Beat Credit Card Fraud This Christmas With PCI DSS
As we all hit the streets, the web and our phones to buy Christmas gifts, we’re possibly treating our payment card purchases with a little more concern and care than we gave them this time last year, and with good reason.
According to the Financial Fraud Action UK, types of fraud where the card holder is not present (phone, online or by mail order purchases) have seen a 23 per cent year-on-year rise. And a staggering total of £450.4 million of fraud losses were recorded on UK cards in 2013.Consumers are becoming more aware of fraud and how their personal data is stored and used, so the way in which you securely handle your customer's payments over any payment method, is becoming increasingly important to them. Two of the main risk areas for data breaches are internal staff access and external phone or network hacking. When customer data falls into the wrong hands, it can potentially spell disaster for the reputation and success of your business.
The USA has felt the full force of large card data breaches this year, with 2014 being the worst on record for card fraud in the country. Recently the Whitehouse even stepped in to force businesses to come together and address the situation. Chip and PIN style cards are planned for release next year, but until then the US is bracing itself the next card fraud victims over the holiday season.
Help is at hand...
The Payment Card Industry Data Security Standards (PCI DSS) provides a set of security rules and practices that all businesses must adhere to if they want to continue accepting credit and debit cards from their customers. These rules help business to ensure their customers' card information is handled securely and disposed of promptly. Following these rules minimizes the risk of fraud and they are enforced by the card organization via fines (up to £500,000 for holding sensitive payment card data) and potentially withdrawal of your transaction services.
So if your business is taking payments over the phone or website this Christmas or will be in the New Year, then PCI Compliance is an absolute must. As a starter, here are 12 PCI requirements - one for each day of Christmas:
The 12 PCI DSS Requirements:
- Install and maintain a firewall configuration to protect cardholder data.
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Physically and logically protect stored cardholder data
- Encrypt transmission of cardholder data across open, public networks
- Use and regularly update anti-virus software
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need-to-know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security for employees and contractors
And that's just systems and processes... what about the people?
Your customer facing staff are both the most important asset to your organization and the biggest risk when it comes to card information. They are also one of the toughest areas to secure without making their work life challenging.
Fortunately systems are now available that not only help eliminate card data from your IT systems but also allow staff to take payments over the phone without accessing card data.
By capturing payment via the touchtone keypad and blanking the tones heard by the staff member, payments can be handled simply without any significant changes how they interact with the customer. The staff member just adds the customer details and the amount to pay, and confirms the payment with the customer. The customers feel more at ease that they are not relaying their card details to a stranger at the other end of the phone, or anyone else in earshot...
Happy secure customers, protected productive business and peace of mind that your compliance needs for card payments are met without complex systems integration.
So a great start to a happy and prosperous 2015!
Healthcare identity theft and fraud is a fast-growing threat in the US, but some…
This year is the 40th anniversary of the classic 1978 sci-fi movie Invasion of…