4 Risk Management Tips for Retail Business
The article emphasizes that retail risk management now extends beyond physical security to include robust cybersecurity measures due to increased online transactions during COVID-19, highlighting common cyberattacks like DDoS, payment card fraud, and inventory hoarding, and recommends developing an enterprise risk management program starting with thorough identification and assessment of cybersecurity risks involving connected systems and third-party vendors.
Retail risk management is about much more than security cameras, mall cops, and theft insurance policies. The COVID-19 pandemic forced the retail industry to focus on e-commerce operations, often requiring rapid changes to move transactions online. These changes have significant implications for risk management, and businesses that overlooked these risks sometimes suffered data breaches or inventory disruptions.
COVID-19 created favorable conditions for hackers and scammers. Online transactions increased, making retailers attractive targets for cybercriminals. The rush to close physical stores and expand online operations led to overlooked safeguards, which attackers exploited.
According to Total Retail, the three most common types of cyberattacks against the retail industry are:
- 1.DDoS (Distributed Denial of Service): Over 20% of attacks against online retailers are DDoS attacks, which flood servers with requests and cause crashes. Attackers may demand ransom to stop the attack, but paying increases the likelihood of future attacks.
- 2.Payment Card Fraud: Another 20% of attacks involve fraudulent use of gift cards and credit cards, offering immediate rewards for cybercriminals.
- 3.Inventory Hoarding: About 15% of attacks involve bots listing in-stock items as unavailable, a tactic known as “inventory denial,” which can go undetected for some time.
Given this heightened threat landscape, developing an enterprise risk management (ERM) program is essential to protect customer data, vendor and contractor information, and proprietary assets.
1. Identify and Assess Your Cybersecurity Risks
The first step is to assess and analyze your cybersecurity risks. Consider the following checklist:
- Are security systems, cameras, or thermostats connected to applications accessible from anywhere? Cloud-based solutions can be hacked, granting access to physical stores or warehouses.
- Who handles your point-of-sale data? Every vendor and subcontractor introduces third-party risk.
- Internet of Things (IoT) devices, such as phones and computers, increase cyber attack risk.
- Bluetooth-connected hardware is vulnerable due to lack of encryption.
- Customer Wi-Fi networks often have poor security monitoring, creating risks for both customers and the business.
- Remote work arrangements can be risky if not managed properly. Are secure VPN connections provided? Who else has access to company laptops used at home?
- Do you monitor social media for imposter accounts mimicking your e-commerce site?
- Do you enforce a clean desk policy for employees both on-site and at home?
Charting a typical order’s journey through your system can help identify vulnerabilities.
2. Analyze and Immediately Remediate the Highest Risk Points
After identifying risks, analyze them and address the most critical points first. For e-commerce, risk assessment methodologies differ from those used in physical stores. Key areas to scrutinize include:
- Ensure IT systems are updated with the latest software versions to protect against new threats.
- Store, access, and process credit card data and customer files securely, using encryption and limiting access.
- Protect against malware and viruses, and use automation to reduce human error.
- Equip employees with the necessary tools to maintain system security.
3. Monitor and Respond
Risk management is an ongoing process. Once systems are secured, continuous monitoring and response are necessary.
- Communicate risk management processes to all employees and ensure everyone knows how to report potential cyberthreats.
- Establish a chain of command for responding to data breaches, security threats, or cyberattacks.
- Use automation and artificial intelligence (AI) solutions to stay ahead of evolving cybercriminal tactics.
- Prepare a plan for repairing systems, recovering data, and remediating brand damage in the event of an attack.
4. Establish a Vendor and Third-Party Risk Management Program
The retail industry often lags in application cybersecurity. According to Thale’s 2018 retail cybersecurity report:
- 50% of retailers experienced a data breach.
- 84% planned to increase IT security spending.
- 85% stored sensitive data in the cloud.
There is no standardized framework for retail IoT security, and cloud environments introduce additional risks. Many retailers moved online rapidly during COVID-19, sometimes creating new divisions under pressure.
If your company moved online quickly, now is the time to assess third-party vendor and partner risk management. Consider the following:
- Ask vendors and contractors about their cybersecurity practices and communicate your standards.
- Know which vendors have access to your data.
- Inquire about vendors’ remote work policies and infrastructure protections.
- Prepare for potential data breaches, including customer and employee communication plans.
- Develop a flexible plan to limit damage if a hacker breaches your system.
- Establish clear internal and external chains of command for reporting and managing security issues.
- Make risk management a best practice for every new vendor engagement.
To modernize IT infrastructure and enhance customer engagement, retail enterprises must move beyond traditional compliance and adopt security-first cybersecurity strategies.
ZenGRC: Worry-Free Retail Risk Mitigation
ZenGRC offers a solution to ease retail risk mitigation, automating document collection for audits and supporting tasks such as:
- Streamlining workflows and integrating with popular solutions like ServiceNow
- Viewing compliance gaps on dashboards and identifying fixes
- Mapping controls to multiple frameworks, standards, and regulations
- Generating and sending vendor questionnaires, and collating results
- Conducting self-audits quickly
- Storing audit-trail documents in a central repository
- Sharing risk management and compliance status with managers and the board
ZenGRC enables worry-free management and monitoring of retail security and compliance, allowing businesses to focus on customers and growth.