What jewellers should know about customer and payment data
ASD's ACSC identifies information such as names, addresses, payment details, email addresses, passwords and phone numbers as examples of personal data.
A jewellery business may/may not hold all of these. The important step is knowing what information your business collects, where it is stored and who can access it.
Know what customer information you hold
ASD's ACSC recommends businesses keep track of customer personal data, limit what they collect and delete information that is no longer needed.
Knowing what you hold can also make it easier to work out what information may be affected after a cyber incident.
Payment information also needs protection
Payment details are among ASD's ACSC examples of personal data.
If your business handles payment information, it should form part of your wider approach to protecting customer data.
How can cyber risk affect a jeweller's POS system?
A POS system forms part of the technology a jewellery business may use to process sales.
If the system becomes unavailable, it may affect the way the business processes transactions. It is also worth understanding what information the system processes or stores and who can access it.
Know what information your POS system handles
Understanding what information your systems process or store can help identify where controls may be needed.
This should form part of the wider review of customer data, payment information and business technology.
Review access to payment-related systems
ASD's ACSC recommends controlling access to customer personal data and limiting employee access to the information needed for their work.
Access controls are also worth considering where payment-related systems provide access to customer personal data.
Why jewellers are a high-value target
- High transaction values, fast-moving goods, time-critical deliveries
- Frequent supplier/courier payments (good for invoice fraud)
- Customer identity + payment information can be valuable
- Often lean IT and shared logins in-store (creates easy entry points)
How jewellers can reduce cyber risk
Insurance is one part of managing cyber risk. Day-to-day security practices also matter.
ASD's ACSC recommends practical steps such as:
- Know what customer information you hold and where it is stored.
- Limit access and remove information that is no longer needed.
- Back up important data and prepare for how you will respond to an incident.
The ASD’s guidance also discusses encryption, monitoring access and secure practices where staff use their own devices for work.
Prepare for a cyber incident
A response plan can help clarify who needs to act, what systems need attention and what reporting requirements may apply.
It can also help identify which insurer, broker or incident response service needs to be contacted if cyber insurance is in place.