Security Case Study. Experience from Europe s most mature market. Retailers choose Point for increased security

Similar documents
IS YOUR CUSTOMERS PAYMENT DATA REALLY THAT SAFE? A Chase Paymentech Paper

Retail Business Technology Expo 2011

We make cards and payments work for people as a part of everyday life. We bring information to life

Merchants & PCI DSS Obse b r se vat va io i n o s n f s rom o a a P a P ym a en e t n Gat a ew e a w y a pe p r e spe sp ct e ive i

PAYMENTS AS A SERVICE. Fully managed multi-channel card acceptance for all business environments.

Statement of Stephen W. Orfei General Manager PCI Security Standards Council

PCI DSS: An Evolving Standard

CASHING UP ON PROGRESS: CUSTOMERS DEMAND NEW WAYS TO PAY

Sage 100 ERP I White Paper. Payment Processing Trends, Tips, and Tricks: What You Need to Know

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance

PCI Security Standards Council

Newtek, The Small Business Authority 855-2thesba thesba.com 855-2thesba

White Paper: Are there Payment Threats Lurking in Your Hospital?

WHITEPAPER PAYMENTS AS A SERVICE HOW MANAGED PAYMENT SERVICES WORK FOR MERCHANTS

COMMERCIAL CARDS BNP PARIBAS

ACQUIRER OR ACQUIRING BANK A financial institution (often a bank) where a merchant has an account to process transactions and card payments

A Brand New Checkout Experience

A Brand New Checkout Experience

Keep money moving. A guide to payment services from Sage Pay.

Enabling European E-commerce

How To Protect Your Credit Card Information From Being Stolen

MASTERCARD PAYMENT GATEWAY SERVICES

Sage ERP MAS I White Paper. Payment Processing Trends, Tips, and Tricks: What You Need to Know

How To Comply With The New Credit Card Chip And Pin Card Standards

Payments Gateways Opportunities for Acquirers

How To Comply With The Pci Ds.S.A.S

How To Protect Your Restaurant From A Data Security Breach

PAYWARE MERCHANT MANAGED SERVICE

PCI DSS COMPLIANCE DATA

How To Protect Visa Account Information

EMV and Small Merchants:

welcome to liber8:payment

MERCHANT NEWS. This Edition of Merchant News NOW INCLUDING RETAIL SPECIFIC NEWS. Our Name is Changing. Fraud Prevention. Card Scheme Compliance

Spotlight on Product & Service: Worldpay - End-to-End Payments Secure Platform at Most Cost-Effective Rates. Accept payments. Anywhere. Anytime.

Cyber Security - What Would a Breach Really Mean for your Business?

OpenEdge Research & Development Group April 2015

Merchant guide to PCI DSS

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Omnichannel Payments

safe and sound processing online card payments securely

Euronet Software Solutions ATM Management System Maintain and Expand Your Automated Service Offerings with a Secure, Flexible and Powerful Solution

EMV and Restaurants What you need to know! November 19, 2014

PCI DSS Investing wisely...

Mobile Near-Field Communications (NFC) Payments

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS)

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

CYBER STREETWISE. Open for Business

global leader in seamless payment

American Express Contactless Payments

PCI and EMV Compliance Checkup

SecurityMetrics Introduction to PCI Compliance

Payment Card Industry Data Security Standard PCI DSS

E-Commerce SOLUTIONS. Generate Online Revenue with E-Commerce Solutions.

Healthcare Payment Security Is Your Patient s Card Data Exposed? May 24, 2016

A Guide to Contactless Cards

Langara College PCI Awareness Training

PAYMENT SECURITY. Best Practices

PCI DSS Compliance Services January 2016

How To Cover A Data Breach In The European Market

PCI Compliance: How to ensure customer cardholder data is handled with care

Payment Card Industry Data Security Standards.

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating

Integrated Payment Solutions

WIRELESS - GPRS iwl250 POS SOLUTION

Understanding PCI Compliance

PCI DSS Compliance Information Pack for Merchants

TOURISM INNOVATIVE PAYMENT SOLUTIONS. Efficient, flexible, worldwide and secure

Payments Transformation - EMV comes to the US

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means

E M V I M P L E M E N TAT I O N T O O L S F O R S U C C E S S, P C I & S E C U R I T Y. February 2014

1 ARE PCI SECURITY MEASURES SUITED TO THE FRENCH MARKET?

Frequently Asked Questions

Secure Payments Framework Workgroup

How To Protect Your Business From A Hacker Attack

REGULATIONS FOR SALES PAID BY CARD SALES IN SHOP (Card Present) (May 2015)

Tahoe Tech Group serves as your technology partner with a focus on providing cost effective and long term solutions.

