Skip to main content
Research Paper Undergraduate 1,668 words

IT Security Strategy for Zappos Online Retail Operations

~9 min read 6 sections Technology · Cybersecurity
Abstract

This paper examines the IT security strategy employed by Zappos, the online footwear and apparel retailer, across multiple organizational levels. It explores how lapses in IT security can erode consumer confidence, diminish competitive advantage, and reduce repeat business. The paper evaluates Zappos' use of Secure Sockets Layer (SSL) encryption, PCI compliance, end-to-end payment encryption, and firewall protections, while also identifying vulnerabilities — particularly the risk of social engineering at the help desk level. Drawing on primary correspondence with Zappos customer service representatives and secondary academic sources, the paper argues that a robust, organization-wide culture of IT security is essential to supplement technical safeguards.

Key Takeaways
  • IT Security and Consumer Confidence in E-Retailing: Why IT security is vital for online retailers
  • Individual-Level Security and Social Engineering Risks: SSL protections and help desk social engineering vulnerability
  • Team and Departmental IT Security Considerations: Securing intranet communications across departments
  • Organizational-Level Protections and PCI Compliance: PCI compliance, encryption, and organizational security culture
  • Interorganizational, Partnership, and Global Security: Security requirements for partners and global customers
  • References: Cited sources and bibliographic information
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Grounds abstract security concepts in a concrete, real-world case study by using Zappos as the focal organization throughout.
  • Incorporates primary evidence — actual email exchanges with Zappos customer service — to illustrate social engineering vulnerabilities, giving the argument empirical grounding beyond secondary sources.
  • Structures the analysis systematically across escalating organizational levels (individual, team, department, organization, interorganization, partnership, global), creating a logical and comprehensive framework.

Key academic technique demonstrated

The paper effectively combines direct quotation from academic sources with applied analysis. Rather than simply citing security concepts in the abstract, it uses each quoted authority (Foster, Hammermaster, Mishra) to frame a specific observed weakness or strength in Zappos' actual practices, demonstrating the ability to synthesize scholarly literature with case-specific evidence.

Structure breakdown

The paper opens with a general argument for the importance of IT security in e-retailing, then narrows into a tiered analysis of Zappos' security posture at the individual, team, departmental, organizational, interorganizational, partnership, and global levels. This funnel-then-expand structure allows the paper to move from conceptual framing to granular operational detail before broadening back out to global considerations. A full reference list closes the paper.

Essay 1,668 words

IT Security and Consumer Confidence in E-Retailing

The implications of IT security for online retailers are fundamental to ensuring consumer confidence and trust (Streeter, 2009). Moreover, online consumers are far less forgiving of IT security failures than they were just a few years ago, given their positive experiences with other secure sites (Streeter, 2009). Lapses in IT security can also cause a loss of business and a diminution of consumer goodwill accumulated over the years, resulting in a loss of competitive advantage (Mishra, 2009). For companies such as Zappos — where consumers' perception of the "look and feel" of the product line is inherently limited by the online retailing experience — ensuring the security of transactions is a paramount consideration. In this regard, Mishra emphasizes that "Unfortunately, the Internet in its current technological form is a poor service delivery medium because it lacks the capacity for direct personal interaction enjoyed by most noninternet-based services" (2009, p. 128).

When any condition adversely affects consumers' online shopping experience, it is reasonable to suggest that it will have a corresponding impact on their propensity to complete a retail transaction or to engage in repeat business. As Mishra points out, "Various researchers have reported poor perception of e-service and many blunders seem to occur because e-companies fail to deliver real added value services to the customers and to meet their expectations" (2009, p. 129). It is therefore vitally important for online retailers such as Zappos to have timely and effective IT security policies and procedures in place across the entire organization.

Individual-Level Security and Social Engineering Risks

Zappos employs approximately 1,500 individuals, with about one-third of these employees located in their help desk and order fulfillment centers (Looking ahead, 2014). The company's servers are all protected by Secure Sockets Layer (SSL) technology and secure firewalls specifically designed to maintain the security of all digital information and to ensure access only by authorized users (Protecting your personal information, 2015). The SSL protocol is used to manage the security of data transmission over the Internet (Kanabar & Kanabar, 2009). Web pages prefaced with HTTPS rather than HTTP are protected by SSL (Kanabar & Kanabar, 2009).

There is, however, a potential for social engineering to defeat these security protocols. Help desk and call center employees at Zappos are encouraged to be friendly, cordial, and humorous, and are even advised to "be a little weird" in communicating with customers. For example, in response to an inquiry concerning the fact that the company's Trustwave seal was not operational, a company representative responded as follows:

Hello! Thank you for contacting the Zappos.com Customer Loyalty Team. I hope you are having a great day so far! It is a beautiful and sunny day here in Vegas today! I hope you are getting some sunshine where you are as well. I am sorry for any confusion regarding our security policy here at Zappos.com. I would be more than happy to look into this further for you. I want to assure you that Zappos.com is a secure site. I have included a link below for your convenience that explains how we protect your personal information: Also, please keep in mind, we are here 24/7 if you have more questions or need further clarification. Feel free to contact us anytime by phone, live chat, or simply respond to this email. I love this time of year and always look forward to picking out a Christmas tree, hot chocolate by the fire, and more than anything, scarf and sweater shopping! I hope you and your family had a wonderful holiday season! Please let us know if there is anything else we can do for you — we're here 24/7. Thank you for being such a great customer. Have a wonderful day! Thanks! Heidi

