Technology

21 digital security tips for retailers

TechnologyApr 30, 2014

21 digital security tips for retailers

With the recent data breaches impacting major retailers and web security issues stemming from Heartbleed, National Jeweler takes a look at what jewelers can do to protect their customers. 

050114_Heartbleed-Article.jpg
Heartbleed, a security flaw in OpenSSL, a cryptographic library used to secure a large percentage of the Internet’s traffic, is the latest threat to private consumer data.

New York--The past six months have been rough for the security of private consumer information.

Target and Neiman Marcus both fell victim to massive data breaches, leaving millions of customers vulnerable. The web world was thrown into further turmoil with news of a massive security flaw in OpenSSL, the security software used on about two-thirds of all servers on the Internet.

Though no cases have yet been reported of the flaw, which is called the Heartbleed bug, being used to obtain information, its potential reach is troubling, allowing for the removal of personal and financial information without anyone’s knowledge. 

Retailers are responsible, from many standpoints, for making sure they’re doing everything they can to protect this information.

National Jeweler talked to a number of security experts--Matt Boaman of EZSolution, James Koons of Listrak, Chris Kronenthal of FreedomPay, Andrew Van Noy of Warp 9, Aaron Janowski of Wellsley Consulting and consultant to the Jewelers’ Security Alliance, and Zilvinas Bareisis of Celent--to compile the following list of tips for retailers to secure their customers’ information.

1. Monitor the information. The Heartbleed bug is invisible, so no one can establish ahead of time what information has already been compromised; instead, jewelers should be monitoring for any signs that it has been. The monitoring and response plan is key to being able to show that the company is taking all reasonable steps to keep secure the personal data that is processed.
2. Test the site. This site provides a place to plug in URLs to check if a website is vulnerable to the Heartbleed flaw.
3. Fix the problem. Contact the web host to ensure that if the web server was running one of the vulnerable versions of OpenSSL, they have updated it or patched it right away. Once that’s finished, get a new key for the site’s security certificate.
4. Communicate with customers. Advise customers not to log into the site until it’s been fixed. Once it has, tell them to reset their user passwords if they have an account through the website. They shouldn’t do so before it’s been fixed as that could open them up to more vulnerability.
5. Don’t store unnecessary information. Don’t keep any unnecessary information on a server that doesn’t need to be there. Instead, encrypt the information before sending to a credit card processor.
6. Plan ahead. Consider getting involved in organizations like the Online Trust Alliance, which advocates

that every organization handling customer data create a data management strategy and incident response plan that evaluates data from acquisition through use, storage and destruction. To help with a preparedness plan, the OTA publishes the Data Protection & Breach Readiness Planning Guide, which is updated at least every year and is available for free download here.

Data breaches also continue to be top of mind, as companies work to make sure they’ve secured their payment systems after millions of customers’ information was stolen from Target and Neiman Marcus. Target recently named a new chief information officer and security updates to show consumers it’s taking steps to protect them.

RELATED CONTENT: Target hires new CIO, announces security updates

These breaches can have numerous negative effects for a retailer.

“Whether the result of an online attack, in-store breach, internal theft, malware or accidental loss of data incident such incidents can have significant financial impact and can have devastating consequences on the value of a company’s brand,” said Koons, who is chief privacy officer at Listrak.

The National Retail Federation has since been urging Congress to overhaul the nation’s credit and debit card system, saying that banks’ insistence on a signature instead of a personal identification number, or  PIN, puts customers at risk. The organization is also urging the card industry to switch to new chip-and-PIN cards, much as Target is doing now, which would require use of a PIN instead of the signature.

There are a number of steps that jewelers can take to prevent a data breach.

1. Check the connection. Make sure that the merchant account with the banks being used to process sales is secure.
2. Check the equipment. Ensure the in-store equipment is loaded with anti-hacking, anti-virus software and/or hardware so that nothing on premises is corrupted, which is usually done by proper firewalls, data encryption and security hardware.
3. Do a double take. Double check with the credit card holder's bank for the validity and security of the credit account being used.
4. Prepare for the possibility. Security threats will always be a possibility, and businesses can’t wait until after it happens to figure out what to do. It’s necessary to have a plan to deal with security breaches and other incidents should it happen.
5. Explore all options. There isn’t one technology that will give all the protection needed against cybercrime. Follow a “layered approach” to security and use a number of tactics, including using EMV, tokenization, point-to-point encryption, and dynamic authentication, among other things.
6. Stay up-to-date.  Make sure antivirus and operating systems are up to date with the latest software updates to provide the best protection against threats.
7. Keep it off-site. Avoid storing data unless absolutely necessary. If it’s necessary, they should follow PCI Security Standards Council guidelines.
8. Be proactive. Ensure cashiers always check the customer’s identification and/or ask for the PIN.

If a data breach should occur, immediate action is necessary to help regain security, preserve evidence and protect the brand. Here are steps to follow within the first 24 hours:

9. Jot down activity. Record the date and time when the breach was discovered as well as the current date and time when the team was alerted to the breach.
10. Secure the site. If a data breach comes from inside the store, secure the premises where it occurred to preserve evidence.
11. Prevent more activity. Stop additional data loss by taking affected machines offline but do not turn them off or start investigating in the computer until professionals are there to help.
12. Take extensive notes. Document everything known about the breach so far, including who discovered it, who reported it, to whom was it reported, who else knows about it, what type of breach occurred, what was stolen, what systems are affected, what devices are missing and any other pertinent information.
13. Interview. Talk to the team members who found the breach and anyone else who may know about it and document it to get all the relevant information.
14. Get professional help. Bring in a forensics team to begin the in-depth investigation.
15. Contact law enforcement. If needed, notify law enforcement after consulting with legal counsel and the entire upper management team.

Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

trend retail.jpg
PodcastsJan 12, 2026
The latest poscast

test

Screenshot from 2026-01-12 06-22-03.png
PodcastsJan 12, 2026
New podcast without sponsor

test

20210205_Alexia_Connellan_Gatsby_earrings.jpg
TrendsJan 12, 2026
New test Article

test article

trend ss21@2x.jpg
Brought to you by
new sponsored article

test

2019_De_Beers_rough_NEW_1.jpg
PodcastsJan 12, 2026
New sponsored podcast

test

Weekly QuizOct 03, 2024
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
MNQ FINAL - NJ web - 1872 x 1052 px.png
PodcastsJan 12, 2026
Introducing My Next Question, the Podcast

A monthly podcast series for jewelry professionals

Screenshot from 2025-12-31 12-03-28.png
PodcastsDec 31, 2025
Test new podcast post

Test new podcast post

Jewelers Mutual Group Cybersecurity
Brought to you by
Navigating Cybersecurity: Essential Guidance for Jewelers

From protecting customer data to safeguarding inventory records, it's crucial to learn how to tackle cybersecurity challenges.

MNQ - studio - screen -1920 x 1080.png
PodcastsDec 29, 2025
Molly Test Podcast Episode

This is the abstract for Molly Test Podcast Episode

image 169 (4 col).png
PodcastsDec 10, 2025
Podcast With Video

Podcast Without Video or Audio or Image

image 169 (4 col).jpg
Recorded WebinarsDec 04, 2025
New Recorded Webinar for tests

New Recorded Webinar for tests

User-Avatar-PNG-Picture.png
PodcastsDec 03, 2025
Test Article Title

test Abstract

20210204_Couture_show_shot.jpg
PodcastsDec 02, 2025
New podcast

test desc

Screenshot from 2025-12-05 13-54-41.png
PodcastsNov 27, 2025
Test Podcast With Video

Test Podcast With Video. New interview with Ada Lovelace.

Image for tests
PodcastsNov 25, 2025
Test New Podcast Post

Abstract for tests. New Podcast interview with John Lennon, Jimi Hendrix and Jim Morison.

National Jeweler columnist Peter Smith
ColumnistsOct 09, 2024
Peter Smith: 7 Things to Know When Selling Luxury

Ahead of the holiday season, Smith delves into the often subconscious reasons people buy luxury products for themselves or their loved ones.

Edgar Mitchell wearing Rolex watch on Apollo 14
AuctionsOct 09, 2024
Rolex Worn on Apollo 14 Mission Up for Sale

The GMT-Master “Pepsi” belonging to astronaut Edgar Mitchell is a standout in RR Auction’s online “Space Auction,” going on now.

Simon meet me at the mall campaign
MajorsOct 09, 2024
New Simon Campaign Invites Gen Z to ‘Meet Me At The Mall’

The ads celebrate the mall culture of the ‘80s and ‘90s.

Platinum Guild International training
MajorsOct 09, 2024
PGI Launches New Virtual Sales Training

Retail sales associates can access the video series on mobile to refresh their selling skills.

Gathering at Bharat Diamond Bourse for COVID vaccinations
Policies & IssuesOct 09, 2024
GJNRF: Reaching Out, Rebuilding Futures

For 25 years, India’s Gem & Jewellery National Relief Foundation has provided aid in the wake of war, natural disasters, and global crises.

Sotheby’s A Tsar’s Treasure: Ferdinand of Bulgaria
AuctionsOct 08, 2024
Sotheby’s Selling Jewelry That Belonged to a Bulgarian Tsar

The November auction will feature a collection of jewels owned by Ferdinand I, the first king of modern Bulgaria, and his family.

Rough diamonds mined at the Diavik Diamond Mine
SourcingOct 08, 2024
Rio Tinto Begins New Phase of Production That Will Extend Diavik’s Life

Commercial production has begun underground at the Canadian diamond mine’s A21 pipe.

Stock image of hand holding phone by keyboard
SurveysOct 08, 2024
What to Know About Online Shopping This Holiday Season

Deloitte and Adobe Analytics shared their insights on the season, from the retail sales forecast to the role of generative AI.

Sylvie and Uncommon Man Campaign
CollectionsOct 08, 2024
Sylvie Adds New Men’s Bands

The Texas-based jeweler collaborated with luxury clothing brand Uncommon Man on men’s bands designed with European influences.

Diamond on polishing wheel Venus Jewel India
SourcingOct 08, 2024
Is Current Diamond Industry Turbulence Shaping a ‘New Normal’?

Industry players have found ways to cope with market conditions while working to reshape themselves in the face of emerging realities.

Rio Tinto 2024 Beyond RareTM Tender Art Series
SourcingOct 07, 2024
Rio Tinto to Offer 76 Diamonds in 2024 Beyond Rare Tender

The sales event, in its second year, features a selection of rare diamonds from the miner’s Argyle and Diavik diamond mines.

Kristi Yamaguchi and Scott Heller
CollectionsOct 07, 2024
Olympian Kristi Yamaguchi Partners With Heller Jewelers on New Collection

A portion of the proceeds from the “Always Dream” collection will go to Yamaguchi's foundation, supporting early childhood literacy.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy