Events & Awards

Live from Conclave: Understanding Cybersecurity Risks

Events & AwardsApr 25, 2018

Live from Conclave: Understanding Cybersecurity Risks

Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?

Nashville, Tenn.—The hacks that make headlines are the ones that involve big companies and thousands, if not millions or billions, of files of customer data—Equifax, Yahoo and, most recently, Saks Fifth Avenue and Lord & Taylor. 

But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked. 

“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.” 

Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.

She started with social engineering and phishing. 

Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.

Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).

While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly. 

The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.

The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back. 

Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.

But that doesn’t always happen.

When a business owner or employee falls for a phish, Myers said options are somewhat limited. 

She said what business owners should not do is pay, as there is no guarantee they will get their data back. 
They should stop their system backup, wipe infected systems and devices, and restore using what was backed up before the malware was installed. (Systems need to be backed up regularly. Myers recommends having a set, repeating cycle; for example, it backs up every day at midnight.)

Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?

While not heavily attended, the Conclave session did generate multiple questions from attendees.

One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.

Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.

Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.

2. Keep an inventory of risks and threats, and use multiple layers of security.

3. Keep systems and devices patched.

All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
 
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”

4. Back up systems and, Myers added, test the back-up.

Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.

5. Establish separation in key systems.

Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.

Also, when someone leaves the company, take away their access to the company’s systems.

6. Train employees on cyber risks at least annually, if not quarterly.

In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.

The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.

Michelle Graffis the editor-in-chief at National Jeweler, directing the publication’s coverage both online and in print.

The Latest

National Jeweler columnist Peter Smith
ColumnistsSep 05, 2025
Peter Smith: A Lasting Lesson From Maurice Tempelsman

Smith recalls a bit of wisdom the industry leader, who died last week, shared at a diamond conference years ago.

Jamie Turner Victoria Labradorite Necklace
CollectionsSep 05, 2025
Piece of the Week: Jamie Turner’s ‘Victoria’ Necklace

The “Victoria” necklace features a labradorite hugged by diamond accents in 18-karat yellow gold.

Stock image of the U.S. Supreme Court
Policies & IssuesSep 05, 2025
Trump Takes Tariffs Case to the Supreme Court

Two lower courts have moved to block the import taxes, which will remain in place as the legal battle continues.

japac-btyb.png
Brought to you by
Rallying Call for the Jewelry Industry on Tariffs and Other Key Issues

Jewelers of America is leading the charge to protect the industry amidst rising economic threats.

Patrick Mahomes Hublot campaign
WatchesSep 05, 2025
Patrick Mahomes Is the New Hublot Brand Ambassador

The Kansas City Chiefs quarterback shares Hublot’s dedication to pursuing greatness, the Swiss watchmaker said.

Weekly QuizSep 04, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
gia-edu main image.png
Supplier BulletinSep 04, 2025
A Brilliant Future Is Here

Sponsored by GIA

Lucara pink diamond
SourcingSep 04, 2025
Lucara Unveils Unusual 37-Carat Pink Diamond

The Type IIa stone, recovered from Botswana’s Karowe diamond mine last month, features unique coloration.

rio-article photo-diamond.jpg
Brought to you by
Taking the Moment Head On: How Rio Grande Champions the Present & Future of Fine Jewelry

As a leading global jewelry supplier, Rio Grande is rapidly expanding and developing new solutions to meet the needs of jewelers worldwide.

Shot from Breitling new NFL campaign
WatchesSep 04, 2025
Breitling Takes Its NFL Game to the Next Level

Breitling is now the NFL’s official timepiece partner, a move that puts the brand in front of the millions of Americans who watch football.

Fabergé x Gemfields Malaika Egg
SourcingSep 03, 2025
Gemfields Confirms Completion of Fabergé Sale

U.S.-based investment company SMG Capital LLC is the new owner of the luxury brand.

Claire’s storefront
MajorsSep 03, 2025
These Are the Nearly 300 Claire’s Stores Set to Close

A new court filing details the locations of the stores that will close, as well as the 830 that will remain open.