This response failed to address the original question about why the Trustwave protection was not in place. A subsequent follow-up email received the following response:

Thank you for contacting the Zappos Customer Loyalty Team. I'm happy to help you today. I hope the weather where you are wasn't too cold today! It's finally getting chilly here in Las Vegas, and we cannot believe the holidays are over! I apologize that your previous email was misread. I did go to our safety page, and you are correct — Trustwave, for some reason, is not recognizing our website, despite the many articles and web searches that link us with them. I have forwarded this information so that it may be corrected. Thank you for bringing this matter to our attention. The security of your personal information is our number one priority, which is why we are consistently ranked among the top websites for positive and safe online transactions. If you are not comfortable purchasing from our website due to this error, we apologize and hope that you are able to find what you are looking for elsewhere. If we can be of any assistance, even to shop on other websites for you, we are here 24/7 to do so. Please let us know if there is anything else we can do for you. Have a wonderful day! Thanks! Heather M.

A subsequent visit to the personal protection page at Zappos revealed that the Trustwave protection seal had been removed. Nevertheless, these exchanges underscore the fact that, in their zeal to be friendly, cordial, and "even a little weird," Zappos employees could unwittingly divulge proprietary information about the company or provide unauthorized access to other customer data. This is a textbook illustration of how social engineering can exploit a culture of openness to bypass technical security controls.

Team and Departmental IT Security Considerations

Zappos places a high priority on the effective collaboration of its teams, irrespective of the format in which they meet (Zappos Family Core Values, 2015). It is therefore vitally important to ensure the security of proprietary information shared between team members, between teams themselves, and across the company's individual departments.

Zappos currently operates the following departments:

Facilities — responsible for stocking the free food and beverages the company provides to all employees, as well as shipping and receiving, office supplies, maintenance, and cleaning.

Finance, Treasury and Accounting — responsible for all financial matters, including payroll processing.

Help Desk — tasked with the provision of online and telephonic customer support services.

Human Resources — provides conventional human resource services, including administering employee benefit programs.

Information Technology — responsible for implementing, maintaining, and upgrading the company's IT systems.

Legal — responsible for the legal aspects of doing business, including the protection of the company's intellectual property (Zappos.com Inc., 2015).

Interdepartmental communications should be protected using a secure company intranet that is not linked to the public Internet. In addition, all communications and collaborations between these departments must be conducted with a view toward an organization-wide culture of IT security.

Organizational-Level Protections and PCI Compliance

Zappos is PCI compliant and encrypts all of its organizational connections using SSL technology. This represents a minimum standard for companies conducting business online. As Hammermaster (2010) reports, "Payment Card Industry (or PCI) compliance is a requirement of all businesses that interact with credit or debit cards. PCI compliance ensures that your clients are up-to-date on the latest best practices to protect their business and their customers from card payment fraud" (p. 22). In addition, Zappos encrypts payment information transmitted within the organization. According to the company, "All payment information is encrypted while in storage within a network that is firewalled off from the rest of the company and the internet" (Protecting your personal information, 2015, para. 2).

This type of end-to-end encryption is widely regarded as a minimum standard of protection for retailers operating online. As Hammermaster (2010) explains, "End-to-end encryption (E2EE) starts with payment capture devices, and goes all the way to the transaction's being authorized. E2EE prevents the card account data from being stolen electronically, and lessens the cost and impact to become a PCI-compliant business" (p. 22).

Notwithstanding these protections, the organization's reliance on a Web hub for its core business means that everyone must be committed to IT security for these protections to be effective (Foster, 2001). As Foster emphasizes, "In the end, company owners and managers must realize that Internet security is a cultural and human resources issue that cannot be solved by technology or policy alone. Instilling a positive organizational culture is the only sure way to guarantee that your employees will be productive and that your company's goals will be met" (2001, p. 34). Although the company notes that its fraud rate is lower than the industry standard, it also concedes that Zappos' IT team remains hard at work minimizing fraudulent activity on its website.

2 Sections Hidden · 240 words
Interorganizational, Partnership, and Global Security120 words
At present, it is unclear whether the company uses SSL encryption in its online communications with other organizations, but this should be a condition of doing business with Zappos for any organization that accesses and processes sensitive information.…
References120 words
Foster, M. (2001, September). Create a positive organizational culture to reduce Internet misuse.…
Key Concepts in This Paper
SSL Encryption PCI Compliance Social Engineering Consumer Trust E-Retailing Security End-to-End Encryption Organizational Culture Help Desk Vulnerability Data Protection IT Security Strategy
Cite This Paper
PaperDue. (2026). IT Security Strategy for Zappos Online Retail Operations. PaperDue. https://www.paperdue.com/study-guide/it-security-strategy-zappos-online-retail-2148376

Always verify citation format against your institution’s current style guide requirements.