Taking a Neighborhood Watch Approach to Retail Cybersecurity

Threatpost

Bugcrowd CTO Casey Ellis covers new cybersecurity challenges for online retailers.

Retail Privacy Network

Data Matters

You are invited to join privacy professionals in the retail sector for topical conversation, learning and networking at the first Retail Privacy Network meeting. This interactive meeting will include hot topics in UK/EU data privacy and cybersecurity with practical case studies on retail industry issues. The post Retail Privacy Network appeared first on Data Matters Privacy Blog.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

ThreatList: Most Retail Hardware Bug Bounty Flaws Are Critical

Threatpost

Overall, across all retail programs, more than 18 percent of all bug bounty submissions are critical in severity, a new Bugcrowd report found. IoT Mobile Security Most Recent ThreatLists bug bounty Bugcrowd Bugcrowd’s 2019 State of Retail Cybersecurity report point of sale retail Retail Security

Hunton Publishes 2020 Retail Industry Year in Review

Hunton Privacy

This is an extraordinary and unprecedented time for the retail industry. Hunton Andrews Kurth’s 2020 Retail Industry Year in Review provides an in-depth analysis of the issues and challenges that retailers faced in the past year, and a look ahead at what they can expect in 2021.

ThreatList: Cyber Monday Looms – But Shoppers Oblivious to Top Retail Threats

Threatpost

Malware Most Recent ThreatLists Web Security black friday cisa alert coronavirus COVID-19 credit cart skimmer cyber monday Cybersecurity digital payment skimmer holiday shopping magecart malicious app online shopping top cyber threats

Securing Retail Networks for an Omnichannel Future

Dark Reading

Retailers who haphazardly move to digital from a brick-and-mortar environment can leave their businesses open to significant cybersecurity vulnerabilities. Here's how to avoid the pitfalls

Retail Banks’ Lofty Goals and Where to Start

InfoGoTo

Retail banks in the United States face a whole host of challenges including customer confidence, regulatory compliance, attracting new customers, cybersecurity, utilizing big data and mastering social media, to name a few. Given these challenges, it’s not so surprising that retail banks would align their priorities with these challenges. This is why being able to successfully execute big data and advanced analytics is so important for retail banks.

CGI Client Global Insights: A look at top retail banking trends and priorities

CGI

CGI Client Global Insights: A look at top retail banking trends and priorities. We summarize the findings and insights from these discussions in the CGI Client Global Insights retail banking report.

Hunton Publishes Retail Year in Review

Hunton Privacy

On January 18, 2018, Hunton & Williams LLP’s retail industry lawyers, composed of more than 100 lawyers across practices, released their annual Retail Year in Review publication. The Retail Year in Review includes several articles authored by our Global Privacy and Cybersecurity lawyers, and touches on many topics of interest including blockchain, ransomware, cyber insurance and the Internet of Things.

Record Levels of Software Bugs Plague Short-Staffed IT Teams in 2020

Threatpost

retailers have vulnerabilities which pose an “imminent” cyber-threat, including Amazon, Costco, Kroger and Walmart. As just one symptom, 83 percent of the Top 30 U.S.

IT 93

Cybersecurity Insurance

Schneier on Security

Companies like retailers, banks, and healthcare providers began seeking out cyberinsurance in the early 2000s, when states first passed data breach notification laws. breaches cybersecurity insuranceGood article about how difficult it is to insure an organization against Internet attacks, and how expensive the insurance is.

Is Your Cybersecurity Ready for the Holidays?

Adam Levin

Retailers around the world are anticipating less foot traffic in their shops this holiday season, with more than 75% of consumers expected to do most of their shopping online due to the pandemic. The post Is Your Cybersecurity Ready for the Holidays?

Are Data Breaches the New Reality for Retail?

Thales Cloud Protection & Licensing

As digital transformation takes hold, the retail industry is under siege from cyber criminals and nation states attempting to steal consumers’ personal information, credit card data and banking information. While retailers digitally transform their businesses to better serve the higher demands of their customers, they’re being challenged with safeguarding personal data to protect customers, partners and suppliers’ critical information.

The Anti-Tom’s Guide to Reckless Holiday Shopping

MediaPro

Blog Confessions of an Awareness Nerd Foundational Security Awareness Thought Leadership cybersecurity online shopping retail scams security awareness security awareness trainingThe post The Anti-Tom’s Guide to Reckless Holiday Shopping appeared first on MediaPRO.

Home Depot Settles 2014 Breach Lawsuit for $17.5 Million

Data Breach Today

Home Supply Retailer Must Also Implement Several Cybersecurity Protocols The Home Depot reached a $17.5 million settlement in a class-action lawsuit stemming from a 2014 data breach that compromised the payment card data of 40 million of the retailer's customers.

Retail 231

How To Keep Cybersecure Over the Holidays

Adam Levin

An enormous number of people are footloose and fancy free when it comes to their interactions with retailers over the holiday season,” says Cyberscout founder and chairman Adam Levin. How to Be Cybersecure in Virtual Family Gatherings.

