Retail Security Compliance & Incident Response

CyberSecOp works with some of the top retailers around the world. Our aim is to help our customers reduce risk, save time, and save money. One of our most recent success stories comes from our work with the big box US department store chain faced with compliance requirements for CCPA, PCI DSS, also in scope is Shield Act with is pending approval for New York.

Their footprint consisted of hundreds of retail stores and several corporate. Their IT organization was significantly understaffed given the large geographic presence, thereby creating inefficient processes and establishing a greater risk profile for potential threats. Added to the current situation, they had purchased Security hardware and software that wasn’t being utilized which reduced the credibility of the IT team and their ability to push for additional network and security enhancements that would better position the business for future growth.

When during out discovery phase CyberSecOp team uncover multiple suspicious events, missing system logs, infected system, system without antivirus, external remote access without multifactor authentication, and evidence 19 compromised systems communicating with malicious IP addresses and domains.

The project quickly turned into a incident response, CyberSecOp risk management team put a quick playbook together for the operation.

Detailing the intricacies of the incident response, CyberSecOp risk management team involved individuals form accounting, forensics, risk management, CISO level resource to provide guidance, fraud detection, human behavior analysis, and interview/interrogation skills.

RECCOMENDATIONS INCLUDED:

  • Implement CyberSecOp SIEM and Managed Detection and Response Toolset

  • CyberSecOp provide 24/7 monitoring, threat hunting and incident response services

  • Create and implement a incident plan and playbook

  • Assess and Implement a comprehensive security program covering physical security, security personnel, emergency plans, and the associated policies, procedures, and processes in compliance with PCI/CCPA.

CYBER SECURITY SERVICES PROVIDED