Stuller’s Tools, Equipment, & Metals and Findings & Metals Catalogs
MajorsSep 03, 2025
Stuller Releases 2 New Catalogs

The new catalogs are “Tools, Equipment, & Metals” and “Findings & Metals.”

Effy Jewelry Multicolor Sapphire Bangle
TrendsSep 03, 2025
Amanda’s Style File: A Perfect Birthstone

Sapphire’s variety of colors make it the perfect birthstone for September.

Woman with hands crossed wearing jewelry
FinancialsSep 02, 2025
Lab-Grown Diamonds, Lower-Priced Fashion Jewelry Drive Signet Jewelers’ Q2 Sales

The retailer has raised its guidance after seeing total sales increase 3 percent in the second quarter, beating expectations.

Jean-Christophe Bédos Birks
MajorsSep 02, 2025
Birks CEO Jean-Christophe Bédos Steps Down

Niccolò Rossi di Montelera, executive chairman of the board, was appointed as interim CEO.

Harry Winston Ginza Flagship Exterior, Interior
MajorsSep 02, 2025
Harry Winston Opens Its Largest Flagship in Japan

The three-floor space also features the jeweler’s largest VIP salon in Japan and offers an exclusive diamond pendant.

All Hours: Stephanie Gottlieb Fine Jewelry x Oak and Luna Campaign Imagery
CollectionsSep 02, 2025
Stephanie Gottlieb Debuts Silver Designs in ‘All Hours’ Collab

The collection is a collaboration between Stephanie Gottlieb Fine Jewelry and Oak and Luna, focusing on understated essentials.

Sothebys The Desert Rose orangy pink diamond collectors week
AuctionsAug 29, 2025
Sotheby’s UAE Sale to Feature 32-Carat Fancy Vivid Orangy Pink Diamond

The highlight of a single-owner jewelry and watch collection, it’s estimated to fetch up to $7 million at auction this December.

Calvin Klein watch and jewelry campaign
FinancialsAug 29, 2025
Movado’s Q2 Sales Rebound Despite Tariff Impact

CEO Efraim Grinberg noted a resurgence in the fashion watch market.

Mark Davis Bullseye Necklace
CollectionsAug 29, 2025
Piece of the Week: Mark Davis’ ‘Bullseye’ Necklace

The “Bullseye” necklace, with vintage bakelite and peridot, August’s birthstone, is the perfect transitional piece as summer turns to fall.

Image #1_Resized.png
Supplier BulletinAug 28, 2025
Clientbook Is Helping Jewelers Turn Clienteling Challenges into Wins with Hands-On Training and Coaching

Sponsored by Clientbook

GIA’s new report for lab-grown diamonds
GradingAug 28, 2025
GIA’s New ‘Quality Assessment’ for Lab-Grown Diamonds Is Coming

It will classify lab-grown stones into one of two categories, “premium” or “standard,” in lieu of giving specific color and clarity grades.

Botswana President Duma Boko
SourcingAug 28, 2025
Botswana Declares Public Health Emergency Amid Diamond Sales Slump

President Duma Boko addressed the country’s medical supply chain crisis in a recent televised address.

Afton Robertson-Kanne Borsheims
MajorsAug 28, 2025
Borsheims Names New Jewelry Buyer

Former Free People buyer Afton Robertson-Kanne recently joined the retailer.

Sissy’s Log Cabin Back to School and Bling
IndependentsAug 28, 2025
Sissy’s Log Cabin Donates School Supplies to Memphis Students

The jeweler teamed up with two local organizations for its inaugural “Back to School and Bling” event.

Taylor Swift Engaged
EditorsAug 27, 2025
Taylor Swift’s Engagement Ring Is a Fairy Tale for Vintage Diamond Cuts

The singer’s new bling, reportedly a natural old mine-cut diamond, is no paper ring.

11,685-carat Imboo emerald
SourcingAug 27, 2025
11,685-Carat Emerald Recovered From Zambia’s Kagem Mine

Dubbed the “Imboo,” or “buffalo,” emerald, the rough gemstone is part of Gemfields’ latest emerald auction, which is taking place now.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy