Share this article
The FCA’s proposal to increase the limit on contactless cards to £100 is in its consultation stage, giving decision makers time to reflect on what we really want from our payments system. Those who favour a “frictionless economy”, want speed and ease of use to be the priority. They want consumers to be able to put a full supermarket shop or fill a full tank at the garage onto a card with one tap.
There is certainly little doubt that a higher threshold for contactless payments has its advantages and the UK increased the limit from £30 to £45 in April. This was largely to encourage the use of contactless payments in the fight against the Covid pandemic. Contactless is considered more hygienic and helps people to make purchases without having to touch a shared keypad.
Yet, if the UK opts for a £100 limit it will have a significantly higher limit than any country in the rest of Europe where most limits are at €50. Even Switzerland, which has the highest, has set it at €76.
While a higher limit might facilitate paying for larger purchases in a contactless way, it does raise some concerns regarding security. After all, if a thief gets their hands on a card at the moment, they know that a card will be quickly cancelled, so they rush to make as many purchases as possible up to the individual limit of £45 per transaction. If the limit is more than double, this exposes card holders to the possibility of losing significantly more before a card can be stopped.
The FCA’s consultation on the proposed contactless payment increase closes at the end of April and it is likely that suggestions will be made about the use of biometrics, digital identities and the Internet of Things (IoT). Some payment systems, like Apple Pay and Google Wallet, already use fingerprint security and traditional banks are also exploring and developing the use of biometrics. As it stands at the moment, many online purchases already require two-factor authentication – something we know works well in other fields of data protection and information security.
The FCA’s consultation document can be found here.
As cyber security specialists, we certainly approve of precautions that reduce risk and deter fraudulent behaviours. As a profession, it would be fair to say that we do tend to assume the worst-case scenario as our starting point. This enables us to help our clients to anticipate criminal activity and to shore up defences to counteract the threats. In addition, we also go a step further by challenging a system to work out where the vulnerabilities lie.
With cyber security, however, it is always a question of weighing up the issues of speed/ease of use with those of security. There is no point in having a system that is so secure it is cumbersome and inoperable. When working with clients we always conduct a risk assessment to ensure that the valuable data is protected, without hindering the ability of the system to function at speed.
With contactless payments the issue of speed vs security is a fine balance. Of course, the primary concern is one of increased threats and fraud. But merchants also need to remember that there is a requirement on their part to ensure that the security of transactions is maintained in line with the Payment Card Industry Data Security Standard (PCI DSS). The rapid growth in contactless payment usage and the reduction in cash-based transactions in the last 12 months makes it more important than ever that anyone accepting, storing, processing or transmitting credit card information is doing so in line with the high standards set out by the PCI Security Standards Council (SSC).
Are you a merchant looking to ensure that you adhere to PCI DSS compliance? Our team of PCI consultants at SRM are here to help. Contact us.