Blog

Tag Archive for the 'payment security' Tag

PCI Compliance – Why Merchants Need To Take It Seriously – Part II

March 31, 2010 Posted by Michael Brooks in Industry Compliance

In Part I, I discussed the importance of PCI compliance, consequences of non-compliance and the effect of account termination on a merchant.  Part II will discuss the basics of PCI compliance responsibility and how merchants can avoid fines and account termination.  Continue reading "PCI Compliance – Why Merchants Need To Take It Seriously – Part II"

PCI Compliance – Why Merchants Need To Take It Seriously – Part I

March 22, 2010 Posted by Michael Brooks in Industry Compliance

Having a merchant account comes with responsibility.  While a merchant may be concerned with revenue and how to grow its business, payment card industry (PCI) compliance should be at the top of the list as well.  The main purpose of PCI compliance is data security, which applies to any party involved in processing credit card transactions.  Not following the rules – or practicing risky activities – can result in card association fines and can also put a merchant account in jeopardy of being terminated – not to mention data breaches that may occur.  A merchant account termination can be detrimental to any business accepting credit cards – especially if they operate purely online. Continue reading "PCI Compliance – Why Merchants Need To Take It Seriously – Part I"

Can You Trust Mobile Phones With Your Money?

January 31, 2010 Posted by Michael Brooks in Payment Innovations & Technologies

Recent reports about the security of mobile phone payments has raised red flags on the next hot payment channel.  Encryption on GSM calls has already been hacked and various researchers have released findings and tools that might encourage cyber crime.  Well, maybe not exactly the motive, but a GSM encryption codebook – a “how-to” guide to break GSM encryption – has been released by a team of German researchers.  Their goal was not to assist cyber criminals, but to encourage stronger security protocols for mobile technology.  Continue reading "Can You Trust Mobile Phones With Your Money?"

Where Are We With Payment Security?

January 19, 2010 Posted by Michael Brooks in Payment Innovations & Technologies

The EMV Standard

In the UK, the migration to EMV technology has reduced fraud in face-to-face transactions since EMV adoption in 2003.  The EMV standard operates with EMV-compliant cards (which have embedded chips instead of magnetic stripes) and EMV-compliant POS terminals.  The chips require a PIN entry for a secure EMV transaction.  The acronym EMV is derived from the initial letters of Europay, MasterCard, and Visa, all of whom cooperated to create the technology standard.  MasterCard merged with Europay in 2002.  JCB and American Express have since joined the organization as well.

EMV is a perfect example of two-factor authentication, where two different factors are required to complete a transaction, and has been referenced as a key solution for secure, fraud-resistant transactions.   Continue reading "Where Are We With Payment Security?"