Navigating a Course to the PCI Safe Harbour

Payment card industry (PCI) compliance – love it or loathe it, but you can’t ignore it has a fast-looming deadline in June 2007. If you’re among the small minority of companies that are now fully PCI compliant, congratulations. If not, there is the very real prospect of a nasty regulatory stick, including hefty, unlimited fines, industry-imposed operational restrictions or even being banned from accepting card payments.

The good news is that there is an unofficial safe harbour. If your organisation is able to demonstrate that you have robust security processes in place, and that you are now actively working towards full PCI compliance, you are very unlikely to be fined. So how do you go about steering your organisation towards this safe harbour and avoid the wrath of the credit card companies?

June 2007: PCI D-Day

What exactly will the passing of the PCI deadline mean for you? Put bluntly, the threats of penalties in the event of security leaks will become reality. Retailers will have the obligation to protect customer cardholder information, and will be liable for any breaches in security as well as the resulting costs.

According to the Department of Trade and Industry (DTI), 87% of UK businesses reported suffering a security breach over the last 12 months, with the average cost of severe breaches being £90,000. Under the new regulations, non-compliant retailers will have to pick up such costs in the event of fraud or inappropriate use of credit card details. It’s not just the cost of any goods or services fraudulently purchased, but also the cost of cancelling and replacing cards.

A Risk Worth Taking?

You may think that it’s worth taking the risk of credit card fraud happening to your company. After all, fast food outlets, coffee shops and corner shops process relatively low-value transactions, so any cost would surely be correspondingly low, right?

Think again. What you have to consider here is the customer data itself. Retail outlets tend to process low-value but high-volume transactions, meaning that in the event that a network is not secure, hackers have access to thousands of customer credit card details – data that has extremely high criminal worth, and would cost your company dearly.

Then there’s your company reputation to consider. Quite apart from the financial implications, the impact of the negative PR resulting from a large fraud incident would have a significant negative business impact.

Missed the Boat?

If achieving compliance before the June 2007 deadline is looking unlikely, retailers can escape the wrath of the PCI by demonstrating that they have taken steps to implement a robust and secure payment processing network to protect credit card data and customer information.

Unfortunately, there isn’t a one-stop solution in a box; in addition to the necessary network infrastructure and IT security, there is also an important people and training element to becoming compliant – companies need to train and educate their staff to ensure best practice and eliminate security breaches.

There are 12 security criteria retailers need to achieve, ranging from firewall and encryption technology to security testing and software updates. PCI-compliant managed service providers can fulfil 10 out of these 12 criteria, ensuring you have the necessary firewall and anti-virus software, that the network is adequately encrypted to protect cardholder data. In addition, they can take care of the testing and updating of systems, to ensure retailers continue to be compliant.

The remaining two criteria that cannot be achieved through IT security and managed services involve training staff, and initiating processes to check and vet the people carrying out card transactions. For these processes, corporates should work with specialist organisations to ensure they pass QSA testing and achieve PCI compliance, and set out long-term policy and best practice.

Conclusion

So, it’s not all bad news. You may not meet the June deadline, but by taking the necessary steps towards PCI compliance now, you can help avoid the financial penalties and negative impact on your company’s reputation.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y