Events & Awards

Live from Conclave: Understanding Cybersecurity Risks

Events & AwardsApr 25, 2018

Live from Conclave: Understanding Cybersecurity Risks

Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?

Nashville, Tenn.—The hacks that make headlines are the ones that involve big companies and thousands, if not millions or billions, of files of customer data—Equifax, Yahoo and, most recently, Saks Fifth Avenue and Lord & Taylor. 

But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked. 

“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.” 

Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.

She started with social engineering and phishing. 

Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.

Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).

While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly. 

The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.

The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back. 

Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.

But that doesn’t always happen.

When a business owner or employee falls for a phish, Myers said options are somewhat limited. 

She said what business owners should not do is pay, as there is no guarantee they will get their data back. 
They should stop their system backup, wipe infected systems and devices, and restore using what was backed up before the malware was installed. (Systems need to be backed up regularly. Myers recommends having a set, repeating cycle; for example, it backs up every day at midnight.)

Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?

While not heavily attended, the Conclave session did generate multiple questions from attendees.

One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.

Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.

Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.

2. Keep an inventory of risks and threats, and use multiple layers of security.

3. Keep systems and devices patched.

All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
 
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”

4. Back up systems and, Myers added, test the back-up.

Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.

5. Establish separation in key systems.

Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.

Also, when someone leaves the company, take away their access to the company’s systems.

6. Train employees on cyber risks at least annually, if not quarterly.

In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.

The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.

Michelle Graffis the editor-in-chief at National Jeweler, directing the publication’s coverage both online and in print.

The Latest

The Nordstrom Men’s Store in New York City
MajorsDec 24, 2024
Nordstrom Family, Partner to Take Retailer Private in $6B Deal

Members of the founding family have partnered with Mexican retail company El Puerto de Liverpool to acquire Nordstrom.

Boucheron Las Vegas Storefront
MajorsDec 24, 2024
Boucheron Bets on Las Vegas

The brand has opened its second U.S. location in the Fontainebleau resort and casino.

B & B Fine Gems gemstone suite
EditorsDec 24, 2024
The Spectrum Jewels I Want to Find Under the Tree

Associate Editor Lauren McLemore highlights pieces from the AGTA Spectrum & Cutting Edge Awards she’d be thrilled to unwrap on Christmas.

ride_or_die_1872x1052.png
Brought to you by
A Diamond Is Forever Celebrates "Forever Present" Holiday Campaign

A Diamond is Forever hosted a holiday celebration in honor of their new marketing campaign, ‘Forever Present.’

Gemfields emeralds
SourcingDec 24, 2024
Gemfields to Temporarily Suspend Emerald Mining

The move is one of several cost-cutting measures outlined by the company as it faces a weaker luxury market and other challenges.

Weekly QuizDec 19, 2024
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Tyrese Maxey The 1916 Company campaign
IndependentsDec 23, 2024
Philadelphia 76ers’ Tyrese Maxey Stars in The 1916 Company’s New Campaign

The retailer’s “On the Clock” campaign celebrates how time, precision, and purpose come together.

Jewelry by Sorellina, Francesca Villa, Cece Jewellery, Retrouvai, Ray Griffiths, Cartier, Cocoerow Fine Jewelry, and Gumuchian
EditorsDec 23, 2024
My Favorite Piece of the Week Jewels of 2024

Associate Editor Natalie Francisco chose her 12 favorite Piece of the Week picks from the year gone by.

me_myself_and_I_1872x1052 .jpg
Brought to you by
De Beers Group Launches Holiday Campaign for Natural Diamonds

‘Forever Present’ campaign revives the iconic A Diamond is Forever tagline and celebrates the diamond dream.

GIA emerald report
GradingDec 23, 2024
GIA Adds Filler Identification to Emerald Reports

Lab clients have the option to request this addition on their emerald reports.

Retrouvai Green Sapphire and Diamond Heirloom Bezel Ring for Charity
CollectionsDec 20, 2024
Piece of the Week: Retrouvaí’s Ring for Charity

In the spirit of giving, Retrouvaí will donate $4,000 from the sale of this ring to the Los Angeles Regional Food Bank.

DeVries Jewelers
IndependentsDec 19, 2024
Michigan’s DeVries Jewelers Unveils New Location in Time for the Holidays

Co-owner Dan DeVries shared what it’s like moving into a space triple the size of its old store and how it feels to be a “real jeweler” now.

State Property Gardens Collection Campaign
CollectionsDec 19, 2024
State Property Transforms Spain’s Generalife Gardens into Jewelry

Along with the latest “Gardens” collection, the brand has released limited-edition designs offering more indulgent pieces.

Two people in a rowboat
CrimeDec 19, 2024
Alleged Jewelry Thieves Attempt Rowboat Escape

The man and woman are accused of stealing jewelry from a shipping container then trying to flee by paddling a small boat out into a bay.

2488-carat diamond found in Botswana
SourcingDec 19, 2024
The Second-Largest Diamond Ever Found Now Has a Name

The 2,488-carat diamond recovered from a mine in Botswana has been dubbed “Motswedi” while its 1,094-carat sibling is “Seriti.”

Rough rubies
SourcingDec 19, 2024
Gemfields Reports Record Ruby Auction Results Despite Challenges at Source

The average price per carat hit a record high for the miner, which said it remains unaffected by the conflict in Mozambique.

alexandrite ring
AuctionsDec 18, 2024
Alexandrite Ring Sells for Record-Setting $1.9M at Sotheby’s

The nearly 17-carat stone made history for the color-change gem that, according to the auction house, is experiencing a “notable surge” in the market.

Tiffany & Co. pocket watch gifted to captain of the Carpathia
WatchesDec 18, 2024
Historic Titanic Pocket Watch Winds Its Way Back to Tiffany & Co.

More than a century after survivors gifted a Tiffany timepiece to the captain of the ship that rescued them, the jeweler has reclaimed it.

Picchiotti Spotlight Campaign Video Still
TechnologyDec 18, 2024
Picchiotti Utilizes AI in ‘Spotlight’ Video Campaign

The videos highlight how pieces from the “Xpandable” and “Reversible Xpandable” collections put the wearer in the spotlight.

Steve Feldman
IndependentsDec 18, 2024
Industry Veteran Steve Feldman Set to Retire

Feldman reflected on 45 years in the jewelry industry and clarified that it’s not a total retirement.

Frank Circelli
SourcingDec 17, 2024
Frank Circelli, Founder of Gem Shopping Network, Dies at 75

Circelli was a pioneer in the world of TV shopping who is remembered for his passion for gemstones and his big personality.

Blue diamond ring
AuctionsDec 17, 2024
Blue Diamond Fetches $8.8M at Christie’s

The nearly 6-carat stone headlined the recent jewelry auction, which also featured Mica Ertegun’s jewelry.

Stock image of a gavel, handcuffs, and books
CrimeDec 17, 2024
‘Black Bin Crew’ Robbers Get 14-16 Years in Prison

The three men, who got their nickname because they’d toss the jewelry they stole into black plastic bins, were arrested back in August.

Cover of the new book “The History of Diamond Engagement Rings: A True Romance”
TrendsDec 16, 2024
Marion Fasel’s New Book Delves Into the History of Engagement Rings

“The History of Diamond Engagement Rings: A True Romance” is a 128-page small-format book containing more than 165 images.

Rolex store on Rodeo Drive
WatchesDec 16, 2024
Take a Look Inside the New Rolex Boutique on Rodeo Drive

Gearys opened a 6,200-square-foot Rolex store with a design that pays homage to the brand’s connection to the ocean.

GCAL 8X pear and marquise-cut diamonds
GradingDec 16, 2024
GCAL By Sarine Expands 8X to 2 More Fancy Shapes

The diamond cut grade is now available for marquise- and pear-shaped diamonds.

Claudia Cividino, Sissy’s Log Cabin, Shri Govind Dholakia, Tanishq
SourcingDec 16, 2024
Diamonds Do Good Announces 2025 Award Recipients

DDG said the honorees’ business practices embody a commitment to positive social impact, industry innovation, and community empowerment.

Selena Gomez, Benny Blanco, Engagement Ring
TrendsDec 13, 2024
Selena Gomez Said ‘Forever Begins Now’ to Marquise Diamond Engagement Ring

Estimates on the size and value of the solitaire diamond, which is mounted on a diamond pavé-set yellow gold band, vary.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy