How PCI DSS builds layers of protection
Articles, Blog, Cyber Risk

How PCI DSS builds layers of protection

By Natasja Bolton, Acquirer Support Manager The primary objectives (or attributes) of security (whether that be ‘information security’ or more recently ‘cyber security’) are encompassed in the CIA triad: Confidentiality, Integrity and Availability which are defined as: Confidentiality: ensuring that information is accessible only to those authorised to have access Integrity: ensuring the accuracy and […]

EMV - The story so far
Articles, Blog

EMV – The story so far

By Natasja Bolton, Acquirer Support Manager Back in late October 2015, we reported how some SMB’s were stating that the “EMV transition is overwhelming”. Fast forward nearly 5 months, the question arising is: how successful has the EMV roll out been so far?   From a consumer perspective, the roll out has seen an estimated […]

It’s all in the details – successful campaign engagement
Articles, Blog, Infographics

It’s all in the details – successful campaign engagement

In our experience we have found that the devil is in the detail when it comes to successfully engaging customers with a multichannel campaign. Changes or alterations that could easily be viewed as minor can often dramatically improve engagement rates.   In the following infographic ‘Boost Your Campaign Engagement’ we examine the details that can […]

The rise of the (Chief) Data Protection Officer
Articles, Blog

The rise of the (Chief) Data Protection Officer

by Dr. Grigorios Fragkos, VP Cybersecurity Back in August 2015, Sysnet discussed the complexity of what the term CyberSecurity represents, especially in the context of today’s threat landscape. This complexity is not only constantly increasing but it is also expanding at an exponential rate. The risks involved demand constant attention and very good understanding of […]

New acquirer responsibilities - Strong customer authentication under forthcoming EU legislation
Articles, Blog

New acquirer responsibilities – Strong customer authentication under forthcoming EU legislation

By Natasja Bolton, Acquirer Support Manager In our December Ecommerce article we discussed the European Banking Authority’s (EBA) new guidelines for the security of internet payments and the possibility that, with the need to enhance protection of consumers against online payment fraud, presenting Payment Service Provider (PSP) hosted payment pages in iFrames may no longer be acceptable. […]

Choosing-the-right-communications-channel-to-drive-engagement
Articles, Blog, Infographics

Choosing the right communications channel to drive engagement

Increasing and maintaining PCI DSS compliance can be a challenge, many factors often come into play, from how customers are engaging with their PCI programme to what channel and communications are compelling them to take action. Every communication channel has a value and a benefit, understanding when to implement which channel and at what stage […]

Merchant aggregators – A risky prospect?
Articles, Blog

Merchant aggregators – A risky prospect?

Over the past number of years the merchant aggregator model has become more and more popular to the point where it might even be considered commonplace. These enterprises that essentially bring together a fragmented marketplace, funnel and process multiple merchant transactions through a single account.   Well-known merchant aggregator brands such as Paypal, Checkout by […]

Articles, Blog

Can Cyber Essentials help your clients towards PCI DSS compliance?

By Natasja Bolton, Acquirer Support Manager Although PCI DSS is a prescriptive set of requirements focussed on payment card data and most cyber-security guides do not go to the same level of detail, being high-level recommendations and advice without specific measures of the achievement of the risk reduction objective, the Cyber Essentials Scheme does cover a […]

Ransomware - Tips on prevention, response and evading extortion
Articles, Blog

Ransomware – Tips on prevention, response and evading extortion

by Dr. Grigorios Fragkos, VP Cybersecurity Ransomware, a malware that prevents or in some cases limits users from accessing their data has been on the rise. Last year, 2015 saw a considerable increase with Crowti (also known as CryptoWall) and FakeBSOD being the two instances that affected more than 850,000 systems between June and November. […]

Why cyber insurance grew in popularity in 2015
Articles, Blog

Why cyber insurance grew in popularity in 2015

by Dr. Grigorios Fragkos, VP Cybersecurity The Cyber Liability Insurance Cover (CLIC) or otherwise referred to as cyber insurance, is a market that grew significantly in 2015. One of the main factors that significantly contributed to this growth is the constant increase of threats in the cyber space and more specifically the high profile data breaches that […]

Do your clients know their cardholder data environment?
Articles, Blog, Whitepapers

Do your clients know their cardholder data environment?

by Jason McWhirr, Information Security Consultant One of the most important (and underused) first steps for any business or service provider when undertaking PCI DSS is to understand how cardholder data is used within their organisation, its people, departments, and systems. Without first knowing this, it is impossible to know which parts of their organisation […]

Articles, Blog

Using data to build better relationships with your SMBs

Every engagement with a client provides an opportunity for you to strengthen your relationship with them. By ensuring that each contact makes them feel that they have a strong business partner that they can trust, rely on, and build their business with, you are fueling their loyalty and strengthening your customer relationship.   Conversely, each […]

PCI Council extends date for migration from vulnerable encryption protocols
Blog

PCI Council extends date for migration from vulnerable encryption protocols

Following significant feedback from the global PCI community and security experts, the PCI Security Standards Council (PCI SSC) has extended the migration completion date for transitioning from SSL and TLS 1.0 to a secure version of TLS (currently v1.1 or higher) to 30 June 2018.   This change gives organisations struggling to move away from […]

The end of the road for Ecommerce iFrames?
Articles, Blog

The end of the road for Ecommerce iFrames?

