SlideShare a Scribd company logo
1 of 38
Download to read offline
PCI Compliance: 
Protect Your 
Business From 
Credit Card 
criminals
Why is cyber security important 
For Your Small Business
Cybercriminals are 
now targeting 
smaller businesses 
In great numbers where security is weaker. 
60% of small businesses that suffer a data 
breach are out of business 6 months later. 
A recent survey by Fortinet found 
nearly two-thirds of consumers 
held merchants responsible 
for data breaches.
A basic overview
To help understand 
these issues we spoke 
with Simon Gamble, 
Small-business cyber 
security expert and president 
of Mako Networks’ U.S. branch. 
He began with three comments:
1) 
Any small business that 
accepts credit cards is a 
potential target for a 
cyber security breach.
2) 
Small businesses are held 
to the same level of credit 
card security standards 
(discussed later in this 
presentation) as large 
businesses such as Target or 
Home Depot.
3) 
Any small business that 
suffers a cyber security 
breach and is found to be 
non-compliant to credit card 
security standards, is fully liable for 
charges related to the breach.
You Could Be a Targert 
If you are a small business who accepts credit cards, then you are vulnerable 
to a cyber attack. Cyber attackers are targeting small businesses more and 
more, because their networks are easier to hack and they are not as regularly 
checked for compliance to credit card security standards.
PCI Compliance 
(Credit Card Security Standards)
If you accept credit cards, 
then you have agreed to 
abide by the PCI DSS 
(Payment Card Industry Data 
Security Standard) 
The PCI DSS is a set of requirements 
designed to ensure that all companies 
that process, store, or transmit credit 
card information maintain a secure 
environment.
Security Breaches, 
Liability, and Other 
Consequences 
If your small business is suspected of a 
security breach, PCI DSS inspectors 
come in and try to determine if there is a 
breach and how it occurred. This 
process in and of itself can be crippling 
for a small business, shutting down 
operations for a minimum of several 
days and costing between $8,000 – 
$20,000 in inspection fees.
If your business is found to be 
non-compilant, you are held 
liable for more charges: 
1. Data Security Fine – Up to 
$500,000 fine per security breach 
incident. 
2. Non-Compliance Fines – Up 
to $50,000 per day for non-compliance 
with published 
standards.
If your business is found to be 
non-compilant, you are held 
liable for more charges: 
3. Card Replacement Fees – $3- 
$10 per card x total number of 
cards compromised. 
4. Refund Fees – Potentially held 
liable for all fraud losses incurred 
from compromised account 
numbers.
How To Be PCI DSS Compliant 
and Protect your Business 
from Cyber Threats
The key is to make 
sure your business is 
PCI DSS compliant. 
Why? First, PCI compliant businesses rarely, 
if ever, have been successfully hacked. 
Second, if your business is sucessfully 
hacked, you are not liable for any fines or 
charges. 
! 
Here’s how to make your business PCI DSS 
compliant.
Know the Requirements for 
PCI DSS Compliance 
You need to know what you have 
signed up for and what is required 
for your business to be compliant. If 
you don’t, you won’t know what 
steps you need to take in order to 
secure your business.
There are two 
main ways to make your 
business more secure 
and PCI DSS compliant 
1. Hire a PCI DSS Qualified Security 
Assessor (QSA) 
2. Do-It-Yourself
PCI Compliance is more than 
Transaction Compliance 
Many businesses purchase a PCI DSS 
compliant POS system and think that 
they are compliant. In reality, this kind 
of compliance relates only to credit 
card transactions and not to your 
business environment/network, 
which must also be 
PCI compliant.
Compliance Areas 
A detailed list of all compliance areas 
can be found here. Remember to 
follow the PCI Standard: 
! 
1. Assess 
2. Remediate 
3. Report 
! 
Learn more about PCI standards here.
Take The Necessary PCI 
Compliance Steps
Hiring a PCI DSS QSA 
PCI SSC certified QSA’s are 
organizations who have been 
qualified by the PCI Council to 
assess compliance to PCI DSS 
standards. Hiring a QSA will 
save you the time it would take 
