Company News • 13.03.2014

High-profile data breaches and You

Things to keep in mind

Target's high-profile data breach provides an excellent opportunity for retailers to take a step back and examine the security of their systems.

Already amounting to millions of dollars in expenses, the cyber attack on Target's system reveals the urgency with which merchants must bolster their defenses and ensure best practices are being followed throughout their operations.

Proper security must be a top priority

Not only do data breaches have the potential to carry mammoth price tags, they're also a public relations nightmare. Exposing customer information can have a long-lasting impact on business.

"Retailers collect a lot of information from their customers, who trust them to manage it responsibly and keep it protected," said Retail Pro International CEO Kerry Lemos. "In its recent public statement the FBI has warned retailers that more attacks mirroring the Target breach are most likely on the way, so it's critical for merchants to evaluate their systems and implement measures to safeguard their data."

Early reports focused on point-of-sale systems as the center of the Target breach. While payment data was extracted and hackers are targeting POS systems, a deeper analysis reveals that vulnerabilities in network systems are the true culprits opening doors to criminals.

Attackers were apparently able to hack into Target's system through a contracted HVAC worker's account. Analysts now believe that the hackers penetrated Target's internal network through a poorly secured contractor account, compromised the Windows file server and then attacked the retail management system, Security Intelligence explained.

"Retailers must tighten their security standards throughout their network to protect customer data and keep malicious malware from their servers," said Kevin Connor, Director of Product Strategy at Retail Pro International. "The issue goes much deeper than transaction points. While the Payment Card Industry Council regulates PCI standards, complying with them is not sufficient to protect against attacks. Instead, comprehensive security must encompass the entire network."

Protecting the system

There has been much discussion about better ways to handle electronic transactions, including implementing technology like chip-and-pin cards, which offer greater levels of protection. However, these measures don't cut to the core of the problem: Poorly managed systems and devices connected to the outside world can create entry points for criminals to install malware and extract information.

To ensure that the transactions themselves are secure, retailers must choose appropriate electronic fund transfer services. There are many EFT products and platforms that can be integrated with the retail management system and are PCI compliant, offering fast, secure transactions. EFT systems should foster confidence in consumers and allow them to choose convenient payment methods.

In addition to the EFT component, retailers need to implement best practices to safeguard their entire system.

"Like in any other industry, retail IT managers need to secure their systems with top-notch, comprehensive anti-virus software, responsible encryption and password practices, as well as ongoing maintenance to mitigate weaknesses in system infrastructure and applications," Connor said. "This must be applied not only to the central infrastructure but to all devices that can access company resources."

If store employees use their own devices to connect with the retail system or contractors access system information on their own computers, retailers should enforce policies that require appropriate security measures. Overall, retailers should assess the security of their entire computer system, making sure they're following proper protocol with strong passwords, up-to-date retail management software and applications, firewalls, anti-virus and controlled user access.

In the end, breach’s toll is far more than the direct liability. The hit to customer loyalty and trust carries with it a huge price tag in of its own.  Target, for instance, reported a 22.4 percent drop in quarterly earnings (compared to previous year) immediately following the announcement of the data breach and recovery via the rebuilding of consumer trust will take time.  

To avoid extreme situations such as this, security within the retail organization requires constant vigilance and needs to be an ongoing process. With threats on the rise and people highly concerned about information security, now is the time to bolster defenses and take an informed, well-orchestrated approach to managing retail data. The stakes are too high to do anything else.

Source: Retail Pro International, LLC

channels: data management

related articles:

popular articles:

Thumbnail-Photo: EuroCIS Germany next stop for ITL’s cash handling and age verification...
13.02.2024   #Tech in Retail #artificial intelligence

EuroCIS Germany next stop for ITL’s cash handling and age verification solutions

Innovative Technology Ltd (ITL) will be joining retail suppliers and industry professionals at ‘EuroShop 2024 – the leading trade fair for retail technology’ which takes place in Düsseldorf, Germany from ...

Thumbnail-Photo: Record numbers for ITL at EuroCIS retail show in Düsseldorf...
07.03.2024   #self-checkout systems #POS software

Record numbers for ITL at EuroCIS retail show in Düsseldorf

Innovative Technology (ITL) reported a successful EuroCIS in Düsseldorf last week, where the organisers announced record visitor numbers. EuroCIS provides an exclusive hotspot for Retail Technology in Europe, ...

