Visa’s deadline is just around the corner, are you prepared?
Blog

Visa’s deadline is just around the corner, are you prepared?

The deadline for the Visa security program’s new annual compliance requirement for Level 4 merchants is getting closer. Starting from January 31st 2017 all US and Canadian acquired Level 4 merchants are required to validate their compliance with the Payment Card Industry Data Security Standard (PCI DSS) yearly. Or if eligible, the merchants must be […]

Blog, Videos

Cyber security threats – Keeping your customers safe with proactive data security services

  In a previous article, written by Sysnet’s Paul Prior, Paul mentioned how he believed that a change was necessary in the industry. A move away from using non-compliance fees as a mechanism to drive engagement and compliance.   He highlighted that most of Sysnet’s clients are evangelising the importance of PCI DSS, however not […]

Non-compliance fees; considering alternative approaches
Blog, Uncategorized

Non-compliance fees; considering alternative approaches

Non-compliance fees are viewed by many as an acceptable short-term solution to a merchant’s unwillingness to engage with a compliance program. However, often despite the best efforts by acquirers, some merchants continue to remain disengaged.   So when a merchant ignores notifications regarding their non-compliance status and the application of non-compliance fees, it may be […]

EU General Data Protection Regulation, what you need to know  
Blog, Uncategorized

General Data Protection Regulation, what you need to know  

By Natasja Bolton, Senior Acquirer Support QSA   The General Data Protection Regulation, or GDPR for short, will affect the processing and movement of the personal data of the approximately 500 million citizens populating the EU Member States. The new legislation will apply across all EU Member States from 25th May 2018.   Furthermore, the […]

Breaches rise in the hospitality industry. Practical advice for your customers
Blog

Breaches rise in the hospitality industry. Practical advice for your customers

Michael Hopewell, Managing Information Security Consultant When a breach is reported in the media, more often than not it’s the well-known large companies that make the headlines. In reality cybercriminals are more successful in attacking smaller companies.   The reason for this is that smaller businesses often have fewer resources and as a result are […]

State of Pay – have mobile payments reached a turning point?
Blog, Uncategorized

State of Pay – have mobile payments reached a turning point?

By Natasja Bolton, Senior Acquirer Support QSA In 2012, Mastercard published the results of their survey of the global mobile payments landscape in their Mastercard Mobile Payments Readiness Index.  The survey recognised that while mobile payments adoption has dependencies on six major elements from infrastructure and financial services to regulation, the critical success factor for […]

New tools in the fight against ransomware
Blog, Uncategorized

New tools in the fight against ransomware

With ransomware showing no signs of disappearing soon, a central repository website entitled “No-More-Ransom” has been established to disrupt cybercriminal businesses with ransomware connections. Europol’s European Cybercrime Centre has teamed up with the National High Tech Crime Unit of the Netherlands’ police, and two cyber security companies to offer advice and troubleshooting services.   A […]

MICROS Security Incident – steps to protect your customers
Blog, Uncategorized

MICROS Security Incident – steps to protect your customers

By Natasja Bolton, Senior Acquirer Support QSA   On August 8th, 2016 Oracle issued a letter informing their MICROS customers that malicious code had been detected in certain legacy systems and advising on the actions their customers should take. Oracle’s letter and subsequent FAQs did not give details of the root cause of the MICROS […]

Ask a QSA
Blog, Uncategorized

Ask a QSA

‘Ask a QSA’ recently received the below question that we believe will be of interest to our readers. Seasoned QSA, Natasja Bolton answers. Do fuel cards need to be included in PCI DSS compliance?   In my experience and my QSA colleagues here at Sysnet, we do not believe that there are card scheme branded […]

Timelines set for EU Directive on Network and Information Security
Blog, Uncategorized

Timelines set for EU Directive on Network and Information Security

By Natasja Bolton, Senior Acquirer Support QSA In our recent data breach article, we discussed the need for businesses to consider both their Payment Card Industry Data Security Standard (PCI DSS) and legal obligations when planning for security incidents and data breach reporting. In this article we discuss the recently published EU directive on Network […]

Blog, Videos

A look inside our contact services facility

    Through our multi-channel contact services centre, we deliver exceptional contact centre services. Our Global Operations Centre provides flexible, on-demand services to help you meet your business objectives. Our Global Operations Centre is based in Dublin, Ireland.   We use a combination of outstanding people, best-in-class technology and quality assurance programmes to make sure […]

Cybercrime is increasing – Preventative steps for businesses
Blog, FDUS - Managers

Cybercrime is increasing – Preventative steps for businesses

By Jason McWhirr, Information Security Consultant Globally, criminals are increasingly abandoning the more traditional approaches to crime. They are looking to the internet for their targets and using it as their preferred route to perpetrate criminal activity. The UK National Crime Agency’s Cyber Crime Assessment 2016 reports that cybercrime has now over taken traditional crime […]

planning-data-breach-businesses-ready-meet-legal-obligations
Blog

Planning for a Data Breach – are businesses ready to meet their legal obligations?

