Too Small to Count

Too Small to CountThe biggest factor facing small businesses today is the ever-present issue of uncertainty. The items that come top of mind are usually taxes, healthcare issues or the economy, but make room for more worries about credit card processing and PCI-DSS compliance.

The PCI Security Standards Council has recently published their change highlights getting ready for PCI-DSS 3.0, indicating new sub-requirements due to the growing maturity and increased security risks in the payment security industry since PCI-DSS inception in 2006.

This industry continually expands through guidelines, education and continued qualification programs that touch every aspect of the ecosystem and providers for credit card processing including the payment processing software programs, the pin-pad terminals, the qualified security assessors, approved scanning vendors and the set of data security standards that merchants need to follow.

For those who may not be familiar with the basics of processing credit cards, it always involves four parties: the merchant, the acquiring bank which provides the processing services for the merchant, the customer and the bank that issued the card to the customer. The agreements, terms, fees and liability is set between the major card brands and these four parties. However, backlash from the constant news of breaches, albeit mostly larger entities, is starting to draw other parties into this equation. This does not look favorable for small merchants that continue to think that security and PCI-DSS compliance isn’t a concern or that they are too small to count.

The usual penalizing mechanisms for a merchant breach with card payment data as outlined by PCI-DSS and would cause the merchant to significantly increase their cost of credit-card processing. They would have to prove PCI-DSS compliance but no longer by the standards set for Level 4 merchants that allows them to provide self-assessment reporting. Annually, they would have to hire a qualified security assessor as listed and certified by the PCI Security Standards Council website and follow the requirements given for Level 1 tier merchants forever more. This cost could range from $5,000 to upwards of tens of thousands of dollars depending on the scope of the card-processing systems and network. It’s unknown how many merchants have been penalized in this manner because of a breach; and likely, we will not know since the terms and required compliance is a closed-agreement between the major card brands and the four parties. But, as maturity continues to come to this industry so does the ability to detect and alert fraudulent trends that point back to the lack of security on the part of the merchants. Do not think that as a small business your volume of transactions is too small to be able to pin-point an issue back to your organization.

Fraud is usually reported to local and state enforcement agencies, but lately, state attorney generals are getting notified. Banks bear a costly burden when they have to re-issue credit cards to their customers and are not pleased when they encounter reoccurring fraud on a single account. In Virginia, for example, a merchant was prosecuted by the state attorney general’s office, holding them accountable for the losses associated with credit card fraud. They were found not in compliance with state laws that require timely resolution and customer breach notification. Because they did not take action quickly to rectify the security situation, their customers were hit with repeating fraud, even after being issued new credit cards.

Acquiring banks and merchants have set agreements and are required to ensure PCI-DSS compliance of any new merchant that they sign on for their services. But, compliance is really only a judgment based on a point-of-time review and is not an indicator that ongoing security basics will be executed to continually protect the credit card data. For the most part, if fraud is detected, the fines and liability fall on the acquiring bank, and they must penalize the merchant that does not keep up with their security responsibilities.

It is human nature, especially if we are time constrained, budget constrained or just hesitant because we don’t understand something to think that if something is working – leave it alone!  Business cannot think about their point of sale systems and online payment services this way; they need to consider these as critical services. With minimal maintenance, actions can be taken to avoid the uncertainty and minimize risk of ruin from preventable fines and possible legal actions:

  • Take cues from the proposed changes to PCI-DSS;
  • Ensure that you change default passwords;
  • Use strong passwords;
  • Plan to change passwords ever so often to prevent unauthorized access;
  • Ensure virus protections, patches and updates to your systems and payment applications are applied in a timely manner; and  
  • Get help from qualified system integrators that have participated in the PCI-DSS certification program or look for approved scanning vendors that help you ensure your report for security self-assessment is accurate.

About the Author

Kim Singletary is the director of product marketing at McAfee where she is focused on how technology, mobility, data, and the Internet of Things are changing our day-to-day work environments and the ramifications of sustainable security, compliance and privacy.

Featured

  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West
  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.