LAYERING SECURITY SOLUTIONS WITH EMV AND TOKENIZATION

Size: px
Start display at page:

Download "LAYERING SECURITY SOLUTIONS WITH EMV AND TOKENIZATION"

Transcription

1 tokenex.com LAYERING SECURITY SOLUTIONS WITH EMV AND TOKENIZATION A TokenEx White Paper

2 White Paper LAYERING SECURITY SOLUTIONS WITH EMV AND TOKENIZATION September 2015 Revision 1.1 EXECUTIVE SUMMARY When a new technology is introduced as a mandatory requirement for doing business, it can initially cause confusion and consternation. Especially a technology that requires expensive upfront investments in equipment. Doubly so if it shifts liability for fraud. So it is today with EMV chip-based payments cards and the required card readers. EMV has, so far, been successful at reducing card present fraud and the proliferation of fake mag-stripe cards in Europe where it has been widely implemented. However, the high cost of implementation and its weakness in preventing card-not-present fraud has slowed the introduction in the United States. Confusion abounds as to what the approaching deadline for implementing EMV technology means to retailers and omni-channel businesses; what it does and doesn t accomplish; and how it fits in with other security strategies. This paper will help you understand these conundrums and how the TokenEx Cloud Security Platform, alongside EMV, can assist you in protecting your payment data while lowering costs of PCI compliance and reducing data theft riskwithout impacting your normal business processes. A TokenEx White Paper Page 1 of 9

3 SHIFTING LIABILITY MEANS MORE WORK FOR MERCHANTS AND CONSUMERS Card brands, payment card issuers, and merchants have been fighting it out for years over who gets to lose the most money over payment card fraud. Card brands want to hold the card issuer liable for the losses. Merchants lose sales and deal with chargebacks while footing the bill for the high cost of PCI compliance. In the middle of this muddle are the consumers. Most card-present fraud is perpetrated when black market hackers steal card data from all type of organizations. Brick and mortar retailers, e-commerce web stores, insurance and healthcare organizations, even charity and nonprofits are targets of borderless hackers. The stolen payment card information is commonly used to create new mag-stripe cards so that goods can be quickly bought and resold before the original accounts are cancelled. This cycle of theft creates problems for everyone: Card Issuers get stung by the unrecoverable charges and card replacement fees. Merchants get hit with chargebacks and lost sales as well as heavy fines if their business systems are breached and customer data is stolen. Consumers have to replace cards and cancel accounts and keep an eagle eye out for false charges. Card brands lose consumer confidence when a particular brand is targeted and bad press ensues. It s an endless cycle of data theft, fraudulent purchases, cancelled accounts, and money lost by everyone except the hackers. The root problem is that as long as the payment data is stored in business systems in the first place, the cycle keeps repeating, gaining momentum as more and more data is stolen and the finger pointing continues. CREDIT CARD COMPANIES LAUNCH THE EMV SALVO With all sides exasperated by losing the ongoing card fraud battles with the seemingly inexhaustible tricks and techniques of international hackers, the technology of chip and pin EMV cards was introduced over 10 years ago by the EMVCo organization s six members: American Express, Discover, JCB, MasterCard, UnionPay, and Visa. The result in Europe, where it was widely deployed, was at first encouraging, as card-present fraud declined sharply. The EMV technology proved nearly impossible for hackers to duplicate the chip and pin card combination to make fake cards. And then, like all successful organisms, the hackers evolved and changed tactics to card-not-present (CNP) transactions, and a literal feeding frenzy of online fraud ensued in countries using EMV. A TokenEx White Paper Page 2 of 9

4 Ironically, CNP fraud is not the fault of EMV technology, it s just the next logical avenue of attack for hackers that EMV wasn t designed to prevent. And it turns out that, in many ways, it s even easier than card-present fraud. Now that it s time for the mandatory debut of EMV cards in the United States, the largest market for transactions with credit and debit cards, expectations-and worries-are high. EMV essentially ensures that a card s primary account number (PAN) belongs to the card with the linked chip. At the time of transaction with an EMV card reader, the encrypted icvv data in the card s embedded chip is transmitted to the card issuer to verify the ownership and validity of the PAN on the card. Once verified, payment data is transmitted as usual to the payment processor on a separate channel. The EMV technology effectively prevents the use of stolen card data to create new cards, thus greatly reducing fraudulent card-present transactions. However effective for preventing card-present fraud, the rollout of new cards has a downside. The new EMV cards must coincide with the installation of new and expensive card readers at the point of sale (POS). But imagine you are a company that manages retail fuel stations over several states, with thousands of pumps. Every one of the pumps should eventually be retrofitted with EMV readers at a cost of millions of dollars. Or you are a retail chain with hundreds of stores and checkout counters. In many cases, accepting the occasional card fraud charge can be more cost effective than installing thousands of new EMV readers. In addition, consumers must learn to leave the card in the reader for the duration of the transaction, increasing the chance that a hurried and harried shopper may forget to retrieve the card from the device e.g., a gas station pump resulting in more hassles for the merchant and the consumer. Card issuers are using the traditional carrot and stick approach to convince merchants to implement EMV terminals. Carrot once EMV readers are implemented, any instances of card fraud are absorbed by the card issuer. Stick if EMV is not implemented, liability and costs shifts to the merchant for fraud at the POS. For merchants, that s big money up front, or unknown amounts of money if fraud occurs in the future. Merchants that historically have low occurrences of card-present fraud need to think twice about how quickly they move to EMV devices. But merchants actually have few choices in the long term to find ways to comply with the new EMV card mandate. Bite the bullet and install EMV readers and software in POS systems. Stick with existing devices and accept the risk and cost of fraudulent card-present transactions. Hope that ApplePay or other NFC (Near field Communication) services take off which still requires new POS terminals but will do away with physical cards altogether at some future time. Regardless of the path merchants take to deal with EMV and preventing fraud through POS cardpresent sales, there is another whole level of complexity with card-not-present acceptance channels with EMV cards. A TokenEx White Paper Page 3 of 9

