The General Manager of SafeCharge Israel talks about the new payment regulation challenges faced by online merchants
On the 1st of June 2015, the new PCI (Payment Card Industry) 3.0 standard became mandatory and all merchants are expected to move to the new standard.
All online merchants who process, transmit or store customer credit cards need to comply with the Payment Card Industry Data Security Standard (PCI DSS, or as its more commonly known PCI Compliance), which is a complex and demanding set of requirements for payment data protection.
For online merchants who manage their own PCI compliance, this can be time consuming and risky, as holding customers’ credit card details on file makes them more vulnerable to malicious hackers. If PCI compliance is outsourced, there are no credit card details on its system as all the card data is processed and stored by a third-party provider, so minimising the liability of their compliance responsibilities.
Outsourcing reduces or eliminates PCI scope, and minimising scope is the simplest way for a merchant to achieve PCI compliance. An outsourced provider should be properly certified, and use the latest technology. All of the merchant’s IT infrastructure should be taken out of PCI scope, as any part of the merchant’s IT system which processes, stores or transmits cardholder data comes under PCI regulations.
One of the methods in which an outsource provider can remove a merchant from PCI scope is tokenisation, whereby a customer’s card details (the primary account number – PAN) are replaced by a token that has no exploitable meaning or value, and takes the place of the card details. With tokenisation, if a hacker were to gain entry to the merchant’s system all he/she would get would be the token, which will be of no use as the hacker has no means of de-tokenisation.
Most of the changes introduced with PCI 3.0 are clarifications and tweaks to existing requirements. The Regulation refinements cover everything from the definition of scope and methods of documentation to new ways of preventing fraud at the point of sale. For merchants who do not outsource their PCI requirements, they will find an ever-increasing amount of their technology systems come under the scope of version 3.0.
It’s not only workstations that handle the credit card data that is included in the scope, it’s now more defined in the regulations that any potentially vulnerable server or workstation that touches the merchant’s network has to be PCI DSS compliant. This extension of the scope has been brought about as a hacker could get into a network by a lesser protected workstation and subsequently gain access to a merchant’s customer data on the supposedly more secure parts of the network.
When deciding on what route to take to be PCI 3.0 compliant, merchants need to consider the following changes to the standards that are now required:
A firewall configuration needs to be installed and maintained to protect cardholder data
Vendor supplied defaults should not be used for system passwords and other security parameters
Stored cardholder data needs to be protected
Encrypt transmission of cardholder data across open public networks
All systems need to be protected against malware
Anti-virus software needs to be regularly updated
Develop and maintain secure systems and applications
Restrict access to cardholder data by “need to know”
Identify and authenticate access to systems components
Restrict physical access to cardholder data
Track and monitor all access to network resources and cardholder data
Regularly test security systems and processes
Maintain a policy that looks at information security for all staff
Finally, something that is out of a merchant’s control, but ironically still part of the merchant’s liability, is that all third parties handling customer credit card data on behalf of a merchant will be included in the new scope. So outsource to payment providers that have a solid list of clients utilising their descoping solution and that perform continuous maintenance checks in adherence with all PCI standards and updates.
This article is part of the FinanceMagnates Community project. If you wish to become a guest contributor, pleaseapply here.
On the 1st of June 2015, the new PCI (Payment Card Industry) 3.0 standard became mandatory and all merchants are expected to move to the new standard.
All online merchants who process, transmit or store customer credit cards need to comply with the Payment Card Industry Data Security Standard (PCI DSS, or as its more commonly known PCI Compliance), which is a complex and demanding set of requirements for payment data protection.
For online merchants who manage their own PCI compliance, this can be time consuming and risky, as holding customers’ credit card details on file makes them more vulnerable to malicious hackers. If PCI compliance is outsourced, there are no credit card details on its system as all the card data is processed and stored by a third-party provider, so minimising the liability of their compliance responsibilities.
