No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

Payment processing security tactics can improve overall enterprise security, expert says

By Kristen Lawrence

12/11/2009 - Successful payment processing security involves more than just compliance to the PCI DSS - it involves best practices about data retention and protection, network security and employee training.

All of these practices can - and potentially should - also be applied to other areas of business operations, such as CRM databases, email servers, personnel files and payroll information, said payment processing expert Evan Schuman.

"Overworked IT executives suffering from staff cuts find checklist security quite comforting," he wrote on the McAfee Security Insights blog. "The checklist mentality says that nothing should be done that isn't mandated. And there are no external rules protecting data, beyond payment card, health-related information and some investment data. Is this wise?"

Schuman noted that information such as customer service files stored in a CRM database, customer loyalty tracking information and even payroll information could be valuable targets to hackers, and should be protected with the same rigour as payment processing infrastructure.

However, merchants may need to invest in their payment processing security first and foremost - the Ponemon Institute and Imperva report that just 28 percent of small businesses and 70 percent of large businesses are PCI compliant.ADNFCR-2514-ID-19457692-ADNFCR

Related News - Security and Fraud

Visa announces new best practices for payment applications

26/08/2010

As part of its continued commitment to security, Visa has announced another set of global industry best practices for payment application vendors, integrators and resellers that employ payment-related systems such as credit-debit machines.

Full Article

Banks get creative to promote overdraft protection

29/07/2010

New regulations born of the financial reform bill may help cut costs for consumers who use point-of-sale terminals, yet banks are still searching for a way to recoup their potential losses.

Full Article

Tokenization can eliminate PCI compliance worries

27/07/2010

Retailers, payment processing companies and others are learning how to implement and accommodate new security practices to protect consumers and lessen their PCI compliance burden.

Full Article

Chip-and-pin technology has reduced fraud, but not interest rates

26/07/2010

With the introduction of credit card chip technology, consumers charging purchases at credit card machines were promised savings in interest rate charges, but have not seen them yet.

Full Article