Popular now
French consumer watchdog fines Shein €22m over retail breaches 

French consumer watchdog fines Shein €22m over retail breaches 

Footasylum partners with streetwear brand Trapstar

Footasylum partners with streetwear brand Trapstar

Howdens agrees to acquire DIY Kitchens for £390m

Howdens agrees to acquire DIY Kitchens for £390m

Staying one step ahead in retail’s shifting cybersecurity landscape

Staying one step ahead in retail’s shifting cybersecurity landscape

On this episode of Talking Shop I’m joined by Alain Bejjani—former Group CEO of Middle East retail giant Majid Al Futtaim, and author of the definitive new book, NEXT: Leading Through the New Realities. Drawing on his childhood in war-torn Beirut, and his experience steering a $9.5bn dollar retail and lifestyle empire through a global pandemic, Alain brings an unmatched perspective on leadership under pressure. Today, we break down his crisis survival playbook for retailers operating in distress. We discuss why resilience must always outpace efficiency, the four assets a brand must protect at all costs, and how to turn macro-turmoil into a long-term direction that scales.

Register to get free articles

No spam Unsubscribe anytime

Want unlimited access? View Plans

Already have an account? Sign in

New advancements in technology are changing the retail industry in unprecedented ways, further blending the physical and digital worlds and forever evolving customer experience. As the industry changes, so do the methods cybercriminals use to steal sensitive data from companies and consumers.

Prior to 2018, cybersecurity data suggested that the most common type of incident in the retail industry was point of sale (POS) intrusion. This included the remote compromise of POS environments, as well as the corresponding malware and payment card exfiltration. Recent data, however, shows that attackers are now targeting retailers through new and improved methods, leaving retailers scrambling to pick up the pieces after a breach has occurred.

Attack Patterns Are Changing

According to this year’s Verizon Data Breach Investigations Report (DBIR), web application attacks have overtaken POS intrusion as the most common cyberattack. Since 2014, POS breaches have decreased by a factor of 10, while web application breaches are 13 times more likely occur and hit unsuspecting retailers.

So how do cyber threat actors pull off these web attacks?

First, they compromise a website’s payment application, and then install code into the application that will capture customers’ payment card information as they complete their purchases. These are the everyday attacks that don’t necessarily make headlines but have the same consequences. Today’s cybercriminals look for vulnerable e-commerce applications to provide an avenue for efficient and automated attacks. In fact, there are criminal groups that specialize in these types of low-hanging fruit attacks.

What Can Companies Do About It?

To keep data safe, retailers must take appropriate measures to help combat cyberattacks. While there is no end-all solution, here are a few steps companies can take to mitigate risk.

Know the importance of integrity software: Cybercriminals who target web applications aren’t targeting data at rest. Rather, they inject code to capture customer data as it’s entered into web forms. To combat this method, consider adding file integrity software to your malware defenses on payments sites, in addition to patching OS, and payment application code.

Embrace what’s new: Continue to embrace new technologies that make it harder for criminals to use POS terminals as low-hanging fruit. Some considerations are EMV and mobile wallets, or any other method that utilizes a one-time transaction code, as opposed to PAN.

Remember, it’s not just the payment cards: While criminals are often after payment card information, it’s not the only data variety that they consider useful. Rewards programs that can be leveraged for ‘points’ are potential targets, as is your customers’ personal information.

For many retail organizations, especially smaller ones, implementing widespread security measures is neither affordable nor feasible. But each security step, no matter how small, can have highly beneficial impacts when it comes to detecting and deterring cybercriminals. It’s also important is to educate your staff on identifying potential threats. Ensuring that someone in your organization can detect a threat is a simple but valuable start.

In the cybersecurity world, retailers live in the unenviable position of having to consider their own data security as well as that of their many customers. In an increasingly digital age, it’s important to install as many security measures as your company can, but equally important is your awareness of what cybercriminals are after and how they’re doing it. Having an open mind to the newest technologies is an invaluable way to always be one step ahead of would-be attackers.


 Ali Neil, director of International Security Solutions at Verizon

Previous Post
M&S to open 60,000 sq ft store in Nottingham near year

M&S to open 60,000 sq ft store in Nottingham near year

Next Post
Bonmarché enters administration putting 2,900 jobs at risk

Bonmarché enters administration putting 2,900 jobs at risk