to do the research yourself 
and will also give you peace 
of mind that the job 
was done right.
The big downside to 
hiring a QSA, is cost. 
You have to pay the QSA fees, which are 
generally quite expensive. One quote I 
checked on, charged a base $5,000 fee 
plus $200 for every hour. On top of that, 
you have to pay for the equipment/software 
to fix whatever problems the QSA finds, 
which is also costly. 
Here is a list of PCI certified QSA companies 
Here is a guide about what to look for in a PCI DSS QSA
Do-It-Yourself 
Here is How to do It 
1. Educate Yourself. 
2. Secure your Payment Network. 
3.Use a Security Software that Tests for 
Vulnerabilities. 
4. Fill out and turn in your PCI DSS Self- 
Assessment Questionnaire
Educate Yourself 
Here is the link again for the quick 
reference PCI DSS compliance 
guide. Although it is a bit rough to 
get through, it is only 33 pages 
and is important to read if you 
plan on monitoring PCI DSS 
compliance for yourself.
Secure your 
Payment Network 
There are 3 main 
recommended action steps 
every small business can 
take to make their network 
more secure and 
compliant:
1. Install a Proper Firewall 
A proper firewall protects hackers from stealing information from 
your business. We recommend Mako Networks, which offers a secure 
and PCI DSS compliant payment network, complete with firewall, 
starting at around $80/month. Check out their distributor list to find 
a reseller near you.
2. Have a separate 
network for payment 
services 
Separating your payment network from your other business 
networks means hackers cannot access sensitive card data from 
anywhere in your general business network.
3. Change Usernames and Passwords every 
90 days or so 
Make sure you change default usernames and passwords as soon 
as you can, because they are rarely secure. Then, change 
usernames and passwords every 90 days. Here is a general guide 
to changing your wireless network password.
Use Security Software that 
tests for Vulnerabilities 
There are various software options 
available that test your network and 
payment terminals for breach 
vulnerability and PCI security 
compliance. Check with your payment 
processor first, some offer free PCI 
DSS testing. If you not, we recommend 
Control Scan Inc’s PCI 1-2-3.
Fill Out Your PCI DSS Self- 
Assessment Sheet 
To be PCI compliant, small businesses are 
required to fill out an annual PCI DSS Self- 
Assessment sheet. This sheet is a DYS 
checklist to determine compliance. 
! 
Instructions and the link to complete this 
self-assessment questionnaire can be found 
on PCI’s self assessment forms page.
What to Do if You Suspect 
You Have Been Breached
If you suspect a breach, here 
is what you need to do: 
! 
1. Report the Breach to Your Payment 
Processor/Merchant Bank 
2. Check State Disclosure Regulations and 
Alert Local Law Enforcement 
3. Comply Fully with any PCI DSS Audit. 
A comprehensive guide to determining and dealing with a possible 
breach is available on Visa’s website.
1. Report the Breach 
If you suspect a breach, contact 
your payment processor or 
merchant bank and let them know 
that a possible security breach 
has been detected. They will then 
go over protocol and determine 
what should be done.
2. Check State 
Disclosure Regulations 
Check your state’s regulations to see who 
you are supposed to inform. In most 
cases, you must let customers know 
that there has been a possible 
security breach, usually in writing. 
! 
Generally, you also should alert your 
local law enforcement agency.
3. Comply Fully with any 
PCI DSS Audit 
Your payment processor or their 
bank normally initiates a PCI DSS 
Audit. If you are notified of an 
upcoming audit, gather all of 
your information related to PCI 
Compliance an have it ready for 
the inspectors when they arrive.
CONCLUSION 
The cyber security and PCI DSS compliance status 
of your small business is an important issue. 
If you follow this guide and take the necessary steps, your business 
will be more secure than many other small businesses out there and 
will be prepared should a cyber attack actually take place.
Join The Community: 
www.FitSmallBusiness.com 
Click here to tweet this 
presentation. 
See the full article here

