More people are shopping online than ever before due to the pandemic. Therefore, businesses had to take extra steps to protect customer data, combat fraud and implement the latest in online safety. In 2020, e-commerce retail sales jumped from 16% to 19%, according to data from United Nations trade and development experts from UNCTAD.

In the U.S., online retail sales jumped 32.4% year-over-year in 2020. The trend continued with a 39% increase in Q1 2021. Reports from IBM’s U.S. Retail Index showed the pandemic sped up the shift away from brick-and-mortar stores by five years. Consumers began to shop for items from school supplies to clothing online.

Retailers are working harder than ever to protect consumers’ data. However, this doesn’t mean they should let up at the point of sale (POS), either.

Check out our tips to help e-commerce and brick-and-mortar retailers protect customer data and their own financial interests from retail cyber attacks. After all, it’s good for businesses to prepare for challenges in the years ahead.

Briefs and Top Insights

🕒  3-minute read

The Shift to E-Commerce: How Retail Cybersecurity Is Changing 

Knowing the threats related to e-commerce security and customer data can help you combat malware and ransomware attacks. It also keeps you aware of data breaches that can threaten your customers’ personally identifiable information and money. BDO International found 57% of retail business owners said that bolstering retail cybersecurity ranked in their top three short-term business goals. However, only about 40% listed it in long-term business goals. Taking a far-sighted approach to digital safety, which includes choosing the right platform for your business, can help you stay ahead of attackers.

Other customer data best practices include:

  • Segment your network to keep customer data safe within separate buckets
  • Install the right malware detection solution across your network, without neglecting POS security
  • Invest in threat intelligence systems.

🕒  4-minute read

Retail Cybersecurity: How to Protect Your Customer Data 

Personalization through artificial intelligence leads to better customer experiences online and more relevant product recommendations. However, increased amounts of customer data also lead to more for attackers to steal in a retail data breach.

To best protect crucial information, first consider each type of data in various buckets. Next, determine its physical location and the best ways to secure it. Deloitte divides customer data into four types:

  • Account, including customer name and address
  • Location, including geographic data and IP addresses
  • Browser data, including the customer’s history
  • Profile, demographics and social media data collected from third-party sites.

Once you’ve found and sorted the different types of data, you can take the following steps to protect it, online and off:

  • Encrypt data, both from online and brick-and-mortar sales
  • Ensure your POS system is updated, including enabling chip and PIN and digital wallet sales
  • Train employees on the importance of securing passwords, not connecting their own mobile devices to your store’s network and how to spot an attack in progress.

🕒  3-minute read

CISO of Major UK Retailer Weighs In on Enterprise IoT Security 

Threats in the retail industry extend beyond customer data security online and in POS transactions. Simon Langley, CISO of UK grocery retailer Morrisons, discussed some of the threats facing businesses adopting Internet of Things (IoT) devices. Reports say that growing numbers of businesses will face attacks that come through the IoT, including through employees’ own digital assistants and other IoT devices.

AI and machine learning stand as possible ways to combat the threat, along with increased efforts to detect anomalies and unmanaged devices on the network. Proactive risk management of IoT devices can help chief information security officers (CISOs) not just combat IoT attacks but also innovate new ways to protect against any security risks in the retail environment.

More on Customer Data Security From Around the Web

2020 Sees Huge Increase in Records Exposed in Data Breaches

Although the number of data breaches in 2020 dropped by nearly half (48%), they exposed more than 37 billion records, spotlighting a need for enhanced cybersecurity measures as more consumers shop online.

Nearly Half of Retailers Hit by Ransomware in 2020

Ransomware attacks may not be the most costly of customer data security threats, but they are on the rise, especially in the retail sector.

COVID-19’s Impact on the Future of IT Budgets

IT spending in the retail sector could drop by as much as 15% in the aftermath of the global pandemic. CISOs will need to spend smartly and do more with less.

More from Identity & Access

Another category? Why we need ITDR

5 min read - Technologists are understandably suffering from category fatigue. This fatigue can be more pronounced within security than in any other sub-sector of IT. Do the use cases and risks of today warrant identity threat detection and response (ITDR)? To address this question, we work backwards from the vulnerabilities, threats, misconfigurations and attacks that IDTR specializes in providing visibility into. As identity threat detection and response (ITDR) technology evolves, one of the most common queries we get is: “Why do we need…

Access control is going mobile — Is this the way forward?

2 min read - Last year, the highest volume of cyberattacks (30%) started in the same way: a cyber criminal using valid credentials to gain access. Even more concerning, the X-Force Threat Intelligence Index 2024 found that this method of attack increased by 71% from 2022. Researchers also discovered a 266% increase in infostealers to obtain credentials to use in an attack. Family members of privileged users are also sometimes victims.“These shifts suggest that threat actors have revalued credentials as a reliable and preferred…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today