No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

Want to spend less on payment processing security? Minimize PCI scope

By Lauren Lindberg

10/03/2010 - Many merchants lament that achieving PCI compliance can be expensive. However, there is a way to reduce compliance costs - minimizing PCI scope.

Walt Conway, a QSA for 403 Labs, recently advised businesses in an article for StorefrontBacktalk.com to take a close look at their payment processing infrastructure - preferably with network diagrams that track cardholder dataflow - to see where PCI scope can be reduced.

In many cases, merchants keep PAN data for chargebacks and refunds, which must be protected according to PCI DSS protocol. Yet these processes do not necessarily require PAN data, so eliminating this storage reduces the amount of data that needs to be protected.

"Treat cardholder data as toxic," Conway wrote. "Seek out and eliminate cardholder data wherever and whenever you can. You likely will need to change some back-office procedures (e.g., processing chargebacks and refunds), and the inconvenience may increase your costs. But it may be cheaper than protecting cardholder data that is spread around the enterprise."

If the cost of reducing PCI scope seems too much, merchants should remember that the cost of a security breach can be astronomically higher. Notoriously breached Heartland Payment Systems, for example, has had to pay US$129 million so far in expenses related to its breach.ADNFCR-2514-ID-19662467-ADNFCR

Related News - Security and Fraud

Study: PCI compliance a no-brainer among Level Four merchants

10/01/2012

A recent survey by research firm Gartner found nearly one-fifth of retailers and credit card processing services are not compliant with Payment Card Industry Data Security Standards.

Full Article

Tracking spending can be made easy with credit cards

06/12/2011

Many people feel that plastic payment processing options can lead to overspending, but a recent article published by Forbes explains that making payments with credit cards is actually a great way to control costs and track expenses.

Full Article

Keeping business bank accounts safe and secure

11/10/2011

The internet has provided consumers with many new and convenient ways to access their account information, but these advances have also created the need for thorough security measures.

Full Article

Personalized payment chips get fraud prevention upgrade

10/10/2011

Payment chips made by Fiserv will now be further personalized using the Europay MasterCard Visa (EMV) standards, a global credit card payments technology that helps prevent fraud from lost, stolen or counterfeit cards.

Full Article