Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
09:00 AM
Peter Martini
Peter Martini
Partner Perspectives

Securing Retail Networks for an Omnichannel Future

Retailers who haphazardly move to digital from a brick-and-mortar environment can leave their businesses open to significant cybersecurity vulnerabilities. Here's how to avoid the pitfalls.

A spate of bad news for former retail giants like Toys 'R' Us and mall-staple Claire’s has cast a dark shadow over the state of brick-and-mortar retail. But the truth of the matter isn’t that retailers will be abandoning their physical footprints going forward. It’s indicative of a larger trend toward more digital, mobile and distributed operations that has been upending processes across industries – and changing how consumers interact with brands in the physical world, rather than retiring the brick-and-mortar storefront altogether.

In fact, rumors started circulating not long after Toys 'R' Us announced they’d be shuttering their entire network of more than 400 stores stateside that Amazon – the company most-cited as the death knell for brick-and-mortar – would be swooping in to purchase a wide swath of the toy seller’s former real estate at bargain-basement prices. The goal would be to both expand Amazon’s number of physical storefronts – from Whole Foods grocery stores, to bookstores, to Amazon Go ‘bodegas’ – while also supporting online shopping operations by creating a larger network of micro distribution centers.

What's really happening is that retail is becoming omnichannel, which means retailers need to be everywhere. It's not a binary choice between brick-and-mortar or online shops but having a play in both arenas PLUS on social media and an array of IoT interfaces. The bad news is that retailers who  haphazardly dive into the omnichannel world can leave their businesses open to significant cybersecurity vulnerabilities, which could send brands down the same path of Claire’s or Toys ‘R’ Us despite their best efforts.

Managing Distributed Networks Requires a Unique Touch
A retailer’s network infrastructure needs to support all of the brand’s omnichannel efforts, which will be distributed to the point where the network perimeter is nearly impossible to track as brands adopt more outreach channels, for example, online stores. This will require robust gateway defenses that assure that all the traffic crossing the network threshold to access sensitive corporate data is legitimate.

This will be an especially difficult challenge for retailers given the diversity of data – in volume, size and sensitivity – that security teams will be tasked with securing, and the many different levels of access that will need to be assigned.

Point-of-sale systems (POS), for instance, are already becoming much more than just transaction terminals. The wireless devices that many companies are adopting for POS have access to inventory information within the store, in far-off warehouses and other branch locations to assure that no shopper leaves the building unsatisfied, even if that means the item they planned on walking out with is instead shipped to their home. At the same time, these devices will be processing sensitive customer payment information that requires a much higher level of security than inventory data (which, by design, should be transparent and widely accessible).

Security teams need to be able to have an active directory of users and devices with assigned permissions that their web gateways can quickly reference to immediately identify potentially suspicious traffic. From there, they need to set a baseline of what is expected/normal traffic based upon device types – frequent traffic between a POS tablet and a warehouse on a busy Saturday, for instance. This will make it easier to identify which activities would immediately appear anomalous, or if an unidentified user/device is attempting to cross the perimeter in the first place.

Separate the Most Sensitive Data
From there, transaction information and other sensitive traffic needs to be vetted through dedicated tools that isolate this information from less-sensitive data, such as inventory figures. This means that retailers should leverage dedicated gateways or paths into the network for transaction data, and similarly separate gateways and pathways for more innocuous information passing in and out of the network.

Inevitably, this will make cybersecurity a more delicate dance than it had been in the past for security and network administrators. That isn’t to say that an organization has to create more splintered operations simply because teams will need distinct capabilities to secure different kinds of traffic. Cloud-based security solutions, for instance, usually enable management of network information through a single console or interface, whereas hardware may require separate management per-device. On the flip side, businesses with sensitive data need to be wary about the information they send into shared-cloud environments, as it may be more prone to breaches by shared parties. The shift to omnichannel will require brands to weigh their priorities and the nature of their data to find a solution that fits best for their interests.

By being able to clearly isolate traffic, identify high-priority data, and secure it all cohesively, brands can more easily transition into an omnichannel future without inadvertently opening themselves up to business-killing data breaches.


As president and co-founder of iboss, Peter Martini has played a major role in developing iboss' innovative technology, and has helped shepherd iboss' phenomenal growth, since its founding. He has been awarded dozens of patents focused on network and mobile security, and with ... View Full Bio
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
11/22/2018 | 1:12:49 AM
Nice article 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
9 Tips to Prepare for the Future of Cloud & Network Security
Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
Attacker Dwell Time: Ransomware's Most Important Metric
Ricardo Villadiego, Founder and CEO of Lumu,  9/30/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-09-30
Re:Desk 2.3 allows insecure file upload.
PUBLISHED: 2020-09-30
Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for a...
PUBLISHED: 2020-09-30
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated ...
PUBLISHED: 2020-09-30
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system...
PUBLISHED: 2020-09-30
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attack...