More Related Content

What's hot

PCI Compliance Seminar
PCI Compliance SeminarPCI Compliance Seminar
PCI Compliance Seminar
dlinehan2
 
PCI DSS Slidecast
PCI DSS SlidecastPCI DSS Slidecast
PCI DSS Slidecast
RobertXia
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
Mark Pollard
 
Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_Payments
Steve Abrams
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
wardell henley
 

What's hot (19)

Requirement of PCI-DSS in India.
Requirement of PCI-DSS in India.Requirement of PCI-DSS in India.
Requirement of PCI-DSS in India.
 
PCI Compliance Seminar
PCI Compliance SeminarPCI Compliance Seminar
PCI Compliance Seminar
 
Evolution Pci For Pod1
Evolution Pci For Pod1Evolution Pci For Pod1
Evolution Pci For Pod1
 
PCI DSS Slidecast
PCI DSS SlidecastPCI DSS Slidecast
PCI DSS Slidecast
 
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce MerchantECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
 
MTBiz May-June 2019
MTBiz May-June 2019 MTBiz May-June 2019
MTBiz May-June 2019
 
Requirement of PCI DSS in India.
Requirement of PCI DSS in India.Requirement of PCI DSS in India.
Requirement of PCI DSS in India.
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
 
PCI DSS Certification
PCI DSS CertificationPCI DSS Certification
PCI DSS Certification
 
Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_Payments
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
 
Data Security: A field guide for franchisors
Data Security: A field guide for franchisorsData Security: A field guide for franchisors
Data Security: A field guide for franchisors
 
The Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card DataThe Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card Data
 
How really to prepare for a credit card compromise (PCI) forensics investigat...
How really to prepare for a credit card compromise (PCI) forensics investigat...How really to prepare for a credit card compromise (PCI) forensics investigat...
How really to prepare for a credit card compromise (PCI) forensics investigat...
 
DSS - ITSEC conf - Arcot - Security for eCommerce - Riga Nov2011
DSS - ITSEC conf - Arcot - Security for eCommerce - Riga Nov2011DSS - ITSEC conf - Arcot - Security for eCommerce - Riga Nov2011
DSS - ITSEC conf - Arcot - Security for eCommerce - Riga Nov2011
 
eCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain MediaeCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain Media
 
Verizon rp pci report-2015-en_xg
Verizon rp pci report-2015-en_xgVerizon rp pci report-2015-en_xg
Verizon rp pci report-2015-en_xg
 
idBUSINESS Red Flag Rules For Dentists
idBUSINESS Red Flag Rules For DentistsidBUSINESS Red Flag Rules For Dentists
idBUSINESS Red Flag Rules For Dentists
 
The CPAs Guide to Buying Cyber Insurance
The CPAs Guide to Buying Cyber InsuranceThe CPAs Guide to Buying Cyber Insurance
The CPAs Guide to Buying Cyber Insurance
 

Viewers also liked

Viewers also liked (12)

Presentación wings etwork
Presentación wings etworkPresentación wings etwork
Presentación wings etwork
 
Apresiasi Puisi - Sajak Sajak Kepada M
Apresiasi Puisi - Sajak Sajak Kepada MApresiasi Puisi - Sajak Sajak Kepada M
Apresiasi Puisi - Sajak Sajak Kepada M
 
Qcl 14-v3 [5-s]_[nitie mumbai]_[pramesh anuragi]
Qcl 14-v3 [5-s]_[nitie mumbai]_[pramesh anuragi]Qcl 14-v3 [5-s]_[nitie mumbai]_[pramesh anuragi]
Qcl 14-v3 [5-s]_[nitie mumbai]_[pramesh anuragi]
 
Web 2.0
Web 2.0Web 2.0
Web 2.0
 
Чемодурова О.Л. Воспитание космического мышления.
Чемодурова О.Л. Воспитание космического мышления.Чемодурова О.Л. Воспитание космического мышления.
Чемодурова О.Л. Воспитание космического мышления.
 
Ко дню культуры, гимназия №410 Санкт-Петербурга
Ко дню культуры, гимназия №410 Санкт-ПетербургаКо дню культуры, гимназия №410 Санкт-Петербурга
Ко дню культуры, гимназия №410 Санкт-Петербурга
 
FREE South Africa trend report
FREE South Africa trend reportFREE South Africa trend report
FREE South Africa trend report
 
мир через культуру, гим 406 санкт петербурга
мир через культуру, гим 406 санкт петербургамир через культуру, гим 406 санкт петербурга
мир через культуру, гим 406 санкт петербурга
 
Презентация "Мир через Культуру"
Презентация "Мир через Культуру"Презентация "Мир через Культуру"
Презентация "Мир через Культуру"
 
キャンペーンの対象者を顧客リストから抜き出す -マイクロソフトアクセスで条件抜き出しをする-【データ分析塾ab004】
キャンペーンの対象者を顧客リストから抜き出す -マイクロソフトアクセスで条件抜き出しをする-【データ分析塾ab004】キャンペーンの対象者を顧客リストから抜き出す -マイクロソフトアクセスで条件抜き出しをする-【データ分析塾ab004】
キャンペーンの対象者を顧客リストから抜き出す -マイクロソフトアクセスで条件抜き出しをする-【データ分析塾ab004】
 
