• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter
  • YouTube
Big Ideas for Small Business logo

Barbara Weltman

Big Ideas for Small Business, Inc.

Whitepaper download

Subscribe and download our eBook, "150+ Tax Deductions for Small Business A to Z."

This field is hidden when viewing the form
Get the:

  • Home
  • About Us
  • Big Ideas For Your Business
    • Idea Of The Day ®
    • SMB Legal
    • SMB Taxes
    • SMB Financial
    • Small Business
    • Newsletter Archive
  • Services
  • Books
  • Blog
  • Multimedia
    • Videos
    • Radio Shows/Podcasts
  • Be a Guest Blogger

Payment Card Security: How Do You Measure Up?

September 19, 2017 / By Barbara Weltman

Payment Card SecurityEquifax recently experienced a data breach that impacted an estimated 143 million people. If it can happen to Equifax, it can happen to any business. If you accept credit cards for payment by customers and clients, are you protected from data breaches? According to the Verizon 2017 Payment Security Report (you have to give your name, email, and company in order to download it), businesses that experienced breaches weren’t fully compliant with suggested security protocols (explained later).

Why payment security matters to you

According to the Verizon report, trust is what matters, and 66% of customers say they’d be unlikely to do business with an organization that experienced a data breach exposing financial and sensitive information.

Perhaps even worse than the loss of trust, which can diminish business revenues, is the financial cost of addressing a data breach. This includes informing customers whose information may have been hacked and usually providing them with assistance (such as credit monitoring). If you fail to follow legal requirements on notice, you can be subject to severe governmental penalties. The National Conference on State Legislatives has a state-by-state list on security breach notification laws. At present there is no federal law addressing required notification by merchants for cardholder data breaches, but there’s a bill now pending.

Compliance protocols

All organizations, including payment service providers, merchant processors, online merchants, and face-to-face merchants, that store, process, or transmit payment card data are mandated by VISA, MasterCard, Discover, American Express, and other payment brands to comply with PCI DSS Standards. These are standards created by the PCI Security Standards Council, which was founded in 2006 by American Express, Discover, JCB International, MasterCard, and Visa. Of the payment card data breaches that Verizon investigated between 2010 and 2016, not a single company was fully PCI DSS compliant.

There are 12 key requirements (some are technical while others are basic business practices):

Goals PCI DSS Requirements
Build and maintain a secure network and systems 1.      Install and maintain a firewall configuration to protect cardholder data

2.      Do not use vendor-supplied defaults for system passwords and other security parameters

Protect cardholder data 3.      Protect stored cardholder data

4.      Encrypt transmission of cardholder data across open, public networks

Maintain a vulnerability management program 5.      Protect all systems against malware and regularly update anti-virus software or programs

6.      Develop and maintain secure systems and applications

Implement strong access control measures 7.      Restrict access to cardholder data by business need to know

8.      Identify and authenticate access to system components

9.      Restrict physical access to cardholder data

Regularly monitor and test networks 10.  Track and monitor all access to network resources and cardholder data

11.  Regularly test security system and processes

Maintain an information security policy 12.  Maintain a policy that addresses information security for all personnel.

Source: PCI Security Council

How to become compliant

If you are concerned about payment card security for your business, review your current security measures.

  • Do a self-assessment of your cardholder data using PCI’s Self-Assessment Questionnaire.
  • Talk with your IT person. Hopefully, the person is versed in PCI DSS. If not, they should be able to refer you to someone who is. As an aside, my IT person told me that it’s easier for small businesses to be compliant because the tech stuff is easy to handle and the non-tech stuff (e.g., limiting personnel who can access computers) is better controlled in small companies).
  • Work with your credit card processor. Your bank or other credit card processor is your active partner on PSI DSS compliance, and should be an excellent resource to assist you in becoming and maintaining compliance.
  • Work with a national PCI DSS expert. Once this expert certifies that you’re compliant, the costs of dealing with a data breach will be far less than if you were noncompliant.