5 CONSUMER AUTHENTICATION FOR CARD-NOT-PRESENT TRANSACTIONS E-commerce merchants or any organization that receives payments over the Internet need to implement additional authentication controls for CNP transactions since the security of the EMV is ineffective without a physical interaction at a POS terminal. Properly implemented on the web store checkout page, an additional authentication code, known only to the consumer and the cardissuing bank, puts the onus of fraud back on the issuer instead of the merchant. But the extra authentication step puts up a potential barrier for the consumer too. The main problem with this isn t technical, it s human nature. Looking at the transaction from the other side of the card, so to speak, consumers will be encouraged by card issuers to implement Consumer Authentication techniques known as 3-D Secure for CNP transactions for online purchases. Unfortunately, each card brand uses a slightly different implementation, so one authentication technique won t work across brands (Visa vs MasterCard vs Discover). Each technique requires passwords, codes, or PINs to be entered for every transaction via online web markets. This proliferation of YAP (yet another password/pin) frustrates consumers and can result in abandoned shopping carts, especially when encountered for the first time by the shopper. Once a web store incorporates a 3-D Secure checkout, the shopper must either have already set up their codes via their banks, or do it on the payment page a potentially complex and baffling process. The first time set up process for establishing unique authentications on the consumer side when online is often ripe for phishing. The Verified-by-Visa protocol, for example, recommends the bank s verification page load in an inline frame session on the merchant s checkout page. However, that process doesn t support any way to verify a security certificate. Hackers have already attacked this process in infected web stores by diverting the setup security window to a fake web page where the card owner literally hands them the keys to the account. How much worse can it get? A TokenEx White Paper Page 4 of 9

6 STOPPING FRAUD AT THE SOURCE Circling back to the real source of card fraud especially CNP is the fact that too many organizations accept, store, and transmit payment card data. This puts organizations at risk for data theft, as well as footing the bill for the high cost of keeping their business systems compliant with PCI Data Security Standards. If payment data is not stored in business systems where it can be stolen, the whole cycle of payment fraud is stopped in its tracks. The mantra of all organizations that work with payment card data should be If you don t need it, don t take it. This deceptively simple model is a guide to protecting your business, your customers information, and disrupting the cycle of fraud. It simply means that unless there is a powerful business reason to accept and store payment card data, you shouldn t touch it at all. With no payment data to steal during a successful hacker breach, organizations can attain three benefits: Reducing PCI compliance costs to the very minimum; Eliminating the risk of losing customer payment (and private) data to hackers; Removing the source of payment fraud because hackers can t steal what s not there. Let s explore how this simple concept can be efficiently implemented before or along with EMV payment technology. Preparing for EMV in Retail and E-Commerce Let s assume that you are a retail organization with both a brick-and-mortar and an online web store presence. This means you have at least two acceptance channels for payments: physical POS checkout and web page shopping cart/checkout. The approaching EMV deadline means you have to: Install EMV terminals in your store, replacing old mag strip readers and update your POS system software. Add a Consumer Authentication step to your web checkout page to protect against CNP fraud. However, even after making these changes, you are still accepting, transmitting, and storing payment data within your business systems. Implementing EMV, while great for protecting the card companies bottom line, does nothing to help you lower your PCI compliance costs or avoid the ramifications of losing customer data during a breach. Since you are revamping your POS and web store acceptance channels, now is the time to examine your need to accept and store payment data at all. By ridding your systems of payment card data, you can save considerable funds that would go to PCI compliance and invest in other security measures such as implementing EMV. A TokenEx White Paper Page 5 of 9

