How to Protect Your Site in Case of Cyber Attack


by Claudia Bruemmer

What should merchants do in case of cyber attack? According to security experts, they should disable their site as soon as they realize they are undergoing a hacking attack. It’s better to shut down an ecommerce site right away and put protections in place than to deny the problem and keep the site going since you can risk further damage.

Disabling your site quickly can enable you to gather evidence that could help law enforcement catch the criminals. Merchants need to prepare for attacks, especially during the holiday shopping season.
Merchant databases are vulnerable to attacks as the countdown to Black Friday ticks away. Criminals want whatever consumer information they can get their hands on − things like credit card numbers, birth dates and addresses.

It is estimated 212 million shoppers will shop in stores and online on Black Friday. Of these shoppers, 154.7 million could be at risk, according to data security firms. It is estimated that 70 percent of the data maintained by retail merchants could be vulnerable to information leakage because of a weakness in software that allows criminals to access the sensitive data mentioned above, in addition to billing and shipping addresses.

Hackers are finding many new ways to steal data – from spear phishing to SQL injection. As holiday shopping gets into full swing, merchants will face more criminal attempts to hack web sites and network security systems.

As merchants prepare for the holidays, in addition to stocking shelves and planning for a rush of customers, they should also ensure they have a strong security system and procedures in place. Below are some tips for responding to and preventing criminal infiltrations of websites and computer networks.

Spear phishing is similar to the email phishing attacks that try to trick email recipients into clicking to a website that looks legitimate but is phony and entering personal information such as credit card numbers or banking data. However, in spear phishing the criminals get the email addresses of people like retail executives, and then send them an email that appears to be a legitimate message from a co-worker. When the recipient clicks the attachment icon, instead of seeing a document they may get a blank page and think it’s a glitch. While the recipient may think nothing of it, what happened when they clicked the attachment is that malware was downloaded to their computer. The malware then searches for security openings that expose data, such as customer email addresses and account information. Merchants can guard against such attacks by installing firewalls to block suspicious emails, training employees to check incoming email headers for unusual characters indicating they are not from a trusted party, and by instructing employees not to click on unexpected attachments without first checking with the sender.

SQL (Structure Query Language) is a programming language for managing data across multiple databases such as customer accountdata and email lists. SQL injection attacks are designed to find website and network security vulnerabilities and then steal or compromise confidential data. On retail sites, criminals insert data-stealing scripts into fields where consumers enter such information as name and address. Security experts advise website managers to install software that screens the data entered in those fields to prevent command scripts from executing. In addition to installing firewalls, companies can mitigate the effect of SQL injection attacks by having a good database management and recovery plan in place. This includes knowing exactly where sensitive data are stored, who has access to the data, and having a designated response team assigned to immediately checking sensitive data when a security breach is discovered.

Cloud-based computing and data storage − which is now a popular way for retailers to use other company’s web servers to managetheir websites, applications and databases − requires retailers to take extra steps to ensure that these systems are built with the proper firewalls and that effective policies are in place should a security breach occur. Cloud environments are not more secure or less secure than any other company’s network environment, but it’s important for cloud agreements to address liability in a detailed manner. If there is a security breach, a service-level agreement with the cloud provider should clarify who has access to data, who responds to and investigates a security breach, and how the merchant is ensured that the breach has been fixed.

To review, merchants should disable their site as soon as they realize they are having a cyber attack rather than to deny the problem and keep the site running. It’s also important to have a good database management and recovery plan in place, allowing your designated response team to immediately check sensitive data if a security breach is discovered.

VN:F [1.9.13_1145]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.13_1145]
Rating: 0 (from 0 votes)

Related Articles

Most Popular Articles

6 Comments

Pingback by Standard procedures: Emergency calls to FEMA sites going well | Sugar Sugar Dating
November 14, 2011 @ 3:46 AM

[...] away and put protections in place than to deny the problem and keep the site … Read more on TopTenWholesale News This entry was posted in Sugar-Daddy-Baby-Sites and tagged Calls, Emergency, FEMA, going, [...]

Pingback by How to Protect Your Site in Case of Cyber Attack – TopTenWholesale News | Zynfo™
November 15, 2011 @ 3:16 AM

[...] TopTenWholesale News [...]

Comment by Rongtai
November 19, 2011 @ 4:08 AM

Rongtai company is located in Zhuhai, China in 1999, consists of one factory, one local marketing company & one oversea marketing company with 360 staffs. Sign to video door phone and access control system.
Kindly look for agent and welcome to join us.

