The Latine-owned New York jeweler is marking two milestones this year: its 50th anniversary and the 25th anniversary of the 9/11 attacks.
Live from Conclave: Understanding Cybersecurity Risks
Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?
But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked.
“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.”
Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.
She started with social engineering and phishing.
Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.
Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).
While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly.
The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.
The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back.
Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.
But that doesn’t always happen.
When a business owner or employee falls for a phish, Myers said options are somewhat limited.
She said what business owners should not do is pay, as there is no guarantee they will get their data back.
Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?
While not heavily attended, the Conclave session did generate multiple questions from attendees.
One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.
Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.
Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.
2. Keep an inventory of risks and threats, and use multiple layers of security.
3. Keep systems and devices patched.
All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”
4. Back up systems and, Myers added, test the back-up.
Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.
5. Establish separation in key systems.
Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.
Also, when someone leaves the company, take away their access to the company’s systems.
6. Train employees on cyber risks at least annually, if not quarterly.
In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.
The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.
The Latest

The stores that have a great December are the ones that made good decisions in August, September, and October, Sherry Smith writes.

The jewelry retail broadcast network has sponsored a new space for Make-A-Wish East Tennessee on its campus in Knoxville.

Submit your pieces for a chance to win in this year's competition.

Keith Rolfe, CFO and COO of Lagos, is now at the jewelry brand’s helm while Steven takes on the role of executive chairman.


Alberto Perez-Elias is one of four men charged in the armed robbery of a Cape Coral, Florida, jewelry store and remains at large.

The “Kat Florence Luminas” will be offered together as one lot and could fetch up to $637,000.

Retailers are seeking new ways to attract customers, increase traffic, and create revenue – Estate buying events are a popular solution.

Four directors were elected to the AGTA board and will serve three-year terms beginning in February.

Ken Citron joins the celebrity memorabilia-focused auction house ahead of its first week-long series of events in Abu Dhabi.

The jewelry retailer said it sees opportunity at higher price points, particularly in natural diamonds for bridal and fashion.

The Los Angeles-based, family-owned jeweler was founded by Lenny and Sunny Friedman in 1946.

The auction, held in Bangkok, was 96 percent sold by lot, with nearly 411,000 carats of Mozambiquan rubies sold.

Fine Jewelry 2027-2028 has more than 900 new styles, including silver, gold-filled, gold-plated sterling silver, and vermeil jewelry.

Learn more about the new terms for lab-grown diamonds and composite gemstones, and the major changes in store for precious metals jewelry.

Bromberg is remembered as a Southern gentleman who always wore a suit and tie and treated others with kindness.

With high durability and a wide range of colors to choose from, sapphires may be the ultimate birthstone, Gizzi claims.

Laughter is often considered a distraction in the workplace, but it has benefits for both staff and management, Peter Smith writes.

Gretchen Koback Pursel is the new chief people officer at the company formerly known as Saks Global.

The California jeweler is renovating its store in Fresno, with plans to show off the new space in December.

A lifelong practitioner of Pilates, Gabrielle looked to the springs’ tension and suspension when creating this ring, our Piece of the Week.

The auction house has promoted Remi Guillemin, formerly its head of watches for the Americas and EMEA, to the role.

Zaven Ghanimian discussed the value of human craftsmanship and where the implementation of artificial intelligence does work.

Jewelers of America also revealed the recipients of the Seymour & Evelyn Holtzman Bench Scholarship and its own scholarship programs.

The British actor, known for his roles in “Twilight” and “The Odyssey,” will star in a campaign for the Master Control Chronometre.

The “Confetti Disco,” “Champagne Cheers,” “Tuxedo,” and “Classic Punk” jewelry collections each capture a distinct spirit of celebration.

Nelson Holdo of Newport Beach pleaded guilty to multiple counts of felony grand theft and writing bad checks and was sentenced Monday.