7 Layering in Tokenization to Disrupt the Fraud Cycle The most thorough way to flush your systems of toxic payment card data is to use a tokenization platform that captures payment data at the very edges of your transaction stream EMV POS terminal and web store server encrypts the PAN, stores it in a secure cloud data vault, and returns only mathematically unrelated tokens to your business systems for use in business processes. The TokenEx Cloud Security Platform does exactly that to ensure that all your business systems are cleansed of toxic payment data. A Semi-Integrated Payment Environment Provides Flexibility One of the options that organizations need to consider when implementing EMV and tokenization is whether to opt for a fully-integrated payment environment or a semi-integrated platform. A fully-integrated payment environment consists of one software platform handling all the data from the EMV terminal reading the card data, to Point of Sale software, to bank verification, all the way to the payment processor. While somewhat simpler to implement, this unified model severely limits the flexibility to add or change the components or architecture. For example, in a fully integrated environment, any changes to the terminals or POS software require recertification of the entire system from the card issuer. This includes adding or changing terminal hardware or upgrading POS software anything in your POS architecture that affects the acceptance of payment cards. Recertification can be costly and time consuming with most of the financial burden on the merchants. In addition, a fully-integrated payment system does not lend itself to a layered security approach because all the elements are tightly integrated. Here again, trying to insert extra security layers, such as tokenization, can be difficult and also triggers recertification audits. A semi-integrated payment environment uncouples the EMV terminal from the POS and the payment processer to provide more flexibility. In a semi-integrated payment environment, payment data transmission is limited to the payment platform and the processor. Payment data never reaches the POS system so it can be limited to the lowest levels of PCI controls, resulting in significant savings and reducing risk of data theft through terminal tampering. It s also much easier to layer in tokenization into a semi-integrated payment environment, which is critical to protecting an omni-channel acceptance environment. With a semi-integrated payment environment, you get flexibility, choice, and lower levels of PCI compliance. The TokenEx Cloud Security Platform integrates between the EMV terminal, just like the current P2PE terminals, capturing the encrypted PAN, relaying it to the TokenEx Secure Data Vault, and returning only a token for the POS system to store and use. The EMV authorization step is unaffected by the TokenEx integration. However, if the terminal is changed, for example with a new NFC capable version, since the POS system is isolated from the change by the TokenEx interface, it does not have to be re-certified by the card vendor, reducing costs and increasing flexibility. A TokenEx White Paper Page 6 of 9

8 TokenEx Hosted Payment Page Simplifies CNP Authorization The TokenEx Cloud Security Platform also helps simplify the 3-D Secure consumer authorization step on a web store checkout page.. As previously discussed, the additional steps required to setup and verify the authorization code can be complex, especially the first time a consumer encounters the requirement, so TokenEx supports this process by adding parameter fields. TokenEx can further simplify this process by hosting your payment page on our TokenEx Cloud Security Platform, alleviating the collection of payment data and processing of consumer authorization codes while maintaining the look and feel of your custom web site checkout page. You can read more about the TokenEx Hosted Payment page at our website. An Open Integration Platform Enables Layers of Fraud Prevention Even though your data is safely tokenized, there is still plenty of unguarded data stored in other organizations systems, and that stolen data can be used fraudulently against your business. TokenEx is provides an open integration platform enabling organizations to layer in additional security solutions with your payment processing and business systems. TokenEx can integrate fraud prevention services, such as Kount, directly into your tokenized payment stream, so you get real time alerts on suspect charges. Other real time or batch processing services such as account updater service can also be layered into your payment streams, lowering risk and protecting you against chargebacks. BEING PAYMENT PROVIDER AGNOSTIC IS ESSENTIAL FOR MAXIMUM FLEXIBILITY In addition to cleaning out your toxic payment data, TokenEx Cloud Security Platform is payment processor agnostic, so you can choose to work with one or multiple payment gateways and processors of your choosing. You can even switch among them to obtain the best service and pricing. In addition, once you have multiple payment vendors set up with the TokenEx Transparent Gateway, you have instant backup and redundancy should one provider go dark. Why is freedom of payment processor choice an important consideration for EMV implementation? In an omni-channel acceptance environment you ll need to accommodate retail POS, as well as web stores, call centers, and mobile apps. Depending on your business rules, you may want to have different payment processors or payment services (e.g., fraud detection) processing payments from the different channels. In a fully-integrated payment system, it s difficult to work with multiple providers. With a semi-integrated payment environment using the TokenEx Cloud Security Platform you can use any provider with any channel you choose, providing maximum flexibility. Freedom of choice also extends to being payment acceptance agnostic. Maintaining a semiintegrated payment environment with TokenEx also lets you accept all types of payment card brands, including merchant-branded loyalty cards. On the other hand, if you choose to let your sole payment processor or card brand issuer manage your tokenization, you lose the ability to work with other brands of cards. Your goal is to be as open as possible to accepting payments from any source that your customers want to use. Tokenizing your payment data with TokenEx gives you that freedom. A TokenEx White Paper Page 7 of 9

