Merchants & PCI DSS Obse b r se vat va io i n o s n f s rom o a a P a P ym a en e t n Gat a ew e a w y a pe p r e spe sp ct e ive i



Similar documents
How To Protect Your Business From A Hacker Attack

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc.

Adyen PCI DSS 3.0 Compliance Guide

Frequently Asked Questions

University of York Policy on the Management of Debit/ Credit Card Data

Understanding and Managing PCI DSS

Payment Card Industry Data Security Standards.

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

Merchant guide to PCI DSS

University of Oregon Policy Statement Development Form

SecurityMetrics Introduction to PCI Compliance

PCI DSS Compliance Information Pack for Merchants

How To Protect Your Credit Card Information From Being Stolen

PCI DSS. CollectorSolutions, Incorporated

PCI Compliance Just the Facts. Rick Dakin President ext. 7001

Drive your fraud rates down

FAQ s. SaferPayments. Be smart. Be compliant. Be protected. The benefits of compliance SaferPayments Non-compliance fees

PCI COMPLIANCE AND WHAT IT MEANS TO YOU IN ENGLISH

How To Protect Visa Account Information

PCI Risks and Compliance Considerations

Executive Briefing on PCI Compliance

Payment Card Industry (PCI) Data Security Standard

PCI Compliance. Top 10 Questions & Answers

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

Payment Card Industry (PCI) Data Security Standard

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Data Security for the Hospitality

ROYAL BOROUGH OF WINDSOR AND MAIDENHEAD SECURITY POLICY. Processing Electronic Card Payments

PCI Compliance Are you at Risk? September 17, 2014 Dan Garrett/Matt Fluegge Vantiv

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Recurring Transactions Enquiry Service. Merchant Implementation Guide

PCI DSS Investing wisely...

PCI Compliance Top 10 Questions and Answers

Fall Conference November 19 21, 2013 Merchant Card Processing Overview

Payment Card Industry Data Security Standard

Frequently Asked Questions

* Any merchant that has suffered a hack that resulted in an account data compromise may be escalated to a higher validation level.

An article on PCI Compliance for the Not-For-Profit Sector

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

SecurityMetrics. PCI Starter Kit

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

PC-DSS Compliance Strategies NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, Merit Member Conference

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

safe and sound processing online card payments securely

Credit Card Processing Summer Lunch & Learn 2016

Version 7.4 & higher is Critical for all Customers Processing Credit Cards!

Payment Card Industry Data Security Standard

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance

Information Technology

How To Become A Pca Compliant Organization

PCI-DSS Compliance. Ron Dinwiddie Chief Technology Officer J. Spargo & Associates

How To Complete A Pci Ds Self Assessment Questionnaire

ACQUIRER OR ACQUIRING BANK A financial institution (often a bank) where a merchant has an account to process transactions and card payments

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

OXY GEN GROUP. pay. payment solutions

Processing e-commerce payments A guide to security and PCI DSS requirements

Newtek, The Small Business Authority 855-2thesba thesba.com 855-2thesba

Langara College PCI Awareness Training

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Your Compliance Classification Level and What it Means

It is important to note, the payment brands and acquirers are responsible for enforcing compliance, not the PCI council.

Payment Card Industry - Achieving PCI Compliance Steps Steps

MERCHANT NEWS. This Edition of Merchant News. Our Name Has Changed. Card Scheme Compliance. Fraud Update. Technology Update / Commercial Opportunities

Why Data Security is Critical to Your Brand

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

PAYWARE MERCHANT MANAGED SERVICE

Frequently Asked Questions

Security Case Study. Experience from Europe s most mature market. Retailers choose Point for increased security

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Why Is Compliance with PCI DSS Important?

PAI Secure Program Guide

PCI Compliance : What does this mean for the Australian Market Place? Nov 2007

White Paper On. PCI DSS Compliance And Voice Recording Implications

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Introduction to. May 18, :15 p.m. 2:15 p.m.

ICS Presents: The October 1st 2015 Credit Card Liability Shift: This Impacts Everyone!

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

PCI DSS Compliance Services January 2016

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Understanding the SAQs for PCI DSS version 3

PCI DSS Gap Analysis Briefing

Agent Registration. Program Guidelines. (For use in Asia Pacific, Central Europe, Middle East and Africa)

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

PCI COMPLIANCE GUIDE For Merchants and Service Members

Protect Data. Secure Business.

Complying with PCI is a necessary step in safely accepting Payment Cards.

