The Dark Side of a Payment Card Breach



Similar documents
Visa global Compromised Account

PCI-DSS Compliance. Ron Dinwiddie Chief Technology Officer J. Spargo & Associates

Retail Roundtable: Payment System Cyber Attacks Preparing, Protecting, and Responding. June 11, 2014

Payment Card Industry Update and Cyber Risk Management

Card Network Update Chip (EMV) Acceptance in the United States At-A-Glance

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

SecurityMetrics Introduction to PCI Compliance

Payment Card Industry Data Security Standards

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

The PCI DSS Compliance Guide For Small Business

Josiah Wilkinson Internal Security Assessor. Nationwide

Westpac Merchant. A guide to meeting the new Payment Card Industry Security Standards

Credit Card Processing Overview

Net Report s PCI DSS Version 1.1 Compliance Suite

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Frequently Asked Questions

Payment Card Industry Compliance Overview

Bradley University Credit Card Security Incident Response Team (Response Team)

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

PCI: It Never Ends. Why?

Payment Card Industry Data Security Standard

CardControl. Credit Card Processing 101. Overview. Contents

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

Credit Card (PCI) Security Incident Response Plan

La règlementation VisaCard, MasterCard PCI-DSS

PCI Compliance Overview

AISA Sydney 15 th April 2009

Introduction to PCI DSS

Payment Card Industry Data Security Standard PCI DSS

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008

Payment Card Industry Data Security Standards

A PCI Journey with Wichita State University

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Project Title slide Project: PCI. Are You At Risk?

How To Become A Pca Compliant Organization

Click&DECiDE s PCI DSS Version 1.2 Compliance Suite Nerys Grivolas The V ersatile BI S o l uti on!

PCI Compliance : What does this mean for the Australian Market Place? Nov 2007

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

Important Info for Youth Sports Associations

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

BRAND-NAME is What COUNTS!!!

PCI Data Security Standards. Presented by Pat Bergamo for the NJTC February 6, 2014

PCI Compliance: How to ensure customer cardholder data is handled with care

Appendix 1 - Credit Card Security Incident Response Plan

Continuous compliance through good governance

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc.

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance

PCI Policies Appalachian State University

Accounting and Administrative Manual Section 100: Accounting and Finance

SecurityMetrics. PCI Starter Kit

PAYMENT CARD INDUSTRY (PCI) SECURITY STANDARDS COUNCIL

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

Payment Card Industry Data Security Standards.

PAI Secure Program Guide

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Two Approaches to PCI-DSS Compliance

DRAFT. Six Recommendations to MasterCard and Visa to Improve Credit and Debit Cardholder Security. Presented by

Privacy Legislation and Industry Security Standards

Sage Payment Solutions. Reduce Your PCI Liability with Integrated Payment Solutions

Payment Card Security

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Fraud - Preparing Data Card Transactions

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

How To Protect Your Credit Card Information From Being Stolen

Data Sheet: IT Compliance Payment Card Industry Data Security Standard

Table of Contents. 2 TouchSuite Welcome Kit

Payment Card Acceptance Administrative Policy

b. USNH requires that all campus organizations and departments collecting credit card receipts:

PCI General Policy. Effective Date: August Approval: December 17, Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS:

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

Data Security, Fraud Prevention, and Cost Control. Mike Dorland, CPP Regional Marketing Representative Michigan Retailers Association

Franchise Data Compromise Trends and Cardholder. December, 2010

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Your Compliance Classification Level and What it Means

PCI Security Compliance

UTAH VALLEY UNIVERSITY Policies and Procedures

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Your Single Source. for credit, debit and pre-paid services. Fraud Risk and Mitigation

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures

PayLeap Guide. One Stop

Merchant guide to PCI DSS

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

How To Protect Visa Account Information

A Compliance Overview for the Payment Card Industry (PCI)

Appendix 1 Payment Card Industry Data Security Standards Program

Data Compromise Management

* Any merchant that has suffered a hack that resulted in an account data compromise may be escalated to a higher validation level.

Questions and Answers PCI Compliance (Updated May 23, 2014)

Data Security Basics for Small Merchants

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Property of CampusGuard. Compliance With The PCI DSS

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL

Payment Card Industry (PCI) Data Security Standard PFI Final Incident Report. Template for PFI Final Incident Report. Version 1.0.