человек, будь человечнее, шк 555 санкт петербурга
человек, будь человечнее, шк 555 санкт петербургачеловек, будь человечнее, шк 555 санкт петербурга
человек, будь человечнее, шк 555 санкт петербурга
 
Time museum
Time museumTime museum
Time museum
 

Similar to PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals

Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link business
Mike Shelah
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCI
Kelly Lam
 

Similar to PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals (18)

PCI Compliance Process
PCI Compliance ProcessPCI Compliance Process
PCI Compliance Process
 
PCI Compliance for Payment Security
PCI Compliance for Payment SecurityPCI Compliance for Payment Security
PCI Compliance for Payment Security
 
PCI FAQs and Myths
PCI FAQs and MythsPCI FAQs and Myths
PCI FAQs and Myths
 
PCI FAQs and Myths - BluePay
PCI FAQs and Myths - BluePayPCI FAQs and Myths - BluePay
PCI FAQs and Myths - BluePay
 
Pci compliance
Pci compliancePci compliance
Pci compliance
 
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSSWhat Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
 
Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link business
 
PCI Compliance Myths, Reality and Solutions for Retail
PCI Compliance Myths, Reality and Solutions for RetailPCI Compliance Myths, Reality and Solutions for Retail
PCI Compliance Myths, Reality and Solutions for Retail
 
PCI Compliance Report
PCI Compliance ReportPCI Compliance Report
PCI Compliance Report
 
How to Prepare for a PCI DSS Audit
How to Prepare for a PCI DSS AuditHow to Prepare for a PCI DSS Audit
How to Prepare for a PCI DSS Audit
 
Introduction To SAQ 4 U
Introduction To SAQ 4 UIntroduction To SAQ 4 U
Introduction To SAQ 4 U
 
Tokenization credit card processing
Tokenization credit card processingTokenization credit card processing
Tokenization credit card processing
 
Importance of Data Security in MLM Software
Importance of Data Security in MLM SoftwareImportance of Data Security in MLM Software
Importance of Data Security in MLM Software
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCI
 
Pci ssc quick reference guide
Pci ssc quick reference guidePci ssc quick reference guide
Pci ssc quick reference guide
 
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
 
Verizon 2014 pci compliance report
Verizon 2014 pci compliance reportVerizon 2014 pci compliance report
Verizon 2014 pci compliance report
 
Verizon 2014 PCI Compliance Report
Verizon 2014 PCI Compliance ReportVerizon 2014 PCI Compliance Report
Verizon 2014 PCI Compliance Report
 

More from Fit Small Business

More from Fit Small Business (20)

Sap sales funnel examples
Sap sales funnel examplesSap sales funnel examples
Sap sales funnel examples
 
Xero Multi Currency
Xero Multi CurrencyXero Multi Currency
Xero Multi Currency
 
Who’s the best online legal service
Who’s the best online legal service Who’s the best online legal service
Who’s the best online legal service
 
25 real estate lead generators
25 real estate lead generators 25 real estate lead generators
25 real estate lead generators
 
Salesforce CRM Review
Salesforce CRM ReviewSalesforce CRM Review
Salesforce CRM Review
 
Nimble CRM Review
Nimble CRM ReviewNimble CRM Review
Nimble CRM Review
 
Microsoft Dynamics CRM Review
Microsoft Dynamics CRM ReviewMicrosoft Dynamics CRM Review
Microsoft Dynamics CRM Review
 
Insightly Review
Insightly ReviewInsightly Review
Insightly Review
 
Hatchbuck CRM Reviefw
Hatchbuck CRM ReviefwHatchbuck CRM Reviefw
Hatchbuck CRM Reviefw
 
Best VoIP
Best VoIPBest VoIP
Best VoIP
 
Bitrix24 crm review
Bitrix24 crm reviewBitrix24 crm review
Bitrix24 crm review
 
How To Set Up Insightly CRM
How To Set Up Insightly CRMHow To Set Up Insightly CRM
How To Set Up Insightly CRM
 
How To Get A Loan To Start A Franchise
How To Get A Loan To Start A FranchiseHow To Get A Loan To Start A Franchise
How To Get A Loan To Start A Franchise
 
