Organisation of Commerce and Management · Ch 5 — Emerging Modes of Business
E-Business Security and Risks
5
E-Business Security and Risks
Why Security Is a Central Concern in E-Business
Because e-business involves transmitting personal information, payment details, and money over the internet, it is exposed to risks that a traditional face-to-face, cash transaction largely avoids. Protecting a transaction's confidentiality, accuracy, and the identity of both parties is essential for customers, and for the government and financial institutions, to trust electronic commerce at all.
Common E-Business Risks
- Hacking — an unauthorised person gaining access to a website, database, or account to steal data, money, or disrupt the business.
- Phishing — fraudulent e-mails, messages, or fake websites designed to trick a person into revealing sensitive information such as passwords, card numbers, or OTPs, by impersonating a genuine bank or company.
- Identity theft — a criminal using someone else's personal or financial details, obtained illegally, to make purchases or transactions the real owner never authorised.
- Data theft / privacy breach — a business's customer database (names, addresses, payment information) being stolen or leaked, causing financial loss and loss of customer trust.
- Viruses and malware — malicious software that can damage a computer system, steal data, or disrupt a website's or company's operations.
- Payment fraud — fraudulent transactions carried out using stolen card details or a compromised account, resulting in loss to the customer, the bank, or the seller.
- Denial-of-service attacks — deliberately overwhelming a website with excessive traffic so that genuine customers cannot access it, disrupting business.
Safeguards Commonly Used
- Encryption — converting data into a coded form during transmission so that even if intercepted, it cannot be read without the correct decryption key; look for "https" and a padlock symbol in a browser as a basic sign that a connection is encrypted.
- Firewalls — software/hardware barriers that monitor and control incoming and outgoing network traffic to block unauthorised access to a business's computer systems.
- Strong authentication — requiring a password together with a One-Time Password (OTP) or another second factor before allowing a login or a payment, so that a stolen password alone is not enough to access an account.
- Secure payment gateways — reputable, certified payment gateways that comply with recognised security standards for handling card and payment data. …
Definition 1Phishing
Fraudulent e-mails, messages, or fake websites designed to trick a person into revealing sensitive information by impersonating a …
Definition 2Encryption
Converting data into a coded form during transmission so it cannot be read without the correct decryption key, protecting …