IT Security Vulnerabilities and Solutions at Zappos.com
This paper analyzes the information technology security challenges facing Zappos.com, a leading online footwear and apparel retailer. Drawing on the company's own published security disclosures and customer service documentation, the paper identifies several active vulnerabilities: a non-functional Trustwave trust seal, disabled SSL/SSLv3 encryption, the OpenSSL Heartbleed Bug, and inconsistent browser security indicators. The paper evaluates the company's critical IT success factors, examines the methods used to analyze and address these issues, and synthesizes findings to recommend a comprehensive solution—including installation of Fixed OpenSSL across all employees, departments, and global supply chain partners—to protect sensitive customer data and preserve the company's reputation for outstanding customer service.
- Introduction: Zappos background and paper overview
- Statement of the Problem: Specific IT security failures and inconsistencies identified
- IT Organizational Success Factors and Their Relationship to IT Security: How IT security connects to Zappos' business model
- The Best Solution: Heartbleed patch and Trustwave remediation evaluated
- Methods of Analysis, Evaluation, and Synthesis: Analytical approach used to assess vulnerabilities
- Findings: SSL and OpenSSL vulnerability findings summarized
- Conclusion: Recommendations for organization-wide IT security fixes
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper grounds its analysis in direct, first-hand observation—visiting Zappos' live web pages and documenting discrepancies between the company's security claims and actual browser behavior, giving the argument concrete evidentiary weight.
- It connects technical security failures to business consequences (customer trust, brand reputation) by linking IT issues to Zappos' well-documented customer service culture, showing how one undermines the other.
- The paper follows a clear problem–analysis–solution structure that moves logically from identifying specific vulnerabilities to evaluating fixes and recommending actionable remediation steps.
Key academic technique demonstrated
The paper demonstrates applied case study analysis: it takes a real organization, isolates a specific operational problem domain (IT security), and applies a structured analytical framework (problem statement → success factors → solution evaluation → findings) to arrive at practical recommendations. This technique shows how academic frameworks can be anchored to observable, real-world evidence rather than abstract theorizing.
Structure breakdown
The paper opens with a company background introduction, then moves into a formal statement of the problem that documents specific security failures with supporting evidence. A section on IT organizational success factors contextualizes security within Zappos' broader business model. The best solution section evaluates the Heartbleed patch and Trustwave issues, followed by a methods section explaining how the analysis was conducted. A findings section summarizes the SSL situation, and the conclusion delivers concrete, organization-wide remediation recommendations.
Introduction
Established in 1999, Zappos.com, operated and maintained by Zappos IP, Inc., has emerged in recent years as one of the leading providers of online apparel and footwear sales (Zappos media kit, 2014). The company has achieved its success through a combination of top-notch customer service, innovative marketing, and order fulfillment practices, as well as providing its customers with an enormous array of selections. At present, Zappos.com features millions of products from more than one thousand shoe and clothing brands (Zappos media kit, 2014). For six years running, Zappos.com has also been designated one of Fortune's 100 Best Companies to Work For (Zappos media kit, 2014). Moreover, Zappos.com has been rated "Elite" by STELLA Service and was designated one of just 40 J.D. Power's Customer Service Champions in the United States in 2011 (Zappos media kit, 2014).
This paper provides an analysis, evaluation, and synthesis of the best solution for the current information technology security issues at Zappos. A summary of the research and important findings concerning these information security issues is provided in the conclusion.
Statement of the Problem
Companies that use a website as their central business hub for integrated marketing must provide a comprehensive approach to customer service (Cusick, 2009). Irrespective of the type of platforms used for customer interactions, the overarching objective is to develop a positive rapport with customers in order to build loyalty and repeat business (Cusick, 2009). According to Cusick, "Zappos understands that — Web company or not — the true customer experience is the cumulative effect of all interactions and communications on the customer's perception of the company" (2009, p. 122).
While the company has managed to deliver the high quality of customer service needed to build and sustain a successful enterprise, Zappos has experienced significant information technology security issues, some of which remained unresolved at the time of this writing. For instance, on the company's webpage "Protecting Your Personal Information," Zappos states that personal customer information is thoroughly protected by Trustwave. The site encourages visitors to "Click on the Trustwave Trusted Commerce Seal for details regarding the Trustwave compliance and security services provided to Zappos. You can also find verification of this certificate on some Zappos.com secure pages, like our checkout and billing pages" (Protecting your personal information, 2015, para. 4). When visitors click the Trustwave Trusted Commerce Seal, however, the following message appears:
Trustwave does not recognize this organization. Trustwave Holdings, Inc. makes no representation or warranty as to whether systems are secure from either an internal or external attack or whether cardholder data is at risk of being compromised. Trustwave Holdings, Inc. makes no representations or warranties regarding this company's business activities or operations. (Trustwave recognition, 2015, para. 1)
An email query concerning the above, directed to the customer service department at Zappos, remained unanswered at the time of this writing. Despite this incongruence, Zappos continues to emphasize the protections afforded to its customers by the Trustwave service. The company's website states, "While on one of these pages, simply click on the key or lock image in the bottom bar of your browser window. A window will appear with our site security information" (Protecting your personal information, 2015, para. 3). Notwithstanding these assurances, a visit to the company's checkout page revealed that no such key or lock image appeared in the bottom bar of the browser window.