ICS Presents: The October 1st 2015 Credit Card Liability Shift: This Impacts Everyone!

A HOLISTIC APPROACH TO MERCHANT PAYMENT SECURITY. 2016, Vantiv, LLC. All rights reserved.

The Relationship Between PCI, Encryption and Tokenization: What you need to know

True Protection To The Core

AUSTRALIAN PAYMENTS FRAUD DETAILS AND DATA

the better way to pay

EMV and Restaurants: What you need to know. Mike English. October Executive Director, Product Development Heartland Payment Systems

Preparing for EMV chip card acceptance

Mobile Contactless Payments and Data Privacy

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper Executive Director, Product Development

Acquirers grapple with new payments landscape

Need to be PCI DSS compliant and reduce the risk of fraud?

Payment Services. The Retail Solution. for large and multi-national retailers

Tokenization: FAQs & General Information. BACKGROUND. GENERAL INFORMATION What is Tokenization?

A CHASE PAYMENTECH WHITEPAPER. Building customer loyalty in a multi-channel world Creating an optimised approach for e-tailers

University Policy Accepting Credit Cards to Conduct University Business

Time to get off the fence?

VERIFONE PAYWARE SOLUTIONS

Adyen PCI DSS 3.0 Compliance Guide

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

SMALL BUSINESS REPUTATION & THE CYBER RISK

Transcription:

Security Case Study Retailers choose Point for increased security Experience from Europe s most mature market Meet the company with 800 security staff

Security is what Point is all about With its clear ambition to always be at the forefront of innovative and forward-looking technology, Point has established itself as a market leader in the field of security for electronic payments. Large-scale investment in new technology and new solutions is regularly made both front of house and behind the scenes. By taking a structured approach to staff, products and systems, the company has succeeded in establishing a level which guarantees that Point s customers will always have access to the most secure and easyto-use payment solutions on the market. Point was founded in 1987 and from the very beginning has assumed the role of innovator and trend-setter for the rest of the market. Represented in 11 countries, Point is today the leading supplier of electronic payment solutions in Europe. Its focus is on payment services for both small shops and multinational retail chains that require multi-channel payment capabilities and an extensive payment capacity. Outside the retail sector, Point s customers include hotels, restaurants, transportation and e-commerce sites, as well as companies that primarily provides business-tobusiness services. Point is a VeriFone company since January 2012. Point always stays one step ahead Despite the constantly increasing cyber threat, Point s data system is one of the most secure on the market today. The company regularly implements new measures to protect against hacking, fraud and various types of misuse. Dimitri Binazzi is the Chief Security Officer at Point and since its foundation in 1987 has been responsible for the company s work on security issues. He confirms that the challenges have altered significantly in recent years. Dimitri Binazzi, Chief Security Officer, Point Just a few years ago, criminals would rob a bank or shop to quickly obtain large sums of money by force. Today, through data hacking and fraud, they obtain smaller sums over a longer period. It s not as quick, but is much more lucrative. And criminals get more and more advanced every day. It is our job here to always stay one step ahead. Extensive efforts are made to ensure that data systems, products and staff are able to handle the risks and threats that are encountered. One of our challenges is to be able to offer our customers a high level of service while at the same time the security of the systems must be faultless, says Dimitri Binazzi. In recent years, we have seen an increase in hacking of various systems around the world, which is something we must try to prevent, even if today s hackers and intruders are incredibly sophisticated. In the unlikely event that they gain access, the aim must be to ensure that their presence is identified and that steps are taken immediately to prevent any negative consequences. Increased protection for Card holder data (CHD) Two examples of the investments made in recent years are the cooperation with the two security companies Tripwire and Verisec. The cooperation with Tripwire was initiated when Point was able to ascertain that far too many organisations are struggling with a serious lack of information about the attacks taking place on their network. It was therefore important to implement tools that are able to prevent and detect unauthorised changes and provide an immediate warning when there is any unexpected activity. Point has now replaced its previous solution with Tripwire Enterprise in order to be able to protect customer information relating to credit cards, for example. The solution covers both card payments and e-commerce. There is of course a difference in security issues for payments at card terminals and the payment procedures for e-commerce, says Dimitri Binazzi. Here we are suddenly exposing CHD to risk in a different way than before. With the help of Tripwire Enterprise, however, we are able to introduce additional checks on systems and people, which is something that gives us a good overview of the changes made in the systems, both authorised and unauthorised, in order to minimise the risk of fraud. Chiave a secure key management system In order to further increase the security of the systems, Point has joined forces with Verisec to develop the Chiave system, which monitors the processes controlling the generation, storage and distribution of cryptographic keys. These keys are used to safeguard the identity of credit card holders, ensure the authority of ATMs and POS terminals and protect the information sent over the payment network, among other things. A secure key management system is vital in creating confidence in electronic payments and the system we have now developed sets a new standard in terms of meeting the security requirements of the industry. Chiave replaces manual processes with automatic ones, which reduces both the risk of human error and the risk of interruptions in the payment network, concludes Dimitri Binazzi. 2

