We all remember the time period when Chipotle repeatedly had one monumental security breach after another. However, data breaches can happen to restaurant chains and small eateries alike. Nearly half of cyber-attacks target small businesses and 60 percent of small companies who experience a significant attack go out of business.
Ahead of Data Security Day on Jan. 28, Society Insurance has put together a brief guide to help you safeguard your restaurant against cyber attacks and what to do if one happens to you.
What are Common Causes of Data Breach?
An overwhelming majority – a staggering 90 percent – of data breaches are due to human errors, such as a laptop or phone being accessible and stolen, employers or vendors having access to information they shouldn’t, a statement being mailed to the wrong address or a WiFi account not being encrypted. However, this is actually “good” news. Since such a large percentage of cyber attacks are because of human error, there are steps you can take to mitigate the risk.
How Can You Prevent Data Breach?
The best offense is truly a good defense. Restaurants can reduce the risk of cyber attacks by taking these proactive measures:
- Make sure your restaurant is Payment Card Industry (PCI) certified. The PCI Data Security Standard is an information security standard to protect credit card data.
- Use secure passwords and properly secure your WiFi network. Make sure any passwords on mobile devices are encrypted and strong.
- Be skeptical of emails. Question generic greetings (i.e. “Dear Customer”) and threats regarding your financial accounts (i.e. “Please reply within five business days”).
- Stay aware of changing techniques for possible data theft. Bluetooth skimmers, RAM scrapers and malware programs are three common methods that thieves use to take advantage of businesses on a regular basis, but crooks are coming up with new methods constantly. During COVID-19, phishing scams have increased 50 percent, according to Security Magazine. Knowledge of the enemy is important in any battle, and fighting to protect customer data is no different.
What To Do if Your Restaurant is the Victim of a Data Breach
Sooner is always better. Don’t wait and don’t try to “fix” the situation; you’ll need professionals to step in right away.
- Reach out to your financial institution.
- Notify your insurance agent or carrier.
- Consult local authorities.
- Contact affected customers. Even though some states don’t require you to inform impacted customers, honesty will serve you better in the long run. Incredible as the direct expenses from a data breach can be, reputational harm can also cause irreparable damage to a business.
- Make sure services offered to customers fit the nature of the exposed data. If debit or credit card information was exposed, credit monitoring is a waste of money—without a Social Security number, a new credit line cannot be opened via an exposed credit card alone. Inform customers to keep an eye on their accounts and advise they speak to their bank about the breach. Most likely, the affected financial institution will issue a new card.
In 2019, 62 percent of customers were concerned about data breaches at restaurants with top worries cited as stolen payment information, account takeovers and hijacked loyalty rewards points. As more restaurants have moved into online and contactless ordering, these concerns are only going to grow. With the current restaurant landscape, the last thing a restaurant needs is a devastating data breach. Let’s protect ourselves in 2021 and give attackers something else to do this year.