier and manufacturer acquired the remarkable 104-gram Zambian emerald at Gemfields’ auction in May.

Two suspects offered to trade the woman a “winning” lottery ticket for her jewelry.

Finsch has been in business rescue since May, and owner Petra Diamonds said it sees no viable path forward for the mine.

Michel Patrick DeSalles was sentenced after pleading guilty to the 2017 murder of Omid Gholian, who owned a jewelry store in Manhattan.

Longtime industry executive Beth Miller has taken on the role.

The brooch was owned by Virginia Fortune Ryan Ogilvy, who served as a lady of the bedchamber to Queen Elizabeth II for nearly 50 years.

Jamie Cygielman will take on the role on Aug. 24.

Moore, Polly’s husband, is remembered as a family man with an easygoing spirit and a love for sports and the outdoors.

Duvall O’Steen and Jen Cullen Williams share the best ways to display, present, and explain colored gemstones to younger customers.






