Lessons for In-House Counsel from Cybersecurity’s Front Lines

HL Chronicle of Data Protection

Recent developments reinforce the urgent need for general counsel and legal departments to deepen their focus on cybersecurity. Lessons for In-House Counsel from Cybersecurity’s Front Lines was written by members of the Hogan Lovells Privacy and Cybersecurity practice Peter M. In today’s environment, any organization can be the target of a cyberattack, regardless of industry, size, or geographic footprint.

The Cost of Dealing With a Cybersecurity Attack in These 4 Industries

Security Affairs

A cybersecurity issue can cause unexpected costs in several different areas, which is the cost of Dealing with an attack in 4 Industries? A cybersecurity issue can cause unexpected costs in several different areas. And, the costs go up if the health care facility does not have a cybersecurity response plan to use after an attack gets identified. Retail. Statistics from 2016 showed that the average cost per compromised retail record was $172.

National Cybersecurity Alliance advocates ‘shared responsibility’ for securing the Internet

The Last Watchdog

NCSA operates the StaySafeOnline website that provides a variety of cybersecurity educational resources and programs. Schrader: We are a leading nonpartisan, nonprofit group that’s very involved as a convener of experts to talk about a number of the top issues in cybersecurity. We also have a lot of educational programs that reach far beyond the insular, cybersecurity expert areas. A large retailer may spend millions on cyber security. The targeting of Sen.

Port Covington, MD re-emerges as ‘CyberTown, USA’ — ground zero for cybersecurity research

The Last Watchdog

When CyberTown, USA is fully built out, it’s backers envision it emerging as the world’s premier technology hub for cybersecurity and data science. DataTribe , a Fulton, MD-based cybersecurity startup incubator, has been a key backer of this ambitious urban redevelopment project , which broke ground last October in Port Covington, MD, once a bustling train stop on the south side of Baltimore.

MY TAKE: Michigan’s cybersecurity readiness initiatives provide roadmap others should follow

The Last Watchdog

or MEDC, I’m prepared to rechristen Michigan the Cybersecurity Best Practices State. My reporting trip included meetings with Michigan-based cybersecurity vendors pursuing leading-edge innovations, as well as a tour of a number of thriving public-private cybersecurity incubator and training programs. What’s noteworthy, from my perspective, is that Snyder had the foresight to make cybersecurity readiness a key component of his reinvent Michigan strategy, from day one.

The Ecommerce Surge: Guarding Against Fraud

Data Breach Today

As more consumers shift to online shopping during the COVID-19 pandemic, retailers must ramp up their efforts to guard against ecommerce payment fraud, says Toby McFarlane, a cybersecurity expert at CMSPI, a payments consultancy

Retail 160

UK ICO Issues Unprecedented Fine Against Mobile Phone Retailer for Lax Security

Hunton Privacy

On January 8, 2017, the UK Information Commissioner (“ICO”) issued an unprecedented monetary penalty of £400,000 against British mobile phone retailer, The Car Phone Warehouse Limited. Cybersecurity Enforcement International Security Breach Encryption EU Regulation Information Commissioners Office Penalty Personal Data Privacy United Kingdom

From channel to customer: How an omni-channel experience is the key to the retail industry’s success

CGI

From channel to customer: How an omni-channel experience is the key to the retail industry’s success. Is the hype around the retail store being dead simply that, hype? Retailers that are thriving in today’s disrupted and highly competitive environment have transformed the role of the brick-and-mortar store to effectively bridge the gap between the physical and digital worlds. One of the largest sporting goods retailers is a good case in point.

Cybersecurity Identified as an SEC OCIE Examination Priority for 2018

Data Matters

On February 7, 2018, the SEC’s Office of Compliance Inspections and Examinations (OCIE) released its 2018 National Exam Program Examination Priorities (2018 Exam Priorities) and, once again, identified cybersecurity as one of its main areas of focus. According to OCIE, each of its examination programs will prioritize cybersecurity. OCIE emphasized the “critical” importance of cybersecurity protection to market operation and the far-reaching effects of cyber threats.

4 Industries That Have to Fight the Hardest Against Cyberattacks

Security Affairs

Recent demonstrations from cybersecurity researchers have shown how it’s possible to hack into medical devices like pacemakers or insulin pumps. So, if nonprofit leaders want to devote more money to cybersecurity, they may feel too financially strapped to make meaningful progress. Also, nonprofits may feel overwhelmed about where to start as they learn about cybersecurity. Retail. Despite those risks, retailers make blunders when budgeting for cybersecurity.

Cybersecurity impact of Covid-19: Q&A with CISO Myke Lyons

Collibra

So we took a moment to ask our CISO Myke Lyons his thoughts on the cybersecurity impact of Covid-19. Prior to coronavirus, how would you describe the global state of cybersecurity? The post Cybersecurity impact of Covid-19: Q&A with CISO Myke Lyons appeared first on Collibra.

