The Do’s and Don’ts of cybersecurity for retailers

The Do’s and Don’ts of cybersecurity for retailers

With $4.45 billion spent during a major online shopping weekend in November 2015 alone (Fortune), it’s clear that the need for retailers to safeguard credit card data, consumer data, transactions and other sensitive data is becoming ever more pressing. Such a large volume of critical data is passed between various points every second, making it essential for the infrastructure to be protected from end to end.

To overcome this, Paul German, VP EMEA, Certes Networks gives five essential Do’s and Don’ts for retailers to keep in mind when putting strategies in place to keep customer data protected from the hackers.

Don’t: Assume your system is safe
Do: Accept a breach is going to happen

Breaches are happening all the time. It’s an unfortunate fact, but one that retailers must come to terms with: data breaches are inevitable. The amount of data breaches hitting the hacking headlines this year alone shows that retailers need to accept that hackers will get in, and instead should focus on using crypto-segmentation strategies to limit what the hackers can access. Don’t: Rely on breach detection and protection policies alone
Do: Focus on breach containment to keep the hackers at bay

With the acceptance that breaches are going to occur must come the recognition that breach protection and detection policies are no longer enough to keep the hackers out. Instead, retailers must open up to the world of breach containment, a strategy that focuses on limiting the scope of a breach by containing it to a single segment of the network, instead of leaving the hackers to move laterally throughout the system at their leisure. Don’t: Define your software strategy by the network
Do: Make security application and user specific

Long gone are the days where it’s acceptable for an effective security strategy to focus purely on the network. Instead, modern, software-defined security positions the security policies and protection functions around applications and users, which, in a retail environment, means only giving access to customer data to those that need it. For example, a sales transaction and the accompanying payment card and consumer data should be accessible to only the authorised sales person conducting the transaction. The company logistics managers, corporate managers, HVAC contractors and others do not need access to the transaction data. Yet the primary security model used by retailers has no effective isolation of the payment card application. In breach after breach, hackers have compromised a user unrelated to the payment card systems, then moved laterally to get to the payment card information. Don’t: Focus security on individual silos
Do: Manage security end to end across all silos

The enterprise IT environment is fragmented across many silos, includ–ing LAN, WAN, Internet, mobile, Wi-Fi, cloud, data centre, remote facilities, disaster recovery and backup and others. Each of these silos has its own method of application protection and access controls, and is commonly managed by separate teams in the enterprise. What’s more, enforcing consistent policies and protection from end to end across all these zones is enormously difficult given the fragmented nature of the technologies and teams. To combat this, a strategy is needed that enforces protection and policies horizontally across all silos, requiring no changes to the network or applications, and putting all control in the hands of the security manager. Don’t: Allow any network to be trusted
Do: Put in place segmentation and isolation to protect applications on all networks

The multiple hacks of 2015 show retailers must adopt a “No Trust” security model, which assumes that there is no such thing as a trusted network or IT environment. Instead, every user, device, network and application must be treated as untrusted, and all enterprise systems should be considered already compromised. Additionally, applications must be segmented, which simply means that an isolation method such as encryption is used to isolate the application flow and prevent access by unauthorised users. However, the most effective approach is to isolate the sensitive data with strong cryptography and tightly control access to it based on user roles. This segmentation should then be applied consistently across all silos, for all users in the enterprise.

An effective cybersecurity strategy needn’t be complicated; however, it’s about knowing which strategies are effective and which approaches to take in order to protect valuable customer data and avoid the PR catastrophes faced by many retailers in the ongoing wave of headline-grabbing data breaches.

[su_button url=”http://certesnetworks.com/” target=”blank” background=”#df2027″ color=”#ffffff” size=”10″ radius=”0″ icon=”icon: arrow-circle-right”]Click here to find out more about Certes Networks[/su_button]

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Graphic displaying a lockdown solution

Netgenium debuts next gen display and touchscreen technologies

Power-over-Ethernet (PoE) solutions specialist Netgenium will be showcasing its new range of IP…

ICT® Launches New TSL Access Reader Series

Integrated Control Technology (ICT®), a leading manufacturer of intelligent access control and…
Image Provided by Paxton

Paxton Partners with Skills for Security

The security technology manufacturer Paxton is proud to announce a partnership with Skills for Security…
Image Provided by ICT

ICT and Ingram Micro sign distribution agreement MEA

Integrated Control Technology (ICT), award-winning global manufacturer of intelligent electronic access control and security solutions..
Image Provided by Toshiba

Toshiba launches new HDD Innovation Lab

Toshiba Electronics Europe GmbH (Toshiba) has inaugurated a new HDD Innovation Laboratory (HDD Innovation Lab) at its site in Düsseldorf..
Image Provided by Verkada

Verkada Doubles Down on the Channel with Strategic New Hire

Verkada, a leader in cloud-based physical security, today announced the appointment of Micah Deriso as Head of Global Channel…
Image Provided by IPSA

IPSA Appoint Frontline Hero as Ambassador

Abdullah, the courageous security officer praised for foiling a horrific knife attack at Leicester Square, has been appointed as…
Image Provided by Codelocks

New Surface Latch from Codelocks

Codelocks is expanding its Gate Solutions by Codelocks range with the introduction of the new Codelocks’ Surface Latch…
Image provided by Genetec

Nicholas Smith to Lead Genetec UK and Ireland Operations

Genetec, provider of enterprise physical security software, announced the appointment of Nicholas Smith as its new Regional Sales Director…

News Desk

View all the latest, product, project and people news

News Desk

Click Here

Technology News

Keep up-to-date with the latest product innovation

Technology News

Click Here

Industry Sectors

Discover technology in action in all applications

Industry Sectors

Click Here

Enter The Awards

Showcase personal or organisation excellence

Advertise With Us

Reach decision makers and amplify your marketing

Advertise With Us

Click Here
Scroll to Top