You are on page 1of 4

CYBERSECURITY FOR

RETAIL ENVIRONMENTS
A Platform Approach

In a competitive and rapidly changing industry that’s continually targeted


by ­cyberthreats, creating a secure digital foundation is critical to success.
Palo Alto ­Networks meets the security needs of retailers by protecting
customer data and v ­ aried retail environments while streamlining s­ ecurity
operations and granting a­ ppropriate network access to employees,
­customers, suppliers and partners.

Challenges
Protect Your Brand From Modern Cyberthreats With a Platform Approach
• Provide excellent in-store
and ­online experiences while Retailers are embracing digital technologies to improve customer experiences and increase
­maintaining customer privacy revenue. With more devices, networks and data, retail IT and security teams need a better,
and continuous availability. more efficient way to thwart new threats and safeguard customer information.

• Preserve brand and consumer trust. Palo Alto Networks® helps retailers around the world ensure service availability and
protect their brands, enabling them to:
• Protect customer data, intellectual
property, inventory, financials, • Simplify compliance by segmenting PCI assets and data.
employee information and other • Protect customer PII and financial information to comply with GDPR and other
sensitive data. regulations.
• Protect a diverse and highly • Grant the right people appropriate access to the right resources.
­distributed environment, often with
limited skilled security ­personnel. • Secure mobile and smart device access.

• Control IT and security costs. • Maintain continuous operations by securing the supply chain and logistics.

• Support smart devices, mo- • Secure cloud and SaaS use.


bility and automation without • Support modern in-store experiences while protecting customer data and
­introducing risks. POS devices.
• Meet regulatory compliance. Palo Alto Networks Security Operating Platform helps retailers remain competitive
• Protect against cyberthreats that by capitalizing on new technologies, including cloud, smart devices, mobile devices
are growing in speed, volume and and ­virtualization, without compromising security or customer service. The platform
sophistication. ­automatically prevents cyberattacks and reduces risk through real-time visibility and
consistent security across retailers’ clouds, networks, endpoint devices and data.

Palo Alto Networks | Cybersecurity for Retail Environments | Brief 1


The platform approach reduces silos of information and manual another level of access control to sensitive data or applications,
intervention from overburdened IT and security teams. Consolidat- enabling retailers to:
ed visibility, policy creation, management, event logging, reporting
• Protect valuable systems, such as POS systems or ­customer
and forensics across security capabilities simplifies operations
databases, in their own network segments, ensuring
and compliance in addition to reducing the potential for miscon-
least-privileged access while continuously scanning for
figurations, outdated policies or overlooked threats. Integration,
threats and data exfiltration.
automation, speedy correlation and other tools in the platform
dramatically reduce events per analyst hour, helping retailers build • Host modern in-store experiences, including customer Wi-
security teams or security operations centers that scale without Fi, smart displays and employee intranet, without adding
the need to add more staff. Existing security staff can improve risk to corporate systems.
response times, focus on critical events, and spend time anticipat-
• Leverage user information from a wide range of repositories,
ing and foiling future attacks.
allowing IT teams to identify users and groups, not just IP
addresses.
Automatically Prevent Known and Unknown Threats From
­Affecting Availability or Reputation • Grant or deny user access to network segments hosting
Employees and contractors may unwittingly or deliberately put the certain functions, such as supplier access to automation or
network or your company’s reputation at risk by following phishing HVAC systems, providing another layer of security beyond
links in emails or downloading files, including ransomware. With usernames and passwords.
new malware created every minute, retail IT teams must constantly • Prevent threats from spreading in the data center using
update their security posture, often manually, to remain effective. east-west segmentation in virtualized public or private
The Security Operating Platform automatically prevents cyberat- environments.
tacks with coordinated anti-malware, web content filtering and
zero-day attack prevention, enabling you to embrace new technol- • Give administrators valuable insight that can prevent security
ogies that improve your competitiveness while vastly reducing the incidents with near-real-time, easily understandable reports.
operational burden on your IT and security teams.
Palo Alto Networks advanced threat analysis environment con- “With Palo Alto Networks and VMware, we know we have a
ducts static and dynamic analysis of suspicious content, even if it’s partner we can trust, whether we are talking about improving
encrypted, in both virtual and bare metal environments. It discovers our processes, adding agility to serve customers, or securing the
brand-new threats never seen anywhere in the world, triggers the data and transactions that run over our network.”
creation of new protections and automatically delivers them to
all platform sensors in as few as five minutes. Security appliances — Tim Melvin, senior director, Global Solutions Delivery,
are continuously updated with intelligence on new phishing and Columbia Sportswear
malware sites, malicious links in emails, and command-and-control
infrastructure, blocking any part of such attacks. The platform
identifies and prevents malware from SaaS applications and public For PCI or data compliance, virtually segmenting cardholder and
cloud environments from infiltrating retailer networks. customer data environments from the rest of the network with
Zero Trust is a best practice that enables retailers to:
Retailers can even block employee credentials from being sent to
unrecognized websites, foiling phishing attempts to steal user- • Restrict access to regulated data by allowing only verified users
names and passwords. and applications to access the environment, blocking all else.
• Use data filtering policies to prevent credit card numbers
“Palo Alto Networks technology enables us to accurately from leaving the environment.
identify and control applications by user, scan content to stop • Reduce the scope of compliance for a PCI or PII audit to just
threats in real time, and prevent data leakage. The company’s the cardholder or customer data environment.
next-generation firewalls help us to create granular, mission-rel-
evant security policies and safely control applications, instead • Simplify audits by identifying users accessing the
of the ‘block-all-or-nothing’ approach offered by traditional ­environment, instead of IP addresses.
port-blocking devices.” Using the threat intelligence and advanced endpoint ­protection
capabilities of the platform, retailers can:
– Christian Brennsteiner, technology architect, SPAR Austria
Group • Meet or exceed IPS requirements and prevent lateral
­movement of malware.