Finland s leading retailer chooses Point for increased security Point s innovative capability, combined with extensive investment in security, means that it is constantly gaining new customers. One example was when Finland s leading retailer, the Kesko Group, signed a cooperation agreement with Point in 2010. Kesko currently has a total of around 2,000 stores in Finland, Sweden, Norway, Estonia, Latvia, Lithuania, Russia and Belarus. The company sells groceries, building materials and home furnishings, as well as vehicle and home electronics. Benjamin von Nandelstadh, Senior Manager, Infrastructure Services at Kesko. A major challenge for the chain came in 2009 when the requirement to comply with the Payment Card Industry Data Security Standard was raised. At the time, Kesko had several different point of sales systems in its chains and the solution it had been using was not PCI-compliant. Like many other Finnish retailers, Kesko also had payment terminals integrated directly in the point of sale. This made it difficult to update the systems quickly and easily. So Kesko went looking for a supplier that could deliver a PCI-compliant payment solution. A strategic decision was then taken to also look for a solution that could be delivered as a service. After surveying the market, the company identified Point as one of the few suppliers that could deliver what they wanted. Payment as a service with superior service package Keskos arguments for choosing Point was based on the fact that Point were considered to be fast and reliable, delivering a user friendly solution. On top of this they had the right service based offering. When we went through the possible suppliers, we found out that Point was one of the few that was able to deliver payment as a service, explains Benjamin von Nandelstadh, Senior Manager, Infrastructure Services at Kesko. Point had a ready-made solution and was one step ahead of its competition in this respect. The rollout began in autumn 2010 and one year later Point s solution was in all of 3

the Kesko Group s Finnish stores. In one year, over 5,000 payment terminals was taken into use. The solution comprises payment terminals and a service package, which among other things includes customer support, replacement service and a reporting system. The reporting system provides each retailer with precise statistics on the sales and transactions in their stores. One advantage is that the reporting system is able to follow our corporate structure. Many of our stores are owned by private retailers, which means that we have to be able to get reports at several different levels, continues Benjamin von Nandelstadh. With this new solution, we are able to provide the retailers with precisely the figures they want, broken down to their store level, while at the same time we are able to provide the more central functions with their summary reports. Another major financial advantage is when we negotiate acquirer agreements, as we are able to get a better price for acquirer services with this new centralized solution. Finally, we can confirm that the new payment solution is safe, easy to use and has gotten a lot of positive feedback from our customers as well as our retailers. The next step for Kesko is to implement the new solution in Kesko s other countries. The aim is to complete the rollout during 2012 so that a PCI-compliant solution can be established in all countries by the end of the year and overall security can be increased at Finland s, and one of the Nordic regions, leading retailers. Payment Card Industry Data Security Standard (PCI DSS) is a data security standard that stipulates how card numbers are handled. This security standard has been developed by American Express, Visa International, MasterCard Worldwide, Discover and JCB International. The purpose of the standard is to ensure that everyone who processes, transports, stores or otherwise handles card information does so in such a way as to prevent unauthorised access to the information. The standard consists of 12 general requirements. Among other things, it specifies how a secure network should be constructed and maintained, how card information should be sent and stored and what security procedures a company should have in place. The leading service centre on the market Alongside central payment gateways and IT systems, products are also a priority area for Point s security work. While the company has seen significant growth, there has also been increased demand for better service and repair of payment card terminals. The equipment suffers wear and requires regular repair or other maintenance. Up to now, each country in the Point Group has managed this individually, but now the Group is taking overall control in order to increase the quality of its services. The requirements from payment card companies for secure processing have increased in recent years and will in all likelihood continue to do so in the future. In order to meet these requirements, Point will centralise its service and repair centres in Sweden, as the Swedish service centre has for a long time been the most advanced in the Group. The service centre has developed a well-structured security process based on many years of experience and on the in-depth knowledge the company has of processes, product security, tools, environments and people. The service and repair centre s processes are also designed and structured in accordance with the latest security standards on the market: PCI DSS, PTS, VISA PIN and NIST. The Swedish service centre also trains all technical staff according to above standards. By making these changes, Point will establish the leading service centre on the market, in terms of performing maintenance work in accordance with the most stringent security requirements. The Point Group s service centre Staff with high level of expertise and payment industry compliance. Processes designed and structured according to security standards such as PCI DSS, PTS, VISA PIN and NIST. Market-leading service organisation with services that meet the most stringent requirements on industrial security from the payment sector. 4

