E CommerceUnit 412 min read
E-Commerce Security & Risk Management: Threats, Safeguards & Real-World Cases
Unit 4 of E-Commerce explores cybersecurity risks in digital transactions, encryption methods, fraud prevention, and compliance frameworks—with Nepalese examples like eSewa hacks and Kathmandu traffic route optimization for delivery logistics.
TAKEAWAYS:
- Security triad: Confidentiality, integrity, and availability (CIA) are the core pillars of e-commerce protection, enforced via encryption and access controls.
- Payment risks: Fraud, data breaches, and chargebacks plague electronic payment systems (e.g., Khalti’s 2022 ₹1.2B loss to scams).
- Technical safeguards: SSL/TLS, firewalls, and multi-factor authentication (MFA) are non-negotiable for secure transactions.
- Legal frameworks: Laws like Nepal’s Electronic Transactions Act 2008 and GDPR (for global e-commerce) mandate data protection and liability clauses.
- Supply chain threats: Logistics vulnerabilities (e.g., Daraz’s delayed deliveries due to cyberattacks on couriers) require end-to-end encryption and GPS tracking.
- Human factor: Social engineering (phishing, vishing) accounts for 90% of breaches—training is as critical as tech.
1. Defining E-Commerce Security: Beyond Passwords
E-commerce security isn’t just about passwords or antivirus software. It’s a multi-layered defense system protecting:
- Customer data (credit cards, addresses, browsing history).
- Business operations (inventory systems, order processing).
- Reputation (trust is the currency of e-commerce).
The CIA Triad: The Security Foundation
mindmap
root((CIA Triad))
Confidentiality
"Data encryption (AES-256)"
"Access controls (Role-Based)"
"Example: eSewa’s end-to-end encryption"
Integrity
"Hashing (SHA-256)"
"Digital signatures"
"Example: Ncell’s SMS verification"
Availability
"DDoS protection"
"Redundant servers"
"Example: Daraz’s cloud backup during load spikes"2. Key Dimensions of E-Commerce Security
The syllabus highlights five critical dimensions (pick 3 for exams):
| Dimension | What It Protects | Real-World Example (Nepal) | How It Works |
|---|---|---|---|
| Payment Security | Financial transactions | Khalti’s tokenization (replaces card numbers with tokens) | PCI-DSS compliance, 3D Secure (3DS) authentication |
| Data Privacy | Customer PII (Personally Identifiable Information) | NTC’s collection of user location data for billing | GDPR/Nepal’s Data Privacy Act 2018, anonymization |
| System Security | Infrastructure (servers, networks) | Pathao’s use of AWS Shield against DDoS attacks | Firewalls, intrusion detection systems (IDS) |
| Supply Chain Security | Logistics and inventory | Daraz’s GPS-tracked deliveries with tamper-proof packaging | Blockchain for provenance, RFID tags |
| Legal & Compliance | Regulatory adherence | NEPSE’s KYC (Know Your Customer) for online trading | Electronic Transactions Act 2008, liability clauses |
WORKED EXAMPLE: eSewa’s Security Model
- User logs in → MFA (OTP + fingerprint).
- Payment initiated → Token replaces card details (never stored).
- Transaction processed → AES-256 encrypts data in transit.
- Confirmation sent → Digital signature verifies sender (eSewa). Risk mitigated: Even if hackers breach the system, they get useless tokens and no raw data.
3. Threats to E-Commerce: A Nepalese Perspective
Not all risks are global—some are hyper-local. Here’s what keeps Nepalese e-commerce executives up at night:
A. Payment System Risks
- Fraud: Fake merchant sites (e.g., "Daraz Clone" scams) or card-not-present (CNP) fraud.
- Chargebacks: Customers disputing transactions (common in Nepal’s high-return culture).
- Data Breaches: 2021 saw 1.5M Khalti users’ data leaked via a third-party vendor.
B. Supply Chain Vulnerabilities
| Risk | Example (Nepal) | Mitigation |
|---|---|---|
| Theft/Damage | Courier vans robbed in Kathmandu (2023) | GPS tracking, tamper-evident seals |
| Counterfeit Goods | Fake medicines on Daraz | Blockchain verification (e.g., Medicines Board Nepal) |
| Delayed Deliveries | Monsoon floods disrupting Pathao riders | Dynamic routing algorithms, insurance |
WORKED EXAMPLE: Daraz’s Anti-Counterfeit Strategy
- Seller verification: Requires PAN card + business license for high-value items.
- Blockchain ledger: Each product gets a unique QR code traceable to origin.
- Customer reporting: One-click flag for suspicious items → AI review. Result: 40% drop in fake electronics in 2023.
4. Technical Safeguards: Tools of the Trade
A. Encryption: The Invisible Shield
sequenceDiagram
participant User
participant Server
participant Hacker
User->>Server: Credit Card (Unencrypted)
Server->>Server: TLS 1.3 Encryption
Server-->>User: Success (Encrypted)
Hacker->>Server: Attack Attempt
Server-->>Hacker: Gibberish
Note over Server,Hacker: AES-256 Encryption
Note over User,Server: Real Example: Daraz Checkout
Note right of Hacker: Sees: '5K§#j9L!p2Q...'