Outsourcing reduces or eliminates PCI scope, and minimising scope is the simplest way for a merchant to achieve PCI compliance. An outsourced provider should be properly certified, and use the latest technology. All of the merchant’s IT infrastructure should be taken out of PCI scope, as any part of the merchant’s IT system which processes, stores or transmits cardholder data comes under PCI regulations.
One of the methods in which an outsource provider can remove a merchant from PCI scope is tokenisation, whereby a customer’s card details (the primary account number – PAN) are replaced by a token that has no exploitable meaning or value, and takes the place of the card details. With tokenisation, if a hacker were to gain entry to the merchant’s system all he/she would get would be the token, which will be of no use as the hacker has no means of de-tokenisation.
Most of the changes introduced with PCI 3.0 are clarifications and tweaks to existing requirements. The Regulation refinements cover everything from the definition of scope and methods of documentation to new ways of preventing fraud at the point of sale. For merchants who do not outsource their PCI requirements, they will find an ever-increasing amount of their technology systems come under the scope of version 3.0.
It’s not only workstations that handle the credit card data that is included in the scope, it’s now more defined in the regulations that any potentially vulnerable server or workstation that touches the merchant’s network has to be PCI DSS compliant. This extension of the scope has been brought about as a hacker could get into a network by a lesser protected workstation and subsequently gain access to a merchant’s customer data on the supposedly more secure parts of the network.
When deciding on what route to take to be PCI 3.0 compliant, merchants need to consider the following changes to the standards that are now required:
A firewall configuration needs to be installed and maintained to protect cardholder data
Vendor supplied defaults should not be used for system passwords and other security parameters
Stored cardholder data needs to be protected
Encrypt transmission of cardholder data across open public networks
All systems need to be protected against malware
Anti-virus software needs to be regularly updated
Develop and maintain secure systems and applications
Restrict access to cardholder data by “need to know”
Identify and authenticate access to systems components
Restrict physical access to cardholder data
Track and monitor all access to network resources and cardholder data
Regularly test security systems and processes
Maintain a policy that looks at information security for all staff
Finally, something that is out of a merchant’s control, but ironically still part of the merchant’s liability, is that all third parties handling customer credit card data on behalf of a merchant will be included in the new scope. So outsource to payment providers that have a solid list of clients utilising their descoping solution and that perform continuous maintenance checks in adherence with all PCI standards and updates.
This article is part of the FinanceMagnates Community project. If you wish to become a guest contributor, pleaseapply here.
Pepperstone Enters the Fighting Ring: Becomes UFC Asia Sponsor
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
Finance Magnates Annual Awards 2024 | FM Awards 2024 Highlights
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
🎥Catch the best moments from the Finance Magnates Annual Awards Gala Dinner!
An evening where top names in finance came together to celebrate achievements, enjoy live music, and connect over a memorable dinner. Watch the highlights and feel the energy of our first gala in Cyprus!
Congratulations to all the winners for their dedication to excellence and leadership in the financial industry, including XM, Trading PRO, FP Markets, Deriv, FxPro, LATAM, Headway, ATFX, FBS, AMEGA, EC Markets, Axi
For more information about the 1st Finance Magnates Annual Awards, visit https://bit.ly/3Zb7wNz
#FinanceMagnatesGala #IndustryExcellence #GalaHighlights #FinanceMagnatesAnnualAwards #FinanceMagnatesAwards #CelebratingSuccess #FinanceCommunity
FMLS:24 | Shaping the Next Era of Financial Evolution
FMLS:24 | Shaping the Next Era of Financial Evolution
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
FMLS:24 | Shaping the Next Era of Financial Evolution
FMLS:24 | Shaping the Next Era of Financial Evolution
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
Welcome to FMLS:24 – the premier event where influential brands and leaders in trading, payments, fintech, and digital assets come together!
Join over 2,500 industry professionals, engage with 150+ expert speakers, and discover endless opportunities with 70+ top exhibitors. FMLS:24 is where senior executives and decision-makers gather to close deals, forge new partnerships, and strengthen connections with long-term clients.
