Company News • 18.11.2019

Seven password best practices for retailers

Authentication, encryption, administration

No one likes to use passwords, but they are critical to securing access to systems with valuable business data. Retailers, like any other business, should require passwords as part of their security policies to protect POS systems, backroom applications, customer databases, and any other business system.

Whether employees work at the POS, the warehouse, the finance department or on the road connecting to the network through VPN, everyone should follow the password policy to minimize the chance of a cyber-attack or accidental data leak.

Supplier
Logo: apg Solutions EMEA Ltd.

apg Solutions EMEA Ltd.

4 The Drove
BN9 0LA Newhaven
UK
Coloreful sticky notes with passwords on a screen
Source: designer491

The following are seven password best practices every retailer should implement:

1. Require strong passwords or passphrases

Simple passwords are easy to crack, which is why they should include upper and lowercase letters, numbers and symbols. But such combinations are easy to forget, so consider requiring passphrases that employees are more likely to remember. A nonsensical word combination such as grasstiremeet will stick to the user’s mind while being hard to crack.

2. Adopt two-factor authentication

Requiring a second authentication method is always a good idea, especially for access to critical systems. With two-factor policies, users must verify their identities through a code they receive by text or security token. New options are also becoming available, such as biometrics such as thumbprints, facial recognition, and retina scans. As these methods improve, they are likely to become a routine part of authentication procedures.

3. Apply password encryption

A password encryption tool adds a layer of protection by making passwords virtually impossible to crack. Even if a cybercriminal gets a hold of a password while in transit over the network to, say, access a website or cloud resource, the password data would be useless without a decryption key.

4. Limit user privileges

One of the common mistakes businesses make is to allow too many users to access sensitive information. Employees should have access only to the systems they need for their jobs. For instance, no one but cashiers and their managers should have access to the POS application. The same goes for finance, HR and any other specialized business function. The more you limit user privileges, the less likely you are to suffer a security breach.

Login box on a screen
Source: SpiffyJ

5. Use a password manager

Keeping track of multiple passwords is hard enough for users, but when you’re the administrator in charge of password management, it’s even tougher. The use of password management tools helps ease the burden. Password managers provide a secure repository for all passwords and passphrases by encrypting the data. They’re available for users and for administrators who must keep a centralized record of all passwords.

6. Deactivate accounts no longer in use 

A key component of any password policy is to make sure accounts of employees who leave the company are immediately closed. That way, former employees cannot access company systems.

7. Publish the password policy 

Simply having a policy won’t get you far. It should be disseminated to all employees, either as part of a comprehensive security policy or as a standalone. It should outline what types of passwords to use and which not to use, and how frequently employees must change them. It also should include common-sense rules such as a prohibition against sharing or reusing passwords.

Enforcing strong password policies is crucial because stolen and weak passwords are a common cause of security breaches. While requiring passwords can be a drag for users, the reality is they’re unavoidable. And if you successfully make the case for why passwords are so critical, users are more likely to embrace them.

related articles:

popular articles:

Thumbnail-Photo: Glory receives 2024 Red Dot award for Product Design...
09.07.2024   #customer experience #design

Glory receives 2024 Red Dot award for Product Design

Glory’s new CI-X Series of retail cash recycling solutions have been awarded a “Red Dot Design Award 2024”, in the product design category.

The Red Dot Award is an international product design award for new products that demonstrate innovation and impact ...

Thumbnail-Photo: Mystery box vending machines: Surprise pack with a success factor?...
14.08.2024   #e-commerce #customer experience

Mystery box vending machines: Surprise pack with a success factor?

New trend tested by iXtenso

Vienna, Berlin, Hamburg, Cologne: mystery boxes or vending machines are popping up in more and more places. The promise: Thrills and spills for little money; after all, you don't know what you're going to get. Reason enough for the iXtenso ...

Thumbnail-Photo: E-commerce in transition? Trends and challenges for retailers...
02.10.2024   #customer experience #artificial intelligence

E-commerce in transition? Trends and challenges for retailers

How Douglas, Shopify, Kapten & Son/Charles and Google see the current market

Representatives from Douglas, Shopify, Kapten & Son/Charles and Google discussed the new challenges and opportunities ...

Thumbnail-Photo: More than just inspiration: What makes Pinterest a successful...
29.08.2024   #customer experience #fashion

More than just inspiration: What makes Pinterest a successful performance marketing channel?

How to reach targeted customers and influence their purchasing decisions

Mit über 580 Millionen aktiven Nutzenden weltweit bietet Pinterest eine gewaltige Reichweite und wächst weiter. Besonders die Gen-Z hebt ...

Supplier

GLORY Global Solutions (Germany) GmbH
GLORY Global Solutions (Germany) GmbH
Thomas-Edison-Platz 1
63263 Neu-Isenburg