Showing posts with label TJX. Show all posts
Showing posts with label TJX. Show all posts

Friday, October 26, 2007

TJX - Who suffers?

Just a quick break from the 7 habits. They take awhile to think out and I need to post something..

All the signs are pointing that TJX has suffered a text book case hack attempt and so all the Security Chicken Littles were salivating because this would be the "I told you so" opportunity of a lifetime.

And it didn't happen. I blogged about it here and here.

So, what happened? My personal feeling is that this was just the first punch in the fight. Consumers have taken the knock and have felt a bit upset by it but they can deal with it.

In the back of their minds though they have decreased the amount that they like both TJX and credit cards and maybe their bank ever so slightly depending on how much this breach has impacted them.

TJX is lucky in that if their service levels are up to scratch and if they have no more major breaches then over time their image will be improved and their customers will be happy once more.

For the credit card companies it will be a bit harder. If someone now suffers a breach at another store it won't impact TJX but the consumer may feel a bit less trusting of the whole credit card process.

This is problematic in the same way my swimming pool theory is bad for networks. Every store only suffers a bit of the problem but the whole credit card process suffers the most. Perhaps this is why the PCI members (Visa, Mastercard, etc) are working hard to get the stores to implement the PCI DSS security standard. They may find consumers start to give up using credit cards as much or at all ever.

Maybe the answer is actually for the whole process to be scrapped and redone.

Monday, August 27, 2007

More on the TJX Stock

It appears that TJX have taken a bit of a knock but their share capital is $14 Billion.

This means that a hack that costs them $118 Million is peanuts. To them. It essentially ends up costing each shareholder 25c per share. I don't see any shareholder selling shares based on this hack attempt.

The other interesting thing is that while Javelin Strategy and Research said that:

"77 percent of consumers intended to stop shopping at merchants that incurred a data breach"

according to research done in April, they have had to explain how just a couple of months later TJX has reported an increase in sales since they were hacked. Javelin explain that there is just not enough competition.

Gartner are also a bit boggled by this fact but they comment that:

"Most TJX customers clearly care more about discounts than about card security, because they know banks will usually cover potential losses if a card is stolen and used, with the costs eventually shifted back to the retailers."
Gartner go on to preach on how retailers should adhere to good security practices but the "... OR ELSE!" is a bit weak.

I guess this proves that people are just not logical. It will probably take a lot more pain on their behalf before they say that they will avoid shopping at a store with bad card protection and then actually do it.

It also shows that TJX is just not a very good example of what effects a hacking incident can have on a business. They have a strong company, a lot of money to play with and the ability to entice customers back even after TJX has lost their private information.

The TJX stock is just not co-operating!

According to wikipedia :
The TJX Companies, Incorporated is the largest international apparel and home fashions off-price department store chain, based in Framingham, Massachusetts in the United States.

[...]

On January 17, 2007, TJX announced that it was the victim of an unauthorized computer systems intrusion.

TJX ended up as the default PCI black sheep. PCI, for those not in the know, is an industry standard created by the credit card companies telling stores how to protect their customer's information, specifically credit card information.

Basically TJX did everything wrong including storing information they should never have stored in the first place. 45 million credit card numbers are now being traded on the black market because of this breach.

Net income for their 2nd quarter dropped 57% due to information security costs related to the breach.

Bad news for the company, right? Wrong. Maybe someone can explain this to me but on January 16th, 2007 the share price was $29.94. Friday's closing price was $30.75. Man, did the market get them (not)! To be fair they have underperformed the S&P500 until recently but the company does not seem to be very hurt by the breach.

Tuesday, May 8, 2007

The Plastic Swimming Pool Theory of Security


This is one of my theories of Security and why it is such a battle.

I'm not sure if I made it up or heard it somewhere but I stand by it.

"When one person pisses in a swimming pool it affects everyone"

This is why patching is so important but ignored. When a PC on the Internet is compromised by a worm the person who is running the PC may be affected a bit. Their link may slow down slightly but when 100,000 of them are used in a bot-net to attack companies it affects the companies, not the person who owns the PC.

It is the same with TJX etc, personal information stolen from their databases leads to identity theft and hence false purchases all over from many different stores. Everyone is affected.

So, just don't piss in the pool, please. And patch!