Following are some key findings from the survey:
- While IT is constantly evolving, security must evolve, and often times much more rapidly than the devices they are tasked with protecting. The ability to tightly manage the enterprise is a big driver in managing security and controlling costs
- Security confidence can be closely tied to the device variability within the store, increasing the number of devices is a key driver around introducing significant complication around the ability to secure the store environment
- In the category of retailers that have more than $1 billion in revenue, there is an equal split amongst retailers using a whitelisting approach as compared to antivirus.
As a result of these changes in retail, two significant events have occurred: the increased sharing of information among more and more types of devices (with either LAN or wireless connections), and the need to be able to share information wirelessly within the store. Additionally, there’s the advancing sophistication of the criminal element looking to compromise retailer systems along with ever evolving PCI compliance requirements.
The study revealed that retailers have a good understanding about PCI compliance, but they struggle when the amount and variety of store systems increase to provide the proper security and compliance management. On average only 22 percent trust the manufacturer to provide security.
“The retail storefront has undergone significant changes to deliver convenience and speed to the customer,” said Tom Moore, vice president of worldwide embedded sales at McAfee. “Data breaches are not new to this industry, but the expanded footprint of systems like kiosks and digital signs to the mix is adding complexity to the environment. This research validates that the security concern is real and that retailers need to provide a secure experience for their customers. This is an opportunity for point of sale manufacturers to not only relieve the burden from retailers and solve the security challenge, but also enables manufacturers to provide a high valued product with built in security as a differentiator.”
According to the report, whitelisting is growing in awareness with 31 percent of the respondents including this in their security strategy for POS systems. With McAfee’s application whitelisting solutions, malware can be stopped from ever compromising and infecting a POS system or other device because only the approved application is authorized to run. Any unauthorized, executable application that is introduced to the system is blocked.
The complete report is available here.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.