DISCUSSION

Where have all the hackers gone?

Written by Guest contributor

Through a special arrangement, what follows is an excerpt of an article from FierceRetail, an e-newsletter and website covering the latest retail technology news and analysis.

It's been awhile since the last major data breach. Have the hackers moved on from retail or is this a calm before another storm? Probably both and neither.

There are a limited number of really accomplished cybercriminals out there. And as retailers have tightened their technological defenses, these bad guys have moved on to easier and perhaps more lucrative pickings.

Has all the talk about tokenization, PCI DSS standards compliance, point-to-point encryption, EMV chip cards, Apple Pay, Bitcoin and better awareness of malware scared them off? Not likely. While going after softer targets, they are also no doubt preparing a new round of attacks.

For instance, a recent study said that as the transition to EMV chip cards gets established, the bad guys will turn their attention from in-store POS systems to card-not-present online transactions.

Password hacker

Or take this metaphorical example: Your house gets robbed, so you get a dog. The next time that robber bypasses your house and breaks into a neighbor's house where there is no dog, that neighbor gets a bigger and meaner dog than yours, and the cycle starts over.

Is there an end to this cybersecurity arms race? No, at least not in the foreseeable future. It's the cost of staying in business in 2015.

Retailers will need all of the above-mentioned technologies, blended together by someone who knows what they are doing and what cybercriminals are up to. "Though tokenization and EMV have a place, there is no silver bullet. Retailers must consider and assess the security along all points in their processing," said Wolfgang Goerlich, a cybersecurity strategist at CBI.

Two deadlines on the horizon should help retailers set priorities.

The June 30 compliance deadline for five mandatory changes accompanying Payment Card Industry Data Security Standard version 3.0 is a response to the methods and tactics of card data thieves. Retailers who experience a data breach and haven't met the requirements will face heavy fines.

The other is the fraud liability shift deadline for EMV chip cards in October. That is when lagging retailers or banks will assume liability for fraudulent card use depending on who is least prepared to accept the EMV chip cards. Whether it is fair or not, the deadline is a way to incent the industry to make the transition sooner rather than later.

That's a start. Hopefully retailers will follow with other security measures and earn a mention on the list of those who haven't been breached.

Discussion Thread0