Experience from Europe s most mature market A company with 800 security staff Point currently has a presence in 11 European countries and is always scanning the market on the lookout for new experiences and skills in the field of security. With over 20 years experience and several major acquisitions behind it, the Group also has access to an extensive range of skills internally. In 2009, the Group acquired UK payment service provider Commidea, bringing experience from perhaps Europe s most modern market. More recently in January 2012, Point was acquired by VerirFone Systems Inc, the global leader in secure payment electronic solutions. We have been using payment cards in Britain since the 1970s and we began using the new EMV standard, which today is in widespread use, a couple of years before our northern European friends, says Paul Holliday, Head of Marketing, VeriFone UK & Ireland. As one of the UK s most experienced companies on the market for electronic payments, we have been able to follow the development of security systems right up to the present day. This, together with the other skills in the VeriFone group of companies, has given us the opportunity to stay one step ahead of our competitors in developing payment solutions of tomorrow. Handles 80 per cent of the UK s contactless payments In 2007, the company was the first UK supplier to offer an integrated contactless payment solution based on NFC technology. The advantage over the competition in this area has been maintained and in 2010, the company processed over 80 per cent of the UK s contactless payments. As a result, the company is currently considered to be the UK s leading supplier of contactless payment solutions. Further evidence of the company s drive came in 2009, with the launch of Ocius Sentinel, the UK s first PCI-compliant point-to-point encryption payment solution. Security has always been the top priority for us, says Paul Holliday, and it is something we have worked on in a number of different ways. One of the more central of these has been security work to help our customers attain and maintain PCI DSS. Security solutions are an integrated part of our range and we can see that customers actively look for these elements when considering payment solution suppliers. EMV (also called Chip & PIN) is an umbrella name for a payment and credit card standard that involves payment and credit cards being equipped with a data chip, among other things to prevent copying ( skimming ). Having secure IT systems and good product handling is not the only thing required in order to deliver secure payments. As technology has developed, criminals have found new ways in. One area that has grown in recent years is the threat linked to Social Engineering. This is not about deceiving IT systems but about tricking users into giving out their password and codes, for example. This is a relatively big problem in Europe, but there have been no major documented cases in Sweden. As a preventive measure, and in order to minimise the risk of this and other threats, Point has trained more than 800 people in the Group s 11 countries. The training aims to create broad expertise in the field of security and therefore covers everything from handling card data and classified information to how to act on the telephone and towards visitors. Training is tailored and adapted for the company s various departments. The training package has also been translated into seven different languages in order to ensure that none of the details are misunderstood. After completing training, staff undergoes a test. If they pass, they are awarded a security certificate and if they fail they must undergo further training before being tested again. Near Field Communication (NFC) is a communication standard for the contactless exchange of data across short distances (typically around 10 cm). This technology aims to create a secure, intuitive and simple communication channel between various electronic devices. For example, you do not need to insert and remove your payment card in a payment card terminal. You just need to hold the card close to the terminal. 5