9 LAYERED SECURITY WITH APPLEPAY AND NFC PAYMENT PROCESSING As you shift your POS to EMV-enabled technology, you should consider the eventual upside to Near Field Communication (NFC), or contactless payments, such as ApplePay or Google Wallet. The NFC technology, while still in its early rollout, will undoubtedly become more prevalent and popular with consumers with its ease of use and security. EMV and NFC capable terminals are not that much costlier than EMV alone. Tokenization is an integral part of ApplePay, albeit a proprietary technique that only works with Apple services. But if consumers have an itunes account, they are likely to use the associated payment card with ApplePay to make purchases. While ApplePay and Google Wallet relieves the merchant of much of the responsibility of payment card fraud, not every customer will have or use this new channel. Plus these vendors exact additional processing fees for every transaction. However, many merchants will ultimately have to accommodate both NFC and EMV purchases. Relying on the TokenEx Cloud Security Platform to encrypt, tokenize, and store all non-applepay transactions provides the same or better level of security, keeping your payment data out of your POS and safe from data theft. With TokenEx, there are no additional costs per tokenization transaction, either. In essence, both EMV and NFC are just additional acceptance channels that merchants must incorporate into their payment strategy. At the end of the day, risk is based on not how you accept payments, but whether you choose to store customer data that can be stolen and used for fraud. Using tokenization to purge all payment data from your business systems is the only real way to ensure that when a breach does occur, there is nothing of value to lose. A TokenEx White Paper Page 8 of 9

10 EMV AND TOKENIZATION WORKING TOGETHER TO PROTECT YOUR ORGANIZATION The sophistication of data thieves and state-sponsored hackers requires layers of security to protect your customers payment and personal data that is the lifeblood of your business. The TokenEx Cloud Security Platform is the best way to get rid of toxic data, so that it can t be stolen from your systems, while lowering the cost of PCI compliance. Its high performance architecture ensures that tokenization integrates readily with your business processes, so that there are minimal changes or impacts to how you operate, while providing the highest level of security for payment card data. EMV is just another layer in the multi-dimensional security architecture required to run a business today. Along with tokenization, fraud detection, chargeback mitigation, and other payment support services, EMV is a necessary layer that keeps your business humming while minimizing payment card fraud, and keeping the burden of financial liability off your shoulders. Need to know more about how EMV and tokenization fits into your specific enterprise? Talk to us today about securing your customer data tomorrow. Contact us at [email protected] or call TOKENEX 1350 South Boulder Suite 1100 Tulsa, Oklahoma A TokenEx White Paper Page 9 of 9

OVERCOMING DATA SECURITY CHALLENGES IN RETAIL PETROLEUM

OVERCOMING DATA SECURITY CHALLENGES IN RETAIL PETROLEUM tokenex.com OVERCOMING DATA SECURITY CHALLENGES IN RETAIL PETROLEUM A TokenEx Case Study Case Study OVERCOMING DATA SECURITY CHALLENGES IN RETAIL PETROLEUM TABLE OF CONTENTS Understanding Data Security

More information

EMV and Restaurants: What you need to know. Mike English. October 2014. Executive Director, Product Development Heartland Payment Systems

EMV and Restaurants: What you need to know. Mike English. October 2014. Executive Director, Product Development Heartland Payment Systems October 2014 EMV and Restaurants: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks, service marks

More information

EMV and Small Merchants:

EMV and Small Merchants: September 2014 EMV and Small Merchants: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks, service

More information

Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER

Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER SHAZAM, Senior Vice President Agenda The Ugly Fraud The Bad EMV? The Good Tokenization and Other Emerging Payment Options

More information

OpenEdge Research & Development Group April 2015

OpenEdge Research & Development Group April 2015 2015: Security, Merchant Readiness & the Coming Liability Shift OpenEdge Research & Development Group April 2015 [email protected] openedgepay.com 2015: Security, Merchant Table of Contents The

More information

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means EMV and Chip Cards Key Information On What This Is, How It Works and What It Means Document Purpose This document is intended to provide information about the concepts behind and the processes involved

More information

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance Payment Security White Paper Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance Breaches happen across all industries as thieves look for vulnerabilities.

More information

EMV in Hotels Observations and Considerations

EMV in Hotels Observations and Considerations EMV in Hotels Observations and Considerations Just in: EMV in the Mail Customer Education: Credit Card companies have already started customer training for the new smart cards. 1 Questions to be Answered

More information

Tokenization: FAQs & General Information. www.tsys.com BACKGROUND. GENERAL INFORMATION What is Tokenization?

Tokenization: FAQs & General Information. www.tsys.com BACKGROUND. GENERAL INFORMATION What is Tokenization? FAQ Tokenization: FAQs & General Information BACKGROUND As technology evolves, consumers are increasingly making their purchases online or through mobile devices and digital wallet applications and their

More information

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard Table of Contents For more than 40 years, merchants and consumers have used magnetic stripe credit cards and compatible

More information

EMV FAQs. Contact us at: [email protected]. Visit us online: VancoPayments.com

EMV FAQs. Contact us at: CS@VancoPayments.com. Visit us online: VancoPayments.com EMV FAQs Contact us at: [email protected] Visit us online: VancoPayments.com What are the benefits of EMV cards to merchants and consumers? What is EMV? The acronym EMV stands for an organization formed

