Why Is Retail Cyber Security So Weak?

Retailers are particularly vulnerable to cyber hacks that prey on human error. Research by SecurityScorecard found retail is the worst ranked industry when it comes to defending against social engineering attacks, which involve hackers tricking employees into divulging sensitive information through practices such as vishing or phishing.

The very nature of the retail industry makes it a soft target for organised crime gangs.

“The ecosystem for the underworld is working so hard to maintain and prosper from the various mistakes that us humans make,” says Fouad Khalil, head of compliance at SecurityScorecard.

Julian Burnett, VP of global markets at IBM’s distribution sector, says the attack surface of the retail industry is particularly large because of the people-heavy nature of it.

“There are lots of staff interacting with many customers, exchanging lots of money, and using lots of tech to achieve it, which means you have got a heady cocktail of risk,” says Burnett, a former CIO at House of Fraser and CTO at John Lewis and Sainsbury’s.

Social engineering is a particularly common means of attack within retail because there are so many staff that can be targeted, who are often inexperienced or temporary.

IBM’s ethical hacking group X-Force Red has found younger staff are particularly susceptible to inadvertently giving away data that is commercially sensitive.

Social Media Engineering
Sensitive data is left all over social media, says Burnett. “We see a particularly significant proportion of younger people in the workforce being largely ignorant to the risks they are taking because they have grown up feeling much more trusting and safe in digital contexts.”

Burnett says the type of information they can inadvertently share includes pictures with a security badge in view, or laptops openly displaying sensitive information on the screen.

Hackers can also exploit the customer service-led nature of the retail industry to steal information through social engineering.
Florence Mottay, chief information security officer at Dutch food retailer Ahold Delhaize Europe says ‘vishing’ (voice phishing) is one of the most popular tactics employed by social engineers in the retail world.

“In a vishing attack, social engineers call a company impersonating someone else looking for sensitive information on customers, associates, or digital products,” says Mottay. “Since customer service is key within retail, victims of social engineering might unknowingly aid attackers over the phone while they are under the impression that they are just doing their jobs.”

The large physical footprint many retailers have adds an additional layer of vulnerability to their businesses as well.
Burnett says that during his time working at retailers there were instances of fake engineers arriving in shops, who installed devices into vulnerable ports on equipment.

Internal Threats
A further human weakness that can be exploited is the deliberate selling of commercially sensitive information.
Recent research by Deep Secure has found that a surprisingly large number of employees would be willing to sell off their company’s information. Just £1,000 would be enough to tempt 25% of employees to give away company information, according to the research.

The human vulnerabilities of a retailer’s cybersecurity operation are numerous, but this does not mean they are impossible to guard against.

Chris Pritchard, a consultant at cybersecurity firm Pen Test Partners, says it is difficult to train staff to avoid them falling victim to social engineering-based cybersecurity attacks.

“If an attacker is prepared to take the risk and appear in person, physically to attempt to gain access to an office, or factory then, if done properly, that’s hard to prevent,” says Pritchard. “But as most attackers like the [telephone or email based] spray and pray method because it’s the least risky, it’s easier to prevent.”

Staff training and education should be the first line of defence against social engineering attacks.
“From a best practice perspective I would focus on training as number one,” says Khalil. “Bring into the light the different angles the attackers are taking to steal personal information.”

Education
“Awareness and education go an awfully long way to improving any organisation’s stance in the face of cyber-crime,” says Burnett. “It is about behaviours and recognising risk and learning not to inadvertently share sensitive information that could be put alongside other information that can be used to create a persona for those prepared to launch an attack.”

Mottay says Ahold Delhaize puts every staff member, whether at corporate or store level, through different types of security awareness training to educate them about social engineering attacks and how to spot them.

“Through simulated phishing and social engineering exercises, our users get trained in a fun and constructive way,” says Mottay. “Awareness exercises are just like fire drills; we conduct them on a regular basis on every aspect of information security - and social engineering is part of these exercises.”

