Showing posts with label pci compliance. Show all posts
Showing posts with label pci compliance. Show all posts

Tuesday, May 28, 2013

Keep The PCI Compliance Process Top Of Mind

Data security and the PCI compliance process always need to stay top of mind for our merchants.

To make sure this is the case, we can’t think of PCI as a one and done deal. We have to reinforce the issue throughout the complete merchant lifecycle. Below are three convenient occasions when you can bring up the PCI compliance process and PCI compliance assessments with your merchants--keeping them compliant and their customers safe.

1. Installation
We often view installation as the final step in the sales process, but you can make it much more than that.

Many merchant service providers will use it as a convenient time to ask for referrals. Others use the occasion to train the business’s personnel on how to operate the terminal. Some try to sell additional services. While all of these are great ideas, we should also use this time to discuss PCI compliance.

Remind the merchant that they must complete a PCI compliance assessment. Reiterate that the way they handle transactions is crucially important. If they have a computer-based point-of-sale system, make sure they know how important it is that they secure their network. If they’re going to be using a terminal, tell them they should never write down complete credit card numbers or keep receipts where someone could see or steal them.

And right before you leave, you should remind them that although they may be PCI compliant today, if they’re not cautious, a single mistake could make them non-compliant. And that mistake would be expensive.

2. Retention
Good communication is the best way to retain your merchants. So if you don’t have a newsletter, you should start one. There are many tools out there to help you create one electronically.

And you should talk about PCI in every edition. It doesn’t have to be the main topic, but you should always bring up data security in some way, shape or form.

3. The Problem Call
Every time a merchant calls you, you have the chance to bring up PCI compliance.

Fix their problem first, of course, but then ask them how they’re doing more generally.  Catch up with them for a few minutes, and see if their situation has changed or if they need something that you can help with--a new product perhaps.

Then ask them if they’ve heard anything new about data security. Talk them through any new insight you might have, then remind them of the steps they should be taking to protect their customers.

I’ve found that these are great times to bring up PCI compliance with merchants. When do you like to broach the subject?


Three Things You Need To Know About PCI Requirements


Although “PCI requirements” and “PCI compliance fees” aren’t quite the buzz words that they were a few years ago, PCI is still vitally important to your business, your clients and their customers.

Here are three things you need to know to keep your merchants compliant and their customers safe.

1. Breach Insurance Isn’t Enough
Most merchants understand that it’s important to keep their cardholders’ data safe and sound. 

But I have found that many still believe that, because they have breach insurance, they don’t have to worry. And so when I ask them what concrete measures they’ve implemented to protect their customers, they give me a blank stare.

Don’t get me wrong--breach insurance is great. But it’s no substitute for taking the necessary steps to fulfill PCI requirements and keep cardholders safe.

That’s why, as merchant service providers, we must constantly emphasize the PCI process.

2. Never Let Them Forget PCI
To ensure that merchants are protecting their customers’ data, you have to emphasize PCI throughout the merchant lifecycle.

I like to bring up PCI at the following occasions: 
  • Installation
At installation, many providers ask their customers for referrals, or they teach the business owner and staff how to operate the terminal. But installation is also a great time to talk PCI. Remind the merchant that they need to complete a PCI compliance assessment. Reiterate how important it is to secure their network. And be transparent about any PCI compliance fees that they’ll have to pay.
  • Retention
Communication is the best way to retain your merchants, so if you don’t have a newsletter, you should put one together today. And in every newsletter, you should touch on PCI. It doesn’t have to be the main article, but a short blurb in every issue will help keep PCI top of mind. 
  • Problem Calls
Every time a merchant contacts you, you have the opportunity to mention PCI. Of course, you should answer their question or solve their problem first. But then ask them how they’re doing. Have they heard anything new about data security? 

3. Compliant Today, Breached Tomorrow
Perhaps the most important thing to communicate to your merchants is the need for constant vigilance.

