Small Business Retailers Lack Security Requirements: Fortinet | eWeek

Small Business Retailers Lack Security Requirements: Fortinet

Small Business Retailers Lack Security Requirements: Fortinet
Written By
Nathan Eddy
Nathan Eddy
Jan 17, 2014
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

While a majority of small business retailers are aware of an increasingly complex threat and regulatory environment and are applying best security practices and compliance policies to keep safe, more than one in five retailers (22 percent) are not compliant with payment card industry data security standard (PCI DSS), according to a survey sponsored by Fortinet.

An additional 14 percent of the 100 small and midsize business (SMB) organizations surveyed don’t know if they are PCI compliant or not, and more than half (55 percent) of surveyed retailers are unaware of their state’s security breach requirements, while 40 percent lack any established policy adhering to those requirements.

The survey also indicated that SMB retailers would be more likely to consider retail analytics if they were more knowledgeable about the technology. Of the 41 percent that said they are unfamiliar with retail analytics, almost half (49 percent) express that they would like to someday use the technology.

More than half (53 percent) of retailers said they are managing and maintaining their own security infrastructure on-site. However, 18 percent of retailers are now also relying on a managed security services provider (MSSP) to augment their security defenses, while another 29 percent are looking to move more security functions to a third party managed service provider.

Eighty percent of retailers said they want to see physical security infrastructure, such as video cameras, DVRs and alarm systems, housed in a single device that also manages network security mechanisms such as firewall, virtual private network (VPN), anti-virus and Web application firewall.

While almost three-fifths (59 percent) of SMB retailers said they have a data disposal policy in place, 29 percent lack any established data disposal plan, while 12 percent are completely unaware of their organization’s data disposal policy.

“This survey was eye-opening for us. Despite looming threats and stiff compliance penalties, more than a fifth of SMB retailers are still not PCI compliant, while many are falling short of security best practices like password safety,” Patrick Bedwell, vice president of product marketing for Fortinet, said in a statement. “The survey also confirmed that – as with larger retailers – SMBs have a strong interest in big-data analytics, as well as standalone products that incorporate both network and physical security capabilities within a single appliance.”

According to the survey, 15 percent of retailers offering free guest WiFi fail to enforce any kind of security policy, such as blocking unacceptable content, malicious Websites or malware.

While 60 percent of SMB retailers have password protections and enforce them regularly, 40 percent of retailers don’t require their employees to change their password at least once a year, which the report said dramatically increases their risk of data loss.

The survey was conducted by GMI, a division of Lightspeed Research, a provider of technology-enabled solutions and online responses for global market research. Each survey respondent claimed to have knowledge of their company’s business network, payment systems and information security policies. Additionally, respondents were limited to those who use credit or debit card transaction as their primary means of accepting payments.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.