We have been analyzing the NCR Retail Online (NRO) business and our NCR Industry Solutions Board, an internal team that helps set strategy, has decided to set the NRO product to End of Life on March 31, 2018 . The CPOnline Product was also recently announced with an end of life date of September 30th, 2017 . The End of Life terms indicate that all current customers will need to be transitioned off their respective product and the servers turned off by 9/30/17 (CPO) & 3/31/18 (NRO) . Your NCR Counterpoint business partner has been notified of this decision in advance and has started taking steps to help you transition your eCommerce solution.
Next Steps
As of today, we are encouraging all customers to reach out to your current NCR Counterpoint Partner to begin the transition to a new eCommerce platform. Your partner will be your best resource in planning and transitioning to a new eCommerce solution.
NCR has worked with several partners to create options for your new eCommerce solution. Please refer to the below chart for information about these options. Your partner can provide you with further documentation about these solutions to assist you with the decision process. You can also view a list of FAQ’s about moving from NRO to one of the below options by clicking here .
We will be discussing this transition directly with the users that attend our Synergy User Conference at the end of June. We will be offering a presentation on eCommerce and we will have representatives at the exhibit booth to handle your questions. In the meantime, please reach out to your partner to help determine your next steps.
We appreciate your business and look forward to taking this next, innovative step together.
Recommended eCommerce Solutions
| Solution | Cost | Platform | Additional Notes | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Commerce5 |
|
Magento | Most tightly integrated with Counterpoint and offers the most advanced features | |||||||||||||||||||||
| CP Magento |
|
Magento | Integrated with Counterpoint and offers features similar to NRO | |||||||||||||||||||||
| CP Shop |
|
Woo Commerce | Catalog, Inventory, and Orders are integrated with Counterpoint | |||||||||||||||||||||
Training Your IT Team for Stronger Ecommerce SecurityEcommerce security protocols are only effective when the people responsible for applying them understand the reasons behind each control. A technically advanced storefront can still be exposed by a reused password, an overlooked software update, or a support employee who cannot recognize a convincing phishing message. Retail businesses face an additional layer of complexity because online stores are connected to inventory, point-of-sale systems, customer accounts, payment services, fulfillment tools, and business management platforms. Training must therefore cover both cybersecurity fundamentals and the operational workflows that keep commerce running. This is especially important for organizations moving away from NCR Retail Online. Since the product was discontinued, customers have needed to evaluate replacement platforms, including Magento and WooCommerce, with migration assistance available through NCR Counterpoint partners. A platform transition is an appropriate time to refresh security knowledge, document responsibilities, and test incident response procedures. Set Clear Security Training GoalsBegin by defining what the IT team must be able to do after training. Goals should include identifying common attack methods, enforcing identity and access controls, protecting customer information, monitoring suspicious activity, and responding quickly when an incident occurs. General awareness is useful, but measurable capabilities produce stronger results. Training should also reflect each employee’s role. A systems administrator may need detailed instruction on server hardening, privileged access, and patch management. A developer may require secure coding guidance, dependency scanning, and application programming interface protection. Help desk staff need practical instruction on identity verification and account recovery. Use real workflows from the business rather than abstract examples. Show how an employee creates an account, changes a product record, processes a return, or grants access to a third-party service. Mapping security controls to everyday tasks helps the team understand where mistakes could affect shoppers, inventory accuracy, payment operations, and business continuity. Teach Identity And Access ManagementStrong authentication is one of the most important subjects in an ecommerce security training program. Require multifactor authentication for administrative accounts, cloud dashboards, remote access, and any service that handles sensitive information. Explain why a password alone is inadequate when credentials are stolen through phishing or malware. Access should follow the principle of least privilege. Employees need enough permission to perform their duties, but not unlimited access to customer records, payment settings, production databases, or deployment tools. Train managers and administrators to review permissions regularly, remove dormant accounts, and revoke access promptly when people change roles or leave the organization. Credential management should include approved password managers, unique passwords, secure recovery processes, and restrictions on sharing accounts. Service accounts deserve the same attention as human users. Document their owners, rotate their secrets, limit their permissions, and monitor their activity so that an abandoned integration does not become a hidden entry point. Protect Applications, Data, And IntegrationsDevelopers and infrastructure teams should learn how ecommerce threats affect the entire application stack. Relevant topics include injection attacks, cross-site scripting, broken authentication, insecure direct object references, and flawed authorization logic. Security testing should be included in the development lifecycle through code review, automated scanning, dependency management, and controlled penetration tests. Sensitive data requires careful classification. Customer names, addresses, order histories, employee records, authentication data, and payment-related information should not be treated as ordinary application content. Training should explain encryption in transit and at rest, secure logging practices, data retention limits, and the importance of removing sensitive values from error messages and diagnostic files. Third-party integrations require a separate review. Inventory synchronization, tax services, shipping providers, payment gateways, analytics tools, and marketing platforms may each receive data or connect to privileged functions. When evaluating an alternative to NCR Retail Online, document every integration, determine what access it needs, and confirm that credentials, webhooks, and API tokens are protected. A public-facing platform overview can provide useful product context, but security decisions should be based on current vendor documentation and formal risk assessments.