Reduce Risk and Enable Compliance With the Zero Trust ­ • Prevent malware from installing on POS terminals,
Security Model ­thwarting even insider threats from those with physical
access to terminals.
Simple-to-manage yet granular network segmentation is key to
enabling compliance and preventing successful cyberattacks while • Streamline ongoing compliance by making use of automated
serving the diverse needs of employees, store employees, custom- updates across endpoint, network and cloud locations.
ers, suppliers and other valid network users. Palo Alto Networks • Simplify compliance through reporting, logging and audit
platform appliances, whether physical or virtual, segment networks trails that are integrated and centralized.
to reduce the chance of threats moving through them and provide

Palo Alto Networks | Cybersecurity for Retail Environments | Brief 2


Figure 1: Palo Alto Networks Security Operating Platform

The Security Operating Platform


The Palo Alto Networks Security Operating Platform prevents Cloud-delivered security services employ global intel-
successful cyberattacks through automation. It is easy to ligence to filter content as well as detect threats and
operate, with enforcement points and shared intelligence that attackers. These services automatically create protections
work together at network speed to prevent ever-changing against new threats and attacks as well as continuously
threats from affecting your uptime, computers, networks or update endpoint, network and cloud sensors.
data. Accurate analytics allow you to streamline routine tasks Palo Alto Networks has recently opened up the platform,
and focus on business priorities. Tight integration across the enabling you to swiftly take advantage of security innovations
platform and with ecosystem partners delivers consistent that meet the unique needs of your retail environment.
security across clouds, ­networks, computers and mobile
devices. Among the core elements: • Application Framework enables rapid development of
custom and third-party applications that make use of
• Network security employs next-generation firewalls data from the Logging Service and other cloud-delivered
to protect networked services ranging from stores and security services.
distribution centers to data centers. Integrated network
security clients extend security policies and protections • Logging Service provides a secure, cloud-based reposi-
to laptops and mobile devices, whether they are in-store tory for all application and appliance data logs, collecting
or at the coffee shop. data from various sources while eliminating the burden of
scaling and maintaining on-premise compute and storage.
• Advanced endpoint protection safeguards servers,
clients and mobile devices against the latest vulnerabil- Palo Alto Networks apps include:
ity exploits, ransomware and other malware delivered • Behavioral analytics that helps discover anomalous and
via any method, including email, USB drives or other malicious user or application activity inside the network.
attached devices, and other channels.
• Contextual threat intelligence service for malware analyt-
• Cloud security provides the same protections as the net- ics and hunting tools for SOC teams.
work security components for private, public and hybrid
cloud environments, as well as SaaS applications. Deep For more information on the Palo Alto Networks Security
integration with native cloud services and automation ­Operating Platform, please visit https://www.paloaltonetworks.
tools speeds up multi-cloud deployments. com/products/security-operating-platform.

