Retail Checklist: 8 Tips for Secure Payments Processing

Retail Checklist: 8 Tips for Secure Payments Processing

Retail Checklist: 8 Tips for Secure Payments ProcessingAs a retailer, deciding on a payments processor can be overwhelming. With the recent string of high-profile customer data breaches, security should be the focal point of your provider’s every service and function.

Here are eight security features to look for when selecting a payments processor:

1. VAULTING

What: A vault is used to set up recurring payments. With a vaulting mechanism, customers can enter their credit card information into the vault via the retailer’s website, and set up recurring payments. Stored information can also be used during the next transaction with the retailer. This is the “remember me” option most of us see when making online purchases.

Why: Vaulting makes you more secure as a retailer because you’re not tasked with the burden of securing that data yourself. That responsibility is left up to the payments processor, as is the case with SecureNet’s PCI compliant vault.

2. TOKENIZATION

What: Tokenization is the process of using a unique code to represent a credit card number, thereby mitigating the risk associated with the exposure of the actual credit card number. To give a simple example, if a credit card number was 1234, it may be tokenized as ABCD. ABCD has zero value for a fraudster because it’s meaningless. For the payment processor, however, ABCD references an actual card number.

Why: Rather than exchange credit card numbers, merchants and payments processors can pass tokens, minimizing visibility into a payment account number. And, while breaches can still occur, hackers who infiltrate a token system will find that information useless.

3. P2P ENCRYPTION

What: In point-to-point (P2P) encryption, the card reader at your point-of-sale reads the information on the magnetic stripe of a credit card and transmits an encrypted version of that data to your payments processor, ensuring sensitive information is encrypted at the earliest possible point in your POS system. The processor then is the only party with a device capable of decrypting the data, which it does to perform an authorization.

Why: Data encrypted end-to-end, from the point of swipe to the point of the payments processor, guarantees zero exposure of plain text, non-encrypted information on the part of the retailer. This protects card numbers from a variety of attacks.

4. ENCRYPTED MOBILE HARDWARE

What: Payments processors that offer P2P encryption must also offer mobile encrypted hardware. The actual point-of-sale device at the register, or the dongle that plugs into a smartphone, should support data encryption from the moment it’s obtained via a credit card’s magnetic stripe.

Why: With mobile encrypted hardware, retailers don’t have to rely on their own infrastructure to be as secure as possible because the data passing through is encrypted and useless to anyone who may gain access on the retailer side. Mobile hardware that encrypts the card data at swipe also offers additional protection against malicious mobile applications that may attempt to access the card data if it were present in plain-text form on the mobile device.

5. EMV

What: EMV stands for Europay, Mastercard and Visa. It’s also often referred to as “chip-and-pin,” in which a microchip is embedded on a credit card to serve as a continually changing data point. This makes the card virtually impossible to clone. Look for a payment processor that has the capability to support chip-and-pin on a worldwide basis. EMV is already widespread in much of Europe, and the technology is quickly coming to the United States.

Why: Cards in the U.S. are very easily cloned just by reading the magnetic stripe off of the back. Even if customer data is compromised, it is extremely difficult to duplicate and make copies of EMV credit cards.

6. PCI COMPLIANCE

What: The payment card industry sets a security standard for all companies processing, storing and transmitting credit card information to protect consumers. Standards are enforced on four levels, based on the volume of transactions processed by a single merchant. PCI compliance should serve as a baseline standard when looking for a payments processor.

Why: All processors are required to be PCI compliant, but retailers may require a level of PCI compliance beyond the minimum standard. It is important to look for a processor with the resources to help small retailers meet whichever PCI-compliant standards they may be subject to, rather than going at it alone or hiring a third party.

7. FRAUD PROTECTION

What: Advanced payment processors can now facilitate automated pre-authorization on fraud checks. Sophisticated analyses of behavioral profiling and multi-currency factoring allow real-time payment authorization, minimizing unnecessary voids and reversals. Self-learning machines even update fraud rules at a high frequency to make the process truly automated.

Why: If the payments processor can minimize fraud that is occurring through them, they won’t have to charge more to recoup from charge losses. A robust fraud protection program benefits both the processor and the retailer from a cost perspective.

8. OMNICHANNEL SECURITY

What: Just as omnichannel payments rely on one processor across all channels (mobile, in-store and online), omnichannel security involves one provider to protect sensitive information across all channels. The same, consistent set of security controls, no matter where your processing is occurring, is key.

Why:  By choosing a processor with omnichannel security capabilities, retailers are tasked with managing just one relationship, rather than three separate for each form of payment. Customer information is contained to just one provider, reducing risk and eliminating the need for data duplication across locations.

About the Author

Avery Buffington is an information security architect at SecureNet with over 13 years of experience in the information security and financial services industries.

Featured

  • The Key to Wellbeing in the Office

    A few years ago, all we saw in the news was the ‘great resignation.’ Now we have another ‘great’ to deal with. According to CBRE, 2023 was the start of the ‘great return’ as office workers returned to their normal offices after working from home. The data shows that two-thirds of all U.S office buildings were more than 90% leased as of Q2 2023. Read Now

  • Failed Cybersecurity Controls Costing U.S. Businesses $30 Billion Yearly

    Panaseer recently released ControlWatch and the Continuous Controls Battle: Panaseer 2025 Security Leaders Report examining the cost of cybersecurity control failures and the impact of growing personal liability for security failings on security leaders. The report analyzes the findings of a survey of 400 security decision makers (SDMs) across the US and UK. It shows that security leaders feel under increasing pressure to provide assurances around cybersecurity, exposing them to greater personal risk – yet many lack the data and resources to accurately report and close cybersecurity gaps. Read Now

  • The Business Case for Video Analytics: Understanding the Real ROI

    For security professionals who may be hesitant to invest in video analytics, now's the time to reconsider. In a newly released Omdia report commissioned by BriefCam (now Milestone Systems), the research firm uncovered a compelling story: more than 85% of North American and European organizations that use video analytics achieve a return on investment within just one year. The study, which surveyed 140 end users across multiple industries, demonstrates that security technology is no longer just for security — it's a cross-organizational tool that delivers measurable business value far beyond traditional safety applications. Read Now

  • Survey: 54% of Organizations Cite Technical Debt as Top Hurdle to Identity System Modernization

    Modernizing identity systems is proving difficult for organizations due to two key challenges: decades of accumulated Identity and Access Management (IAM) technical debt and the complexity of managing access across multiple identity providers (IDPs). These findings come from the new Strata Identity-commissioned report, State of Multi-Cloud Identity: Insights and Trends for 2025. The report, based on survey data from the Cloud Security Alliance (CSA), highlights trends and challenges in securing cloud environments. The CSA is the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

Featured Cybersecurity

Webinars

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3