Simplêfy Client Support and Information Services. PCI Compliance Guidebook

SellWise User Group. Thursday, February 19, 2015

PCI PA-DSS Requirements. For hardware vendors

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

A PCI Journey with Wichita State University

Section 1: Assessment Information

Transcription:

Merchants & PCI DSS Observations from a Payment Gateway perspective

It has the words DON'T PANIC inscribed in large friendly letters on its cover

Who are you?? 17 years in the Irish & European Acquiring business

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective...

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective...

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective...

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007,

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007, 2008,

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007, 2008, 2009,

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007, 2008, 2009, 2010

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007, 2008, 2009, 2010 What have I learned about PCI DSS?

Who are you?? 17 years in the Irish & European Acquiring business From the merchant perspective... And from the Acquirer perspective... And back to the merchant perspective... Have achieved PCI DSS Level 1 certification as a Payment Gateway 2007, 2008, 2009, 2010 What have I learned about PCI DSS? You don t want to have to do a PCI DSS Level 1 certification annually!

Why PCI DSS? a brief history of card (in)security Zip zap machines Chinese restaurant dumpster hack

Why PCI DSS? a brief history of card (in)security Zip zap machines Chinese restaurant dumpster hack POS terminals totally unencrypted broadcast over a public network very low return to effort for hacking

Why PCI DSS? a brief history of card (in)security Zip zap machines Chinese restaurant dumpster hack POS terminals totally unencrypted broadcast over a public network very low return to effort for hacking Integrated ipos Integrated ipos normally unencrypted large volumes of card data mainly Security through obscurity

Why PCI DSS? a brief history of card (in)security Zip zap machines Chinese restaurant dumpster hack POS terminals totally unencrypted broadcast over a public network very low return to effort for hacking Integrated ipos normally unencrypted large volumes of card data mainly Security through obscurity And then everything changed...

Why PCI DSS? a brief history of card (in)security Zip zap machines Chinese restaurant dumpster hack POS terminals totally unencrypted broadcast over a public network very low return to effort for hacking Integrated ipos normally unencrypted large volumes of card data mainly Security through obscurity And then everything changed... but it s not just ecommerce that is impacted

How vulnerable am I? The emergence of Social Networking is a major phenomenon

How vulnerable am I? The emergence of Social Networking is a major phenomenon Fraudsters have their own Social Networks proper business, with suppliers & consumers what is the going the going rate for valid UK card number with CVV?

How vulnerable am I? The emergence of Social Networking is a major phenomenon Fraudsters have their own Social Networks proper business, with suppliers & consumers what is the going the going rate for valid UK card number with CVV? It is not teenage hackers having some fun

How vulnerable am I? The emergence of Social Networking is a major phenomenon Fraudsters have their own Social Networks proper business, with suppliers & consumers what is the going the going rate for valid UK card number with CVV? It is not teenage hackers having some fun It is ORGANISED crime

How vulnerable am I? The emergence of Social Networking is a major phenomenon Fraudsters have their own Social Networks proper business, with suppliers & consumers what is the going the going rate for valid UK card number with CVV? It is not teenage hackers having some fun It is ORGANISED crime Merchants need to be organised too, to avoid becoming vulnerable Have you been targeted yet?

How vulnerable am I? The emergence of Social Networking is a major phenomenon Fraudsters have their own Social Networks proper business, with suppliers & consumers what is the going the going rate for valid UK card number with CVV? It is not teenage hackers having some fun It is ORGANISED crime Merchants need to be organised too, to avoid becoming vulnerable Have you been targeted yet? YES!

How real is the threat? Biggest Merchant data breach: Number of cards compromised: 46,000,000+ Fines to date: $41M (Visa) Total Cost: $100M+

How real is the threat? Biggest Merchant data breach: Number of cards compromised: 46,000,000+ Fines to date: $41M (Visa) Total Cost: $100M+ Biggest Processor Data Breach: Number of cards compromised: 100,000,000+ Fines to date: $100M and counting...

Remember...

Common initial questions about PCI DSS? Can I just ignore it? It is already mandatory You are already exposed to potential fines

Common initial questions about PCI DSS? Can I just ignore it? It is already mandatory You are already exposed to potential fines Is it here to stay? Like Chip & PIN, the industry is going to make this work Like Chip & PIN, a lot of merchant disruption & cost

Common initial questions about PCI DSS? Can I just ignore it? It is already mandatory You are already exposed to potential fines Is it here to stay? Like Chip & PIN, the industry is going to make this work Like Chip & PIN, a lot of merchant disruption & cost It s got to be done, it s not going to go away, so need to accept we re going to have to live with it

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems Sorry, hotel sector

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems Sorry, hotel sector Sorry, subscription payments

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems Sorry, hotel sector Sorry, subscription payments Sorry, MOTO merchants

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems Sorry, hotel sector Sorry, subscription payments Sorry, MOTO merchants Sorry,...