More information

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper 2014. Executive Director, Product Development

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper 2014. Executive Director, Product Development A Heartland Payment Systems White Paper 2014 Heartland Secure. By: Michael English Executive Director, Product Development 2014 Heartland Payment Systems. All trademarks, service marks and trade names

More information

Understand the Business Impact of EMV Chip Cards

Understand the Business Impact of EMV Chip Cards Understand the Business Impact of EMV Chip Cards 3 What About Mail/Telephone Order and ecommerce? 3 What Is EMV 3 How Chip Cards Work 3 Contactless Technology 4 Background: Behind the Curve 4 Liability

More information

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP WHERE IS THE U.S. PAYMENT CARD INDUSTRY NOW? WHERE IS IT GOING? Today, payment and identification cards of all types (credit

More information

The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses. National Computer Corporation www.nccusa.com

The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses. National Computer Corporation www.nccusa.com The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses Making the customer payment process convenient,

More information

Grow with our omni-channel payment processing technologies and merchant services.

Grow with our omni-channel payment processing technologies and merchant services. Grow with our omni-channel payment processing technologies and merchant services. Get ready for growth Payment processing solutions ecommerce mcommerce In-app payments Virtual terminal Card present EMV

More information

Secure Payments Framework Workgroup

Secure Payments Framework Workgroup Secure Payments Framework Workgroup EMV for the US Hospitality Industry Version 1.0 About HTNG Hotel Technology Next Generation (HTNG) is a non-profit association with a mission to foster, through collaboration

More information

What Merchants Need to Know About EMV

What Merchants Need to Know About EMV Effective November 1, 2014 1. What is EMV? EMV is the global standard for card present payment processing technology and it s coming to the U.S. EMV uses an embedded chip in the card that holds all the

More information

Flexible and secure. acceo tender retail. payment solution. tender-retail.acceo.com

Flexible and secure. acceo tender retail. payment solution. tender-retail.acceo.com Flexible and secure payment solution acceo tender retail payment solution tender-retail.acceo.com Take control of your payment transactions ACCEO Tender Retail is a specialized middleware that handles

More information

How Multi-Pay Tokens Can Reduce Security Risks and the PCI Compliance Burden for ecommerce Merchants

How Multi-Pay Tokens Can Reduce Security Risks and the PCI Compliance Burden for ecommerce Merchants How Multi-Pay Tokens Can Reduce Security Risks and the PCI Compliance Burden for ecommerce Merchants 2012 First Data Corporation. All trademarks, service marks and trade names referenced in this material

More information

EMV and Encryption + Tokenization: A Layered Approach to Security

EMV and Encryption + Tokenization: A Layered Approach to Security EMV and Encryption + Tokenization: A Layered Approach to Security 2012 First Data Corporation. All trademarks, service marks and trade names referenced in this material are the property of their respective

More information

Preparing for EMV chip card acceptance

Preparing for EMV chip card acceptance Preparing for EMV chip card acceptance Ben Brown Vice President, Regional Sales Manager, Wells Fargo Merchant Services Lily Page Vice President, Wholesale ereceivables, Wells Fargo Merchant Services June

More information

Chargelytics Consulting

Chargelytics Consulting Chargelytics Consulting Case Study: Understanding the Impacts of Consumer Authentication on Approved Transactions 1 CardinalComerce Chargelytics Consulting Table of Contents: Table of Contents. 1 Executive

More information

Credit card: permits consumers to purchase items while deferring payment

Credit card: permits consumers to purchase items while deferring payment General Payment Systems Cash: portable, no authentication, instant purchasing power, allows for micropayments, no transaction fee for using it, anonymous But Easily stolen, no float time, can t easily

More information

Apple Pay. Frequently Asked Questions UK Launch

Apple Pay. Frequently Asked Questions UK Launch Apple Pay Frequently Asked Questions UK Launch Version 1.0 2015 First Data Corporation. All Rights Reserved. All trademarks, service marks and trade names referenced in this material are the property of

More information

Payments simplified. 1

Payments simplified. 1 1 Payments simplified. T H E PAY M E N T I N D U S T RY A I N T W H AT I T U S E D T O B E 2 Complexity is increasing, More change in next 5, than last 50 Emerging payments / loyalty / rewards / coupons

More information

Apple Pay. Frequently Asked Questions UK

Apple Pay. Frequently Asked Questions UK Apple Pay Frequently Asked Questions UK Version 1.0 (July 2015) First Data Merchant Solutions is a trading name of First Data Europe Limited, a private limited company incorporated in England (company

More information

The Comprehensive, Yet Concise Guide to Credit Card Processing

The Comprehensive, Yet Concise Guide to Credit Card Processing The Comprehensive, Yet Concise Guide to Credit Card Processing Written by David Rodwell CreditCardProcessing.net Terms of Use This ebook was created to provide educational information regarding payment

More information

Introductions 1 min 4

Introductions 1 min 4 1 2 1 Minute 3 Introductions 1 min 4 5 2 Minutes Briefly Introduce the topics for discussion. We will have time for Q and A following the webinar. 6 Randy - EMV History / Chip Cards /Terminals 5 Minutes

More information

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc.

