Card Security - How is the Industry Protecting its Customers?

Open a magazine or newspaper from the past few weeks, and there will be a story about the security of card payments – whether it is a keystroke logger threatening online banking customers, or attempts to hijack a Chip and PIN system, there have been a number of attempts made to undermine the card security schemes that are in place. This pressure on banks and retailers together with the sensitivity of information that is passed throughout their networks means that security standards have to be incredibly high.

The most important security standard in the industry is the Payment Card Industry Data Security Standard (PCI DSS). It covers best practice on how payment transactions are made by retailers and processors, including how to build and maintain a secure network, regulating access to critical data and how to protect cardholder information. The latest version of this framework has recently been completed and a Security Standards Council has been set up to govern how the standard should develop in future.

As a single payment can cross over many different company networks and boundaries, from a retailer to a processor, then on to a bank or credit organisation and back again, this standard ensures that all organisations within any payment chain are up to the required security standards. This approach also deals with the question of responsibility: all the companies involved in processing these payments have the same set of rules to adhere to, regardless of size or volume of transactions.

If a customer’s account is fraudulently accessed due to a fault in the security of a payments transaction, organisations who have taken all the necessary steps of conforming to the PCI guidelines will be given a significantly reduced level of penalties compared to an organisation that is not measuring up to the required standards. An organisation that does not measure up to PCI DSS will be liable for US$100,000 per incident of data loss or theft, along with fines of US$500,000 for any service provider or merchant that is compromised and not compliant.

Payment Application Best Practice

For the organisations that supply the retailers and banks with their applications, the PCI has created a subset of the DSS standards. The Payment Application Best Practice (PABP) guidelines are the same as parts of the PCI DSS standard and are designed to allow organisations to meet their overall security requirements automatically. Since it is aimed at regulating the security of the applications used to process payments, demonstrating PABP compliance is therefore the responsibility of the software vendors who must prove that their systems are secure. While PABP is not yet a mandatory standard for applications in this market, deploying an application that has been audited and approved as PABP-compliant will help organisations reach their PCI DSS requirements.

An example of application best practice is not retaining magnetic stripe data or the card verification value (CVV2) following a transaction. CVV2 is used for fraud prevention and ensures that the customer physically has the credit card in their possession and that the card is valid. This value has to be protected during the transaction itself and then not stored, so any data has to be erased and unrecoverable. This overall process also has to be documented, so any transaction can be shown to be compliant.

By meeting these requirements, the application being used can automatically guarantee that the customer is adhering to its own security mandate, PCI DSS. Making sure that the applications are themselves meeting the requirements of reliable security and safety for customer data therefore goes a long way to helping the retailers and banking organisations meet their own levels of security.

Meeting the PCI security requirements is mandatory for all organisations that process payments, but there are other business benefits to participating within the scheme. For the consumer, there is a higher level of safety around each payment they make and they can be protected against identity theft. For the payment processors and merchants involved, being able to guarantee customer security is a crucial goal, and maintaining this level of trust is critical for any organisation that processes payments. However, the other benefits that organisations see include raising the overall numbers of payments that are being made and therefore increasing revenues generated, as well as giving their organisations a better standing within the industry in general. There has been a lot of interest in the PCI DSS standard and how PABP ties into this standard – adherence to this has become a potential deal-winner for the application vendors and also the payment processors themselves.

Conclusion

Security will always be a critical part of the payments landscape, both for the industry in general and those organisations working within it. However, PCI DSS is not set in stone – it will grow with the industry it regulates to give competitive advantages to members of the scheme, as well as highlighting the work that these organisations are doing to protect their customers. It is also more interactive – all stakeholders involved in the payments industry can participate in how the standard evolves through the PCI Security Standards Council. Vendors, retailers, banks and processors can all make a difference to the standard of security that is put in place. Ultimately, these rules will create a greater aura of trust around using card systems, and will therefore encourage more customers to use them.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y