By Natasja Bolton, Acquirer Support Manager As we discussed in the Ecommerce SAQ Selection guide, business seeking to minimise their PCI DSS compliance obligations for their ecommerce payment channel often outsource all capture and processing of payment card data to validated PCI DSS compliant payment service providers (PSPs).   The most common method of doing […]

EU agreement on response to cyber-attacks
Blog

EU agreement on response to cyber-attacks

by Natasja Bolton, Acquirer Support Manager On 7th December 2015 it was announced that the European Parliament, the European Council and the European Commission have agreed on the first EU-wide legislation on cybersecurity: the EU Network and Information Services (NIS) Directive. With the emerging threat of cyber-attacks, it is hoped that the NIS directive will […]

Customer engagement - driving compliance through customer engagement
Articles, Blog, Whitepapers

Customer engagement – driving compliance through customer engagement

Many factors can impact the effective delivery of a PCI programme for acquirers, processors and ISOs.  From how customers are engaging with their PCI programme to what channel and communications are compelling them to take action.   Download our Best Practice Guide where we take a look at how an omni-channel approach can improve customer […]

The Requirement for Service Provider PCI DSS Compliance
Articles, Blog

The Requirement for Service Provider PCI DSS Compliance

by Natasja Bolton, Acquirer Support Manager     Business customers engage with all manner of third party service providers to support their business, whether that be IT support providers, data centres, offsite storage providers, hosting providers or payment processors. What is not always understood is that outsourcing a business operation or buying in a service […]

A guide to ecommerce SAQs
Articles, Blog, Client Resources, Whitepapers

A guide to ecommerce SAQs

by Natasja Bolton, Acquirer Support Manager Most small and medium-sized merchants rely on an online compliance portal, such as our Sysnet.air solution, to determine the appropriate SAQ for their PCI DSS self-assessment. SAQ determination is based on the merchant’s completion of a series of questions on their  payment channels and payment processing methods.   For many merchants […]

Blog, Client Resources

Malware POS Alert – AbaddonPOS and Cherry Picker

by Dr. Grigorios Fragkos, VP Cybersecurity Two new malware files have been identified targeting point-of-sale (POS) terminals called AbaddonPOS and Cherry Picker. The AbaddoPOS malware is delivered by the Angler Exploit Kit or through an infected Microsoft Office document. The malware targets the memory of all processes running on the infected system (excluding its own […]

Easier PCI compliance with PCI-validated P2PE Solution
Articles, Blog, Client Resources

Easier PCI compliance with PCI-validated P2PE Solution

by Jason McWhirr, IS Consultant Not surprisingly, most retailers are focussed on their customers and sales, using the tools that best facilitate that, not on security systems to protect cardholder data – despite the hazards that a data breach could present.   Sysnet’s contact centre and acquirer support teams help retail merchants with their annual […]

Articles, Blog, Sysnet.air

“EMV transition is overwhelming” – Many SMBs struggle with the liability change

With the EMV transition deadline of October 1st having passed, many small business have still not upgraded their terminals to the new standard and many are not aware of the financial and legal liabilities that they are now responsible for. In fact many small business are feeling overwhelmed, according to a recent article on Paymenteye.com. […]

Articles, Blog, Client Resources

EMV – Taking care of business in the U.S

With 85% of merchant businesses unaware of the financial and legal liabilities they’ll be responsible for starting at the beginning of October, we take a look at the key impacts that will affect these businesses. “Download our whitepaper: Taking-Care-of-Business-in-the-U.S. where we examine what the impact the EMV roll out will have on merchants and list potential […]

Blog, Sysnet.air

Managing the Compliance process in PCI Level 1, 2 & other strategically important merchants

by Paul Prior, SVP Client Engagement   VISA Inc, in a bulletin issued the middle of last year outlined enhancements to their PCI DSS Enforcement Plan for merchants and service providers. The plan defined a structure of escalating consequences for entities either with expired PCI DSS Compliance or those who have never demonstrated PCI DSS […]

Blog, Risk & Assurance

Ecommerce Security and PCI DSS compliance – Encouraging security awareness, Part 2

by Natasja Bolton, Acquirer Support Manager, Risk and Assurance Division In part 1 last week, I discussed how businesses may be putting themselves at risk by assuming that ‘PCI DSS compliant’ also meant secure, (for part 1 please click here).    Maybe what we should be doing is encouraging businesses to focus less on compliance as […]

Blog, Risk & Assurance

Ecommerce Security and PCI DSS compliance – A broader perspective on security, Part 1

by Natasja Bolton, Acquirer Support Manager, Risk and Assurance Division Ecommerce merchants are encouraged to reduce the risk of payment card data compromises in their online trading by outsourcing the acceptance and processing of cardholder data to validated PCI DSS compliant service providers.   The simplest and cheapest option for small ecommerce merchants is to […]