Bring Your Own Device Security and Privacy Legal Risks

Transcription:

The Dark Side of a Payment Card Breach

Road Map Introduction The Rules of the Game Pitfalls & Strategies Takeaways Q&A

The Rules of the Game

What is the Game? Payment Card Industry Data Security Standard Data security breach of merchant involving cardholder data PCI Forensic investigator and report Fines, penalties and assessments determine by the card brands based on card brand rules Collection from the merchant by payment processors or merchant banks

What is the Exposure? Fines and penalties For non-compliance with Card Brand Rules $2,000 - $500,000 depending on violation Assessments Operating expense recovery card reissuance (set amount per card) Fraud recovery amount of fraud perpetrated on breached cards (depends on actual activity can be in the millions)

Who are the Players? The Standards Setter PCI Council The Rule Makers Card Brands The Enforcers Merchant Banks and Processors The Harmed Parties Issuing Banks The Investigators PCI Forensic Investigators The Liable Parties Acquiring Banks /Merchants

The Rules of the Game AMEX DSOP Visa GCAR PCI-DSS MasterCard ADC Discover DISC

The PCI Contract Chain Card Brand Rules Card Brands Membership Agreement Merchant Banks Merchant Agreement Merchants

Key Merchant Agreement Terms PCI Compliance Compliance with card brand rules Reimbursement and indemnification Processor s right to establish a reserve fund Right to terminate (with or without cause) Payment card black list (if merchant fails to pay assessment)

VISA GCAR Qualification Account Data and Card Verification Value (CVV) Magnetic-Stripe Data Violation of PCI-DSS that could have allowed a compromise At least 15,000 compromised cards potentially at risk A combined total of US $150,000 or more Counterfeit Fraud Recovery and Operating Expense Recovery for all Issuers involved in the event.

Pitfalls & Strategies

What Happens? Merchant receives notice from processor of potential breach (usually based on Common Point of Purchase ) methodology Card brands/merchant bank requires PCI Forensic Investigator Lawyers PFI Investigation (scope and PCI-DSS) PFI Report

Significance of PFI Investigation PFI report is the key input into card brands assessment processes and calculations Gray areas often exist Key data can be lost (unplugging the machine / anti-virus) Determine PCI-DSS compliance

Significance of PFI Investigation Determine scope of incident and number of cards potentially at risk ( window of intrusion ) Limited depth of analysis Potential conflict of interest

PFI Investigation Window of Intrusion Smaller window = less than 15,000 cards or less compromised cards Access v. acquisition Conclusive v. inconclusive findings What systems and data were actually affected?

PFI Investigation Timing Issues Fraud may be ongoing Fraud counted 12 months back and 1 month forward (from CAMS alert ) Delays in issuing a PFI report can result in higher fraud assessment May also be helpful if more fraud was perpetrated near the 12 month look back

The Right Entity? Lumping related but separate merchants (separate merchant ID) together for purpose of card or fraud count minimums o One merchant with 20,000 compromised cards -or- 5 merchants with 4,000 cards? Catastrophic Cap Calculations o 2-5% of annual Visa sales (parent and subsidiaries) o Look at the corporate structure and merchant / merchant bank relationships

Additional Strategic Considerations Financial stress / bankruptcy Fighting attitude / cost-benefit Look for mistakes Appeal rights Threat of litigation o Genesco, Inc. v. Visa U.S.A., Inc. (2013) o Cisero s v. Evalon, Inc., U.S. Bank (2012)

Takeaways

Security & Forensics Be Compliant. Before the breach ask yourself: o o o Where does Cardholder Data exist in or pass through our environment? How long do we hold Cardholder Data for and is it encrypted? Do we keep log files for our firewalls and domain controllers for at least 90 days? Contain the breach Review and challenge forensic findings BEFORE finalization/issuance of PFI report

Legal Legal and independent forensic involvement ASAP (not after the PFI report has been issued) Understand potential conflicts of interest (PFI, Processor) and consider an independent forensic investigator Know the rules of the game (esp. ADCR/ADC) Work to get the best PFI report possible Get copies of qualification summaries and look for mistakes

The Dark Side of a Payment Card Breach

Thanks! David Navetta, Esq., CIPP InfoLawGroup LLP 303.325.3528 dnavetta@infolawgroup.com www.infolawgroup.com Serge Jorgensen Sylint Group 941.951.6015 sjorgensen@usinfosec.com www.usinfosec.com