Categories: Articles

Are you protecting your customer data?

used with permission from HP Technology at Work

Once upon a time, the only person worrying about securing customer data might have been the grizzled IT veteran in the company’s basement cubicle. Customers seldom thought twice about how their data was protected, and many businesses didn’t either. Security was simply not high priority, and for most people, not a problem [1, 2].

Once upon a time, that might have been true. But not anymore.

Recent headlines have disclosed major data breaches affecting millions of consumers worldwide. It’s become clear that protecting customer data can no longer be just another item on the agenda to be taken care of “later.” The consequences of losing customer information are severe. A recent survey by Harris Interactive reveals that 89 percent of consumers avoid doing business with companies they believe do not protect their privacy [3]. And customer concern is growing: A full 74 percent of internet users are more worried about their online privacy than they were a year ago [3]. Loss of customer data can mean loss of consumer confidence, fines and lawsuits and the expense of restoring your compromised systems.

To stay ahead of the threats, you need to make sure you’re doing everything you can to secure your customers’ data. Here are some tips on where to start:

In the office

  • Retain data logs longer: Two thirds of data breaches are not discovered until over a month after they occur. And roughly 70 percent are discovered not by the company affected, but by an external third party. Keeping older data logs allows you to understand how your network was breached and what data may have been stolen [4].
  • Review your encryption: If your company already uses encryption, great. But it might not be enough. Methods that were standard five years ago may be easy to break today, so it’s important to regularly review your protocols. It’s also important to make sure you’re deploying encryption effectively. For example, if data is encrypted on your server but not while it’s on an employee’s laptop, you remain vulnerable.

At the store

  • Follow PCI recommendations: The PCI Security Standards Council publishes publicly available best practices for retailers. Their standards for data are outlined in the PCI Data Security Standard (PCI DSS). Every business working with sensitive customer data and credit cards should make sure they’re applying its recommendations. While not sufficient on their own to protect against every threat, they serve as a good starting point for securing your data.
  • Consider tokenization: Often used in e-commerce, this high-level security strategy replaces consumer information such as credit card data with unique identification symbols as it travels through your network, keeping your clients anonymous and protecting their data from prying eyes.

In the cloud

  • Demand the best: Not all cloud providers are equal, especially when it comes to security. It’s important to understand what kind of policies a provider has in place before signing any contract. For example, HP Cloud offers small and medium businesses enterprise-level security services like comprehensive logging and kernel auditing.
  • Consider data loss prevention: Often employed by global organizations in the past, this effective strategy is now also accessible by small and medium businesses. Data Loss Prevention (DLP) tools like those offered by HP include policy-based data monitoring and tracking to preemptively stop exfiltration of data.

The volume and sophistication of attacks is increasing every year. In fact, 19 percent of data breaches combined phishing, malware, hacking and entrenchment in order to gain access to valuable customer data [4]. To protect your customers’ information, it’s important to regularly review your security practices, and research new services like cloud computing before you deploy them. A proactive approach will help you build customer loyalty, effectively launch new technologies and defend against evolving threats.

[1] Newtek Business Services, Majority Of Business Owners Not Concerned About Credit Card Security, March 2014
[2] NFIB, Small Business Problems and Priorities, August 2012
[3] TRUSTe Privacy Index, 2014 Consumer Confidence Edition, December 2013
[4] Verizon, The 2013 Data Breach Investigations Report, April 2013

To learn more, contact us today.

eMazzanti Technologies

Recent Posts

How to Manage Remote Workers

With a global customer base, eMazzanti Technologies positions engineers and project managers in various locations…

4 years ago

Tips for Transitioning to Remote Work

Over a period of three weeks, most of the workforce in the United States found…

4 years ago

Collaborate with Exceptional Security and Privacy Using Microsoft 365 for Remote Work

Three years ago, Microsoft launched Teams, a powerful component of Office 365 (now Microsoft 365),…

4 years ago

You Look Marvelous! The Sprint to Video-based Team Interaction

In our new work-from-home (WFH) world, the requirement for on demand video conferencing has exploded…

4 years ago

5 Endpoint Security Best Practices When Remote Work Takes Center Stage

With the majority of employees working from home this spring, organizations have encountered new challenges.…

4 years ago

Cloud-based Security Solutions Deliver Powerful, Scalable Protection for SMBs

The average small to medium business (SMB) has most likely migrated at least some essential…

4 years ago