You could be doing everything right. You could have completed all your compliance assessments. You could have secured your network.

And then, one day, you make a single mistake, and your customers’ accounts will be compromised. You will no longer be compliant. And that mistake will cost you.

What do you think are the most important things to know about PCI?

Tuesday, February 26, 2013

PCI Compliance Fees: What They Tell You About Your Processor

Recently, many agents and ISOs have come to me and complained about PCI compliance fees.

Monthly PCI fees can range from $5-$20, and annual fees can set you back $60-$130 (and sometimes merchants have to pay both!). But while merchants certainly don’t like paying them, the real problem is often that processors don’t clearly explain them. They stick the fee information in the fine print or they don’t communicate all the details so when merchants receive their monthly statements and find the fees on them, they grab their phones and give their merchant processor an earful.

But while murky PCI compliance fees are a pain in the neck by themselves, they often tell a much bigger story: the general state of your relationship with your processor.

Delve into your processor’s PCI compliance process and ask yourself these questions. They’ll let you know if you need to think about a change:

  • How does your processor handle interchange fees? Do they pass them along at cost, or do they mark them up?
  • Does the merchant application or agreement clearly disclose merchant fees? Or are they hidden in the fine print somewhere?
  • On the merchant’s monthly statement, are fees labeled clearly and are the counts and amounts used to calculate the fees included?
  • Is it easy to read and understand your residual report? Or is it filled with long paragraphs of jargon and winding, tortuous sentences that go on and on, not really say anything, repeating themselves, kind of like this?

After asking yourself those questions, ask yourself one more: does your partner consistently hide fees in order to make more revenue? If so, this pattern will probably continue.

Will the amount they charge be reasonable or exorbitant? Will merchants be able to control the amount of the fee, or will they be left helpless? And will processors clearly explain the fees to merchants and ISOs, or will they conceal or camouflage them so that they can increase their profits?

Pay close attention to how your processor responds to these types of situations. If it isn’t to your liking, you probably have other issues as well. And you may need to start thinking about changing processors.

#

Jeff Zimmerman is Vice President of Product Management and Marketing at Clearent. He has 15 years of experience in marketing, finance and product management. Clearent can offer you a hassle-free PCI compliance process with no PCI compliance fees for merchants.

Thursday, May 5, 2011

Merchant Awareness of PCI: Success or Failure?

It's been nearly a decade now, so are small merchants aware of PCI? Yes, it's already been 10 years. Visa brought the Cardholder Information Security Program (CISP) to fruition in 2001, and in 2004 it evolved into the Payment Card Industry (PCI) Data Security Standard (DSS).

After several years of comprehensive efforts in the payment processing industry to inform and educate merchants, and the fact that payment card industry compliance is required, results and opinions are mixed. A recent study by the National Retail Federation provides information to make a case for both success and failure of the program and here they are:

Success

• 66% of small merchants are aware of the PCI DSS.

• The majority of merchants who are aware of PCI take it seriously. 74% of them have had a PCI compliance assessment.

• 94% of merchants care about keeping card information secure.

• 50% of merchants are aware of some consequences of a breach, such as getting sued by cardholders and losing the ability to accept Visa and MasterCard

Failure

• 34% still have a lack of awareness of PCI despite the immense industry efforts.

• 51% of all merchants still have not had a PCI compliance assessment.

• 64% are unaware of the dangers and don't believe their business is vulnerable to card data theft.

• 60% of merchants don't have a strong understanding of the costs, including fines by Visa/MasterCard, liability for use of stolen cards, and per-card fees for every canceled card.

So, has this all been a success or a failure? While my answer might be an open invitation to accusations of being a politician or fence-sitter, my answer is "Yes." As an industry, we've made great progress, and had a significant impact on the industry in a positive way, but we have a long way to go to get payment card industry compliance where it needs to be.

Let's not stop at that, let's offer a few explanations for why awareness and compliance are potentially lower than one might expect.

