# Safeguarding payments against cybercrime
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-07-21
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Protect Your Business with Cyber Security &amp; PCI DSS
Meta Description: Learn how allpay Limited can help safeguard your business payments through Cyber Security solutions like Cyber Essentials Plus and PCI DSS compliance. Stay
URL: https://financedigest.com/safeguarding-payments-against-cybercrimehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/earth-globemyweifrd-1736843672313-compressed.jpg)

**Ross Macmillan, head of research and intelligence at** [**allpay Limited**](http://www.allpay.net/) **, the UK’s leading payment specialist**

Cyber-attacks are worryingly prevalent at the moment, with large, high-profile organisations like the [NHS falling prey to hackers](http://blogs.lse.ac.uk/politicsandpolicy/wannacry-the-ransomware-attack-on-the-nhs-and-what-we-can-learn-from-it/). Businesses are under threat, so cyber security has become a significant issue – with safeguarding payments of paramount importance.

However,some organisations may not know their systems have been compromised until consultants are called in. Such organisations face being specifically targeted by fraudsters, with the primary risk being in accessing personal data and payment processes. Fraudsters are believed to penetrate phone systems first, if only to gauge potential for access. Therefore, it’s [important for businesses](https://www.financedigest.com/the-importance-of-intuition-in-business.html "The Importance of Intuition in Business ") to implement the necessary cyber-protection controls now – before it’s too late.

[**Cyber Security**](https://www.financedigest.com/the-new-cyber-agency-helping-tech-startups-stay-secure.html "The New Cyber Agency Helping Tech Startups Stay Secure")

Organisations should ensure their chosen suppliers meet high standards for cyber security through government-supported and industry-backed schemes like [Cyber Essential Plus](https://www.cyberaware.gov.uk/cyberessentials/) to ensure they are sufficiently covered.

Here at [allpay Limited](http://www.allpay.net/) we recently joined a small number of payment companies in being accredited to this scheme, which verifies that organisations have the appropriate security protocols in place to stave off the most prevalent forms of attack. The scheme discourages suppliers from being irresponsible about cyber security, whilst continuing to protect customer data.

A [landmark report on Common Cyber Attacks issued by GCHQ detailed for the first time the common attacks used by cyber criminals](https://www.financedigest.com/australia-drops-landmark-criminal-cartel-case-against-citi-deutsche.html "Australia drops landmark criminal cartel case against Citi, Deutsche"). The report used real case studies to [explain the nature](https://www.financedigest.com/explainer-whats-on-the-agenda-at-the-u-n-s-cop15-nature-summit.html "Explainer-What’s on the agenda at the U.N.’s COP15 nature summit?") of the risk and how it can be prevented. Around 80% of cyber-attacks could be prevented if businesses put simple security controls in place. The Cyber Essentials scheme shows how to put these controls in place.

**PCI DSS Compliance**

Safeguarding payments is paramount in the face of [cyber threats](https://www.financedigest.com/how-are-rising-cyber-threats-boosting-demand-for-public-safety-software.html "How are Rising Cyber Threats Boosting Demand for Public Safety Software") and being fully PCI DSS-compliant is a crucial step towards a secure payments environment and reassures buyers that suppliers are taking the appropriate measures to protect data.

PCI DSS, or the Payment Card Industry Data Security Standard, is a [set of security](https://www.financedigest.com/u-s-russian-officials-set-for-security-talks-on-january-10-u-s-official.html "U.S., Russian officials set for security talks on January 10 – U.S. official") standards that any organisation which processes, stores or transmits debit and credit card information must adhere to. By becoming PCI DSS-compliant, organisations can preserve customer trust, ensure compliance, lower costs and, importantly, reduce risk.

The UK Cards Association stipulates that, [should a business lose card data and not be PCI DSS-compliant, it faces non-compliance fines and the operational costs associated with replacing accounts, as well as liability for any fraud losses.](mailto:http://www.theukcardsassociation.org.uk/security/Non_compliance_PCIDSS.asp)

Latest revisions of the PCI DSS standards have tightened security requirements, and technology can help to mitigate risks for organisations.

A good example is where organisations are taking payments via their call centres, with the potential for security [breaches when handling customers’ card data](https://www.financedigest.com/amazons-twitch-blames-configuration-error-for-data-breach.html "Amazon’s Twitch blames configuration error for data breach"). Recent [innovations such as cloud-based call masking services](https://www.financedigest.com/the-elder-care-services-market-to-witness-innovation-oriented-sustenance.html "The Elder Care Services Market to witness innovation-oriented sustenance") can help to create a secure environment when operatives are handling card data when processing a payment. By rerouting the call through a secure cloud-based environment, it can completely remove desktops, IT and telephony systems, agents and call recordings from PCI DSS compliance scope, enabling customers to type their card numbers securely into the telephone keypad, rather than speaking them aloud to an agent which can be potentially be recorded and/or stored.

[Great Places Housing Group](http://www.greatplaces.org.uk/) recently procured allpay’s DTMF tone masking solution in order to reduce the risk of fraud and data breaches. The group, which owns and manages more than 18,000 homes across the North West and Yorkshire region, is one of the [largest developing housing associations in the North](https://www.financedigest.com/north-america-to-emerge-as-largest-market-for-softball-equipment-through-2026.html "North America to Emerge as Largest Market for Softball Equipment Through 2026") of England, so protecting its database and customer information was fundamental.

Becoming PCI DSS-compliant independently, and achieving ongoing compliance, can be an onerous and complex process for businesses, incurring high fees and using valuable staff time that could be [invested more effectively](https://www.financedigest.com/enabling-effective-esg-investment.html "Enabling effective ESG investment") elsewhere.

Outsourcing PCI compliance to a [Level 1 PCI DSS compliant payment service provider can make a material](https://www.financedigest.com/electronic-board-level-underfill-and-encapsulation-material-market-to-expand-at-a-cagr-of-5-5-by-during-the-forecast-period-of-2020-2030.html "Electronic Board Level Underfill And Encapsulation Material Market to expand at a CAGR of 5.5% by during the forecast period of 2020-2030") difference in administration and cost. For example, outsourcing can see organisations only having to complete a shorter version of a mandatory Self-Assessment Questionnaire (SAQ) to their merchant acquirer. Where SAQ A is the least onerous with circa 10 requirements; SAQ D is the most onerous with in excess of 250 requirements, which would also include quarterly scans of their card payment environment. If the solution is outsourced the organisation only requires the completion of SAQ A.

At a [time where protection of data](https://www.financedigest.com/data-time-for-some-levelling-up.html "Data – Time for some “Levelling Up”") and security is all too prevalent in the news, it’s important to ensure systems are protected – and for this to be done in a cost effective and efficient manner. This needn’t be costly or onerous – with much of the risk, compliance and cost outsourced to third-party providers.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

