Welcome!

Cloud Security Authors: Zakia Bouachraoui, Elizabeth White, Pat Romanski, Yeshim Deniz, Liz McMillan

Related Topics: Cloud Security, Microservices Expo, Agile Computing

Cloud Security: Blog Post

Making ‘The Year of the Retail Breach’ a Thing of the Past By @ForeScout

While retail IT organizations are keenly aware of the problem, they are often not so clear on the solution

The steadily increasing frequency of data breach occurrences in 2014 has been both astounding and worrisome. From Target and Neiman Marcus to Michaels, Chick-fil-A and Home Depot, fraudsters are leaving no stone unturned, and the millions of customers unlucky enough to use infected point of sale (POS) machines at these retailers now need to worry about whether their sensitive information has fallen into the wrong hands.

While retail IT organizations are keenly aware of the problem, they are often not so clear on the solution. Granted, though fraud-prevention solutions such as chip-and-PIN can help reduce the possibility that a customer's stolen information is useable to a hacker, this is not a failsafe approach and will not prevent an attack in the first place. The vast majority of brick-and-mortar retail attacks are the result of malware being installed on POS terminals, relaying customer data directly to hackers upon a scan. That said, the real problem lies in the endpoint (POS), and once a particularly malicious malware, such as Backoff, takes hold, it is able to proliferate across other POS endpoints on the same network, creating one giant collection facility for hackers that provides customer credit and debit information.

The situation may sound dire, but there are approaches that retail IT teams can take to protect both their and their customers' sensitive data assets. For example, because malware infects the POS machines, and then proliferates to other machines on the same network, implementing a next-generation network security solution capable of continuous monitoring and automatic remediation can help stop an attack before it gains a foothold in a retailer's system.

One important thing to note here is that many legacy network access control (NAC) solutions aren't continuously monitoring for endpoint changes, especially after the endpoint successfully connects to the network. The continuous monitoring piece is an imperative, as it allows IT to spot a change to an endpoint as it occurs, in contrast to periodic scans conducted at specific times that may miss a critical endpoint breach until it's too late to contain. Therefore, a strong security solution capable of continuous monitoring combined with a set of strong security policies to automate remediation allows for the immediate isolation of an offending POS machine from the rest of the network. This allows IT to take all necessary steps to eliminate the malware once removed from the mix.

Next-generation NAC solutions are one place to start looking at solving these issues.

More Stories By Sandeep Kumar

Sandeep Kumar is principal solution marketing manager at ForeScout. He has 20 years of experience in IT security and enterprise products and services. He has previously held senior positions in product marketing, product management and engineering at several enterprise technology companies including Symantec. He holds an MS and bachelor’s degree in computer science.

More than 1,800 of the largest enterprises and government organizations in more than 62 countries use ForeScout’s next-gen network access control for continuous monitoring and mitigation of network threats. The company, located in Campbell, Calif., is a leader in Gartner's network access control Magic Quadrant.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
Dynatrace is an application performance management software company with products for the information technology departments and digital business owners of medium and large businesses. Building the Future of Monitoring with Artificial Intelligence. Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more busine...
If a machine can invent, does this mean the end of the patent system as we know it? The patent system, both in the US and Europe, allows companies to protect their inventions and helps foster innovation. However, Artificial Intelligence (AI) could be set to disrupt the patent system as we know it. This talk will examine how AI may change the patent landscape in the years to come. Furthermore, ways in which companies can best protect their AI related inventions will be examined from both a US and...
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities - ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups.
Chris Matthieu is the President & CEO of Computes, inc. He brings 30 years of experience in development and launches of disruptive technologies to create new market opportunities as well as enhance enterprise product portfolios with emerging technologies. His most recent venture was Octoblu, a cross-protocol Internet of Things (IoT) mesh network platform, acquired by Citrix. Prior to co-founding Octoblu, Chris was founder of Nodester, an open-source Node.JS PaaS which was acquired by AppFog and ...
The deluge of IoT sensor data collected from connected devices and the powerful AI required to make that data actionable are giving rise to a hybrid ecosystem in which cloud, on-prem and edge processes become interweaved. Attendees will learn how emerging composable infrastructure solutions deliver the adaptive architecture needed to manage this new data reality. Machine learning algorithms can better anticipate data storms and automate resources to support surges, including fully scalable GPU-c...
Cloud-enabled transformation has evolved from cost saving measure to business innovation strategy -- one that combines the cloud with cognitive capabilities to drive market disruption. Learn how you can achieve the insight and agility you need to gain a competitive advantage. Industry-acclaimed CTO and cloud expert, Shankar Kalyana presents. Only the most exceptional IBMers are appointed with the rare distinction of IBM Fellow, the highest technical honor in the company. Shankar has also receive...
The standardization of container runtimes and images has sparked the creation of an almost overwhelming number of new open source projects that build on and otherwise work with these specifications. Of course, there's Kubernetes, which orchestrates and manages collections of containers. It was one of the first and best-known examples of projects that make containers truly useful for production use. However, more recently, the container ecosystem has truly exploded. A service mesh like Istio addr...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.