Executive Summary


Why are there still security breaches in the retail industry?



Yüklə 29,51 Kb.
səhifə4/5
tarix02.06.2023
ölçüsü29,51 Kb.
#115104
1   2   3   4   5
Information Security Assignment Informat

Why are there still security breaches in the retail industry?

The security performance fell lower than last year in the retail business. Hence it made it hard for the store administration to save their important data from hackers which made it competitive. All stores are trying to adopt new technologies, especially in their payment methods. But it also has been found that most of the retailers are ignoring it because they don’t want to spend more money on the enhancement of the payment methods. It was a time when retailers can survive with their old software and information security systems but now the customers are aware of security breaches and with the advancement in the technology especially social media customers are aware of their rights and how much their personal information is important for them. Which means the retailers must update their software to stop the hackers and other malware to get into the network system.




Solution:

Monitoring the threats in the industry is the best option. Retail store have their own apps and web sites if they start taking care of the security breaches time to time it can help them to tackle the new malware. The data should be encrypted and there should be proper authentication between the app and the server. All the apps must have proper authentication like password and biometric for both staff and customers.


Home Depot information security issue:

Not more than 6 years ago there was the biggest credit card compromised incident ever seen. It affected almost 56 million people. Home Depot was not the only victim, but it was the biggest incident in the history of cybercrime and security breach at that time. The attackers gain access to the third-party vendors log on credentials and get into the Home depot corporate environment through that. They used memory scrapping malware that is used to scan the memory of digital devices to get personal information. This malware successfully captures credit card details of 56 million customers and emails of 52 million customers. These can be used for phishing on a large scale. The reason for all this was home depot POS terminal did not securely configure both as hardware and software. There was no proper network surveillance. But Home Depot did have the SEP as a proper Antivirus. but the only problem was that they did not have proper network threat protection. The point to point encryption was also missing by which the credit card data encrypted. as soon as the customer swipes the card. The operating system that was being used was also not secured. They were using Windows XP sp3 which is really inviting for the attacks and malware. But how did the attacker get into the vendor's logon this is also an issue but if you look into it more deeply you will know that there was no proper potential threat and vulnerability policy in that retail chain. They should have learned from the security breach of the target in 2013 just a year before the incident. Now, this issue has also been resolved by using the technology of NFC like Apple Pay and Google Pay. But of course, there was a huge amount that was paid by the home depot as compensation and a penalty to be careful in future.





Yüklə 29,51 Kb.

Dostları ilə paylaş:
1   2   3   4   5




Verilənlər bazası müəlliflik hüququ ilə müdafiə olunur ©genderi.org 2024
rəhbərliyinə müraciət

    Ana səhifə