Data Security

Web Site Security for Catalogers
April 1, 2005

Be afraid. Be very afraid. As you read this, hackers are scanning your servers for open ports. Or perhaps at this moment a hacker is pasting odd strings into your catalog request form to steal credit card numbers. Worse yet: Your machines might already be compromised โ€” and you donโ€™t even know it. Yes, my intent is to scare. And yes, I sound paranoid. But Iโ€™m actually not. As one security expert told me with no trace of humor, โ€œItโ€™s not paranoia when they really are trying to get you.โ€ As a multichannel merchant, your days should be spent worrying about merchandise, customer

Patch It: Common Network Security Breaches
March 15, 2005

Many merchants still havenโ€™t adequately protected their customersโ€™ data from falling into the wrong hands, said Joe Majka, vice president at VISA USA, during his talk at the conference of the eCommerce and Catalog Systems Forum, held March 3 and 4 in New Orleans. In his work with merchants, Majka says he still finds many merchants guilty of the following: ยฅ No segmentation and/or firewall installed on networks. โ€œThieves can get into a merchantโ€™s system and go anywhere they want to within that data network,โ€ Majka said. ยฅ Un-patched systems and/or default configuration.โ€I often see merchants who havenโ€™t changed the default password that comes

By the Stats: The Impact of Computer Virus Attacks on Business
March 15, 2005

Three-quarters of information technology (IT) managers said their companies are not adequately protected from, or able to prevent, computer virus attacks. Hereโ€™s what else the study from solutions provider SupportSoft found: ยฅ 86% of IT managers said not all of their companiesโ€™ computer systems are updated with software patches when initially distributed. ยฅ 74% said their companies are hit monthly with one or more computer viruses. ยฅ 86% said their No. 1 fear is the loss of employee productivity when their companies are hit with computer viruses. ยฅ 71% said unauthorized programs such as spyware and malware are major concerns and increase IT help

By the Stats: Internet Most Fertile Ground for Fraud
March 1, 2005

Internet-related complaints comprised 53 percent of all fraud complaints processed in 2004, according to a report issued in February by the U.S. Federal Trade Commission. Other statistics reported by the agency: ยฅ Online and offline identity theft accounted for 39 percent of the 635,173 fraud complaints filed in 2004. ยฅ Internet auctions accounted for 16 percent of complaints. ยฅ Shop-at-home and catalog sales accounted for 8 percent of complaints. ยฅ Losses due to Internet fraud amounted to $265 million. ยฅ In 35 percent of all fraud cases, victims were initially contacted via e-mail. For more information, visit www.ftc.gov/opa/2005/02/top102005.htm.

IT Management: Four Steps to Properly Backing Up Your Web Site Data
February 15, 2005

โ€œFor businesses using the Web as a revenue-generating channel, their data are important company assets,โ€ says Chris Kivlehan, marketing manger for INetU Managed Hosting, a Web hosting provider. Losing a customer database in a system-wide crash or other crisis can devastate your business. Orders can go unfulfilled leading to dissatisfied customers and, in turn, reduced revenue. Kivlehan recommends that you talk with your IT manager or a qualified consultant/vendor to discuss back-up procedures and the technologies (e.g., tape drives, separate network storage devices, CDs) needed to do the job properly. In the meantime, here are four steps to help you focus your efforts: 1. Write a

Manage E-mail Privacy Across Multiple Channels
January 4, 2005

With the start of the 2005, the Can Spam Act reaches its one year anniversary. As the year unfolds, itโ€™s especially important to make sure your multichannel business is compliant. Bennie Smith, chief privacy officer at DoubleClick, offers the following tips on how to unify your e-mail campaigns and protect your customersโ€™ privacy. - All e-mail communication to customers should be presented in a clear, consistent and standard fashion. This includes standardizing e-mail subject lines, headers and footers. Your e-mails need to clearly designate they are an advertisement or solicitation, as well as provide functional opt-out mechanisms, says Smith. - Multiple e-mail marketing databases of opt-in

Safeguard Personal Data in Your Care, a Security Checklist
October 12, 2004

Building a solid relationship with customers starts on a foundation of trust. From faith in your product to faith that youโ€™ll deliver on time, the consumer has to have confidence that youโ€™ll keep up your part of the bargain. With identity theft and e-commerce attacks on the rise, one of the biggest leaps of faith that a consumer takes is just handing over his or her personal information to you. The Direct Marketing Association offers the following tips to keep your customersโ€™ information secure: 1. Have a security policy. Establish information security policies and practices to ensure the uninterrupted security of your information systems.

Get Whatโ€™s Coming to You
October 1, 2004

For catalogers, payment fraud accounts for a high cost of doing business. On the Internet alone, estimates are that losses from payment fraud exceeded $1.6 billion in 2003. For direct-response merchants, credit card fraud losses averaged 1 percent of orders in 2003, which may not sound exorbitant, but in terms of total sales, the costs are huge. The good news is that online fraud losses declined from 2.9 percent of total online revenues in 2002 to 1.7 percent in 2003, according to Cybersource Corp./Mindwave Research. The cost to your customers also is high, because for every fraudulent order, merchants reject another three or

Secure Your Customer Data: Hereโ€™s How
August 1, 2003

A computer programmer visited Guess.com last year to look for jeans. Before entering his order, he keyed into the siteโ€™s address bar a string of characters, and up popped about 200,000 of Guess.comโ€™s customer names and credit card numbers. His selection of characters wasnโ€™t random. Rather, the code he keyed in is well-known among programmers, and plugging it in is called an SQL (Structured Query Language) injection attack. In June, Guess.com settled for an undisclosed sum with the Federal Trade Commission (FTC) on charges that it misled consumers by stating in its privacy policy that it protected consumer data when, in fact,

Privacy Under Scrutiny
June 1, 2003

Consumers are nervous about how much of their information is readily available to anyone who knows how to access it. Weโ€™re not talking just about identity theft, which is a criminal offense, but about legal marketing practices. Indeed, consumers are being deluged with direct marketing offers pitched at them by mail, e-mail and telephone. Think about it from their viewpoint. While you think youโ€™re helping consumers by making just-in-time offers to satisfy their needs and desires, theyโ€™re thinking: โ€œWhoa! Can we get a little privacy over here?โ€ Just how much do consumers care about this issue? A lot. For example, 69 percent