ICS Presents: The October 1st 2015 Credit Card Liability Shift: This Impacts Everyone!



Similar documents
The Future of Payments

Credit Card Processing Overview

CardControl. Credit Card Processing 101. Overview. Contents

PCI and EMV Compliance Checkup

Understand the Business Impact of EMV Chip Cards

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc.

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Corbin Del Carlo Director, National Leader PCI Services. October 5, 2015

PCI Data Security Standards. Presented by Pat Bergamo for the NJTC February 6, 2014

Your Reference Guide to EMV Integration: Understanding the Liability Shift

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means

Preparing for EMV chip card acceptance

Sage ERP MAS I White Paper. Payment Processing Trends, Tips, and Tricks: What You Need to Know

Payment Methods. The cost of doing business. Michelle Powell - BASYS Processing, Inc.

Sage 100 ERP I White Paper. Payment Processing Trends, Tips, and Tricks: What You Need to Know

The Adoption of EMV Technology in the U.S. By Dave Ewald Global Industry Sales Consultant Datacard Group

Data Security Basics for Small Merchants

EMV and Small Merchants:

Mitigating Card System Breaches. October 11, :00 pm 2:50 pm

PCI Compliance Overview

What is EMV? What is different?

EMV and Restaurants: What you need to know. Mike English. October Executive Director, Product Development Heartland Payment Systems

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

welcome to liber8:payment

Wayne EMV Solutions. Protect your business with a complete EMV Solution inside and out.

Project Title slide Project: PCI. Are You At Risk?

Why Is Compliance with PCI DSS Important?

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard

How To Protect Your Credit Card Information From Being Stolen

8/17/2010. Over 90% of all compromised merchants are PCI level 4 (small) merchants or merchants with less than 1 million transactions per year

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

NCR CONNECTED PAYMENTS

What Merchants Need to Know About EMV

EMV in Hotels Observations and Considerations

Modernizing H-E-B s Point-of-sale Systems

Introduction to PCI DSS

Office of Finance and Treasury

mobile payment acceptance Solutions Visa security best practices version 3.0

How To Protect Your Business From A Hacker Attack

Becoming PCI Compliant

A RE T HE U.S. CHIP RULES ENOUGH?

Payment Card Industry Compliance Overview

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating

Credit Card Processing, Point of Sale, ecommerce

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

EMV FAQs. Contact us at: Visit us online: VancoPayments.com

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

EMV : Frequently Asked Questions for Merchants

Visa Recommended Practices for EMV Chip Implementation in the U.S.

NCR Secure Pay FAQ Updated June 12, 2014

Secure Payments Framework Workgroup

Payment Card Industry Compliance

Breach Findings for Large Merchants. 28 January 2015 Glen Jones Cyber Intelligence and Investigation Lester Chan Payment System Security

Security. Tiffany Trent-Abram VP, Global Product Management. November 6 th, One Connection - A World of Opportunities

OpenEdge Research & Development Group April 2015

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

PCI Security Standards Council

EMV's Role in reducing Payment Risks: a Multi-Layered Approach

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP

SETUP GUIDE. Thank you for your purchase of Hamilton products! In this handy guide, you will discover: ADDITIONAL REQUIREMENTS SETUP HOW IT WORKS

Payment Card Industry Data Security Standards

EMV Frequently Asked Questions for Merchants May, 2014

EMV Acquiring at the ATM: Early Planning for Credit Unions

PCI DSS. CollectorSolutions, Incorporated

AIS Webinar. Payment Application Security. Hap Huynh Business Leader Visa Inc. 1 April 2009

PCI Compliance: How to ensure customer cardholder data is handled with care

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper Executive Director, Product Development

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

PCI PA-DSS Requirements. For hardware vendors

How To Protect Visa Account Information

PLACE GROUP UK LONDON STUDENT HOUSING GROUP PAYMENT CARD INDUSTRY DATA SECURITY STANDARD COMPLIANCE STATEMENT PCI DSS (09) VERSION: 2009PCIDSSP4S01

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

Apple Pay. Frequently Asked Questions UK Launch

Two Approaches to PCI-DSS Compliance

Transcription:

ICS Presents: The October 1st 2015 Credit Card Liability Shift: This Impacts Everyone! Presenters: Cliff Gray Senior Associate of The Strawhecker Group Jon Bonham CISA, Coalfire

The opinions of the contributors expressed herein do not necessarily state or reflect those of the International Carwash Association, its directors or employees. Reference herein to any specific commercial products, process, or service by trade name, trademark manufacturer, or otherwise, shall not constitute or imply an endorsement, recommendation, or support by the International Carwash Association. The International Carwash Association makes no warranty, express or implied, nor does it assume any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process described in these materials. All commentary and information provided by the speakers represents individuals opinion only. The International Carwash Association makes no recommendation or representation regarding such market information and commentary. All such information and commentary is subject to change without prior notice. Any prediction, estimation and projection is not necessarily indicative of future performance and is for reference only. The International Carwash Association will not accept any responsibility or liability of any kind with respect to such information or opinion expressed herein. Investment involves risk. Past performance of any business opportunity is no guide to its future performance. The information or investment opportunities expressed herein may not be suitable for all investors. Before making any investment decision, investors should read and understand the relevant nature, risks, terms and conditions of an investment opportunity and be capable of and wiling to assume the associated risks in light of their own investment objectives, financial circumstances or particular needs and exercise their independent judgment. If needed, investors should seek independent professional advice.