Conclusion

Carrying cyber liability coverage may not be a substitute for being PSI DSS compliant. In light of one federal case involving P.F. Chang, it seems that this coverage only extends for data breaches where the policy explicitly references it; otherwise it’s excluded. Take the initiative and learn about PSI DSS compliance with this helpful guide.

 

This article was prepared with the assistance of Jim Higgins, president of the payment consulting firm of Jim Higgins & Associates, Inc.

Tags compliance protocols credit card Equifax payment card security payment security PCI DSS Standards

Primary Sidebar

Categories

  • General Business (506)
  • Guest Blog (113)
  • Homepage (22)
  • Small Business (1,002)
  • SMB Financial (328)
  • SMB Legal (66)
  • SMB Taxes (326)

Barbara’s Recent Posts

  • 10 Ideas for Coping with Cash Flow Challenges June 26, 2025
  • 5 Insurance Traps to Avoid June 24, 2025
  • Creating a Feng Shui Office Layout for Your Business June 20, 2025
  • Scaling Your Business by Optimizing Social Media Marketing June 19, 2025
  • The Timeless Value of Business Cards in a Digital World June 18, 2025
  • What Does the Latest IRS Data Book Tell Us? June 17, 2025
  • Business Advice from Famous Dads June 12, 2025
  • How Important Is Higher Education for Small Business Owners June 11, 2025
  • Business Planning in a Period of Uncertainty June 10, 2025
  • 9 Smart Financial Decisions for Business Owners in Retirement June 6, 2025
  • Preview of Tax Changes this Year: Actions to Take Now June 5, 2025
  • Becoming Penniless: What Does this Mean for Your Business? June 3, 2025
Awarded Top 100 Small Business Blog medal (link will open in a new window or tab)
Marquis Who's Who 2023 Badge
Top Small Business Blogs (Link will open in a new window or tab.)
8 Financial blogs small business Owners Need to Read. Invoice home.  (link will open in a new window or tab)
Best Small Business Blog, Expertido.org
Top 50 Small Business Blogs 2018
Best Small Business Blogs
BizHumm Top 100 Business Blog Award to Barbara Weltman
FitsSmallBusiness.com: Award for Best Small Business Blog 2017 (link will open in a new window or tab)
FitsSmallBusiness.com: Award for Best Small Business Blog 2016 (link will open in a new window or tab)

Footer

Big Ideas for Small Business logo

Small business ideas, business tax news and small business consulting from Barbara Weltman to provide business owners with the information they need to succeed. Visit our small business blog, Idea of The Day®, small business books and articles on small business taxes, small business finance and small business legal advice.

Contact Us

[email protected]

(772) 492-9593

gacor maxwin situs slot thailand terpercaya situs slot gacor situs gacor akun pro thailand slot bandar togel terpercaya

Latest Tweets

bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
June 29

Authors call on publishers to limit their use of AI | TechCrunch https://tcrn.ch/4l42ZEO #authors #publishers #AI

Reply on Twitter 1939443882917331435 Retweet on Twitter 1939443882917331435 Like on Twitter 1939443882917331435 2 Twitter 1939443882917331435
bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
June 29

Personalising the Benefits Experience: Why Employees Need More Than Just Information - HR Daily Advisor https://bit.ly/44kqgLD #smallbusiness #workplace #benefits

Reply on Twitter 1939397042272456958 Retweet on Twitter 1939397042272456958 Like on Twitter 1939397042272456958 1 Twitter 1939397042272456958
bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
June 29

10 Ideas for Coping with Cash Flow Challenges https://bit.ly/3ttGBgf #smallbusiness #cashflow #finance

Reply on Twitter 1939354941362999307 Retweet on Twitter 1939354941362999307 Like on Twitter 1939354941362999307 Twitter 1939354941362999307
Load More

Copyright © 2008–2025 Big Ideas for Small Business, Inc  |  Designed by Hudson Fusion

  • Privacy Policy
  • Sitemap