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc. Payment Methods The cost of doing business Michelle Powell - BASYS Processing, Inc. You ve got to spend money, to make money Major Industry Topics Industry Process Flow PCI DSS Compliance Risks of Non-Compliance

More information

Mobile Near-Field Communications (NFC) Payments

Mobile Near-Field Communications (NFC) Payments Mobile Near-Field Communications (NFC) Payments OCTOBER 2013 GENERAL INFORMATION American Express continues to develop its infrastructure and capabilities to support growing market interest in mobile payments

More information

PCI and EMV Compliance Checkup

PCI and EMV Compliance Checkup PCI and EMV Compliance Checkup ATM Security Jim Pettitt Director, ATM Security Diebold Incorporated Agenda ATM threats today Top of mind risk PCI Impact on Security U.S. EMV Migration Conclusions / recommendations

More information

Changing Consumer Purchasing Patterns. John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association

Changing Consumer Purchasing Patterns. John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association Changing Consumer Purchasing Patterns John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association Michigan Retailers Association! Michigan Retailers Association is trade

More information

Wayne EMV Solutions. Protect your business with a complete EMV Solution inside and out.

Wayne EMV Solutions. Protect your business with a complete EMV Solution inside and out. Wayne EMV Solutions Protect your business with a complete EMV Solution inside and out. The transition to Europay, MasterCard, Visa (EMV) standards: Significantly reduce your risk of payment card fraud

More information

Trends in Merchant Payment Acceptance

Trends in Merchant Payment Acceptance Trends in Merchant Payment Acceptance December 6, 2007 Credit approval required. Merchant accounts are issued through BB&T Bankcard Corporation, a Georgia Corporation, Member FDIC. 2007 BB&T. All rights

More information

Common Mistakes to Avoid When Selecting a Payment Processor

Common Mistakes to Avoid When Selecting a Payment Processor 7 Common Mistakes to Avoid When Selecting a Payment Processor Introduction Selecting a payment processor is one of the most important steps to getting paid online. But comparing solutions for accepting

More information

Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement"

Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement !!!! Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement" Here$is$a$simple,$cost$effective$way$to$achieve$transaction$security$for$ mobile$payments$that$allows$easy$and$secure$provisioning$of$cards.$

More information

Revenue Security and Efficiency

Revenue Security and Efficiency Revenue Security and Efficiency Discussion with the Mid-Atlantic Oracle Applications Users Group CardConnect Solution Oracle EBS Validated Application Oracle EBS Validated Application Securing Payment

More information

White Paper: Are there Payment Threats Lurking in Your Hospital?

White Paper: Are there Payment Threats Lurking in Your Hospital? White Paper: Are there Payment Threats Lurking in Your Hospital? With all the recent high profile stories about data breaches, payment security is a hot topic in healthcare today. There s been a steep

More information

A RE T HE U.S. CHIP RULES ENOUGH?

A RE T HE U.S. CHIP RULES ENOUGH? August 2015 A RE T HE U.S. CHIP RULES ENOUGH? A longer term view of security and the payments landscape is needed. Abstract: The United States is finally modernizing its card payment systems and confronting

More information

What is EMV? What is different?

What is EMV? What is different? U.S. consumers are receiving new debit and credit cards with embedded chip technology that better stores and protects cardholder information. These new chip cards are part of the new card standard, Europay,

More information

U.S. Smart Card Migration: Stripe to EMV Claudia Swendseid, Federal Reserve Bank of Minneapolis Terry Dooley, SHAZAM Kristine Oberg, Elavon

U.S. Smart Card Migration: Stripe to EMV Claudia Swendseid, Federal Reserve Bank of Minneapolis Terry Dooley, SHAZAM Kristine Oberg, Elavon U.S. Smart Card Migration: Stripe to EMV Claudia Swendseid, Federal Reserve Bank of Minneapolis Terry Dooley, SHAZAM Kristine Oberg, Elavon UMACHA Navigating Payments 2014 October 8, 2014 Who We Are Claudia

More information

THE ROAD TO U.S. EMV MIGRATION Information and Strategies to Help Your Institution Make the Change

THE ROAD TO U.S. EMV MIGRATION Information and Strategies to Help Your Institution Make the Change THE ROAD TO U.S. EMV MIGRATION Information and Strategies to Help Your Institution Make the Change Advancements in technological capabilities, along with increasing levels of counterfeit fraud, led the

More information

Bringing Mobile Payments to Market for an International Retailer

Bringing Mobile Payments to Market for an International Retailer Bringing Mobile Payments to Market for an International Retailer Founded in 2011, Clearbridge Mobile has emerged as a world class studio developing state of the art wearable and mobile wallet / payment