Burnett advises retailers take care to ensure educational programmes are effective for those who are only working at the company for short time frames such as seasonal workers at Christmas.

This training could include warning younger staff about the potential dangers of posting pictures of them at work on social media websites. 

It is more difficult to stop disgruntled staff from leaking commercially sensitive information, but systems can still be put in place to try and stop such scenarios.

“I would encourage companies to think about monitoring the output of the company on the many channels we use in big business,” says Burnett.

This could include monitoring who is saying what and keeping an eye on what attachments are being shared via email.

“The level of sophistication in monitoring is improving and increasing all the time,” says Burnett. “Applying a level of analytical insight above and beyond monitoring can help you understand the risk profile of an individual and their propensity to act.”

Unfortunately, there is no such thing as an entirely flawless cybersecurity defence. But there are many things that can be done to minimise risk.

The retail industry is such low hanging fruit for organised crime that it is likely cyber-attacks will only rise further and become ever more sophisticated. Retailers would be wise to do all in their power to ensure they cut out the basic human errors that are opening the door to cyber-attacks.

Essemtial Retail:        Image: Nick Youngson

You Might Also Read:

Banks And Retailers Track How You Type, Swipe And Tap:

« Improving Electric Power-Grid Security
Police Forensic Firm Has Paid Ransom »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Lantronix

Lantronix

Lantronix is a global provider of secure data access and management solutions for Internet of Things (IoT) and information technology assets.

Security Innovation

Security Innovation

Security Innovation is a leader in software security assessments and application security training to top organizations worldwide.

Cyber London (CyLon)

Cyber London (CyLon)

CyLon is a leading cyber security accelerator and seed investment programme. We help entrepreneurs from across the globe to build cyber security businesses, raise investment, and develop partnerships.

Private Internet Access

Private Internet Access

Private Internet Access is a Virtual Private Network services provider offering secure encrypted access to the internet.

National Digital Exploitation Centre (NDEC) - United Kingdom

National Digital Exploitation Centre (NDEC) - United Kingdom

NDEC is a project to create a centre of cyber and digital development and education for the UK. It will offer training in digital practices, cyber security and research.

Beazley

Beazley

Beazley are a specialist insurer with three decades of experience in providing clients with the highest standards of underwriting and claims service worldwide.

Vilnius Tech Park

Vilnius Tech Park

The region‘s most complex and integrated ICT hub, Vilnius Tech Park aims to attract and unite innovative talent from big data, cyber security, smart solutions, fintech and digital design.

Stratum Security

Stratum Security

Stratum Security is an information security consulting company that focuses on providing clear and concise risk guidance to its clients through high quality assessment services.

Avetta

Avetta

Avetta One is the industry’s largest Supply Chain Risk Management (SCRM) platform. It enables clients to manage supply chain risks and suppliers to prove the value of their business.

Brightsolid

Brightsolid

Brightsolid are experts in Hybrid Cloud. We design, build and manage secure, scalable cloud environments that meet customers’ business ambitions.

Intel 471

Intel 471

Intel 471 provides adversary and malware intelligence for leading intelligence, security and fraud teams.

IDECSI

IDECSI

IDECSI delivers cutting-edge technology and engages all employees in the security system for effective and cost-efficient data protection.

ZX Security

ZX Security

ZX Security is a New Zealand owned and operated cyber security consultancy.

Saudi Information Technology Company (SITE)

Saudi Information Technology Company (SITE)

SITE is a forward-thinking enterprise, which aims at revitalizing Saudi Arabia’s digital infrastructure, cybersecurity, software development, and big data and analytics capabilities.

Cyber Security Certification Australia (CSCAU)

Cyber Security Certification Australia (CSCAU)

CSCAU is the world’s first 'for mission' industry council set up to address small and medium-sized business (SMB) cyber resilience through annually updated certifiable standards.

Business Communications Inc (BCI)

Business Communications Inc (BCI)

BCI is a leading technology company known for its exceptional team of experienced engineers with a focus on providing top-notch technology and security products and services.