What Is PCI Protect Card Holder Data Jon Bonham Coalfire

PCI PCI DSS applies to all entities involved in payment card processing including merchants, processors, acquirers, issuers, and service providers. PCI DSS also applies to all other entities that store, process or transmit cardholder data (CHD) and/or sensitive authentication data (SAD). PCI DSS v3.1 page 5 Cliff Gray The Strawhecker Group

What Is PCI Cliff Gray The Strawhecker Group

Current State of PCI PA-DSS The car wash owner is responsible for securing network: technology, policy, & procedures Implementation guides need to be followed for a compliant installation Always evolving and changing There are NO car wash merchants who do not have to be PCI compliant Cliff Gray The Strawhecker Group

Current State of PCI PCI-DSS Cliff Gray The Strawhecker Group

Breach Larger merchant breaches dominate the media. Yet smaller merchants (level 4) suffer 90% of the breaches Significant financial threat looms Jon Bonham Coalfire»Typical for breach damages to approach from $50,000 to $100,000 per incident for smaller merchants

Breach Small merchant breaches and stats»card present transactions account for 80% of fraud and breach»more than 50% of merchants do NOT survive a breach, or suffer disruptive changes Jon Bonham Coalfire Source: Visa

Breach in the Car Wash Space Bad Business Practices Binder with club data Fleet billing with a credit card file on the computer Employees taking card to POS Not inspecting hardware for skimmers Found USB drive Vulnerable remote access software Jon Bonham Coalfire

Breach in the Car Wash Space Weak Policies Improperly configured routers & access points Unrestricted internet & email access No anti-virus protection Jon Bonham Coalfire

Breach in the Car Wash Space Car Wash Merchant is Still Impacted Impact goes beyond PCI damages Damaged reputation Loss of consumer confidence» Club cancellations» Loss of credit card business Lower revenue Jon Bonham Coalfire

Everything Changes with EMV Securing the Credit Card Network EMV - EuroPay, MasterCard, Visa» First version was 2.0 in 1995» Version 4.3 is in effect since November 2011 2005 2006 2008 2011 2012 2015 Europe LAC S. Africa Jon Bonham Coalfire Africa Asia/ Pacific Middle East Brazil Colombia Mexico New Zealand Canada Australia United States

Everything Changes with EMV Securing the Credit Card Network New technology» Chip» EMV terminals New process» Chip and signature» Chip and PIN (most secure) Jon Bonham Coalfire

Everything Changes with EMV Securing the Credit Card Network October 1, 2015 Liability Shift Damages shift from Bank to Merchant»No confusion as to the date of liability shift to YOU the merchant»october 1, 2015 The WEAK LINK Pays! Jon Bonham Coalfire

VISA Explains it Best Jon Bonham Coalfire

VISA Explains it Best Jon Bonham Coalfire

VISA Explains it Best Jon Bonham Coalfire

Visa Explains it Best Exceptions Jon Bonham Coalfire

EMV Adoption Chip-Card Rollout Has Banks, Retailers Scrambling To cut credit-card fraud, issuers are embedding chips; merchants say they can t get card readers fast enough Some 575 million of the new cards representing about three-quarters of U.S. credit cards and about 40% of debit cards are expected to be in the wallets of American consumers by year-end, making it the biggest rollout of new cards in decades. The WSJ, Robin Sidel, April 21, 2015 Cliff Gray The Strawhecker Group

EMV Adoption Threats to car wash operators who do not adopt EMV» Weak link is liable» PCI compliance still required Cliff Gray The Strawhecker Group

Credit Card Compliance & Risk Risk too great to keep magnetic stripe only»pci related damages for a breach»impact business reputation PCI-DSS Evolution»Incremental steps creating a secure network»you need to be a part of it Cliff Gray The Strawhecker Group

EMV with Validated Point-to-Point Encryption Merchants validate as PCI compliant using the simplest SAQ applicable Cliff Gray The Strawhecker Group

October 1 st, 2015 Liability Shift Key Take Away Points Offer your customers the best credit card protection EMV with PCI validated point-to-point encryption»offers the most secure network solution»lowers compliance costs Cliff Gray The Strawhecker Group

October 1 st, 2015 Liability Shift Key Take Away Points Real threat to merchants who delay EMV adoption Avoid half-step solutions that still keep you exposed to liability Anticipate a scramble as liability shift date approaches Cliff Gray The Strawhecker Group

October 1 st, 2015 Liability Shift Key Take Away Points Solutions are limited Processor and POS vendor deployment capacity is limited Credit card and car cash industries may not have capacity to perform upgrades for all merchants by October 1 st, 2015 Cliff Gray The Strawhecker Group

October 1 st, 2015 Liability Shift Key Take Away Points This liability shift is REAL This IMPACTS your business Doing nothing could CLOSE your business Cliff Gray The Strawhecker Group

Q&A Additional Questions? Cliff Gray will be in the ICS Booth #2325 on Thursday during show hours to answer any follow up questions