What Is CRM Software? An Introduction For Small Businesses
What Is CRM Software? An Introduction For Small BusinessesWhat Is CRM Software? An Introduction For Small Businesses
What Is CRM Software? An Introduction For Small Businesses
 
How To Raise Money From Family And Friends The Right Way
How To Raise Money From Family And Friends The Right WayHow To Raise Money From Family And Friends The Right Way
How To Raise Money From Family And Friends The Right Way
 
Insightly vs. Salesforce: How To Choose The Right CRM
Insightly vs. Salesforce: How To Choose The Right CRMInsightly vs. Salesforce: How To Choose The Right CRM
Insightly vs. Salesforce: How To Choose The Right CRM
 
How To Advertise Using Bing Ads & FREE $50 Coupon
How To Advertise Using Bing Ads & FREE $50 CouponHow To Advertise Using Bing Ads & FREE $50 Coupon
How To Advertise Using Bing Ads & FREE $50 Coupon
 
25 Hotel Marketing Ideas
25 Hotel Marketing Ideas 25 Hotel Marketing Ideas
25 Hotel Marketing Ideas
 
How to Market a Dental Practice
How to Market a Dental PracticeHow to Market a Dental Practice
How to Market a Dental Practice
 
25 Restaurant Marketing Resources The Pros Use
25 Restaurant Marketing Resources The Pros Use25 Restaurant Marketing Resources The Pros Use
25 Restaurant Marketing Resources The Pros Use
 

Recently uploaded

call Now 9811711561 Cash Payment乂 Call Girls in Dwarka
call Now 9811711561 Cash Payment乂 Call Girls in Dwarkacall Now 9811711561 Cash Payment乂 Call Girls in Dwarka
call Now 9811711561 Cash Payment乂 Call Girls in Dwarka
vikas rana
 
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
ZurliaSoop
 
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdfEnabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
Smartinfologiks
 

Recently uploaded (20)

Dehradun Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Dehradun Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceDehradun Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Dehradun Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Sangareddy Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Sangareddy Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceSangareddy Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Sangareddy Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
JAIPUR CALL GIRLS SERVICE REAL HOT SEXY 👯 CALL GIRLS IN JAIPUR BOOK YOUR DREA...
JAIPUR CALL GIRLS SERVICE REAL HOT SEXY 👯 CALL GIRLS IN JAIPUR BOOK YOUR DREA...JAIPUR CALL GIRLS SERVICE REAL HOT SEXY 👯 CALL GIRLS IN JAIPUR BOOK YOUR DREA...
JAIPUR CALL GIRLS SERVICE REAL HOT SEXY 👯 CALL GIRLS IN JAIPUR BOOK YOUR DREA...
 
Dàni Velvet Personal Brand Exploration (1).pptx
Dàni Velvet Personal Brand Exploration (1).pptxDàni Velvet Personal Brand Exploration (1).pptx
Dàni Velvet Personal Brand Exploration (1).pptx
 
call Now 9811711561 Cash Payment乂 Call Girls in Dwarka
call Now 9811711561 Cash Payment乂 Call Girls in Dwarkacall Now 9811711561 Cash Payment乂 Call Girls in Dwarka
call Now 9811711561 Cash Payment乂 Call Girls in Dwarka
 
Connaught Place, Delhi Call girls :8448380779 Model Escorts | 100% verified
Connaught Place, Delhi Call girls :8448380779 Model Escorts | 100% verifiedConnaught Place, Delhi Call girls :8448380779 Model Escorts | 100% verified
Connaught Place, Delhi Call girls :8448380779 Model Escorts | 100% verified
 
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verifiedSector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
 
Sohna Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Sohna Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceSohna Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Sohna Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
Dive into Angel Investing s 2024 0502.pptx
Dive into Angel Investing s 2024 0502.pptxDive into Angel Investing s 2024 0502.pptx
Dive into Angel Investing s 2024 0502.pptx
 
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
Jual Obat Aborsi Bojonegoro ( Asli No.1 ) 085657271886 Obat Penggugur Kandung...
 
Tirupati Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Tirupati Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceTirupati Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Tirupati Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Shareholders Agreement Template for Compulsorily Convertible Debt Funding- St...
Shareholders Agreement Template for Compulsorily Convertible Debt Funding- St...Shareholders Agreement Template for Compulsorily Convertible Debt Funding- St...
Shareholders Agreement Template for Compulsorily Convertible Debt Funding- St...
 