Specific sectors can have specific issues: Some sectors have historical procedural issues that cause problems Sorry, hotel sector Sorry, subscription payments Sorry, MOTO merchants Sorry,... Will just have to accept that these processes cannot go on, and adapt there are PCI solutions available today to address all of these situations virtual terminals, tokenisations solutions, recurring payment solutions...

Are you a multi channel merchant? Multi channel merchant means multiple channels that need to be secured Only as strong as the weakest link look at TK Maxx U.K. Channel Mix (F2F = Card-Present; Multi-Channel = F2F & Online; Online = ecommerce only) Small Merchants (< 500k Mil. Card Turnover) Medium-Sized Merchants (< 500k- 5MM Card Turnover) F2F 350,000 82% Middle-Market Merchants ( 5-100MM Card Turnover) F2F 3,500 64% Multi- Channel 58,000 13% Online Only 20,000 5% Multi- Channel 1,600 29% Online Only 400 7% F2F 27,000 74% Large Corporate Merchants (>100MM Card Turnover) F2F 235 59% Multi- Channel 7,200 20% Online Only 2,400 6% Multi- Channel 131 33% Online Only 33 8%

Who gets the free pass? Some merchants will have very little to do

Who gets the free pass? Some merchants will have very little to do If you have Acquirer-owned, stand-alone POS devices, lucky you

Who gets the free pass? Some merchants will have very little to do If you have Acquirer-owned, stand-alone POS devices, lucky you (though you still have to complete the SAQ self assessment questionnaire)

Who gets the free pass? Some merchants will have very little to do If you have Acquirer-owned, stand-alone POS devices, lucky you (though you still have to complete the SAQ self assessment questionnaire) (and are there any other channels or procedures that need to be reviewed?)

Who gets the free pass? Some merchants will have very little to do If you have Acquirer-owned, stand-alone POS devices, lucky you (though you still have to complete the SAQ self assessment questionnaire) (and are there any other channels or procedures that need to be reviewed?) For the rest, time to roll up the sleeves.

Quick, what should I do? Looking for one of these?

Quick, what should I do? Looking for one of these? Unfortunately, as in life, no one size fits all

Quick, what should I do? Looking for one of these? Unfortunately, as in life, no one size fits all If in doubt, get some expert advice

Quick, what should I do? Looking for one of these? Unfortunately, as in life, no one size fits all If in doubt, get some expert advice Do not treat PCI as a NCT for your payments

The cost issue The range of costs is enormous Put the costs of compliance to one side: Because it s mandatory it s nothing compared to the cost of a breach make sure you get a solution appropriate to your own requirements if in doubt, get some expert advice

Most common merchant feedback?

Most common merchant feedback?

Most common merchant feedback? In part, this is a communications failure by the Card Schemes

Most common merchant feedback? In part, this is a communications failure by the Card Schemes But also because it is complicated fraud is very sophisticated

Most common merchant feedback? In part, this is a communications failure by the Card Schemes But also because it is complicated fraud is very sophisticated Raise your hand if confident you are fully PCI compliant...

Most common merchant feedback? In part, this is a communications failure by the Card Schemes But also because it is complicated fraud is very sophisticated Raise your hand if confident you are fully PCI compliant... You should be, it s mandatory.

Need to change mindset Of course I need to have cardholder payment details for customer queries for customer support for chargeback management for reconciliation

Need to change mindset Of course I need to have cardholder payment details for customer queries for customer support for chargeback management for reconciliation Why do I need to have any visibility of cardholder payment details there are PCI compliant solutions available today for all processing requirements if you think you need to store card details, should probably re-examine your procedures

Final Points Remember: PCI DSS compliance does not GUARANTEE that your systems are secure

Final Points Remember: PCI DSS compliance does not GUARANTEE that your systems are secure They should be seen as the minimum standards required

Final Points Remember: PCI DSS compliance does not GUARANTEE that your systems are secure They should be seen as the minimum standards required Make sure you are not the weakest link in the (overall) chain

Final Points Remember: PCI DSS compliance does not GUARANTEE that your systems are secure They should be seen as the minimum standards required Make sure you are not the weakest link in the (overall) chain But make sure you are aware of all of your own internal links!

Remember...

www.worldnettps.com