Why Is Retail Cyber Security So Weak?

Retailers are particularly vulnerable to cyber hacks that prey on human error. Research by SecurityScorecard found retail is the worst ranked industry when it comes to defending against social engineering attacks, which involve hackers tricking employees into divulging sensitive information through practices such as vishing or phishing.

The very nature of the retail industry makes it a soft target for organised crime gangs.

“The ecosystem for the underworld is working so hard to maintain and prosper from the various mistakes that us humans make,” says Fouad Khalil, head of compliance at SecurityScorecard.

Julian Burnett, VP of global markets at IBM’s distribution sector, says the attack surface of the retail industry is particularly large because of the people-heavy nature of it.

“There are lots of staff interacting with many customers, exchanging lots of money, and using lots of tech to achieve it, which means you have got a heady cocktail of risk,” says Burnett, a former CIO at House of Fraser and CTO at John Lewis and Sainsbury’s.

Social engineering is a particularly common means of attack within retail because there are so many staff that can be targeted, who are often inexperienced or temporary.

IBM’s ethical hacking group X-Force Red has found younger staff are particularly susceptible to inadvertently giving away data that is commercially sensitive.

Social Media Engineering
Sensitive data is left all over social media, says Burnett. “We see a particularly significant proportion of younger people in the workforce being largely ignorant to the risks they are taking because they have grown up feeling much more trusting and safe in digital contexts.”

Burnett says the type of information they can inadvertently share includes pictures with a security badge in view, or laptops openly displaying sensitive information on the screen.

Hackers can also exploit the customer service-led nature of the retail industry to steal information through social engineering.
Florence Mottay, chief information security officer at Dutch food retailer Ahold Delhaize Europe says ‘vishing’ (voice phishing) is one of the most popular tactics employed by social engineers in the retail world.

“In a vishing attack, social engineers call a company impersonating someone else looking for sensitive information on customers, associates, or digital products,” says Mottay. “Since customer service is key within retail, victims of social engineering might unknowingly aid attackers over the phone while they are under the impression that they are just doing their jobs.”

The large physical footprint many retailers have adds an additional layer of vulnerability to their businesses as well.
Burnett says that during his time working at retailers there were instances of fake engineers arriving in shops, who installed devices into vulnerable ports on equipment.

Internal Threats
A further human weakness that can be exploited is the deliberate selling of commercially sensitive information.
Recent research by Deep Secure has found that a surprisingly large number of employees would be willing to sell off their company’s information. Just £1,000 would be enough to tempt 25% of employees to give away company information, according to the research.

The human vulnerabilities of a retailer’s cybersecurity operation are numerous, but this does not mean they are impossible to guard against.

Chris Pritchard, a consultant at cybersecurity firm Pen Test Partners, says it is difficult to train staff to avoid them falling victim to social engineering-based cybersecurity attacks.

“If an attacker is prepared to take the risk and appear in person, physically to attempt to gain access to an office, or factory then, if done properly, that’s hard to prevent,” says Pritchard. “But as most attackers like the [telephone or email based] spray and pray method because it’s the least risky, it’s easier to prevent.”

Staff training and education should be the first line of defence against social engineering attacks.
“From a best practice perspective I would focus on training as number one,” says Khalil. “Bring into the light the different angles the attackers are taking to steal personal information.”

Education
“Awareness and education go an awfully long way to improving any organisation’s stance in the face of cyber-crime,” says Burnett. “It is about behaviours and recognising risk and learning not to inadvertently share sensitive information that could be put alongside other information that can be used to create a persona for those prepared to launch an attack.”

Mottay says Ahold Delhaize puts every staff member, whether at corporate or store level, through different types of security awareness training to educate them about social engineering attacks and how to spot them.

“Through simulated phishing and social engineering exercises, our users get trained in a fun and constructive way,” says Mottay. “Awareness exercises are just like fire drills; we conduct them on a regular basis on every aspect of information security - and social engineering is part of these exercises.”

Burnett advises retailers take care to ensure educational programmes are effective for those who are only working at the company for short time frames such as seasonal workers at Christmas.

This training could include warning younger staff about the potential dangers of posting pictures of them at work on social media websites. 

It is more difficult to stop disgruntled staff from leaking commercially sensitive information, but systems can still be put in place to try and stop such scenarios.

“I would encourage companies to think about monitoring the output of the company on the many channels we use in big business,” says Burnett.

This could include monitoring who is saying what and keeping an eye on what attachments are being shared via email.

“The level of sophistication in monitoring is improving and increasing all the time,” says Burnett. “Applying a level of analytical insight above and beyond monitoring can help you understand the risk profile of an individual and their propensity to act.”

Unfortunately, there is no such thing as an entirely flawless cybersecurity defence. But there are many things that can be done to minimise risk.

The retail industry is such low hanging fruit for organised crime that it is likely cyber-attacks will only rise further and become ever more sophisticated. Retailers would be wise to do all in their power to ensure they cut out the basic human errors that are opening the door to cyber-attacks.

Essemtial Retail:        Image: Nick Youngson

You Might Also Read:

Banks And Retailers Track How You Type, Swipe And Tap:

« Improving Electric Power-Grid Security
Police Forensic Firm Has Paid Ransom »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

DMH Stallard

DMH Stallard

DMH Stallard is a mid-market law firm. Areas of expertise include cyber security and cyber crime.

Thycotic

Thycotic

Thycotic prevents cyber attacks by securing passwords, protecting endpoints and controlling application access.

NetGuardians

NetGuardians

NetGuardians is a leading Fintech company recognized for its unique approach to fraud and risk assurance solutions.

Nexusguard

Nexusguard

Nexusguard is at the forefront of the fight against malicious Internet attacks, protecting organizations worldwide from threats to their websites, services, and reputations.

UM Labs

UM Labs

UM Labs is a developer of security products for Voice over IP (VoIP), protecting SIP trunk connections, safeguarding mobile phone communications and enabling BYOD.

Abusix

Abusix

Abusix specializes in Internet security, network abuse handling, antispam and fraud prevention.

DOS

DOS

DOS is an Ecuadorian company with 3 decades of presence in the market and extensive experience in the planning, management and execution of IT Service Integration Projects.

CipherTrace

CipherTrace

CipherTrace develops cryptocurrency Anti-Money Laundering, cryptocurrency forensics, and blockchain threat intelligence solutions.

Fyde

Fyde

Fyde helps companies with an increasingly distributed workforce mitigate breach risk by enabling secure access to critical enterprise resources.

LOGbinder

LOGbinder

LOGbinder eliminates blind spots in security intelligence for endpoints and applications.

Prosperoware

Prosperoware

Prosperoware develop software for cybersecurity, privacy, and regulatory compliance for content systems, and financial matter management.

Cider Security

Cider Security

Cider Security - It’s time to revolutionize the way Security, Dev and DevOps teams work together to supercharge security at the speed of engineering.

Chainguard

Chainguard

Founded by the industry's leading experts on open source software, security and cloud native development, Chainguard are on a mission to make the software supply chain secure by default.

Three Wire Systems

Three Wire Systems

Three Wire is a leader in innovative and efficient technology solutions for government agencies and large enterprise corporations.

LockMagic

LockMagic

Lockmagic is an information asset management solution to protect, track, audit and control accesses to sensitive information inside and outside your organization.

Digital Security Authority (DSA)

Digital Security Authority (DSA)

The establishment of the Digital Security Authority, which incorporates the National CSIRT, is crucial to significantly raising the cybersecurity posture and capabilities of Cyprus.