More information

EMV's Role in reducing Payment Risks: a Multi-Layered Approach

EMV's Role in reducing Payment Risks: a Multi-Layered Approach EMV's Role in reducing Payment Risks: a Multi-Layered Approach April 24, 2013 Agenda EMV Rationale Why is this worth the effort? Guides how we implement it EMV Vulnerability at the POS EMV Impact on CNP

More information

Table of Contents. Overview. What is payment processing? Who s Who. Types of Payment Solutions. Online Transactions. Interchange Process

Table of Contents. Overview. What is payment processing? Who s Who. Types of Payment Solutions. Online Transactions. Interchange Process Overview Credit Card Processing 101 is your go-to handbook for navigating the payments industry. This document provides a quick and thorough understanding on how businesses accept electronic payments,

More information

Your Reference Guide to EMV Integration: Understanding the Liability Shift

Your Reference Guide to EMV Integration: Understanding the Liability Shift Your Reference Guide to EMV Integration: Understanding the Liability Shift UNDERSTANDING EMV EMVCo was formed in February 1999 by Europay, MasterCard and Visa to establish and maintain global interoperability

More information

Digital Payment Solutions TSYS Enterprise Tokenization:

Digital Payment Solutions TSYS Enterprise Tokenization: Digital Payment Solutions TSYS Enterprise : FAQs & General Information FAQ TSYS DIGITAL DIGITAL PAYMENT PAYMENTS SOLUTIONS SOLUTIONS Account Holder Experience Apple Pay 1 Android Pay 2 Samsung Pay 2 Issuer

More information

Accepting Ecommerce Payments & Taking Online Transactions

Accepting Ecommerce Payments & Taking Online Transactions Accepting Ecommerce Payments & Taking Online Transactions Accepting credit and debit cards is mandatory for Ecommerce websites. This method is fast and efficient for you and your customers and with the

More information

EMV-TT. Now available on Android. White Paper by

EMV-TT. Now available on Android. White Paper by EMV-TT A virtualised payment system with the following benefits: MNO and TSM independence Full EMV terminal and backend compliance Scheme agnostic (MasterCard and VISA supported) Supports transactions

More information

Mistake #1: Assuming that lowest rate means lowest overall cost.

Mistake #1: Assuming that lowest rate means lowest overall cost. Introduction Congratulations you ve selected a top-notch e-commerce website solution. But you re not done yet. In fact, the next choice you make will be one of the most important in the process of setting

More information

How Online Payments Really Work

How Online Payments Really Work Insights for Businesses How Online Payments Really Work If you re thinking about setting up an online store, you re in good company. Shoppers are increasingly turning to online options, as their access

More information

Payments Transformation - EMV comes to the US

Payments Transformation - EMV comes to the US Accenture Payment Services Payments Transformation - EMV comes to the US In 1993 Visa, MasterCard and Europay (EMV) came together and formed EMVCo 1 to tackle the global challenge of combatting fraudulent

More information

EMV EMV TABLE OF CONTENTS

EMV EMV TABLE OF CONTENTS 2 TABLE OF CONTENTS Intro... 2 Are You Ready?... 3 What Is?... 4 Why?... 5 What Does Mean To Your Business?... 6 Checklist... 8 3 U.S. Merchants 60% are expected to convert to -enabled devices by 2015.

More information

EMV FAQs for developers

EMV FAQs for developers EMV FAQs for developers You accept the Information presented herein as is, without any representation as to its accuracy or completeness. What are the three levels of EMV certification? There are three

More information

PCI Compliance for Healthcare

PCI Compliance for Healthcare PCI Compliance for Healthcare Best practices for securing payment card data In just five years, criminal attacks on healthcare organizations are up by a stunning 125%. 1 Why are these data breaches happening?

More information

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism Tokenization Amplified XiIntercept The ultimate PCI DSS cost & scope reduction mechanism Paymetric White Paper Tokenization Amplified XiIntercept 2 Table of Contents Executive Summary 3 PCI DSS 3 The PCI

More information

EMV and Restaurants What you need to know! November 19, 2014

EMV and Restaurants What you need to know! November 19, 2014 EMV and Restaurants What you need to know! Mike English Executive Director of Product Development Kristi Kuehn Sr. Director, Compliance November 9, 204 Agenda EMV overview Timelines Chip Card Liability

More information

Credit Card Processing Overview

Credit Card Processing Overview CardControl 3.0 Credit Card Processing Overview Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

Online Payment Processing What You Need to Know. PayPal Business Guide

Online Payment Processing What You Need to Know. PayPal Business Guide Online Payment Processing What You Need to Know PayPal Business Guide PayPal Business Guide Online Payment Processing 2006 PayPal, Inc. All rights reserved. PayPal, Payflow, and the PayPal logo are registered

More information

E M V I M P L E M E N TAT I O N T O O L S F O R S U C C E S S, P C I & S E C U R I T Y. February 2014

E M V I M P L E M E N TAT I O N T O O L S F O R S U C C E S S, P C I & S E C U R I T Y. February 2014 E M V I M P L E M E N TAT I O N T O O L S F O R S U C C E S S, P C I & S E C U R I T Y February 2014 A G E N D A EMV Overview EMV Industry Announcements EMV Transaction Differences, What to Expect Solution

More information

How to Prepare. Point of sale requirements are changing. Get ready now.

