Events & Awards

Live from Conclave: Understanding Cybersecurity Risks

Events & AwardsApr 25, 2018

Live from Conclave: Understanding Cybersecurity Risks

Do your employees understand when an email should raise alarm bells? And are you patching your software when prompted?

Nashville, Tenn.—The hacks that make headlines are the ones that involve big companies and thousands, if not millions or billions, of files of customer data—Equifax, Yahoo and, most recently, Saks Fifth Avenue and Lord & Taylor. 

But that doesn’t mean a small business, like a family-owned jewelry store, can’t be hacked. 

“Every organization is a target,” Mary Myers, an information security analyst with Jewelers Mutual Insurance Group, said. “There are just different rationales for why.” 

Myers presented a breakout session Monday morning at Conclave outlining the cybersecurity risks businesses face and detailing what jewelers should do if they are hacked.

She started with social engineering and phishing. 

Social engineering is the act of manipulating employees into doing something they otherwise would not do. Phishing is social engineering via email and can involve attachments, directing the recipient to fake websites, or fake emails.

Myers said phishing emails are often unexpected and written in a way that makes them seem urgent (your immediate reply is requested, etc.).

While they can contain misspellings and grammatical errors, she noted that hackers are getting smarter and cleaning up their emails so there are fewer of these. Phishing messages also can come from email addresses that are nearly identical to (or exactly the same as, which is called spoofing) those of people with whom the business owner and/or employees communicate regularly. 

The emails try to bait the the receiver into replying and engaging in a conversation, opening an attachment or clicking a link for the purposes of installing malware on the business’ computer systems.

The malware widely in use by hackers right now is called ransomware, Myers said. Hackers lock victims’ computers with encryption and demand they pay a ransom, via Bitcoin, to get their data back. 

Her initial recommendation is, of course, not to click on links or open the attachments in emails that seem suspicious. Delete the email, call the sender and ask if they sent that specific email with an attachment or consult IT support.

But that doesn’t always happen.

When a business owner or employee falls for a phish, Myers said options are somewhat limited. 

She said what business owners should not do is pay, as there is no guarantee they will get their data back. 
They should stop their system backup, wipe infected systems and devices, and restore using what was backed up before the malware was installed. (Systems need to be backed up regularly. Myers recommends having a set, repeating cycle; for example, it backs up every day at midnight.)

Jewelers also face cybersecurity risks from both employees and vendors/contractors who could accidentally load a virus onto a system by clicking a phishing link or visiting a disreputable site, or who could violate a business intentionally, by purposely loading or sending a virus or sharing sensitive customer information. Myers said business owners need to provide guidance to employees, vendors and contractors and to clearly define: what does acceptable internet use at the company look like?

While not heavily attended, the Conclave session did generate multiple questions from attendees.

One jeweler asked if should she turn off her servers at night to help protect against attacks. You can, Myers answered, but it won’t necessarily prevent anything, as some of this software is malware designed to enter the system and lie dormant until it can be activated.

Another asked if paid-for anti-virus software is better than free. Myers said anything that will help a business quarantine and clean up a virus is “great.” What will work best a particular business really depends on its size, needs and risk factors.

Myers wrapped up with a list of a half-dozen additional tips for increasing cybersecurity.
1. Keep an inventory of key systems and applications.

2. Keep an inventory of risks and threats, and use multiple layers of security.

3. Keep systems and devices patched.

All software has “gaps” that make it vulnerable to hackers, Myers said. “Patches” are released regularly by software companies and are intended to seal those gaps. Microsoft releases patches for its software on a monthly basis, but probably the most well-known example of a patch are the “updates” Apple regularly sends for iPhones and iPads.
 
“If you don’t close it,” Myers said of the gap, “you’re exposed. Patching is super, super critical.”

4. Back up systems and, Myers added, test the back-up.

Having a virus-infected system is going to create an “emotionally charged” situation. She said business owners don’t want that to be the first time they’ve ever walked through the process of employing their back-up.

