ROI: What's the first step retailers can take to protect themselves from such a breach?
CS: Take steps to move their security measures from a negative to a positive. More simply put, they need to get into a proactive state when it comes to the security of their systems and gain the visibility to see if all their in-scope systems (point of sale, terminals, ATMs, back-office servers, workstations, etc.) are within an acceptable configuration, not drifting into a risky state. Having full, real-time visibility throughout their systems will ensure they're compliant with IT and regulatory policy.
Many regulations and best practices around retail (e.g., PCI DSS Version 3.0) call for merchants to move to a proactive security monitoring state, where they can ensure that the security controls they put in place are affective at protecting their systems. The key is to entertain security solutions that let you take control of your systems and actively enforce the security policy, focusing on the business process defined into a trust policy or known good.
- Companies:
- Target
- People:
- Chris Strand