How to Prepare. Point of sale requirements are changing. Get ready now. How to Prepare for EMV Point of sale requirements are changing. Get ready now. The EMV mandate is fast approaching. Now is the time to plan a strategy to prepare for this change. 2 EMV: The Backstory 3

More information

PayLeap Guide. One Stop

PayLeap Guide. One Stop PayLeap Guide One Stop PayLeap does it all. Take payments in person? Check. Payments over the phone or by mail? Check. Payments from mobile devices? Of course. Online payments? No problem. In addition

More information

Card Network Update Chip (EMV) Acceptance in the United States At-A-Glance

Card Network Update Chip (EMV) Acceptance in the United States At-A-Glance Card Network Update Chip (EMV) Acceptance in the United States At-A-Glance Allegiance Merchant Services is committed to assisting you in navigating through the various considerations that you may face

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011

Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011 Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011 On 5 th March 2010, The Association of Banks in Singapore announced key measures to adopt a holistic

More information

Cost-management strategies. Your guide to accepting card payments cost-effectively

Cost-management strategies. Your guide to accepting card payments cost-effectively Cost-management strategies Your guide to accepting card payments cost-effectively Table of Contents Guidance from Wells Fargo Merchant Services...3 The secret to better interchange rates...4 Why interchange

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

Best practices for choosing and integrating a mobile payments platform. A GlobalOnePay White Paper

Best practices for choosing and integrating a mobile payments platform. A GlobalOnePay White Paper Best practices for choosing and integrating a mobile payments platform A GlobalOnePay White Paper Mobile commerce (mcommerce) purchases and in-app payments made on mobile devices are rapidly becoming just

More information

The Adoption of EMV Technology in the U.S. By Dave Ewald Global Industry Sales Consultant Datacard Group

The Adoption of EMV Technology in the U.S. By Dave Ewald Global Industry Sales Consultant Datacard Group The Adoption of EMV Technology in the U.S. By Dave Ewald Global Industry Sales Consultant Datacard Group Abstract: Visa Inc. and MasterCard recently announced plans to accelerate chip migration in the

More information

NCR CONNECTED PAYMENTS

NCR CONNECTED PAYMENTS NCR CONNECTED PAYMENTS For more information visit ncr.com or contact us at [email protected] A winning combination of payment security and payment innovation Evolving payment industry regulations and the

More information

CardControl. Credit Card Processing 101. Overview. Contents

CardControl. Credit Card Processing 101. Overview. Contents CardControl Credit Card Processing 101 Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new and old

More information

Android pay. Frequently asked questions

Android pay. Frequently asked questions Android pay Frequently asked questions June 2015 Android Pay - FAQs In May 2015, Android Pay was announced by Google. Android Pay is Google s payments solution that allows consumers to do in-store and

More information

American Express Contactless Payments

American Express Contactless Payments PRODUCT CAPABILITY GUIDE American Express Contactless Payments American Express Contactless Payments Help Enable Increased Convenience For Card Members At The Point Of Sale American Express contactless

More information

Chip Card (EMV ) CAL-Card FAQs

Chip Card (EMV ) CAL-Card FAQs U.S. Bank Chip Card (EMV ) CAL-Card FAQs Below are answers to some frequently asked questions about the migration to U.S. Bank chipenabled CAL-Cards. This guide can help ensure that you are prepared for

More information

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating Given recent payment data breaches, clients are increasingly demanding robust security and fraud solutions; and Financial institutions continue to outsource and leverage technology providers given their

More information

CITGO CHIP & MOBILE TM. Quick-Start Guide YOUR CUSTOMERS. are

CITGO CHIP & MOBILE TM. Quick-Start Guide YOUR CUSTOMERS. are CITGO CHIP & MOBILE TM Quick-Start Guide are YOUR CUSTOMERS EMV CHIP CARD This... plus this... MOBILE PAYMENTS 1 Equals Success GET AHEAD FOR YOUR CUSTOMERS STAY AHEAD FOR YOUR BUSINESS. Fast Convenient

More information

Here a token, there a token...

Here a token, there a token... Here a token, there a token... By PYMNTS@pymnts - What s Next In Payments 6:15 AM EDT June 26th, 2015 Tokenization may not be new, but it is a hot topic in payments, thanks to the introduction of the network

More information

Transitions in Payments: PCI Compliance, EMV & True Transactions Security

Transitions in Payments: PCI Compliance, EMV & True Transactions Security Transitions in Payments: PCI Compliance, EMV & True Transactions Security There have been more than 600 million records compromised from approximately 4,000 data breaches since 2005 and those are just

More information

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc.

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc. PCI 3.1 Changes Jon Bonham, CISA Coalfire System, Inc. Agenda Introduction of Coalfire What does this have to do with the business office Changes to version 3.1 EMV P2PE Questions and Answers Contact Information

More information