5. Establish separation in key systems.

Business owners who host their own websites should separate it internally and not have it on the same server as the rest of their data. They also need to rotate job duties. They can’t “give the keys to the kingdom” to one person; hackers would have to have access to several people if there's separation.

Also, when someone leaves the company, take away their access to the company’s systems.

6. Train employees on cyber risks at least annually, if not quarterly.

In response to one jeweler’s question, Myers said business owners can require employees who connect personal devices to the store’s Wi-Fi to update those devices when prompted. She recommended writing it into the store’s policy.

The JSA also recently released a list of cybersecurity recommends, which was included in National Jeweler’s article about Saks getting hacked.

Michelle Graffis the editor-in-chief at National Jeweler, directing the publication’s coverage both online and in print.

The Latest

Alfredo Colmenero-Martinez and Jarren Frazier
CrimeAug 18, 2026
2 California Men Arrested in Fatal Vehicle Smash Robbery

One is the driver who allegedly crashed a car into a Sacramento jewelry store in April, striking a 71-year-old employee who later died.

The Retail Smiths Principal Partner and National Jeweler columnist Peter Smith
ColumnistsAug 18, 2026
Peter Smith: The IKEA Effect and Bridal Branding

In a new column, Peter Smith posits that people actually enjoy putting together IKEA furniture, and the same is true for engagement rings.

Police car with lights on
CrimeAug 18, 2026
Thieves Snatch $1M in Jewelry From New Jersey Jeweler

9lakha Jewelers in Iselin, New Jersey, was the target of a smash-and-grab robbery on Aug. 8.

1872-x-1052-July-ad (1).png
Brought to you by
Why More Jewelry Retailers Are Hosting Turnkey Estate Buying Events

Retailers are seeking new ways to attract customers, increase traffic, and create revenue – Estate buying events are a popular solution.

Ring Concierge x 818 Tequila Bridal Giveaway
Lab-GrownAug 18, 2026
Ring Concierge, Kendall Jenner Collab on Bridal Earrings Giveaway

The jeweler has partnered with Jenner’s 818 Tequila brand to gift lab-grown diamond studs to a bride-to-be and their bridal party.

Weekly QuizAug 13, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Spinelli Kilcollin Inara Ring
CollectionsAug 17, 2026
Marquise Diamonds Dance in Spinelli Kilcollin’s ‘Wren’ Collection

Marquise-cut diamonds in drop charms are the center of the new collection, reflecting the movement of a dancer in modular styles.

Karl Getschel and Bob Yanega of Smyth Jewelers
IndependentsAug 14, 2026
Smyth Jewelers to Open Fourth Location

The family-owned jeweler will open a new showroom in Bel Air, Maryland, this fall.

Brought-To-By-Article-Top-Image.jpg
Brought to you by
Wedding Band Trends 2026: Personalization Takes Center Stage

Colored gemstones, artisan finishes, mixed metals, and meaningful details are shaping demand in bridal jewelry.

Stock image of a gavel
CrimeAug 14, 2026
Wife of Man Convicted in Jeweler’s Murder Sentenced for Conspiracy

Amanda Ileana Hernandez is married to Carlos Hernandez, one of two men in prison for the 2024 murder of Michigan jeweler Hussein Murray.

Paul Morelli Wavey Vine Earrings
TrendsAug 14, 2026
Paul Morelli’s Latest ‘Wavey Vine’ Earrings Embrace Color

The reimagined jewel, our Piece of the Week, trades the diamonds in the original 1998 design for blue, pink, yellow, and green sapphires.

Cover.jpg
Supplier BulletinAug 13, 2026
Your Piece Could Be the One Editors Talk About

Sponsored by American Gem Trade Association

Two Pandora Talisman pendants
FinancialsAug 13, 2026
Pandora’s ‘Talisman’ Collection Shines, Lab-Grown Diamond Sales Fall

In the United States, second-quarter sales were flat amid soft consumer sentiment and lower in-store traffic.

