Latest news and announcements

Cyber Security Month: How clean is your contact centre?
Wednesday, 09 October 2019

Cyber Security Month aims to teach 'cyber hygiene' tips to consumers— but companies need to scrub up too, because contact centres can have dark corners where fraud festers.

Cyber security hygiene blog 900

One of the big themes of this year's European Cyber Security Month is cyber hygiene — and how consumers can follow the kinds of daily routines, checks and behaviour that will help them to stay safe online.

The campaign offers security tips and advice to the public which ranges from using a firewall and not leaving your laptop unattended, to remembering to use a password on your phone and never opening email attachments from unknown sources.

It's simple, sensible stuff. But consumers' diligent personal care could be undermined — if the organisations they trust become breeding grounds for security problems themselves, especially around card payments.

During Cyber Security Month, Eckoh’s big question for companies is: How clean is your contact centre?

To find out, here are three 'sniff tests' for organisations:

Test #1: Are you still asking customers to read out card details over the phone?
In theory, there's nothing wrong with this — but it's risky if contact centre agents can hear the card numbers, see them on the screen, or be able to access them from call recordings.

Card Not Present (CNP) fraud is predicted to reach £680m in 2021[1]. All it takes is a rogue agent copying a person's card details or doing this on a large scale and selling numbers to criminals. Alternatively, digital card records could be hacked or even shared accidentally by clumsy employees.

The average UK company uses three different solutions to handle call payments. But they're often fraught with risks and awkwardness. Pause-and-resume methods are prone to errors and feel disjointed, as agents dip in and out of conversations.

It's also a poor customer experience if calls are transferred to another department for the 'payment bit'. Rigorous agent vetting and the setting up of clean rooms, where pencils and mobile phones are banned, can help to raise security levels. But there's always the risk of a lapse and a few bad apples.

Increasingly, consumers understand the sensitivity of their data and feel uncomfortable handing it over to strangers. In fact, 68% of consumers believe that reading their card details out over the telephone is not secure[2]. Customers need a payment system that gives them absolute reassurance.

Test #2: Can you handle every kind of payment securely?

The way consumers prefer to interact with organisations ranges from the web, phone calls and mobile apps, through to email, web chat, social media and more. In fact, some customers will flit effortlessly between these channels and expect organisations to keep up.

Increasingly, they'll also expect to pay for items via whichever channel they happen to be using at any time.

What's more, they may want to pay for items in a host of different ways. It's worth noting that over half of all online transactions will be made using alternative payment methods by 2021, according to Worldpay[3].

This explosion in contact channels and payment services creates enormous pressures on contact centres. When it comes to card security, the 'attack surface' within contact centres is stretched more and more.

Companies can't say 'No' to customer demands — or say 'Yes' to taking risks. They can't afford to be able to handle some payments securely but take a chance with others. Criminals will hunt out any weak links, so it's important that security is rock solid on every channel.

Test #3: Are you putting too much faith in PCI DSS compliance?

This sounds a bit like a trick question. Every company that accepts, processes, stores or transmits credit card information must achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS) which puts you on the right track for processing card payments securely and reducing card fraud.

But PCI DSS is only a standard, it's not a guarantee. Even if your contact centre achieved PCI DSS compliance a few weeks ago, you can't be sure your security is watertight today. You're still at serious risk of a data breach if there's any lapse in security — an uncomfortable truth that can keep executives awake at night.

And it can happen all too easily. In fact, 90 percent of data breaches are caused by human error[4]. What’s more, while compliance addresses some aspects of data protection it does not guarantee a secure contact centre.

So what's the best way forward?
Cyber Security Month is a great way to educate consumers about staying safe. But more companies need to get serious about securing sensitive data, especially people's card details.

A security breach can have devastating consequences. Even for small companies, the average cost of a cyber breach can be £267,000, so it's no wonder that 87% of companies view cyber liability as one of their top 10 business risks[5].

Faced with growing threats and more data to defend, companies are increasingly looking to trusted payment partners to give them PCI DSS compliance and maintain it for them — by actually managing secure payments on their behalf.

With the right approach, contact centres can take payments over the phone, web and other channels, but sensitive card information is never heard, seen or recorded by their staff. Any sensitive data is simply passed seamlessly to their payment partner who authorises the transaction, without card details ever entering the contact centre's environment.

This is the kind of service provided by Eckoh to clients as diverse as BMW, O2, Transport for London, Parcelforce, the UK Ministry of Justice and the global travel organisation Carnival. Eckoh's secure payment solution wraps neatly around contact centres — and there's no integration or changes to systems required.

You call also follow us on Facebook, Twitter and LinkedIn where we’ll be sharing cyber security risks on a regular basis during October.

  • Companies can discover more about contact centre security by downloading a free copy of the CNP guide from Eckoh. It profiles fraudsters' range of tactics — and the defence measures that organisations can take to stop them.
  • If you’d like to talk to us about how our solutions can help address cyber security challenges then get in touch.

Sources: [1] National Audit Office 2017, [2] Syntec 2018, [3] Worldpay Global Report 2018, [4] Kapersky Lab 2019, [5] Ponemon Institute 2017.

About the Author

Ashley Burton

Ashley Burton

Head of Product

Ashley joined Eckoh’s contact centre in 1999 and over the last 20 years has worked in a variety of roles including project management, business analysis, data warehousing and mobile application development before becoming Head of Product.  Ashley is passionate about identifying emerging technology and applying it to contact centres to improve customer experiences, and deliver outstanding engagement and trust.  Ashley leads and curates Eckoh;’s product roadmap, fostering innovation throughout the business. Ashley identifies emerging technology and applies it to contact centres to improve customer experience, realise Omnichannnel solutions and deliver outstanding engagement and trust.

Connect with us on LinkedIn

Tweets by @Eckoh

Eckoh (@Eckoh)

Eckoh (@Eckoh)

Check out our eGuide "Evolving your IVR into multi-channel customer engagement" for helpful advice on making your IVR an effective part of your customer experience. #CustomerExperience #CustomerService #contactcenter
Eckoh (@Eckoh)

Eckoh (@Eckoh)

Interactive quiz: Is your CX a winner or loser in the COVID-19 era? Four simple questions will help you find out, and show you what to do next. #contactcentre #CX #customerexperience #resiliency
Eckoh (@Eckoh)

Eckoh (@Eckoh)

Eckoh wins a six-year Capita and TfL contract renewal worth £4m to provide services to the Congestion Charge as well as the new Ultra and Low Emissions Zone project. #securepayments #contactcentres