1. Quantities of new businesses

Many small business owners have a lengthy list of responsibilities and to-dos; it's not a huge surprise that these businesses are not familiar with PCI out of the gates. Exaggerating this impact is the fact that many new businesses open every year. According to Census data, 700,000 new businesses are "born" each year. This is reflected in the NRF study where 27% of merchants were less than three years old.

2. "Bad things only happen to other people" mentality

It can be human nature to assume the best and that "it won't happen to me." When dealing with the risk of a security breach involving cardholder data, many merchants appear to take that approach, rather than planning with Murphy's Law in mind.

3. Focus on fees rather than compliance

There is no reason to hide the fact that most processors and acquirers have fees for PCI programs. The fees have created controversy because they can seem high and are often not tied to compliance. As a result, perhaps PCI fees have become the main focus for many ISOs and merchants instead of PCI compliance itself.

ISOs are you fed up with high fees associated with your current payment partner's Payment Card Industry (PCI) compliance assessment program? Are they causing attrition in your portfolio? Do their fees make it difficult for you to sign new merchants? Clearent has a unique approach to PCI compliance:

No PCI Fees - That's right, there are no PCI fees for merchants who complete our questionnaire
Keep it Simple - Merchants save time thanks to our simplified PCI questionnaires
Know Your Status - Monitor your portfolio's status at-a-glance with our online reports

Contact Clearent for more information on payment processing solutions for ISOs and FIs.

PCI DSS Compliance and Adressing the Blame Game

We all know the "Blame Game." We were introduced to it as a child. It typically involves breaking, spilling, or loosing something that your mother didn't want you tinkering with in the first place. The game changes as we get older - our arguments get stronger but we still pass the blame.

Here are some classic responses we've either said - or heard - at one time or another:
• "(Name) did it."
• "It wouldn't have happened if (Name) did (Desired Action)."
• "It's not my fault."

As a result, today our society could be defined as a litigious one. People are quick to sue and claim that they shouldn't be held accountable and that it's someone else's fault that something bad happened.

Merchants are no different because of the pressures they face, especially with the varying changes in regulation and the economy over the past few years. There are all sorts of opportunities for errors and finger pointing.

One area that is very important is maintaining data security, PCI DSS compliance. Vulnerabilities can be created from careless actions, and vulnerabilities can result in a breach, as well as hefty fines, penalties and more.

When this happens, it's likely that the merchant is going to look outside of his business for someone to blame. And when he thinks he's found that someone, a lawsuit could be the next thing to follow.

To protect themselves and their merchant customers, most payment processors will insist on the completion of a PCI compliance assessment. The processor then reviews the assessment to identify merchants whose actions may put them at risk for a compromise. This helps keep the blame at bay but its not the best.

It's common for ISOs to want to provide the best possible service to their merchants and they may want to complete the self-assessment questionnaires (SAQs) on behalf of their merchant.

What happens if, for some reason, a merchant is then breached? If it is determined that the merchant was not PCI compliant and the questionnaire was not completed accurately, who will the merchant blame? It was the ISO who helped them complete their PCI compliance assessment, of course.

PCI DSS compliance and data security are very important, but processors shouldn't put ISOs in the middle of their approach. That isn't their job, and frankly, they shouldn't be expected to be a PCI compliance expert. Also, remember that why one of the best way to avoid this Blame Game is a self-assessment questionnaire, designed to be taken by merchants because they know the details of their operation best.

So what's the solution?

At Clearent, we use an online questionnaire, designed to be completed by the merchant to assist with PCI DSS compliance. We believe it shouldn't be part of the application process, but rather part of the support your payment processor provides to your merchants. And it shouldn't come with a cost to complete.

It's a simple approach, but one that any ISO today with the desire to grow should appreciate. That way if a breach should ever happen, you can easily say, "It wasn't me. I wasn't even involved." - and truly mean it. Otherwise, it may be prudent to have an attorney on retainer.