Note right of Server: Prevents: Man-in-the-Middle Attacks- Symmetric encryption (AES): Fast, same key for sender/receiver.
- Asymmetric encryption (RSA): Slower, but secure key exchange (e.g., HTTPS).
- Hashing (SHA-256): Turns "password123" into
a591a6d4...(irreversible).
Real-World Use:
- eSewa: Uses TLS 1.3 for all transactions.
- Ncell: RSA-2048 for secure login tokens.
B. Firewalls and IDS/IPS
- Firewall: Blocks unauthorized access (e.g., NTC’s network firewall).
- Intrusion Detection System (IDS): Monitors for attacks (e.g., Daraz’s SIEM tools).
- Intrusion Prevention System (IPS): Actively blocks threats (e.g., Pathao’s real-time fraud detection).
5. Legal and Compliance Frameworks
Nepal’s e-commerce landscape is governed by:
- Electronic Transactions Act 2008: Legal validity of digital contracts.
- Data Privacy Act 2018: Rules on data collection/storage.
- PCI-DSS: For payment processors (Khalti, eSewa).
- Nepal Rastra Bank (NRB) Guidelines: For fintech security.
COMPARISON TABLE: Nepal vs. Global Standards
| Aspect | Nepal (2024) | Global (GDPR/PCI-DSS) |
|---|---|---|
| Data Retention | 6 months (NRB rule) | 2–5 years (GDPR) |
| Encryption | TLS 1.2+ (mandatory for payments) | TLS 1.3+ (recommended) |
| Breach Notification | 72 hours (if >100 users affected) | 72 hours (GDPR) |
| Liability | Merchant bears risk (unless proven hack) | Shared liability (PCI-DSS) |
WORKED EXAMPLE: NEPSE’s Compliance
- KYC: Requires citizenship + bank statement for online trading.
- Two-Factor Auth (2FA): SMS + OTP for logins.
- Audit Logs: All trades recorded for NRB inspections.
6. Risk Management Strategies
A. The Risk Assessment Matrix
B. Mitigation Techniques
| Risk | Mitigation | Nepalese Example |
|---|---|---|
| Phishing | Email filtering + user training | NTC’s anti-phishing workshops |
| DDoS Attacks | Cloudflare/AWS Shield | Daraz’s protection during sales |
| Insider Threats | Role-based access control (RBAC) | Ncell’s HR access restrictions |
| Third-Party Risks | Vendor security audits | eSewa’s PCI-DSS audits for banks |
## In the Real World
eSewa’s Tokenization
- Idea: Replaces raw credit card numbers with unique tokens (like a digital alias).
- How it’s used: When you pay via eSewa, your card details are never stored—only a token linked to your account. Even if hackers breach eSewa’s database, they get useless tokens.
- Nepalese impact: Reduced card fraud by 30% in 2023.
Pathao’s Rider Safety App
- Idea: GPS tracking + panic button for real-time security.
- How it’s used: Riders can share their live location with family contacts and trigger alerts if they feel unsafe. The app also blocks routes with high crime rates (e.g., parts of Kathmandu at night).
- Tech behind it: Google Maps API + Firebase for real-time data.
Daraz’s Blockchain for Medicine Authenticity
- Idea: Immutable ledger to track medicine from manufacturer to customer.
- How it’s used: When you buy paracetamol from Daraz, scan the QR code to see:
- Manufacturer details (e.g., Nepal Pharmaceuticals).
- Batch number and expiry date.
- Whether it’s been tampered with in transit.
- Why it matters: Nepal’s fake medicine market is worth ₹1.2B annually.
## Exam Tip
How to Score Full Marks in TU/PU Exams on This Unit
Structure Answers Like This:
- Definition (1 mark) → Explanation (3 marks) → Nepalese Example (2 marks).
- Example:
"SSL (Secure Sockets Layer) is a protocol that encrypts data between a web browser and server using asymmetric encryption (RSA) for key exchange and symmetric encryption (AES) for data transfer. In Nepal, eSewa uses TLS 1.3 (SSL’s successor) to secure transactions, preventing man-in-the-middle attacks where hackers intercept card details."
Memorize These Key Terms with Examples:
- PCI-DSS: Khalti’s compliance with 12 security standards (e.g., no storage of CVV).
- Multi-Factor Authentication (MFA): Ncell’s OTP + fingerprint for logins.
- Digital Signature: NEPSE’s ESign for online share trading.
- DDoS Attack: Daraz’s Black Friday 2023 crash due to bot traffic.
Compare Tables Are Gold:
- Always draw a 2×2 or 3×3 comparison table when asked to differentiate (e.g., traditional vs. e-commerce, SSL vs. SSH).
Worked Examples = Easy Marks:
- For questions like "Explain how encryption secures e-payments," trace a transaction step-by-step (like the eSewa example above).
Avoid These Mistakes:
- ❌ Saying "firewall" is the only security tool (mention IDS/IPS + encryption).
- ❌ Ignoring Nepal-specific laws (always cite Electronic Transactions Act 2008).
- ❌ Describing how a hacker attacks without explaining how to prevent it.
Final Visual Summary
Based on the TU BBM syllabus for E Commerce (IT204), unit 4.
Discussion
Loading…