More people are shopping online than ever before due to the pandemic. Therefore, businesses had to take extra steps to protect customer data, combat fraud and implement the latest in online safety. In 2020, e-commerce retail sales jumped from 16% to 19%, according to data from United Nations trade and development experts from UNCTAD.

In the U.S., online retail sales jumped 32.4% year-over-year in 2020. The trend continued with a 39% increase in Q1 2021. Reports from IBM’s U.S. Retail Index showed the pandemic sped up the shift away from brick-and-mortar stores by five years. Consumers began to shop for items from school supplies to clothing online.

Retailers are working harder than ever to protect consumers’ data. However, this doesn’t mean they should let up at the point of sale (POS), either.

Check out our tips to help e-commerce and brick-and-mortar retailers protect customer data and their own financial interests from retail cyber attacks. After all, it’s good for businesses to prepare for challenges in the years ahead.

Briefs and Top Insights

🕒  3-minute read

The Shift to E-Commerce: How Retail Cybersecurity Is Changing 

Knowing the threats related to e-commerce security and customer data can help you combat malware and ransomware attacks. It also keeps you aware of data breaches that can threaten your customers’ personally identifiable information and money. BDO International found 57% of retail business owners said that bolstering retail cybersecurity ranked in their top three short-term business goals. However, only about 40% listed it in long-term business goals. Taking a far-sighted approach to digital safety, which includes choosing the right platform for your business, can help you stay ahead of attackers.

Other customer data best practices include:

  • Segment your network to keep customer data safe within separate buckets
  • Install the right malware detection solution across your network, without neglecting POS security
  • Invest in threat intelligence systems.

🕒  4-minute read

Retail Cybersecurity: How to Protect Your Customer Data 

Personalization through artificial intelligence leads to better customer experiences online and more relevant product recommendations. However, increased amounts of customer data also lead to more for attackers to steal in a retail data breach.

To best protect crucial information, first consider each type of data in various buckets. Next, determine its physical location and the best ways to secure it. Deloitte divides customer data into four types:

  • Account, including customer name and address
  • Location, including geographic data and IP addresses
  • Browser data, including the customer’s history
  • Profile, demographics and social media data collected from third-party sites.

Once you’ve found and sorted the different types of data, you can take the following steps to protect it, online and off:

  • Encrypt data, both from online and brick-and-mortar sales
  • Ensure your POS system is updated, including enabling chip and PIN and digital wallet sales
  • Train employees on the importance of securing passwords, not connecting their own mobile devices to your store’s network and how to spot an attack in progress.

🕒  3-minute read

CISO of Major UK Retailer Weighs In on Enterprise IoT Security 

Threats in the retail industry extend beyond customer data security online and in POS transactions. Simon Langley, CISO of UK grocery retailer Morrisons, discussed some of the threats facing businesses adopting Internet of Things (IoT) devices. Reports say that growing numbers of businesses will face attacks that come through the IoT, including through employees’ own digital assistants and other IoT devices.

AI and machine learning stand as possible ways to combat the threat, along with increased efforts to detect anomalies and unmanaged devices on the network. Proactive risk management of IoT devices can help chief information security officers (CISOs) not just combat IoT attacks but also innovate new ways to protect against any security risks in the retail environment.

More on Customer Data Security From Around the Web

2020 Sees Huge Increase in Records Exposed in Data Breaches

Although the number of data breaches in 2020 dropped by nearly half (48%), they exposed more than 37 billion records, spotlighting a need for enhanced cybersecurity measures as more consumers shop online.

Nearly Half of Retailers Hit by Ransomware in 2020

Ransomware attacks may not be the most costly of customer data security threats, but they are on the rise, especially in the retail sector.

COVID-19’s Impact on the Future of IT Budgets

IT spending in the retail sector could drop by as much as 15% in the aftermath of the global pandemic. CISOs will need to spend smartly and do more with less.

More from Identity & Access

X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon

4 min read - Every year, IBM X-Force analysts assess the data collected across all our security disciplines to create the IBM X-Force Threat Intelligence Index, our annual report that plots changes in the cyber threat landscape to reveal trends and help clients proactively put security measures in place. Among the many noteworthy findings in the 2024 edition of the X-Force report, three major trends stand out that we’re advising security professionals and CISOs to observe: A sharp increase in abuse of valid accounts…

Web injections are back on the rise: 40+ banks affected by new malware campaign

8 min read - Web injections, a favored technique employed by various banking trojans, have been a persistent threat in the realm of cyberattacks. These malicious injections enable cyber criminals to manipulate data exchanges between users and web browsers, potentially compromising sensitive information. In March 2023, security researchers at IBM Security Trusteer uncovered a new malware campaign using JavaScript web injections. This new campaign is widespread and particularly evasive, with historical indicators of compromise (IOCs) suggesting a possible connection to DanaBot — although we…

Taking the complexity out of identity solutions for hybrid environments

4 min read - For the past two decades, businesses have been making significant investments to consolidate their identity and access management (IAM) platforms and directories to manage user identities in one place. However, the hybrid nature of the cloud has led many to realize that this ultimate goal is a fantasy. Instead, businesses must learn how to consistently and effectively manage user identities across multiple IAM platforms and directories. As cloud migration and digital transformation accelerate at a dizzying pace, enterprises are left…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today