Build Monitoring And Incident Response SkillsSecurity monitoring training should teach staff what normal ecommerce activity looks like and which deviations deserve attention. Examples include repeated failed logins, unusual administrator activity, sudden changes to product prices, unexpected bulk exports, unfamiliar API calls, and payment behavior that differs sharply from established patterns. The team should know how alerts move from detection to action. Define severity levels, escalation contacts, evidence-preservation requirements, and decision-making authority. An alert that affects a test environment may require routine investigation, while a suspected account takeover or payment compromise may require immediate containment and executive notification. Incident response exercises make these procedures practical. Run scenarios involving stolen credentials, malicious code injected into a storefront, exposed API keys, or a compromised plugin. After each exercise, record delays, unclear responsibilities, missing contacts, and technical obstacles. Update the response plan while the lessons are still fresh. Make Migration Security A Shared ResponsibilityMoving to Magento, WooCommerce, or another ecommerce platform is a security project as much as a technology project. Training should cover data migration, environment separation, backup validation, plugin or extension review, domain changes, and the retirement of legacy accounts. Employees need to understand that old credentials and unused connections remain risks until they are formally removed. Create a migration inventory that identifies data fields, system owners, destinations, retention requirements, and validation steps. Test imports with sanitized data before using production records. Compare customer accounts, product information, stock levels, orders, and fulfillment details after migration to detect both operational errors and unauthorized changes. NCR Counterpoint partners may support customers during platform transitions, but internal staff should retain ownership of security decisions. Establish who approves integrations, who reviews vendor assurances, who monitors the new environment, and who handles emergency access. Clear accountability prevents important tasks from being assumed rather than completed. Reinforce Learning With Practical ExercisesSecurity awareness improves when it is continuous and relevant. Short monthly sessions can cover phishing, browser security, social engineering, software updates, access reviews, and recent incidents in the retail sector. Keep technical workshops separate from general employee awareness training so that each audience receives material suited to its responsibilities. Phishing simulations can test whether employees report suspicious messages without creating a punitive atmosphere. Developers can complete secure coding exercises, while administrators can practice rotating credentials or restoring a clean backup. Customer service teams can rehearse identity verification before changing account details or issuing refunds. Use metrics to measure progress. Useful indicators include multifactor authentication coverage, time to revoke access, patch completion rates, phishing report rates, unresolved high-risk findings, and recovery exercise results. Metrics should guide investment and coaching rather than encourage employees to hide mistakes. Create A Security-First Operating Routine
Training should be reinforced by written procedures that employees can find during a busy incident. Maintain runbooks for account compromise, suspicious orders, malware detection, data exposure, service outages, and failed deployments. Each runbook should include technical actions, communication requirements, evidence-handling guidance, and approval thresholds. For customer-facing ecommerce businesses, security also supports trust during ordinary shopping activity. A retailer reviewing online merchandising or preparing seasonal campaigns, such as a couples gift catalog, should apply the same discipline to promotional pages, tracking scripts, checkout integrations, and account features as it does to core infrastructure. A well-trained IT team turns security from a set of isolated controls into a repeatable business practice. Begin with a role-based skills assessment, align it with the platform transition plan, and schedule exercises that test both technical defenses and human decision-making. Then document the results, close the gaps, and make the next training cycle part of the operating calendar. |
||||||||||||||||||||||||
After you have completed your move to a new eCommerce platform, don’t forget to submit the Store Closure Request form to close your NRO site and cancel your billing subscription.