Recent Risk Alerts by SEC OCIE Highlight Privacy and Cybersecurity Issues in Examinations

Data Matters

The SEC’s Office of Compliance Inspections and Examinations (OCIE) released two Risk Alerts, on April 16, 2019 and May 23, 2019, highlighting the importance of privacy and cybersecurity compliance for SEC-registered investment advisors and broker-dealers under Regulation S-P. As previously covered on Data Matters, OCIE has consistently identified cybersecurity as one of its main areas of focus for examinations. Cybersecurity Enforcement Financial Privacy SEC

Joker's Stash Advertises Second Batch of Indian Card Data

Data Breach Today

Haul of 460,000 Bank Cards Retailing for $4.2

Retail 170

Spotlight Podcast: At 15 Cybersecurity Awareness Month Grows with Cyber Risk

The Security Ledger

In this Spotlight Podcast, sponsored by RSA: October is Cybersecurity Awareness Month. But what does that mean in an era when concerns about cybersecurity permeate every facet of our personal and professional lives? Russ Schrader of the National Cybersecurity Alliance (NCSA) and Angel Grant of RSA join us to discuss the history of Cybersecurity. » Related Stories Spotlight Podcast: 15 Years Later Is Cybersecurity Awareness Month Working?

RH-ISAC's Role in Countering Threats

Data Breach Today

Tommy McDowell, Vice President, on the Value of Information Sharing In response to large data breaches, the retail and hospitality industry formed the RH-ISAC to serve as a central hub for sharing sector-specific cybersecurity information and intelligence, says Tommy McDowell, vice president, who explains how ISACs' roles are changing

Retail 144

SEC and FINRA Issue 2020 Examination Priorities (Including Cybersecurity) for Broker-Dealers and Investment Advisers

Data Matters

OCIE’s 2020 Examination Priorities for broker-dealers and investment advisers include the protection of retail investors (including compliance with new standard of care requirements and interpretations), cyber and information security risks, anti-money laundering compliance, firms engaging in the digital asset space and the provision of electronic investment advice. Protection of Retail Investors . Retail-Targeted Investments. Cybersecurity. The U.S.

2018 Predictions – Rise of IoT adoption will increase cybersecurity attacks

Thales Cloud Protection & Licensing

With 2018 approaching, I have been thinking about what will happen in the cybersecurity landscape and would like to make some predictions for the year ahead. For example, Apple Pay is already potentially limitless, although most retailers will have a maximum spend of about 40 dollars, which is linked to the liability that most issuers are prepared to accept for a single transaction.

IoT 75

The Rise of “Bulletproof” Residential Networks

Krebs on Security

In late April 2019, KrebsOnSecurity received a tip from an online retailer who’d seen an unusual number of suspicious transactions originating from a series of Internet addresses assigned to a relatively new Internet provider based in Maryland called Residential Networking Solutions LLC. All too often, it seems, the people who profit the most in this scheme are using multiple sets of compromised credentials from consumer accounts at online retailers, and/or stolen payment card data.

Retail 187

50 Ways to Avoid Getting Scammed on Black Friday

Adam Levin

It’s worth noting that there’s no reason a legitimate retailer would need that last one — the skeleton key to your identity — to process a purchase.). Shop at reputable and recognizable retailers. Check urls for slight modifications to a popular retailer’s name.

E-Skimming Strikes Again: Macy’s Confirms Magecart Data Breach

Adam Levin

In a letter to affected customers, the retailer said that it had detected malware on its e-commerce website on October 15 and that it had been active for a little over a week. . Magecart attacks are a growing threat to online retailers and e-commerce sites, where rogue code is inserted into sites to “skim” customer card information. Data Security Cybersecurity Data breach featured holiday macys magecart

Episode 205 – Google’s Camille Stewart: InfoSec’s Lack of Diversity is a Cyber Risk

The Security Ledger

According to an estimate from Cybersecurity Ventures, the shortage of US cyber security workers could reach 500,000 people in 2021. ISC2 data show that just 24% of cybersecurity workers are women. We know that the shortage of infosec pros poses a cybersecurity risk.

Risk 52

8 Ways to Protect Yourself against Scams on Black Friday and Cyber Monday

Adam Levin

Legitimate retailers are never going to make you dig for the deals, so they aren’t going to put the good stuff in an attachment. It’s not just attachments from retailers, but also from shipping companies or financial institutions.

New Areas Ripe for Exploitation in 2018

Data Breach Today

Dave DeWalt, former CEO of McAfee and FireEye, identifies the next generation of cybersecurity threats in the latest edition of the ISMG Security Report. Also featured: an analysis of the recent news of the Meltdown and Spectre microprocessor flaws and the POS malware attack on retailer Forever 21

Retail 115

FIN7 hackers target enterprises with weaponized USB drives via USPS

Security Affairs

One of these attacks was analyzed by experts from Trustwave, one of the clients of the cybersecurity firm received a letter was supposedly from Best Buy giving out a $50 gift card to its loyal customers.