Scale With Consistent Security at Every Location Palo Alto Networks offers a range of platform sizes and virtual
Since retail locations vary in size, function and security needs, deployments for a variety of environments, bringing consistent
retailers often choose different network security vendors for visibility, control, threat posture and security policies to every
their small and large stores, distribution centers, headquarters location. This means:
and data centers. This fragmentation results in greater over- • Stores that are linked back to a central data center via
head for security teams, who must learn and manage several MPLS can backhaul security functions to a large next-­
point products. Fragmented network security also limits threat generation firewall.
visibility and makes compliance complex, with threat detection
and device event reporting that are time-consuming to correlate, • Stores that have more advanced security or local ­internet
if not entirely separate. needs can choose one of several on-premise security
­appliances sized for a variety of remote environments.

Palo Alto Networks | Cybersecurity for Retail Environments | Brief 3


• Larger stores or distribution centers can integrate Palo Alto • A network security client makes use of a secure VPN to add
Networks Security Operating Platform into their on-­­­premise a layer of security to store-owned mobile devices, such as
virtualization environments to maximize flexibility and simpli- tablets for mobile checkout or stock checking, and enforces
fy operations. acceptable use policies.
• Platform components include all suitable protections for • Virtual network segmentation separates customer Wi-Fi
internet gateway and perimeter uses. ­access from employee intranet zones and zones that commu-
nicate with POS terminals or handle sensitive customer data.
• Data centers can deploy stand-alone appliances or lever-
age virtualized platforms to segment east-west traffic and • Advanced endpoint protection pre-emptively protects store
secure communications with external partners, protecting services and computers from zero-day malware, known and
the supply chain. unknown threats, and exploits.

Safely Enable Cloud Use and SaaS Applications Increase ROI With Palo Alto Networks Offerings for Retail
With Palo Alto Networks virtualized platform deployments, Eliminating point products increases the speed and efficacy of
retailers can extend the security of the on-premise network to threat prevention while reducing costs and management over-
public and private clouds. You can protect Amazon® Web Services, head. Retailers may start with one capability and add new ones
Microsoft® Azure® and Google® Cloud Platform environments to the platform over time, growing protection levels without the
and private clouds from advanced cyberattacks while providing cost and complexity of installing and managing new network
application-level control between workloads, consistent policy devices. Each security capability automatically correlates insights
from the network to the cloud, fast deployment and dynamic on emerging threats across endpoints, data centers, SaaS and
security policy updates as workloads change. cloud resources, ensuring fast responses to any threat without
manual intervention. As you add security capabilities, coordination
SaaS applications are traditionally invisible to IT. Palo Alto
increases, as does your return on investment.
­Networks solves this problem by providing full visibility into
the day-to-day activities of employees using SaaS applications,
Getting Started
such as Microsoft Office 365®, Workplace by Facebook®,
­ServiceNow® and many more. Once you determine which Start by gaining visibility into the users, applications and content
applications you want to sanction and tolerate, granular security on your network. Sign up for a free Security Lifecycle Review.
policies block unsanctioned SaaS apps. SaaS security then blocks This non-disruptive process will help define top risks due to
any malicious files from SaaS environments and enforces granular usage, unknown applications, malware and more.
security policies across users, folders and file activities, protecting Customers in more than 150 countries and in every industry
your data that resides in SaaS applications. rely on us to improve their cybersecurity posture. For more
information on Palo Alto Networks, please visit https://www.­
Enable Modern In-Store Experiences While Protecting Customer paloaltonetworks.com­/company/about-us.
Data and POS Devices
For more information on how we protect retail networks
Retailers are employing digital technologies in stores to reduce
­worldwide, please visit https://www.paloaltonetworks.com/­
costs, improve customer experiences and increase sales. The
solutions/industries/enterprise/retail.
Palo Alto Networks Security Operating Platform includes
­multiple features that reduce risk and increase visibility in
modern store environments:
• The platform integrates with leading network access of-
ferings for the mobile enterprise, enabling secure in-store
Wi-Fi for customers and employees as well as devices, such
as tablets, smart displays and kiosks. Customers enjoy a
secure Wi-Fi environment that limits exposure to threats
while stores gain valuable control and visibility over what
customers are doing on the network.

3000 Tannery Way © 2018 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 trademark of Palo Alto Networks. A list of our trademarks can be found at
Main: +1.408.753.4000 https://www.paloaltonetworks.com/company/trademarks.html. All other
Sales: +1.866.320.4788 marks mentioned herein may be trademarks of their respective companies.
Support: +1.866.898.9087 cybersecurity-for-­retail-environment-sb-053018

www.paloaltonetworks.com

You might also like