Additional inconsistencies were identified in the company's information technology security systems. The company states that its servers are protected by secure firewalls that provide complete protection for its customers: "You're absolutely safe while you shop. SSL Technology, Trustwave, and Industry Standard Firewalls all work together to ensure your privacy and to assist in protecting your personal data" (Protecting your personal information, 2015, para. 4). Not only is the company's Trustwave protection disabled, but Zappos also reported on October 15, 2014 that it had experienced other problems in its IT security systems. According to a Zappos technician, "Due to the SSL vulnerability that was announced [October 14, 2014], Zappos has taken proactive steps to disable SSLv3/v2. SSL or secure sockets layer provides encryption to prevent your information from being intercepted in between you and a service provider, such as Zappos" (Zappos technology, 2014, para. 2).
Rather than fixing the problem outright, the company instructed its customers to make changes on their own: "If you are using an older browser to connect to our site, you will be impacted by this change and should upgrade to a more secure version" (Zappos technology, 2014, para. 3). Notably, Zappos customers would not know this unless they took the time and effort to explore the company's technology web pages — and even then, not everything works as intended. Similarly, the company states that it does not require customers to provide the 3-digit security code from the back of their credit cards — as virtually every other online transaction requires — because it is not necessary to complete the transaction. The company does emphasize, however, that it employs staff who review transactions for fraudulent activity, and that this policy may change in the future (Protecting your personal information, 2015). The company also continued to experience problems with the manner in which its secure pages were transmitted across different browsers, meaning some customers may not have been fully protected until Zappos identified and implemented corrective actions (Protecting your personal information, 2015).
Finally, a post by the company's information security officer (ZISO) entitled "Heartbleed" (April 17, 2014) reported a major security issue affecting the company's OpenSSL applications. According to the ZISO, a flaw in the company's OpenSSL enabled hackers and other perpetrators to defeat its encryption technologies, revealing usernames, passwords, and other sensitive customer information. Notwithstanding assurances from the company that the problem had been resolved, the ZISO conceded that many customers still reported problems with the company's IT security systems.
IT Organizational Success Factors and Their Relationship to IT Security
Individual information systems and technology (IST) organizational success factors for Zappos relate directly to the company's website hub and the thousands of brands it features. The emerging model used by Zappos is focused on leveraging its human capital resources to maximum advantage — particularly with respect to frontline customer service. Indeed, the company proudly notes that it holds the record for a customer call exceeding ten hours (Zappos media kit, 2014). The critical success factors for the company's IT security systems include the extent to which (a) information provides a vehicle for expressing, sharing, and using knowledge, and (b) the tools of information systems and technology serve as enablers of business processes and networks among employees as well as with customers, suppliers, and partners (Marchand, 2000, p. 137).
As a critical success factor, the company's customer service is inextricably linked to its IT security systems (Cusick, 2009). Rather than using an interactive voice response (IVR) system, Zappos employs live human beings who are intensively trained before being allowed to interact with customers (Cusick, 2009). Trainees are paid during their training and are even offered a $2,000 bonus to decline the job after completing training — a practice that appears to pay off by providing the company with employees who are genuinely committed to its vision and values (Vincent, 2012). As Vincent notes, "Only the employees who truly care about customers and service stay the course. They're the ones who talk to customers over the phone or connect with them via e-mail" (2012, p. 37). Furthermore, customer service representatives at Zappos are empowered to take whatever steps are necessary to satisfy customers, including spending extended time on orders and sending replacement shoes in the event of a quality issue — without requiring the return of the defective pair. As Cusick emphasizes, "Zappos trusts you. Let me repeat that. Zappos trusts you. Imagine how that makes you feel as a customer. It's a powerful sentiment and emotion that connects with people at a very deep level" (2009, p. 122). This powerful sentiment, however, can easily be disrupted by a flaw in the company's IT security systems.
Conclusion
The research showed that Zappos has grown its online business by providing high-quality customer service and a broad array of brands. The company's success is threatened, however, by several IT security issues. In response to these problems, the company should resolve the Trustwave issues and install Fixed OpenSSL for all of its 1,500 employees — including traditional and virtual teams as well as its various departments organization-wide. In addition, all inter-organizational communications must be protected by the Fixed OpenSSL solution, as must the systems of all of the company's global supply chain partners.
Create your account
Always verify citation format against your institution’s current style guide requirements.