Cuckoo Cuckoo Cadbury Conundrum egg
AuctionsAug 13, 2026
This Gold Cadbury ‘Conundrum’ Egg Set a World Auction Record

The 22-karat gold egg, sold at Batemans Auctioneers in the U.K., was part of a 1980s treasure hunt ad campaign for Cadbury Creme Eggs.

Picture of 2,488 carat rough diamond next to tweezers, a golf ball, and a loupe
SourcingAug 13, 2026
2,488-Carat Diamond, Largest Found in Botswana, Has a New Owner

Lucara Diamond Corp., which recovered the “Motswedi” diamond from the Karowe mine, sold the stone for an undisclosed amount.

John Hardy Heishi Collection Campaign Imagery
CollectionsAug 13, 2026
John Hardy Infuses ‘Icon,’ ‘Heishi’ Collections with Color

The expanded collections now feature hand-cut gemstones like topaz, tanzanite, chrysoprase, chalcedony, smoky quartz, and fire opal.

Jean Dousset Westfield Valley Fair
Lab-GrownAug 13, 2026
Jean Dousset Opens Third Store

The lab-grown diamond jewelry brand’s newest boutique is in Westfield Valley Fair in Santa Clara, California.

Legacy emerald
SourcingAug 12, 2026
Eshed-Gemstar on the Painstaking Process of Cutting ‘The Legacy Emerald’

The gemstone supplier and manufacturer acquired the remarkable 104-gram Zambian emerald at Gemfields’ auction in May.

Surveillance image of jewelry thieves
CrimeAug 12, 2026
Elderly NYC Woman Targeted in Jewelry Swap Scheme

Two suspects offered to trade the woman a “winning” lottery ticket for her jewelry.

The Finsch Diamond Mine in South Africa, owned by Petra Diamonds Ltd.
SourcingAug 12, 2026
Another Diamond Mine Poised to Close

Finsch has been in business rescue since May, and owner Petra Diamonds said it sees no viable path forward for the mine.

Stock image of gavel, handcuffs, and law books
CrimeAug 12, 2026
Jewelry Store Employee Gets 20 Years to Life in Choking Death of Boss

Michel Patrick DeSalles was sentenced after pleading guilty to the 2017 murder of Omid Gholian, who owned a jewelry store in Manhattan.

Beth Miller Frederick Goldman
MajorsAug 12, 2026
Frederick Goldman Names New SVP of Sales

Longtime industry executive Beth Miller has taken on the role.

Verdura unicorn brooch
AuctionsAug 11, 2026
Verdura Unicorn Brooch With Royal Connection Up for Auction

The brooch was owned by Virginia Fortune Ryan Ogilvy, who served as a lady of the bedchamber to Queen Elizabeth II for nearly 50 years.

Jamie Cygielman
MajorsAug 11, 2026
Signet Jewelers Selects Mattel Exec to Lead Zales, Banter

Jamie Cygielman will take on the role on Aug. 24.

Richard Moore
IndependentsAug 11, 2026
Polly’s Fine Jewelry Co-Owner Richard Moore Dies at 69

Moore, Polly’s husband, is remembered as a family man with an easygoing spirit and a love for sports and the outdoors.

National Jeweler columnists Duvall O’Steen and Jen Cullen Williams
ColumnistsAug 11, 2026
Creative Connecting: How to Sell Colored Gemstones to Gen Z

Duvall O’Steen and Jen Cullen Williams share the best ways to display, present, and explain colored gemstones to younger customers.

NAJA logo
Events & AwardsAug 11, 2026
NAJA Announces Lineup For 2026 Fall Virtual Conference

The mid-year conference for jewelry and watch appraisers will take place Sept. 5-6 on Zoom.

Honest Hands Workbench Ring Builder
TechnologyAug 10, 2026
Colorado Jeweler Launches Customization Tool He Built Himself

Honest Hands Ring Co. Founder Benjamin Bosworth shared his thoughts on jewelry technology and why AI can never replace the human element.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy