More people are shopping online than ever before due to the pandemic. Therefore, businesses had to take extra steps to protect customer data, combat fraud and implement the latest in online safety. In 2020, e-commerce retail sales jumped from 16% to 19%, according to data from United Nations trade and development experts from UNCTAD.

In the U.S., online retail sales jumped 32.4% year-over-year in 2020. The trend continued with a 39% increase in Q1 2021. Reports from IBM’s U.S. Retail Index showed the pandemic sped up the shift away from brick-and-mortar stores by five years. Consumers began to shop for items from school supplies to clothing online.

Retailers are working harder than ever to protect consumers’ data. However, this doesn’t mean they should let up at the point of sale (POS), either.

Check out our tips to help e-commerce and brick-and-mortar retailers protect customer data and their own financial interests from retail cyber attacks. After all, it’s good for businesses to prepare for challenges in the years ahead.

Briefs and Top Insights

🕒  3-minute read

The Shift to E-Commerce: How Retail Cybersecurity Is Changing 

Knowing the threats related to e-commerce security and customer data can help you combat malware and ransomware attacks. It also keeps you aware of data breaches that can threaten your customers’ personally identifiable information and money. BDO International found 57% of retail business owners said that bolstering retail cybersecurity ranked in their top three short-term business goals. However, only about 40% listed it in long-term business goals. Taking a far-sighted approach to digital safety, which includes choosing the right platform for your business, can help you stay ahead of attackers.

Other customer data best practices include:

  • Segment your network to keep customer data safe within separate buckets
  • Install the right malware detection solution across your network, without neglecting POS security
  • Invest in threat intelligence systems.

🕒  4-minute read

Retail Cybersecurity: How to Protect Your Customer Data 

Personalization through artificial intelligence leads to better customer experiences online and more relevant product recommendations. However, increased amounts of customer data also lead to more for attackers to steal in a retail data breach.

To best protect crucial information, first consider each type of data in various buckets. Next, determine its physical location and the best ways to secure it. Deloitte divides customer data into four types:

  • Account, including customer name and address
  • Location, including geographic data and IP addresses
  • Browser data, including the customer’s history
  • Profile, demographics and social media data collected from third-party sites.

Once you’ve found and sorted the different types of data, you can take the following steps to protect it, online and off:

  • Encrypt data, both from online and brick-and-mortar sales
  • Ensure your POS system is updated, including enabling chip and PIN and digital wallet sales
  • Train employees on the importance of securing passwords, not connecting their own mobile devices to your store’s network and how to spot an attack in progress.

🕒  3-minute read

CISO of Major UK Retailer Weighs In on Enterprise IoT Security 

Threats in the retail industry extend beyond customer data security online and in POS transactions. Simon Langley, CISO of UK grocery retailer Morrisons, discussed some of the threats facing businesses adopting Internet of Things (IoT) devices. Reports say that growing numbers of businesses will face attacks that come through the IoT, including through employees’ own digital assistants and other IoT devices.

AI and machine learning stand as possible ways to combat the threat, along with increased efforts to detect anomalies and unmanaged devices on the network. Proactive risk management of IoT devices can help chief information security officers (CISOs) not just combat IoT attacks but also innovate new ways to protect against any security risks in the retail environment.

More on Customer Data Security From Around the Web

2020 Sees Huge Increase in Records Exposed in Data Breaches

Although the number of data breaches in 2020 dropped by nearly half (48%), they exposed more than 37 billion records, spotlighting a need for enhanced cybersecurity measures as more consumers shop online.

Nearly Half of Retailers Hit by Ransomware in 2020

Ransomware attacks may not be the most costly of customer data security threats, but they are on the rise, especially in the retail sector.

COVID-19’s Impact on the Future of IT Budgets

IT spending in the retail sector could drop by as much as 15% in the aftermath of the global pandemic. CISOs will need to spend smartly and do more with less.

More from Identity & Access

Kronos Malware Reemerges with Increased Functionality

The Evolution of Kronos Malware The Kronos malware is believed to have originated from the leaked source code of the Zeus malware, which was sold on the Russian underground in 2011. Kronos continued to evolve and a new variant of Kronos emerged in 2014 and was reportedly sold on the darknet for approximately $7,000. Kronos is typically used to download other malware and has historically been used by threat actors to deliver different types of malware to victims. After remaining…

An IBM Hacker Breaks Down High-Profile Attacks

On September 19, 2022, an 18-year-old cyberattacker known as "teapotuberhacker" (aka TeaPot) allegedly breached the Slack messages of game developer Rockstar Games. Using this access, they pilfered over 90 videos of the upcoming Grand Theft Auto VI game. They then posted those videos on the fan website GTAForums.com. Gamers got an unsanctioned sneak peek of game footage, characters, plot points and other critical details. It was a game developer's worst nightmare. In addition, the malicious actor claimed responsibility for a…

What is the Future of Password Managers?

In November 2022, LastPass had its second security breach in four months. Although company CEO Karim Toubba assured customers they had nothing to worry about, the incident didn’t inspire confidence in the world’s leading password manager application. Password managers have one vital job: keep your sensitive login credentials secret, so your accounts remain secure. When hackers compromise these software applications, the entire industry of identity and access management (IAM) takes notice. As an alliance of tech giants leads a global push…

Beware of What Is Lurking in the Shadows of Your IT

This post was written with contributions from Joseph Lozowski. Comprehensive incident preparedness requires building out and testing response plans that consider the possibility that threats will bypass all security protections. An example of a threat vector that can bypass security protections is “shadow IT” and it is one that organizations must prepare for. Shadow IT is the use of any hardware or software operating within an enterprise without the knowledge or permission of IT or Security. IBM Security X-Force responds…