Share this article
Even before the COVID-19 pandemic forced businesses to move transactions online and adopt contactless payments to reduce the spread of the virus, cash was in decline. In 2019, 7.4 million people already lead “cashless lives” by using cash once a month or less on average. But by the end of 2020 it was believed that this figure had almost doubled. In fact, between 2010 and 2020, cash payments have declined by 70%, according to UK Finance.
With card payments now dominant in the marketplace, it is more important than ever that the handling of transactions is smooth, seamless and secure. Yet, we know that there are many challenges being faced by merchants around the world today. According to a report from financial services and insurance experts Aite-Noverica, online credit card fraud has jumped from $6 billion in 2019 to an expected $8 billion by the end of 2021.
The festive season typically marks the most dangerous period for shoppers. From Black Friday weekend through to the Boxing Day sales, millions of transactions will be taking place every day – and this presents a substantial, ongoing risk to information security.
With so many transactions being processed, this time of year serves to highlight the importance of PCI DSS compliance in ensuring that merchants are taking the appropriate steps to mitigate risk and safeguard the data of their customers.
The mission of PCI DSS, is to ensure that card transactions are secure to both increase consumer trust and safety, and reduce losses in the event of a breach. It applies to every organisation responsible for storing, processing or transmitting card data.
In order to achieve compliance there are 12 broad rules to be adhered to – which we have covered previously on the blog here. But increasingly, merchants are looking to automated solutions that can aid them meet the requirements of the standard and ensure ongoing compliance.
Typically, these tools are cloud-based and draw all of the requirements together into one place so that they may be presented for regular auditing. While achieving compliance in the first instance is often a relatively straightforward project for organisations, staying compliant and maintaining high standards is always the greater challenge. This is where automation can be particularly helpful – serving to perform much of the heavy lifting when it comes to the monotonous and resource-intensive tasks.
Automated tools can help with the monitoring and management of passwords, administrative access and entitlements. As enterprises grow, it can be difficult to maintain compliance as new administrators gain access to critical systems, so having tools that proactively alert administrators to security deficiencies can be incredibly useful.
A key benefit of automated checking is that it can be scaled within large organisations. Similarly, it is prone to fewer errors than manual checking and is significantly quicker.
Given that credit card data represented around a third (32%) of the 18.9 billion records exposed through data breaches in the first half of this year, according to Risk Based Security’s 2021 Mid-Year Report, implementing solutions that serve to reduce risk and improve processes has never been more important.
Of course, as with any digital solution or tool, it is important to bear in mind that the technology is only ever as good as the instructions it is given or the data input. It is always critical that automated tools are themselves regularly monitored and checked by an expert in the field.
Seeking support from Qualified Security Assessors (QSAs) can help you meet regulations and protect your organisation from a potential data breach, by advising on the best routes to compliance and casting an experienced eye over the tools being used to manage risk and monitor information security.
If you would like more information on PCI DSS and securing your organisation against cyber threats, get in touch with the team at SRM today. Click here