By Natasja Bolton, Senior Acquirer Support QSA   In order to help your merchant businesses with the definition and documentation of their Incident Response Plan, Sysnet has created a template document – Download the Security Incident Response Plan Template.   All merchants self-assessing their Payment Card Industry Data Security Standard (PCI DSS) compliance now need […]

Articles, Blog, Uncategorised, Videos

Protecting card reading devices – 6 suggestions for your customers

Businesses that accept payment cards for goods or services are often targeted by criminals who will attempt to tamper or substitute their card reading device. Regular inspection of payment card terminals and PIN entry devices is one of the most effective ways that businesses can ensure that their devices are secure from tampering and substitution. In the […]

Articles, Blog, Uncategorised

Sysnet’s Natasja Bolton discusses involvement in Small Merchant Taskforce

We recently reported that Sysnet’s Natasja Bolton, Senior Acquirer Support had contributed to the development of new payment resources to help small merchants and their banks defend against cybercrime. In this follow-up article we asked Natasja to elaborate further on what her role entailed and how she contributed to the development of this new vital […]

Articles, Blog, Uncategorised

Sysnet is now a PCI approved Qualified Integrator and Reseller (QIR)

Sysnet is pleased to announce that we are now a Qualified Integrator and Reseller (QIR) provider. The PCI Security Standards Council accreditation, allows qualified companies to implement, configure, and/or support validated PA-DSS Payment Applications on behalf of merchants or service providers for the purposes of performing Qualified Installations as part of the QIR Programme.   […]

One more nail in the coffin for iFrames?
Articles, Blog, Uncategorised

One more nail in the coffin for iFrames?

By Natasja Bolton, Senior Acquirer Support Businesses like the iFrame method as it allows them to entirely outsource the capture and processing of cardholder data. The data is outsourced to a validated Payment Card Industry Data Security Standard (PCI DSS) compliant Payment Service Provider (PSP).   From a consumer perspective it offers a streamlined checkout […]

Updated - Prioritised Approach for version 3.2 
Articles, Blog, Uncategorised

Updated – Prioritised Approach for version 3.2 

By Natasja Bolton, Senior Acquirer Support   The Prioritised Approach for PCI DSS, has been updated by the PCI Council to reflect the updated PCI DSS version 3.2. As most of you will know, the Prioritised Approach and its associated Excel Tool offers a risk-based, incremental approach to PCI DSS compliance.  It defines six security milestones […]

SHA-1 certificates – what your ecommerce customers need to know
Articles, Blog

SHA-1 certificates – what your ecommerce customers need to know

By Natasja Bolton, Senior Acquirer Support In 2015 use of the 20 year old SSL security protocol for encryption of sensitive data in transmission was deprecated (in PCI DSS v3.1) to encourage ecommerce businesses to migrate to TLS (Transport Layer Security).    In 2016, further technology changes are underway that will impact those of your customers […]

Are your customers aware of the new SAQ A requirements?
Articles, Blog, Uncategorised

Are your customers aware of the new SAQ A requirements?

By Natasja Bolton, Senior Acquirer Support   SAQ A v3.2 has introduced a number of changes to the self-assessment that will impact your customers that have chosen to outsource the handling and processing of cardholder data to external third party providers.   Although the fundamental expectation of SAQ A has not changed (that all payment […]

Why P2PE Solution Validation is not as hard as you may think
Articles, Blog

Why P2PE Solution Validation is not as hard as you may think

Natasja Bolton, Senior Acquirer Support, investigates   We previously wrote about the release of PCI P2PE Version 2 and its impact for acquirers and their merchants. In this follow-up article we explore an issue that has come to Sysnet’s attention: that many terminal solution providers and point-of-sale (POS) vendors appear to be actively avoiding P2PE […]

Merchant Receipts: Are your customers storing more payment card data than they need?
Articles, Blog

Merchant Receipts: Are your customers storing more payment card data than they need?

By Natasja Bolton, Senior Acquirer Support   Face to face card payment transactions generate two receipts – the cardholder copy, on which the Primary Account Number (PAN) must be truncated, and the merchant copy which will usually show the full PAN.   Businesses are well aware that they must retain their merchant copy receipts in […]

Criminals aren’t just after payments data, they want a consumer’s identity
Articles, Blog

Criminals aren’t just after payments data, they want a consumer’s identity

By Jason McWhirr, Information Security Consultant It is commonplace for organisations to ask consumers to provide Personally Identifiable Information (PII) to prove identity, strengthen authentication mechanisms, and speed-up payments. Most organisations will have an identity profile of each of their consumers that incorporates PII data.   This includes common fields such as; address, date of […]