Events & Awards

Live from Conclave: Understanding Cybersecurity Risks

Events & AwardsApr 25, 2018

Live from Conclave: Understanding Cybersecurity Risks

Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?

Nashville, Tenn.—The hacks that make headlines are the ones that involve big companies and thousands, if not millions or billions, of files of customer data—Equifax, Yahoo and, most recently, Saks Fifth Avenue and Lord & Taylor. 

But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked. 

“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.” 

Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.

She started with social engineering and phishing. 

Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.

Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).

While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly. 

The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.

The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back. 

Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.

But that doesn’t always happen.

When a business owner or employee falls for a phish, Myers said options are somewhat limited. 

She said what business owners should not do is pay, as there is no guarantee they will get their data back. 
They should stop their system backup, wipe infected systems and devices, and restore using what was backed up before the malware was installed. (Systems need to be backed up regularly. Myers recommends having a set, repeating cycle; for example, it backs up every day at midnight.)

Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?

While not heavily attended, the Conclave session did generate multiple questions from attendees.

One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.

Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.

Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.

2. Keep an inventory of risks and threats, and use multiple layers of security.

3. Keep systems and devices patched.

All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
 
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”

4. Back up systems and, Myers added, test the back-up.

Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.

5. Establish separation in key systems.

Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.

Also, when someone leaves the company, take away their access to the company’s systems.

6. Train employees on cyber risks at least annually, if not quarterly.

In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.

The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.

Michelle Graffis the editor-in-chief at National Jeweler, directing the publication’s coverage both online and in print.

The Latest

Women’s Jewelry Association logo
MajorsJan 30, 2025
WJA Chapter Leaders Resign as Fallout From DEI Remarks Snowballs

The boards of at least five chapters have resigned in response to controversial statements the WJA national board president made last month.

Jewelry writer and curator Melanie Grant
Policies & IssuesJan 30, 2025
RJC Executive Director Melanie Grant Is Stepping Down

An experienced jewelry writer and curator, Grant led the organization for two years.

Pharrell Williams and Tiffany Titan by Pharrell Williams Tahitian Pearl Necklace
CollectionsJan 30, 2025
Pharrell Williams Brings Tahitian Pearls to His New Tiffany & Co. Collection

Five new designs were added, all donning Tahitian cultured pearls and spear-like trident motifs, along with the new “Titan” setting.

Resolutions - 2025.jpg
Brought to you by
3 New Year’s Resolutions for Jewelry Lovers

The new year feels like a clean slate, inspiring reflection, hope, and the motivation to become better versions of ourselves.

Annie Doresca, Jake Duneier, John W. Ford Sr., Margot Grinberg, and Ivette Stephanopoulos
MajorsJan 30, 2025
24 Karat Club of New York Elects 5 New Members

Jewelers of America’s Annie Doresca and AGTA CEO John W. Ford Sr. are among the new members.

Weekly QuizJan 23, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Boucheron Scarabée Rhinocéros ring/brooch and Chardon necklace
CollectionsJan 29, 2025
Boucheron’s High Jewelry Takes the Form of ‘Untamed Nature’

The jeweler’s latest high jewelry collection looks into the Boucheron archives to create a “living encyclopedia of high jewelry.”

Elsa Peretti for Tiffany & Co. Bone Cuff
FinancialsJan 29, 2025
LVMH Watch, Jewelry Sales End the Year Down

Watch and jewelry sales slipped 3 percent in 2024, though the luxury conglomerate did see business pick up in the fourth quarter.

ride_or_die_1872x1052.png
Brought to you by
A Diamond Is Forever Celebrates "Forever Present" Holiday Campaign

A Diamond is Forever hosted a holiday celebration in honor of their new marketing campaign, ‘Forever Present.’

Olivier Kessler-Gay
MajorsJan 29, 2025
Chanel Names New General Manager of Watches, Fine Jewelry for US

Olivier Kessler-Gay will take over the role on March 3.

Stock image of couple shopping for jewelry
SurveysJan 29, 2025
Consumer Confidence Slips for Second Consecutive Month

It hit a four-month low in January due to concerns about the job market, though consumers remain bullish about the stock market.

WFDB Moments campaign
SourcingJan 28, 2025
WFDB Joins Efforts to Promote Natural Diamonds With New Campaign

The “Moments” social media campaign emphasizes the emotional ties between natural diamonds and life’s special milestones.

