HomeSponsored ContentAre retail online and MPOS applications secure? (Sponsored Content: Mazars)

Are retail online and MPOS applications secure? (Sponsored Content: Mazars)

According to the National Retail Foundation, retail has grown almost 4 percent annually since 2010. NRF expects retail sales in 2018 to increase at a minimum of 4.5 percent over 2017. Depending on who you read, current industrywide online sales make up between 9-11 percent of all retail sales. Past numbers support continual year-over-year growth of online sales that are estimated between 17-20 percent by 2021. According to Security Scorecard‘s “2018 Retail Cybersecurity Report,” online purchases during November and December 2017 reached nearly $700 billion, while data breaches also increased, with 50 percent of retailers experiencing a breach, up from 19 percent the prior year.

With the continued growth in online sales and mobile point-of-sale, or mPOS, application security concerns are highlighted. New privacy regulations can have severe fines, along with legal pursuit of damages by individuals. Recent studies further suggest that privacy is steadily becoming a significant factor in customer loyalty, all of which makes security and privacy a new priority for retail.

A retailer’s reputation and market share are becoming a high stakes digital game. According to a Harris Interactive and TRUSTe study, 89 percent of consumers won’t do business with companies that don’t protect them online. At the same time, Security Scorecard’s “2018 Retail Cybersecurity Report” has the retail industry as a bottom performer for application security, ranked 17 out of 18 industries studied.

The increased reliance on applications, paired with the decreased level of security, will lead to troubling times for retailers who do not change. Those retailers who make security a priority and promote privacy options for their customers will not only advance brand loyalty, they will take market share from competitors who don’t.

Retailers should consider taking a program approach, regardless of whether the platform(s) is on internal infrastructure, in the cloud, or a hybrid. The first step is to establish the rules, consider creating policies based on PCI, GDPR and an industry standard such as NIST or ISO2700x series. These rules/policies will drive the requirements of your information technology security and/or service provider to properly secure transactions and access to critical information.

To secure your critical applications, gain a business advantage and market share, consider the following application security and privacy areas related to mPOS and web applications:

  1. Securely develop your applications. There are several secure development approaches (PCI-Mobile Payment) and guidelines (OWASP) along with using some or all of privacy by design as the overarching framework.
  2. Develop an encryption strategy for all aspects of customer interaction; mPOS and web applications usage, transactions, storage of data and when sensitive information is accessed by authorized staff or the customer themselves.
  3. Be transparent with your customers and let them know you care about them and the importance of keeping their personal information private.
  4. In the privacy policy, provide an understandable explanation of why the information is needed and what the information will be used for. This should be supplied prior to a customer providing any personal information or creating an account.
  5. Don’t hold information hostage to a transaction, allow customers to supply information one time if they want. If you say they must create an account and/or give you consent to do something with the information outside of the transaction, it is not only illegal under a number of international laws, it is reducing customer loyalty.
  6. Secure your infrastructure that will be supporting your online and mPOS applications. Consider going to the cloud with eyes wide open, don’t assume you are secure just because you move to the cloud. Get outside help beyond the service provider to make sure you are operating at an appropriate risk level. Good consulting organizations will not only help you be secure, they should be able to help you reduce cost and increase productivity with a strategy to scale up and down, on demand.

Mazars wrote this article to provide some guidance and improve the overall retail industry. Feel free to reach out with feedback, questions or to gain further understanding on retail security and privacy.

Related Articles

Powerfleet lands major public-sector contract with South Africa government

Powerfleet Inc., a Woodcliff Lake-based provider of artificial intelligence of things (AIoT) software-as-a-service (SaaS) solutions for mobile asset management, announced Feb. 9 it has...

Verisk names Kauderer president of claims solutions 

Verisk, a Jersey City-based publicly traded strategic data analytics and technology partner to the global insurance industry, announced that Steven Kauderer has been named...
00:10:27

Steve Adubato Talks with the VP of IUOE Local 825 about New Jersey’s Energy Crisis

Steve Adubato speaks with Greg Lalevee, Business Manager & General Vice President of the International Union of Operating Engineers Local 825, about New Jersey’s...

Corcentric announces partnership with Workato to expand integration capabilities

Corcentric, a global provider of best-in-class procurement and finance solutions based in Cherry Hill, announced a strategic partnership with Workato, a leader in enterprise...

This Heart Month, Take Action Before Heart Disease Starts

February is American Heart Month, an important time to raise awareness about cardiovascular health. Cardiovascular diseases are the leading cause of death globally, according to the World Health...

Opici Family Distributing continues partnership with Provi to boost digital omnichannel strategy

Opici Family Distributing, the Glen Rock-based leading family-owned wine and spirits distributor, announced on Feb. 3 the continuation of its partnership with Provi, a...

Latest Articles

HBSE names Wheeler general manager of Loew’s Jersey Theatre

Harris Blitzer Sports & Entertainment (HBSE) said Feb. 10 that entertainment industry veteran Bruce Wheeler has become general manager of the nearly 100-year-old Loew’s...

African American Chamber of Commerce of N.J. to honor 6 at Circle of Achievement Awards Gala

The African American Chamber of Commerce of New Jersey (AACCNJ) will honor the achievements of six honorees at its 16th Annual Circle of Achievement...

Celularity of Florham Park gets $12.2M from sale of New Jersey net operating losses

Florham Park-based Celularity Inc., a regenerative and cellular medicine company, said Feb. 10 it was in receipt of $12.2 million in net cash proceeds...

Experic appoints Mollan to CEO with retirement of Wood

Experic, a Cranbury-based contract development and manufacturing organization (CDMO) and clinical trial supply services company serving the biopharmaceutical industry, announced the appointment of Matthew...

Sitex Group acquires an infill low coverage site in South Plainfield from Progressive

Sitex Group, a privately held investor and developer of industrial real estate, has purchased a 22,000-square-foot property at 152 West St. in South Plainfield....

Storage Post acquires former CubeSmart location in Newark, expanding N.J. presence

Storage Post, a leading owner and operator of self-storage facilities, announced the acquisition of a new location in Newark at 353–367 Park Avenue, which...

Latest Articles

HBSE names Wheeler general manager of Loew’s Jersey Theatre

Harris Blitzer Sports & Entertainment (HBSE) said Feb. 10 that entertainment industry veteran Bruce Wheeler has become general manager of the nearly 100-year-old Loew’s...

African American Chamber of Commerce of N.J. to honor 6 at Circle of Achievement...

The African American Chamber of Commerce of New Jersey (AACCNJ) will honor the achievements of six honorees at its 16th Annual Circle of Achievement...

Celularity of Florham Park gets $12.2M from sale of New Jersey net operating losses

Florham Park-based Celularity Inc., a regenerative and cellular medicine company, said Feb. 10 it was in receipt of $12.2 million in net cash proceeds...

Experic appoints Mollan to CEO with retirement of Wood

Experic, a Cranbury-based contract development and manufacturing organization (CDMO) and clinical trial supply services company serving the biopharmaceutical industry, announced the appointment of Matthew...

Sitex Group acquires an infill low coverage site in South Plainfield from Progressive

Sitex Group, a privately held investor and developer of industrial real estate, has purchased a 22,000-square-foot property at 152 West St. in South Plainfield....