abednarz
Executive Editor

Security plagues retailers

News
Nov 7, 20053 mins

Retailers on the costs and risks associated with security breaches, and the types of data-fraud schemes perpetrated by organized-crime rings and individuals

CHICAGO – Within 24 hours of telling the public about a data leak earlier this year, ChoicePoint lost Wall Street’s confidence and gained unwanted attention from would-be hackers and thieves.

ChoicePoint’s market capitalization plummeted $300 million, and the number of exploratory pings aimed at its servers jumped from 100,000 to a couple of million overnight, said Marty Smith, the company’s business information officer and chief architect. The company is still under federal investigation about the breach and is battling financially. Smith laid out his company’s landscape to an audience of IT executives at the Retail Data Security Forum, held last week at Marshall Field’s department store in Chicago.

Data broker ChoicePoint handles more than 17 billion consumer records. Its services include providing data for identity verification, pre-employment screening, insurance underwriting and asset location. The Alpharetta, Ga., company estimates that about 145,000 consumers may have had their personal information exposed when scammers fraudulently obtained access to its data.

ChoicePoint publicly disclosed the data breach in February. Criminals had set up dozens of fraudulent accounts with ChoicePoint by posing as legitimate businesses needing consumer data.

In Chicago, Smith talked about the costs and risks associated with security breaches, and the types of data-fraud schemes perpetrated by organized-crime rings and individuals. Data criminals are after any record that associates the name of a party with another identifier, such as a home address, work address, telephone number, Social Security number, place of birth or a description of the person. “It’s amazing to me what little information these people need to commit fraud,” he said.

There are technology-related ways to mitigate and control data breaches – from multi-factor authentication and real-time monitoring to honeypots and audit controls, Smith said. In addition, education and awareness are important. Retailers should use technology to track patterns of access and behavior. They also should share information about known or suspected misuse, and get involved with local and national legislative efforts.

Vigilance required

Erik Goldoff, IT systems manager at the HoneyBaked Ham Co., stressed the need for companies to regularly peruse system data, such as server logs and bandwidth histograms, to better understand typical usage trends.

Securing data stores

Brian Kilcourse, chief strategist at Retail Systems Alert Group, recommends these three tactics for keeping tighter rein on consumer-specific data.
Control ad-hoc queries of the data.
Encrypt consumer-specific information inside databases.
Capture forensic data related to the creation, retrieval and updating of consumer-specific data.

“When a purse gets stolen, it’s gone. But when someone steals your data, everything looks the same as it did before, only someone else has a copy of it.”

Goldoff’s company has hardened its IT assets against internal and external threats by locking down desktops. HoneyBaked Ham requires periodic password changes and doesn’t allow users to receive Zip files or install unauthorized software.

The company also doesn’t do wireless. “We don’t allow wireless in our infrastructure, because of the cost of implementing security,” Goldoff said. “It can be done right, but it’s expensive and complicated.”

Industrywide, retailers need to be careful about how they collect, use and protect consumer data, said Brian Kilcourse, chief strategist at Retail Systems Alert Group, which sponsored the event. Kilcourse shared preliminary results of a study the group is conducting to see how retailers handle customer data.

Only 32% of retailers encrypt consumer-specific data within databases, and only 40% capture forensic data about how consumer-specific information is put to use, Kilcourse said.

Additionally, less than half of retailers have a formal incident-response plan for breaches of consumer data.

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author