Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why you Should be Doing More about your Company’s Data Security
Articles

Why you Should be Doing More about your Company’s Data Security

ISBuzz TeamBy ISBuzz TeamDecember 22, 20154 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Company’s Data Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In September, CVS/pharmacy finally confirmed that it had been hit by a data breach of the third-party vendor that operates its photo-printing site. This breach, along with similar breaches at Costco Wholesale and Walmart, resulted in the exposure of consumer credit card information. The news, while widely reported, didn’t make the headlines the way the Target and The Home Depot breaches did.

Over a relatively short span of time, the way consumers and the media react to these exposures of personal data has changed. Studies show that, despite the incidents of data breaches increasing, most customers make no changes to their behavior or attitudes toward companies, believing the breaches to be unavoidable. The result is a limited impetus for companies to improve their security protocols.

But companies that take this laissez-faire attitude on security aren’t just risking customer privacy — they’re failing to seize an opportunity. In a world where data breaches seem inevitable, the first company that can prove the opposite is one that will garner trust and consumer devotion.

The True Cost of Bad Security

Even without negative response from customers, the recovery cost for companies that suffer a breach is still steep. The Home Depot’s data breach of 2014 has been estimated to cost a staggering $10 billion. The Home Depot will survive, but only because its pockets are deep. For smaller businesses, a breach like that could mark a company’s final days.

But even setting aside the high price tag, keeping security as a low priority is just bad marketing. There’s a space in the market for truly security-conscious businesses, and someone is going to fill it.

Locating a Breach

Before you can prevent a breach, it’s important to understand the common weak points in the system.

There are three main areas where breaches usually occur:

  • Point-of-sale systems: Hackers often put malware on POS devices and use them to steal credit card information with each swipe. Many of the high-profile breaches in 2013 were a result of this type of hack.
  • During the transfer of data: While data may be encrypted both before it’s transferred and after it’s stored, the transfer itself is often through unencrypted channels, leaving data vulnerable. Keeping these easily readable channels is similar to wearing a meat suit while scuba diving — it’s not recommended.
  • Where data is stored: This is usually the most difficult of the three to access, but it can also be the most dangerous because of the breadth of data that can be gathered.

Locking Down Your Data

While there’s no way to protect yourself 100 percent, there are steps you can take to ensure sensitive information remains as private as possible.

  1. Update regularly.POS systems should be continually up-to-date with the latest software and firmware. If you’re using a third-party POS device, take special note of the company maintaining the service and its security protocols. Remember that, ultimately, a data breach is your PR problem.
  2. Encrypt all data. This is an easy step, but one that’s often overlooked when data is transferred. You shouldn’t necessarily develop your own algorithm — instead, use trusted modern-day encryption to make your data unreadable, even if hackers do get a hold of it.
  3. Triple-check your storage security. You can’t be too secure when it comes to data storage. The system should be behind a physical firewall with appropriate intrusion detection and intrusion prevention systems. Personnel-wise, access to sensitive data should be kept to as few employees as possible.

Most of all, it’s important to be proactive in your practices and policy; never be satisfied with “good enough.” Deviants will constantly be looking for new ways to get your data, so you must, in turn, find new ways to keep them out. Having a good security plan on paper is a start, but putting it into practice regularly is what’s vital.

By following these three steps on a consistent basis, and being open about them with your customers and partners, you can create a safer business that the public will trust.

[su_box title=”Dusty Wunderlich, Founder and CEO of Bristlecone Holdings” style=”noise” box_color=”#336588″]Dusty WunderlichDusty Wunderlich is the founder and CEO of Bristlecone Holdings, a high-growth network of consumer and business-to-business finance platforms and financial technologies. Its mission is to democratize the world of finance for the better. Dusty is a current recipient of the Twenty under 40 Awards in Reno, Nevada and is a member of the Young Entrepreneur Council.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}