{"id":41311,"date":"2019-09-11T12:42:49","date_gmt":"2019-09-11T11:42:49","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=41311"},"modified":"2019-09-18T08:16:49","modified_gmt":"2019-09-18T07:16:49","slug":"managing-cybersecurity-risks-in-the-retail-sector","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/09\/11\/managing-cybersecurity-risks-in-the-retail-sector\/","title":{"rendered":"Managing cybersecurity risks in the retail sector"},"content":{"rendered":"\n<p><strong><em>Organisations operating in the retail sector are responsible for safeguarding huge amounts of customer data and ensuring a secure, smooth shopping experience for those who choose to use online services. The cost of a breach is huge, both financially and reputationally. Shailendra&nbsp;Singh, Chief Information Security Officer \u2013 Capillary Technologies, talks us through some of the main cyber-risks and how these can be addressed. <\/em><\/strong><\/p>\n\n\n\n<p>The retail sector is a prime target for hackers and cybercriminals, and why not?<\/p>\n\n\n\n<p>Look at the sheer volume of data generated on a daily basis. Customers\u2019 personal details along with their credit card numbers make a lucrative target. <\/p>\n\n\n\n<p>However,\nthe retail sector by design is not strongly focused on information and data\nsecurity because their connection to \u2018valuable data\u2019 is not evident. <\/p>\n\n\n\n<p>Information\nis usually and rightly viewed to be a domain involving software and digital\ninteractions while retail has to do with physical products and offline stores. <\/p>\n\n\n\n<p>This is changing rapidly with the advent of online retailing and digitisation of CRM, loyalty and business analytics solutions.<\/p>\n\n\n\n<p><br> Retail giants started using software solutions a long time ago to improve their customer engagement efforts and to improve their sales and margins through advanced data analytics.&nbsp;<\/p>\n\n\n\n<p>With\nthe advent of cloud-based solutions for analytics, CRM, loyalty and e-commerce,\nthe high volume of data and information which resided earlier in discrete form\nin individual stores started being collected and collated in centralised data\nrepositories. <\/p>\n\n\n\n<p>This\npermitted a greater degree of digital processing. Unfortunately, it was not\nalways the case that the data was handled in a secure manner, mostly due to a\ngeneral lack of understanding on how security should be implemented.<\/p>\n\n\n\n<p>This\nproblem of lax security has been resolved to a great extent when the software\nsolution is provided by a software product company. <\/p>\n\n\n\n<p>Security\nis of prime importance for such organisations. In cases where the software is\nbuilt in-house or outsourced to a vendor who is not specialised in providing\nsoftware solutions specifically meant for large enterprise clients, the problem\nof security usually continues to persist.<br>\n<br>\nRetail companies are becoming aware about the dangers involved in ignoring\nsecurity&nbsp; as the impact of breaches have\nbecome more costly in the current market landscape where retail is driven by\nsocial media. <\/p>\n\n\n\n<p>Protecting information and data is not only about protecting\ncompetitive information, but also about protecting brand image in the market. This has caused a significant\nshift in the security focus and expectations of retail organisations, whether\nit is towards in-house solutions or outsourced ones. <\/p>\n\n\n\n<p>The\nretail industry has now become well-aware about information security\ncertifications such as ISO 27001:2013 &amp; PCI DSS, including the role that\nthese certifications play in increasing assurance against security breaches. <\/p>\n\n\n\n<p>Creating\nand promoting a security department within their organisations has become a\ncommon trend even in retail organisations<ins>,<\/ins> where\ntypically such practices were either viewed as unnecessary or excessive.<\/p>\n\n\n\n<p>Another\nmajor factor that has resulted in more security due diligence exercises being\nconducted by retail organisations is that their parent organisation holds a\nwider portfolio of companies, some of which are closely connected to the domain\nof information security. <\/p>\n\n\n\n<p>These\nparent organisations have a greater need for maintaining their brand image\ngiven their wider presence across multiple domains in the industry and hence\nthey are more inclined towards conducting a thorough security due diligence on\ntheir vendor organisations.<\/p>\n\n\n\n<p>Prioritising security alongside other business objectives is highly\nrecommended even for those retail organisations that do not think that\ninformation and security matter to them.<\/p>\n\n\n\n<p>Digitisation has touched every aspect of our world, which means that the potential for an embarrassing security breach exists for almost any and every type of organisation.&nbsp; <br> <\/p>\n\n\n\n<p>Retail\norganisations must consider obtaining information security certifications such\nas ISO 27001:2013 and PCI DSS if their software development and management is\ndone in-house.&nbsp;<\/p>\n\n\n\n<p>Alternately,\nif they outsource such activities or obtain a platform-based solution from an\nexternal vendor, then they must conduct a security due diligence exercise\nannually. <\/p>\n\n\n\n<p>The\nrisk of security breaches exists in every organisation and a vendor that is\nable to adequately provide assurance affirming that they consider security as\nan important business objective for themselves<ins>,<\/ins> is the\none that will usually be able to avoid such embarrassing and costly incidents.<\/p>\n\n\n\n<p><br>\nRetail organisations should also consider including security metrics in their\nown business reviews. These could include numbers related to vulnerabilities\ndiscovered and resolved in the software applications that are being actively\nused, the number of incidents or events that surfaced in given duration. <\/p>\n\n\n\n<p>It\ncan also include whether an active bug bounty program has been implemented and\nif so, then how many bugs were reported and resolved within a given period. It\nshould also review what the risk assessment of the data that is being saved,\nwhether a detailed risk mitigation and business continuity plan exists and\nwhether these plans have been tested.<\/p>\n\n\n\n<p><br>\nRetail organisations should also consider including\nclauses and penalties related to data protection and data privacy in their\nvendor agreements. This ensures that a vendor becomes legally bound to\nprovide adequate measures of security as part of their promised security\ndeliverables. <\/p>\n\n\n\n<p>The retail\nindustry as a whole has been adopting most of the practices that appreciate\nsecurity as an important business objective for them and it is quite likely\nthat those who treat security seriously are the ones that will ultimately\nprevail in the market. <\/p>\n\n\n\n<p>Security\nand privacy consciousness of the general population has been improving rapidly\nin the post EU GDPR world. This industry stands to upset the very audience it\ntargets if security is not treated the way it should be.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Organisations operating in the retail sector are responsible for safeguarding huge amounts of customer data and ensuring a secure, smooth shopping experience for those who choose to use online services. The cost of a breach is huge, both financially and reputationally. Shailendra&nbsp;Singh, Chief Information Security Officer \u2013 Capillary Technologies, talks us through some of the [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":41312,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,809,3629,4320,79],"tags":[8671,7940,6277,4931,494,1530,1544,775,9139,6556,8299],"class_list":["post-41311","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","category-newsletter","category-retail","category-used","tag-capillary","tag-capillary-technologies","tag-chief-information-security-officer","tag-ciso","tag-crm","tag-cybersecurity","tag-data","tag-retail","tag-shailendra-singh","tag-shopping","tag-software"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=41311"}],"version-history":[{"count":8,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41311\/revisions"}],"predecessor-version":[{"id":41329,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/41311\/revisions\/41329"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/41312"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=41311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=41311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=41311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}