Supplier data leak: What fashion retailers need to know and do, according to experts

Three European retailers — Dutch department store De Bijenkorf, Amsterdam eyewear label Ace & Tate and German online fashion platform About You — disclosed customer data leaks in August. These companies faced the consequences of a cyber incident at logistics service provider Ceva Logistics, even though their own systems were not directly hacked. The case illustrates a risk facing any retailer that outsources part of its operation, and raises two questions: how can a retailer prevent customer data from being exposed via a third party, and what action should be taken if something does go wrong?

FashionUnited spoke with experts from the retail, privacy and cybersecurity sectors. They shared what retailers can do to mitigate risks in the supply chain, which agreements they should make with suppliers, and what steps are necessary when an external party is affected.

A retailer does not need to be hacked directly to face the consequences of a data leak. When customer data is held by a logistics, IT, or fulfilment partner, an incident at that supplier can have direct consequences for the retailer. According to Harry Bijl of INretail, retailers still underestimate this risk too often.

“Many retailers think that if they have outsourced something, they have also outsourced the risk. That is precisely the misconception,” states Bijl. The Dutch Data Protection Authority (AP) also emphasises that a retailer remains responsible to the customer when an external party processing personal data is affected. The retailer must report the incident to the AP, when necessary, and inform customers.

Map the data chain

According to Bijl, preventing problems starts with knowing where customer data ends up. Retailers work with a variety of parties, from point-of-sale systems and fulfilment companies to email services; parcel couriers; and loyalty platforms. It is not always clear precisely which data all these parties process.

His advice is therefore to map the entire data flow. Which party has access to which data, why is that data needed, and how long is it stored? A retailer can then assess which information is not essential and therefore does not need to be shared or stored.

This aligns with the advice from the AP. The regulator highlights the importance of data minimisation and retention periods. In simple terms, this means the less personal data a company collects and stores, the less data can be stolen in a data leak.

Check suppliers and preparations

According to Bijl, drafting a contract is not sufficient. He believes retailers must also verify how suppliers secure their systems. A certification like ISO 27001 (international standard for information security) or SOC 2 (standard for controls on system and data security) does not automatically guarantee current security levels. He advises using audit rights and requesting recent pentests (a controlled security test where experts attempt to breach a system) and information on how identified vulnerabilities have been addressed.

According to Koos Wolters, partner and head of cyber security at KPMG in the Netherlands, retailers must also determine which suppliers are essential for daily operations and on which services they depend. He believes supplier risk should therefore be viewed as a business continuity risk.

Clear agreements must be made in advance with key suppliers regarding incident reporting and escalation; minimum security requirements; and collaboration during an incident. According to Wolters, agreements on recovery and downtime, audit rights, and alternative solutions are also important.

For retailers, this could mean considering alternative logistics routes and emergency procedures for order processing in advance. It must also be clear which systems, such as webshops, point-of-sale systems, and distribution centres, will be prioritised during recovery.

If a supplier fails

When a supplier is actually affected by a cyber incident, Wolters says a retailer must first determine the incident's impact on processes, systems, and data. A broadly composed crisis and incident team must then be activated. According to Wolters, this team should include individuals responsible for cybersecurity; IT; privacy; communications; and HR. It should also be supplemented by representatives from the affected business process(es) and senior management. This approach ensures the consequences of an incident can be addressed quickly and in a coordinated manner at the appropriate level.

Where necessary, connections and access rights can be revoked to mitigate further risks. Simultaneously, business continuity measures must be implemented. An investigation into the cause and scope of the incident must also be conducted.

According to Wolters, organisations do not always have a clear view of their supply chain dependencies. Additionally, incident plans are not always practised, which can lead to confusion about responsibilities during a crisis.

Wolters therefore advises retailers to regularly test their incident response and reporting plans and to practise cyber crisis scenarios. “Treat supplier risk as a business continuity risk,” he states. “Know your critical suppliers, formalise agreements, practise scenarios, and ensure you have a viable alternative if a supplier fails.”

Work remains even after a leak

In addition to security shortcomings, the AP also observes issues with the handling of data leaks. According to the regulator, customers are often not informed quickly or specifically enough. They need to know what has happened, what data may have been leaked, and where they can direct their questions as soon as possible.

This is also a security issue. Leaked names, addresses, and order details can be used to create convincing phishing messages. It can be more difficult for a customer to recognise that a message is from a criminal precisely because the information is correct.


OR CONTINUE WITH
Data
Technology