Whether you’re in finance, technology, or payments, this summit is your gateway to future growth, meaningful collaborations, and industry-leading insights.
👉 Don't miss out – secure your ticket now at https://events.financemagnates.com/ZQEYy0?utm_source=youtube&utm_campaign=fmls24-awareness&utm_medium=video&RefId=MLS%3A24+Video+Promo
#fmls #fmls24 #fmevents #financemagnates #forex #payments #crypto #events #london #fintech #ai #generativeai #technology #onlinetrading #forex #investing #investors #tech
📣 Stay updated with the latest in finance and trading!
Follow FMevents across our social media platforms for news, insights, and event updates. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/showcase/financemagnates-events/
👍 Facebook: https://www.facebook.com/FinanceMagnatesEvents
📸 Instagram: https://www.instagram.com/fmevents_official
🐦 Twitter: https://twitter.com/F_M_events
🎥 TikTok: https://www.tiktok.com/@fmevents_official
▶️ YouTube: https://www.youtube.com/@FinanceMagnates_official
Don't miss out on our latest videos, interviews, and event coverage. Subscribe to our YouTube channel for more!
FM's Andrea Badiola Mateos at LSEG's Cyprus event
FM's Andrea Badiola Mateos at LSEG's Cyprus event
FM's Andrea Badiola Mateos at speaking in a panel discussion at LSEG's Cyprus event
FM's Andrea Badiola Mateos at speaking in a panel discussion at LSEG's Cyprus event
The Role of PAMM, MAM & Copy Trading in Business Growth Strategies | Webinar
The Role of PAMM, MAM & Copy Trading in Business Growth Strategies | Webinar
The copy trading market is projected to double in size, growing from $2.2 billion to $4 billion by the end of this decade. In light of this, brokers and financial institutions are increasingly adopting PAMM, MAM, and Copy Trading solutions to scale operations and drive profitability. In this insightful webinar, Sergey Ryzhavin, Product Owner at B2COPY, outlines the advanced features of the B2COPY platform, showcasing how it enhances Copy Trading, PAMM, and MAM performance. Sergey also explores strategies for using these tools to attract new clients, improve customer engagement, and create additional revenue streams.
📣 Stay updated with the latest in finance and trading!
Follow Finance Magnates for news, insights, and event updates across our social media platforms. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/company/financemagnates/
👍 Facebook: https://www.facebook.com/financemagnates/
📸 Instagram: https://www.instagram.com/financemagnates_official
🐦 X (Twitter): https://twitter.com/financemagnates/
📡 RSS Feed: https://www.financemagnates.com/feed/
▶️ Telegram: https://t.me/financemagnatesnews
Don't miss out on our latest videos, interviews, and event coverage.
🔔 Subscribe to our YouTube channel for more!🔔
The copy trading market is projected to double in size, growing from $2.2 billion to $4 billion by the end of this decade. In light of this, brokers and financial institutions are increasingly adopting PAMM, MAM, and Copy Trading solutions to scale operations and drive profitability. In this insightful webinar, Sergey Ryzhavin, Product Owner at B2COPY, outlines the advanced features of the B2COPY platform, showcasing how it enhances Copy Trading, PAMM, and MAM performance. Sergey also explores strategies for using these tools to attract new clients, improve customer engagement, and create additional revenue streams.
📣 Stay updated with the latest in finance and trading!
Follow Finance Magnates for news, insights, and event updates across our social media platforms. Connect with us today:
🔗 LinkedIn: https://www.linkedin.com/company/financemagnates/
👍 Facebook: https://www.facebook.com/financemagnates/
📸 Instagram: https://www.instagram.com/financemagnates_official
🐦 X (Twitter): https://twitter.com/financemagnates/
📡 RSS Feed: https://www.financemagnates.com/feed/
▶️ Telegram: https://t.me/financemagnatesnews
Don't miss out on our latest videos, interviews, and event coverage.
🔔 Subscribe to our YouTube channel for more!🔔