Bangalore Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Bangalore Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceBangalore Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Bangalore Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdfEnabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
Enabling Business Users to Interpret Data Through Self-Service Analytics (2).pdf
 
How to structure your pitch - B4i template
How to structure your pitch - B4i templateHow to structure your pitch - B4i template
How to structure your pitch - B4i template
 
Lucknow Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Lucknow Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceLucknow Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Lucknow Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
EV Electric Vehicle Startup Pitch Deck- StartupSprouts.in
EV Electric Vehicle Startup Pitch Deck- StartupSprouts.inEV Electric Vehicle Startup Pitch Deck- StartupSprouts.in
EV Electric Vehicle Startup Pitch Deck- StartupSprouts.in
 
Hyderabad Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Hyderabad Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceHyderabad Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Hyderabad Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Karol Bagh, Delhi Call girls :8448380779 Model Escorts | 100% verified
Karol Bagh, Delhi Call girls :8448380779 Model Escorts | 100% verifiedKarol Bagh, Delhi Call girls :8448380779 Model Escorts | 100% verified
Karol Bagh, Delhi Call girls :8448380779 Model Escorts | 100% verified
 
NEON LIGHT CITY pitch deck for the new PC game
NEON LIGHT CITY pitch deck for the new PC gameNEON LIGHT CITY pitch deck for the new PC game
NEON LIGHT CITY pitch deck for the new PC game
 

PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals

  • 1. PCI Compliance: Protect Your Business From Credit Card criminals
  • 2. Why is cyber security important For Your Small Business
  • 3. Cybercriminals are now targeting smaller businesses In great numbers where security is weaker. 60% of small businesses that suffer a data breach are out of business 6 months later. A recent survey by Fortinet found nearly two-thirds of consumers held merchants responsible for data breaches.
  • 5. To help understand these issues we spoke with Simon Gamble, Small-business cyber security expert and president of Mako Networks’ U.S. branch. He began with three comments:
  • 6. 1) Any small business that accepts credit cards is a potential target for a cyber security breach.
  • 7. 2) Small businesses are held to the same level of credit card security standards (discussed later in this presentation) as large businesses such as Target or Home Depot.
  • 8. 3) Any small business that suffers a cyber security breach and is found to be non-compliant to credit card security standards, is fully liable for charges related to the breach.
  • 9. You Could Be a Targert If you are a small business who accepts credit cards, then you are vulnerable to a cyber attack. Cyber attackers are targeting small businesses more and more, because their networks are easier to hack and they are not as regularly checked for compliance to credit card security standards.
  • 10. PCI Compliance (Credit Card Security Standards)
  • 11. If you accept credit cards, then you have agreed to abide by the PCI DSS (Payment Card Industry Data Security Standard) The PCI DSS is a set of requirements designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment.
  • 12. Security Breaches, Liability, and Other Consequences If your small business is suspected of a security breach, PCI DSS inspectors come in and try to determine if there is a breach and how it occurred. This process in and of itself can be crippling for a small business, shutting down operations for a minimum of several days and costing between $8,000 – $20,000 in inspection fees.
  • 13. If your business is found to be non-compilant, you are held liable for more charges: 1. Data Security Fine – Up to $500,000 fine per security breach incident. 2. Non-Compliance Fines – Up to $50,000 per day for non-compliance with published standards.
  • 14. If your business is found to be non-compilant, you are held liable for more charges: 3. Card Replacement Fees – $3- $10 per card x total number of cards compromised. 4. Refund Fees – Potentially held liable for all fraud losses incurred from compromised account numbers.
  • 15. How To Be PCI DSS Compliant and Protect your Business from Cyber Threats
  • 16. The key is to make sure your business is PCI DSS compliant. Why? First, PCI compliant businesses rarely, if ever, have been successfully hacked. Second, if your business is sucessfully hacked, you are not liable for any fines or charges. ! Here’s how to make your business PCI DSS compliant.
  • 17. Know the Requirements for PCI DSS Compliance You need to know what you have signed up for and what is required for your business to be compliant. If you don’t, you won’t know what steps you need to take in order to secure your business.
  • 18. There are two main ways to make your business more secure and PCI DSS compliant 1. Hire a PCI DSS Qualified Security Assessor (QSA) 2. Do-It-Yourself
  • 19. PCI Compliance is more than Transaction Compliance Many businesses purchase a PCI DSS compliant POS system and think that they are compliant. In reality, this kind of compliance relates only to credit card transactions and not to your business environment/network, which must also be PCI compliant.
  • 20. Compliance Areas A detailed list of all compliance areas can be found here. Remember to follow the PCI Standard: ! 1. Assess 2. Remediate 3. Report ! Learn more about PCI standards here.
  • 21. Take The Necessary PCI Compliance Steps
  • 22. Hiring a PCI DSS QSA PCI SSC certified QSA’s are organizations who have been qualified by the PCI Council to assess compliance to PCI DSS standards. Hiring a QSA will save you the time it would take to do the research yourself and will also give you peace of mind that the job was done right.
  • 23. The big downside to hiring a QSA, is cost. You have to pay the QSA fees, which are generally quite expensive. One quote I checked on, charged a base $5,000 fee plus $200 for every hour. On top of that, you have to pay for the equipment/software to fix whatever problems the QSA finds, which is also costly. Here is a list of PCI certified QSA companies Here is a guide about what to look for in a PCI DSS QSA
  • 24. Do-It-Yourself Here is How to do It 1. Educate Yourself. 2. Secure your Payment Network. 3.Use a Security Software that Tests for Vulnerabilities. 4. Fill out and turn in your PCI DSS Self- Assessment Questionnaire
  • 25. Educate Yourself Here is the link again for the quick reference PCI DSS compliance guide. Although it is a bit rough to get through, it is only 33 pages and is important to read if you plan on monitoring PCI DSS compliance for yourself.
  • 26. Secure your Payment Network There are 3 main recommended action steps every small business can take to make their network more secure and compliant:
  • 27. 1. Install a Proper Firewall A proper firewall protects hackers from stealing information from your business. We recommend Mako Networks, which offers a secure and PCI DSS compliant payment network, complete with firewall, starting at around $80/month. Check out their distributor list to find a reseller near you.
  • 28. 2. Have a separate network for payment services Separating your payment network from your other business networks means hackers cannot access sensitive card data from anywhere in your general business network.
  • 29. 3. Change Usernames and Passwords every 90 days or so Make sure you change default usernames and passwords as soon as you can, because they are rarely secure. Then, change usernames and passwords every 90 days. Here is a general guide to changing your wireless network password.
  • 30. Use Security Software that tests for Vulnerabilities There are various software options available that test your network and payment terminals for breach vulnerability and PCI security compliance. Check with your payment processor first, some offer free PCI DSS testing. If you not, we recommend Control Scan Inc’s PCI 1-2-3.
  • 31. Fill Out Your PCI DSS Self- Assessment Sheet To be PCI compliant, small businesses are required to fill out an annual PCI DSS Self- Assessment sheet. This sheet is a DYS checklist to determine compliance. ! Instructions and the link to complete this self-assessment questionnaire can be found on PCI’s self assessment forms page.
  • 32. What to Do if You Suspect You Have Been Breached
  • 33. If you suspect a breach, here is what you need to do: ! 1. Report the Breach to Your Payment Processor/Merchant Bank 2. Check State Disclosure Regulations and Alert Local Law Enforcement 3. Comply Fully with any PCI DSS Audit. A comprehensive guide to determining and dealing with a possible breach is available on Visa’s website.
  • 34. 1. Report the Breach If you suspect a breach, contact your payment processor or merchant bank and let them know that a possible security breach has been detected. They will then go over protocol and determine what should be done.
  • 35. 2. Check State Disclosure Regulations Check your state’s regulations to see who you are supposed to inform. In most cases, you must let customers know that there has been a possible security breach, usually in writing. ! Generally, you also should alert your local law enforcement agency.
  • 36. 3. Comply Fully with any PCI DSS Audit Your payment processor or their bank normally initiates a PCI DSS Audit. If you are notified of an upcoming audit, gather all of your information related to PCI Compliance an have it ready for the inspectors when they arrive.
  • 37. CONCLUSION The cyber security and PCI DSS compliance status of your small business is an important issue. If you follow this guide and take the necessary steps, your business will be more secure than many other small businesses out there and will be prepared should a cyber attack actually take place.
  • 38. Join The Community: www.FitSmallBusiness.com Click here to tweet this presentation. See the full article here