VA:F [1.9.13_1145]
Rating: 0.0/5 (0 votes cast)
VA:F [1.9.13_1145]
Rating: 0 (from 0 votes)
Comment by seohztonxpiz
January 4, 2012 @ 9:21 PM

Environment tension [url=http://coachoutlet.factamation.com/ ] [b]coach outlet[/b] [/url] assembly Greenpeace could very well be ongoing it’s advocating crusade next t hurtful chemical interior outfit offer string while utilising th launch engaging new enquiry which often proposes footprints engaging venomous aggregate being present in apparel from form which encompass Adidas, cheap uggs forwomen Abercrombie&Fitch.Collocation is very significant pertaining t ugg [url=http://coachoutlet.factamation.com/ ] http://coachoutlet.factamation.com/ [/url] on the market. Along with bemoaning a lessening of development interior their women’s have o, US apparel retailer Distance Inc has admonished their trading and advocating notion internet trading “ineffective” in traveling buyer journeys over th next district.These uggs sales [url=http://coachoutlet.factamation.com/ ] [b]coach outlet[/b] [/url] are offered in numerous colors, methods and fashoins. Fixin these two locations elizabeth instant ar between their things company claims.

[url=http://www.gamenarcs.com/forum/viewtopic.php?f=47&t=207948]cheap ugg boots and cheap ugg boots online [/url]
[url=http://www.burschen-esting.de/Kalender-file-submit.html]cheap ugg boots for women and cheap uggs for sale [/url]
[url=http://www.rhy-wehra-schraenzer.de/hp/index.php]cheap ugg boots sale and cheap ugg boots [/url]
[url=http://www.lowcostlifeinsurance.biz/alison-denis-joins-liberty-life-insurance-company-as-marketing-director/#comment-1829/]cheap ugg boots for girls and cheap ugg boots [/url]

[url=http://cheapuggbootstore.blogspot.com/ ] [b]cheap ugg boots[/b] [/url]
[url=http://cheapuggbootstore.blogspot.com/ ] [b]cheap ugg boots[/b] [/url]
[url=http://cheapuggbootstore.blogspot.com/ ] [b]cheap ugg boots[/b] [/url]
[url=http://cheapuggbootstore.blogspot.com/ ] [b]cheap ugg boots[/b] [/url]
[url=http://cheapuggbootstore.blogspot.com/ ] [b]cheap ugg boots[/b] [/url]

VA:F [1.9.13_1145]
Rating: 0.0/5 (0 votes cast)
VA:F [1.9.13_1145]
Rating: 0 (from 0 votes)
Comment by Play Station 3
January 5, 2012 @ 8:24 AM

I simply could not go away your site before suggesting that I really loved the usual info a person supply on your guests? Is gonna be back ceaselessly to inspect new posts

VA:F [1.9.13_1145]
Rating: 0.0/5 (0 votes cast)
VA:F [1.9.13_1145]
Rating: 0 (from 0 votes)
Comment by Join Scentsy Puerto Rico Sell Scentsy Canada Sell Scentsy Florida Become a Scentsy Consultant Guam Sell Scentsy Online Sell Scentsy Candles from Home Sell Candle from Home Sell Candles Online Start a Candle Business Online Work from Home Legitimate Work f
January 5, 2012 @ 8:26 AM

Thanks a bunch for sharing this with all of us you really realize what you are speaking about! Bookmarked. Please additionally talk over with my site =). We may have a link trade arrangement between us

VA:F [1.9.13_1145]
Rating: 0.0/5 (0 votes cast)
VA:F [1.9.13_1145]
Rating: 0 (from 0 votes)

RSS feed for comments on this article

Leave a comment

Sign In  |  Register

your E-Mail Address will not be published

 





RSS Feed facebook LinkedIn YouTube
Kole Imports Retail Minded ASD Las Vegas Sourcing at Magic

News Contributors

Claudia Bruemmer Claudia Bruemmer Claudia Bruemmer is the Chief Editor of the TopTenWholesale Newsroom. Experience inclu ... more »
Jason Kole Jason Kole Jason Kole is the VP of Business Development at Kole Imports currently working to make ... more »
Jessica Wang Jessica Wang Jessica Wang is a certified PRC attorney in Shanghai, China. Jessica graduated from Na ... more »
John Stanley John Stanley John Stanley is a coach, consultant, author, speaker and trainer. He has been describe ... more »
Karla Villalobos Karla Villalobos Karla Villalobos has more than 7 years experience in B2B marketing. Currently, she is ... more »
My Nguyen My Nguyen My Nguyen is a professional writer whose interests in music, fashion, and style has le ... more »
Nicole Reyhle Nicole Reyhle Nicole Leinbach Reyhle is an experienced retail and wholesale professional with a pass ... more »
Roger Rappoport Roger Rappoport Roger is the leader of Procopio's Emerging Growth and Technology Practice Group. He ha ... more »
Rueben Marley Rueben Marley Based out of China since 2006, Rueben Marley has a unique and first-hand perspective o ... more »