Thumbnail-Photo: Ask the Bot: generative AI in retail
02.01.2024   #Tech in Retail #food retail

Ask the Bot: generative AI in retail

Revolution in retail: the era of generative AI and AI bots

They are able to analyse data, write product descriptions, answer shoppers’ questions or write codes...

Thumbnail-Photo: ‘Problem-solving mission’ with updated Modern Store Framework...
16.02.2024   #Tech in Retail #personnel management

‘Problem-solving mission’ with updated Modern Store Framework

Zebra Technologies will be looking to address challenges with expertise and new solutions at EuroCIS

Zebra Technologies Corporation (NASDAQ: ZBRA), a leading digital solution provider enabling businesses to intelligently connect data, assets, and people, today announced it’s taking the newly enhanced Modern Store framework on a ‘problem ...

Thumbnail-Photo: EuroCIS 2024 - technology special
11.12.2023   #online trading #e-commerce

EuroCIS 2024 - technology special

The latest technology solutions and trends for you and the retail sector

At EuroCIS 2022 from February 27 to 29, 2024, the Leading Trade Fair for Retail Technology, we will be looking at all the important and current topics relating to technology in retail: AI and Machine Learning, Payment, Connected Retail, Seamless Store and Smart Energy Management and many more.

Thumbnail-Photo: SES-imagotag becomes VusionGroup
29.01.2024   #software applications #artificial intelligence

SES-imagotag becomes VusionGroup

A new identity highlighting the broader portfolio of innovative solutions
developed by the Group to solve the major challenges of physical commerce

SES-imagotag (Euronext: SESL, FR0010282822), the global leader in digital solutions for physical commerce, today announced that it has changed its name to VusionGroup. This new name embodies the various product lines and solutions that have enhanced ...

Thumbnail-Photo: New German vending partner for ITL
30.11.2023   #Tech in Retail #cash management

New German vending partner for ITL

Innovative Technology (ITL) have recently announced Bernd Boddart as their latest trading partner

Bernd Boddart will be supplying their cash validation and biometric age verification solutions to the German vending market. Bernd Boddart, based in Mönchengladbach, Germany, have 30 years of experience in the field of coffee machines, table ...

Thumbnail-Photo: Payment as a success factor: more than just paying...
15.01.2024   #Tech in Retail #payment systems

Payment as a success factor: more than just paying

Flashback to 1994: databases and ERP systems, first commercial websites, mobile phones with colour displays, CD-ROMs, Java as a programming language ...

Thumbnail-Photo: First of its kind accessible checkout unveild by Woolworths, creating...
03.01.2024   #Tech in Retail #cashpoints

First of its kind accessible checkout unveild by Woolworths, creating new employment opportunities

Breaking Barriers in Retail: Woolworths' New Checkout Design for Wheelchair Users

In what is believed to be a world first, Woolworths has unveiled an accessible checkout, designed specifically for team members living with a physical disability, including people who use wheelchairs and other mobility aids such as walkers.The first ...

Thumbnail-Photo: Trigo and Netto Announce Autonomous Supermarket with Real-Time Receipt...
24.01.2024   #Tech in Retail #artificial intelligence

Trigo and Netto Announce Autonomous Supermarket with Real-Time Receipt Capability.

‘Final step’ in frictionless shopping drives trust by enabling consumers to view their receipts BEFORE leaving the store
Full size 800m2 grocery supermarket powered by computer vision AI is Europe’s largest retrofitted frictionless store

Trigo, a leading provider of AI computer vision technology that transforms traditional brick-and-mortar retail outlets into digital smart stores, and discount supermarket chain Netto Marken-Discount (also known as Netto), have partnered to launch ...

Supplier

Zebra Technologies Germany GmbH
Zebra Technologies Germany GmbH
Ernst-Dietrich-Platz 2
40882 Ratingen
VusionGroup SA
VusionGroup SA
55 place Nelson Mandela
90000 Nanterre
SALTO Systems GmbH
SALTO Systems GmbH
Schwelmer Str. 245
42389 Wuppertal
Innovative Technology Ltd.
Innovative Technology Ltd.
Innovative Business Park
OL1 4EQ Oldham