Bliss Lau As We Are Collection Campaign
CollectionsJan 28, 2025
Bliss Lau Celebrates the Intricate Mosaic of Identity in New Collection

The versatile “As We Are” collection features 14 pieces with interlocking designs allowing for 27 different looks worn around the body.

Olympic gold medalist and De Beers ambassador Letsile Tebogo
SourcingJan 28, 2025
Botswana’s First Olympic Gold Medalist Is Now a De Beers Ambassador

Letsile Tebogo will help to promote natural diamonds and the good they have done for his country.

Hargreaves Stockholm NouvelleBox
Events & AwardsJan 28, 2025
NouvelleBox Show Returns to New York City

The showcase, in its second year, will feature more than 20 international brands at its curated event from Feb. 2-4.

Graphic for “Predictions for the Year Ahead” webinar
Recorded WebinarsJan 28, 2025
Watch: Fine Jewelry Market Predictions for 2025

“My Next Question” guests Sherry Smith and Edahn Golan share their 2025 forecasts, from sales and marketing to what retailers should stock.

AGTA Seminar Series
Events & AwardsJan 28, 2025
Here Is the 2025 AGTA GemFair Tucson Educational Lineup

The seminar series covers topics from market trends and colored stone terminology to working with museums and growing an Instagram profile.

A picture of the LeVian family including Larry LeVian
MajorsJan 27, 2025
Le Vian Corp. Chairman Larry LeVian, a Man of Faith and Family, Dies at 73

LeVian is remembered for his leadership in the jewelry industry and for being a selfless and compassionate person.

Stock image of gavel, books, and handcuffs
CrimeJan 27, 2025
New Jersey Jeweler Sentenced to 2 1/2 Years for Evading Customs

Monishkumar Kirankumar Doshi Shah pleaded guilty to evading customs on more than $13.5 million of jewelry imported into the U.S.

 Jemora Gemhouse
SourcingJan 27, 2025
Dev Shetty To Head New Auction House for Rare Colored Gems

Jemora Gemhouse’s inaugural auction, slated for March, will take place in Dubai and feature polished sapphires.

Rachel Quinn and Gemfields’ Crazy Love collection campaign
CollectionsJan 27, 2025
Rachel Quinn Embodies Feelings of Falling in Love in New Collection

Quinn partnered with Gemfields to create “Crazy Love,” which features Zambian emeralds and Mozambican rubies across 10 pieces.

Arch Crown 2025 Tag & Label catalog
MajorsJan 27, 2025
Arch Crown’s 2025 ‘Tag & Label’ Catalog Is Out Now

The catalog is 48 pages and features more than 100 styles.

Ashley Zhang Jewelry 2025 Lunar New Year Snake Necklace
CollectionsJan 24, 2025
Piece of the Week: Ashley Zhang Jewelry’s Lunar New Year Necklace

The one-of-a-kind necklace was designed in celebration of the Chinese New Year, as 2025 is the Year of the Snake.

Ethical Gem Fair Tucson Anza Gems
SourcingJan 24, 2025
Ethical Gem Fair Heads Back to Tucson

The gemstone show is slated to take place at the Scottish Rite Cathedral.

Ophelia Eve 15 mm yellow gold and diamond hoops
Policies & IssuesJan 24, 2025
These Designers and Retailers Are Raising Money for LA Wildfire Relief

From raffles to auctions to donations, the industry is working to aid charities in Los Angeles amid the raging wildfires.

Mugshots of Zacary Briggs, Aaron Hammond, Tre’von Anthony Neal, and Evan Puckett
CrimeJan 23, 2025
4 Men Arrested After Allegedly Plotting to Kidnap Jeweler

The suspects are accused of planning to kidnap a Miami jeweler and rob him of his cryptocurrency.

Loose diamonds from Namdia
CrimeJan 23, 2025
Security Guard Killed in Armed Robbery at Namibian Diamond Co.

Francis “Gosh” Eiseb, 58, was a senior protection officer for Namib Desert Diamonds, also known as Namdia, in Windhoek, Namibia.

Gemstone Trading Network by RapNet and AGTA
SourcingJan 23, 2025
RapNet, AGTA Partner to Launch Gemstone Trading Network

The online diamond and jewelry marketplace has expanded, introducing a new platform dedicated to colored gemstone trading.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy