It seems you cannot go a day without hearing about someone or some group hacking a website or stealing credit card and other sensitive data from ecommerce sites.
So how do you protect your e-commerce site from being hacked and sensitive customer data from being stolen? We have compiled a list of 15 things you can do today to help ensue your sites security & prevent it being hacked.
Choose a secure e-commerce platform:
Put your ecommerce site on a platform that uses a sophisticated object-orientated programming language.
We’ve used plenty of different open source e-commerce platforms in the past and the one we’re using now is by far the most secure. Our administration panel is inaccessible to attackers because it’s only available on our internal network and completely removed from our public facing servers. Additionally, it has a secondary authentication that authenticates users with our internal Windows network.
Use a secure connection for online checkout & make sure you are PCI compliant:
Use strong SSL [Secure Sockets Layer] authentication for Web and data protection. It can be a leap of faith for customers to trust that your ecommerce site is safe, particularly when Web-based attacks increased 30 percent last year. So it’s important to use SSL certificates to authenticate the identity of your business and encrypt the data in transit. “This protects your company and your customers from getting their financial or important information stolen. Even better: integrate the stronger EV SSL [Extended Validation Secure Sockets Layer], URL green bar and SSL security seal so customers know that your website is safe.
SSL certificates are a must for transactions. To validate our credit cards we use a payment gateway that uses live address verification services right on our checkout. This prevents fraudulent purchases by comparing the address entered online to the address they have on file with their credit card company.
Don’t store sensitive data:
There is no reason to store thousands of records on your customers, especially credit card numbers, expiration dates and CVV2 [card verification value] codes. In fact, it is strictly forbidden by the PCI Standards.
We recommend purging old records from your database and keeping a minimal amount of data, just enough for charge-backs and refunds. The risk of a breach outweighs the convenience for your customers at checkout. If you have nothing to steal, you won’t be robbed.
Employ an address and card verification system:
Enable an address verification system (AVS) and require the card verification value (CVV) for credit card transactions to reduce fraudulent charges.
Require strong passwords.
While it is the responsibility of the retailer to keep customer information safe on the back-end, you can help customers help themselves by requiring a minimum number of characters and the use of symbols or numbers. Longer, more complex logins will make it harder for criminals to breach your site from the front-end.
Set up system alerts for suspicious activity:
Set an alert notice for multiple and suspicious transactions coming through from the same IP address.
Similarly, set up system alerts for “multiple orders placed by the same person using different credit cards, phone numbers that are from markedly different areas than the billing address and orders where the recipient name is different than the card holder name.
Layer your security:
One of the best ways to keep your business safe from cybercriminals is layering your security. Start with firewalls, an essential aspect in stopping attackers before they can breach your network and gain access to your critical information. Next, add extra layers of security to the website and applications such as contact forms, login boxes and search queries. These measures will ensure that your ecommerce environment is protected from application level attacks like SQL (Structured Query Language) injections and cross-site scripting (XSS).
Provide security training to employees:
Employees need to know they should never email or text sensitive data or reveal private customer information in chat sessions as none of these communication methods is secure.
Employees also need to be educated on the laws and policies that affect customer data and be trained on the actions required to keep it safe. Use strict written protocols and policies to reinforce and encourage employees to adhere to mandated security practices.
Use tracking numbers for all orders:
To combat chargeback fraud, have tracking numbers for every order you send out. This is especially important for retailers who drop ship.
Monitor your site regularly and make sure whoever is hosting it is, too!
Always have a real-time analytics tool. It’s the real world equivalent of installing security cameras in your shop. Tools like Woopra or Clicky allow you to observe how visitors are navigating and interacting with your website in real time, allowing you to detect fraudulent or suspicious behavior. With tools like these we even receive alerts on our phones when there is suspicious activity, allowing us to act quickly and prevent suspicious behavior from causing harm.
Also, make sure whoever is hosting your ecommerce site regularly monitors their servers for malware, viruses and other harmful software. Ask your current or potential Web host if they have a plan that includes at least daily scanning, detection and removal of malware and viruses on the website.
Perform regular PCI scans:
Perform regular quarterly PCI scans through services like Trustwave to lessen the risk that your ecommerce platform is vulnerable to hacking attempts. If you’re using third-party downloaded software like Magento or PrestaShop, stay on top of new versions with security enhancements. A few hours of development time today can potentially save your entire business in the future.
Patch your systems:
Patch everything immediately literally the day they release a new version. That includes the Web server itself, as well as other third-party code like Java, Python, Perl, WordPress and Joomla, which are favorite targets for attackers.
Breached sites are constantly found running a three-year-old version of PHP or ColdFusion from 2007. So it’s critical you install patches on all software like: Your Web apps, Xcart, OSCommerce, ZenCart and any of the others all need to be patched regularly.
Make sure you have a DDoS protection and mitigation service:
With DDoS [Distributed Denial of Service] attacks increasing in frequency, sophistication and range of targets, ecommerce sites should turn to cloud-based DDoS protection and managed DNS services to provide transactional capacity to handle proactive mitigation and eliminate the need for significant investments in equipment, infrastructure and expertise.
The cloud approach will help [e-commerce businesses] trim operational costs while hardening their defences to thwart even the largest and most complex attacks. In addition, a managed, cloud-based DNS hosting service can help deliver 100 percent DNS resolution, improving the availability of Internet based systems that support online transactions and communications.
Consider a fraud management service:
Fraud does happen. And for merchants, the best resolution is to make sure you are not holding the bag when it does. Most credit card companies offer fraud management and chargeback management services.
This is a practical approach to take because most security experts know there is no such thing as 100 percent safe.
Make sure you or whoever is hosting your site is backing it up & has a disaster recovery plan:
Businesses have big gaps in their data backup plans are putting themselves at risk for losing valuable information in the instance of power outage, hard drive failure or even a virus. So to make sure your site is properly protected, back it up regularly or make sure your hosting service is doing so.
Want news and tips from us delivered directly to your inbox? Sign up for the Social Incite Weekly Digest using the box located here. Get tips, reviews, news, and giveaways reserved exclusively for our subscribers!
Welcome February 2017! Let’s make it a great month. Our quote for the week ahead…. “Opportunities just don’t happen. You create them…..” Start this month by creating & implementing a strong fraud & hacking prevention strategy!
Questions? Drop us a note here.
Social Incite Team