Mitigating The Security Risks Of Black Friday 

One of the biggest shopping events of the year is looming where busy retailers and eager shoppers are gearing up for Black Friday. Limited time offers encourage higher purchase numbers and rising sales, but businesses must also be aware of the increased risk of cyber attacks during this period.

Website traffic, online transactions and data transfers significantly rise during Black Friday as consumers take advantage of the unmissable deals and discounts on offer, and with more shoppers expected to shop online rather than in-store, retailers are a tempting target for cybercriminals looking to disrupt their operations. Businesses focus on allowing customers to conduct online transactions but they often fail to implement adequate cybersecurity measures, leaving them vulnerable to attacks. 

Protecting Data & Information

It’s paramount for retailers to ensure the security of their customer's data and personal information. Dominik Birgelen, CEO of oneclick AG explains that retailers' success during the Black Friday period depends on performance and security. He explains that “The right solutions, infrastructure and technical setup will support retailers during this time by ensuring lightning-fast and responsive e-commerce websites as well as uninterrupted service during peak demand.” He also adds that to effectively mitigate internal and external cybersecurity risks “Retailers need robust solutions that not only allow them to secure their assets but also to consistently monitor and spot malicious activities.”

The consequences of a cyberattack not only negatively impact sales, but are also extremely damaging to a retailer’s reputation, putting them at risk of losing their customers’ trust and loyalty. Some of the most common cyber security threats facing retailers include credential threats, phishing and bot scams, and insider threats

The majority of online users think that retailers are personally responsible for tackling these problems. Michael Jenkins, CTO at ThreatLocker agrees, stating “Organisations are responsible for protecting the data of their stakeholders, employees and customers, making them liable for implementing data breach prevention methods.”

Human error remains one of the largest contributors to cyber attacks, with 9 out of 10 of all data breaches being caused by employee mistakes. Michael also adds that “While operating on a tight schedule, an employee opening an inappropriate link, mistakenly giving users access to private information, or downloading compromised data can cause significant downtime, severely limiting businesses' ability to capitalise on Black Friday opportunities, loss of profit and damage to reputation.

“Businesses should prepare for the surge in cyberattacks during Black Friday by first educating their employees about potential threats and behaviours that make them vulnerable to ransomware and other potential threats.”

A Zero Trust Strategy

To effectively mitigate internal and external cybersecurity risks over the festive period, retailers need robust solutions that not only allow them to secure their assets but also to consistently monitor and spot malicious activities. Michael recommends zero trust, explaining that “The concept of ‘Zero Trust’ seeks to eliminate the idea of default access and trust. Just because a device is within a trusted firewall, network, or software, it does not mean that it should be trusted automatically. Zero Trust means that internal or external access is independently verified.

“Zero Trust is a comprehensive cybersecurity strategy that addresses both software and network vulnerabilities. Allowlisting and Ringfencing are examples of tools that, respectively, limit a single person's access to software and applications, as well as create firewall-like restrictions that limit application access to files, registry, the internet, and interaction with other applications."

Dominik also agrees that this strategy allows retailers to mitigate cyberattacks explaining “A Zero Trust Approach is a security framework that assumes no inherent trust within a network. It focuses on verifying every user and device attempting to access resources, regardless of their location or network. Retailers can adopt ZTA principles by implementing multifactor authentication, granular access controls, and continuous monitoring to ensure that only authorised entities can access sensitive data or systems.” 

Being Vigilant For An Attack

Fraudsters stole £580 million from British consumers and businesses in the first six months of 2023. Black Friday offers bad actors the chance to capitalise even further on these fraudulent attacks. Despite the technological advancements that have empowered businesses to bolster their cybersecurity, hackers continue to leverage the latest innovations to make their attacks more sophisticated.

This should act as a wake-up call for retailers to adopt a cybersecurity strategy and educate employees on the relevant tactics that can help them fend off a cyber attack this Black Friday.

Image: Unsplash+    thumbnail:  ElisaRiva

You Might Also Read:

Why Is Retail Cyber Security So Weak?:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


« Australian Ports Recovering After Large-Scale Attack 
Surging Attacks On Israeli Websites »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Bloombase

Bloombase

Bloombase is the leading innovator in Next-Generation Data Security solutions for Global 2000-scale organizations

RedLock

RedLock

The RedLock Cloud 360TM platform correlates disparate security data sets to provide a unified view of risks across fragmented cloud environments.

Zerocopter

Zerocopter

Zerocopter enables you to confidently leverage the skills of the world's most knowledgable ethical hackers to secure your applications.

Infopulse

Infopulse

Infopulse is a global provider of Software Engineering, Cloud & IT Infrastructure Management, and Cybersecurity services.

Aspisec

Aspisec

Aspisec is a cybersecurity company specialized in Firmware Security and Critical Infrastructure Protection.

LinkUp

LinkUp

LinkUp is a leading data-driven job search company. Every day we index millions of job openings directly from employer websites.

N8 Identity

N8 Identity

N8 Identity helps organizations realize the vision of Autonomous Identity Governance™ with AI-driven Identity solutions.

Havoc Shield

Havoc Shield

Havoc Shield is an all-in-one information security platform that includes everything a growing team needs to secure their remote workforce.

Larsen & Toubro Infotech (LTI)

Larsen & Toubro Infotech (LTI)

LTI is a global technology consulting and digital solutions company with operations in 33 countries.

Appsian Security

Appsian Security

Appsian provides powerful solutions that help organizations take control of their business critical data and financial transactions.

Cybaverse

Cybaverse

Cybaverse (formerly North Star Cyber Security) was founded to create the perfect blend of a Managed Security Service Provider (MSSP) and a Cyber Security Consultancy in one.

Phriendly Phishing

Phriendly Phishing

Phriendly Phishing offers phishing awareness training programs designed to ward off potential security threats and minimise the impact of cyber attacks.

Protecto

Protecto

Make privacy and governance effortless. Brakes allow you to drive faster. Stronger data privacy and security enable companies to unlock the full potential of the data.

ECIT

ECIT

ECIT is your preferred provider of finance and IT services. We believe in the value of combining financial and IT services to streamline and improve the operation of your business.

Evolver

Evolver

Evolver delivers technology services and solutions that improve security, promote innovation, and maximize operational efficiency in support of government and commercial customers.

CyberTest

CyberTest

CyberTest offers cybersecurity consulting and penetration testing services that helps organizations and businesses securing their assets.