Cybersecurity affects us all—take proactive measures instead of reacting
Digital threats such as phishing, ransomware, or data breaches can occur at any time and severely disrupt business processes. Recent security incidents in the industry clearly show that being prepared not only protects systems but also safeguards customer data and corporate assets.
On this page, you’ll find:
- a concise FAQ with answers on prevention, what to do in an emergency, and rapid recovery,
- as well as a video that explains the most common cyber risks and shows you how to protect yourself both at work and in your personal life.
Everyone can help reduce risks—by acting prudently, implementing consistent safety measures, and communicating clearly.
FAQ
Cybersecurity encompasses measures that protect the confidentiality, integrity, or availability of data or information systems. An IT security incident is an event that jeopardizes these protection objectives, e.g., through unauthorized access, malware infections, phishing, social engineering, or data loss due to theft, hardware failure, or inadequate backup.
IT is essential for virtually all business processes; breaches of information security can reduce performance or bring business processes to a standstill. In addition to technical risks, individuals are often the target of attacks on corporate information. Cybersecurity is essential because various actors (cybercriminals, hacktivists, state-sponsored hackers, insiders, script kiddies) specifically target companies such as the REWE GROUP to make financial gains, pursue political or social goals, gain economic or geopolitical advantages, or cause damage out of curiosity. Their motivations range from extortion to data theft to sabotage.
- Social engineering (manipulating people into disclosing confidential information)
- Phishing (fraudulent emails or messages designed to obtain login credentials)
- Malware (viruses, worms, Trojans, ransomware)
- DDoS Attacks (Denial-of-Service Attacks)
- Ransomware (data is encrypted, and a ransom is demanded)
- Exploits (Exploiting Unknown Vulnerabilities)
- Insider threats (intentional or accidental attacks by employees)
Social engineering is a manipulative technique in which attackers trick people into revealing confidential information or performing actions that compromise security. This technique exploits the target’s trust.
Every employee contributes to prevention by following guidelines and procedures (e.g., awareness training, strong passwords, multi-factor authentication (MFA), regular updates, firewalls, antivirus software, backups, and access rights management).
A secure password should be at least 15 characters long; for privileged accounts, it should be at least 20 characters long. At least 5 of these characters must be different. Be sure to include at least three of the four character types: uppercase letters, lowercase letters, numbers, and special characters. Additionally: The password must contain at least 2 letters, at least 1 special character (e.g., !, $, #, %, ?, +, -, ~, /), and at least 2 non-letter characters (i.e., numbers or special characters). The password must not contain your first name, last name, or employee ID number. Instead of individual words, it is recommended to use passphrases consisting of several random words that cannot be publicly searched. Each account must have a unique password; reusing personal passwords for work accounts is prohibited. Passwords are changed only if a compromise is suspected; there is no policy for regular password expiration. For secure management, password managers such as KeePass are permitted after IT approval, while storing passwords in browsers or using automatic logins via macros is prohibited. In addition, multi-factor authentication (MFA) should be enabled wherever possible to further enhance security.
Tip: Use the first letters of a sentence or combine random words, e.g., BlueDog!Summer2024.
Multi-factor authentication (MFA) means that, in addition to a password, at least one other independent factor—such as a one-time code, a hardware token, or a biometric feature—is required to log in. It offers significantly enhanced security by creating an additional layer of protection. Even if a password is compromised, a second factor is required, which makes attacks considerably more difficult. Studies show that over 80% of all hacking incidents are attributable to weak or stolen passwords. The use of MFA can prevent up to 99 % of automated attacks. For this reason, the use of MFA is strongly recommended to increase account security and make it significantly more difficult for attackers to gain access.
Stores: Use the self-service feature on the store computer or in the Mein BILLA app to reset your password yourself.
Headquarters: Use the official password reset link at https://passwordreset.rewe-group.com and answer the security questions on file.
Keep safety in mind:
- Always check the URL to avoid phishing.
- Do not use any unofficial links or redirects.
No. Passwords and passphrases are strictly confidential and must not be shared with anyone; shared user accounts are not permitted (except in justified, documented cases following consultation).
Phishing attempts can usually be identified by suspicious emails from fake senders that contain attachments or links and ask for confidential information. Exercise particular caution with emails from unknown external senders—always verify the credibility of the message. Such emails should only be read in the Outlook preview pane; do not open any attachments or links. If in doubt—even with known senders—you should first contact the alleged sender. Report unsolicited emails immediately to sicherheit@rewe-group.at—under no circumstances should you reply to them.
Any potential security incident (e.g., clicking on a suspicious link) must be reported immediately to sicherheit@rewe-group.at.
Send information to external parties only in encrypted form; obtain consent from the person in charge before sharing it, and, if necessary, review or enter into any existing confidentiality agreements.
- Perform regular software updates
- Use firewalls and antivirus software
- Create Backups
- Manage Access Rights
- Display alerts for unusual activity and warnings on the device
- Lock devices to prevent unauthorized access (e.g., Windows key + L)
- Protect screens from prying eyes; use anti-theft measures in areas open to the public
- Do not change the central configuration for mobile devices (smartphones/tablets)
- Use the latest firmware supported by the manufacturer; problematic apps may be blocked or removed
- Encrypt the storage of confidential/strictly confidential data on mobile devices
- Store paper documents securely (cabinet/safe)
- Do not leave work equipment unattended off-site; prevent third parties from accessing it; document any transfers or transport as necessary
- Comply with clean-desk policies
- Clean Whiteboards/Flip Charts After Use
The use of unsecured Wi-Fi hotspots, such as those offered in cafés, train stations, or hotels, is not permitted due to strict security requirements. Instead, only password-protected Wi-Fi or LAN connections may be used in combination with the centrally configured VPN connection (e.g., FortiClient or Cisco AnyConnect). Alternatively, a mobile hotspot can be used via the company cell phone or the built-in data card—also only in conjunction with a VPN. Public networks are considered “untrusted” and therefore must not be used to access company data.
A VPN (Virtual Private Network) creates an encrypted connection between your device and the company network, ensuring that data is transmitted securely. You should always use it when working outside the company network. This helps protect confidential information from unauthorized access.
First and foremost, personal data—that is, any information that can identify a natural person, such as name, address, contact information, or job application materials—deserves special protection. In addition, this includes the special categories of data under the GDPR, such as health data, genetic and biometric data, information regarding sexual orientation, as well as information about political opinions, religious or philosophical beliefs, and union membership. Likewise, confidential business information—such as trade secrets and official secrets, development data, passwords, financial information, and strategic plans—is considered particularly worthy of protection. Finally, this also includes business assets such as documents, merchandise, hardware, laptops, and data from centralized IT environments, which must be handled in accordance with the protection classes of confidentiality, integrity, and availability.
Obtain consent from the data controller(s); review/enter into confidentiality agreements; Encrypt emails containing confidential information when sending them to external parties; when faxing, verify the recipient’s identifier and, if necessary, coordinate the time of transmission; immediately retrieve printouts containing confidential information (ideally using a “Follow-Me” printer).
Send a message to sicherheit@rewe-group.at.