80 likes | 203 Vues
As organized crime targets Level 4 merchants, recent statistics reveal alarming trends in payment security compromises. With 84% of breaches stemming from PC-based POS systems—primarily in the restaurant sector—merchants must remain vigilant. Most compromises result from third-party errors, emphasizing the need for compliance with PCI DSS standards. Merchants are responsible for losses and may face forensics audits at their own expense. It's crucial to implement robust security measures, including firewalls, remote access controls, and password management, to safeguard your business.
E N D
Mercury Payment Systems Dan Osby Director, Technical Services Technical Lead, Incident Response dosby@mercurypay.com
Recent Statistics • Organized crime has learned to hack • Level 4 merchants are new target • 84% were from PC based POS systems • Approximately 60% were within the restaurant environment
Compromise Statistics Cases by Card Acceptance About 5 out of every 6 cases is a traditional Brick and Mortar environment. Card Present Merchants are not aware of these risks!
Compromise Statistics Merchant Error vs. 3rd Party Error Majority of the compromises were caused by a fault in the service provided by a 3rd party to a merchant. POS developers, integrators, IT firms are not following PCI DSS and leaving merchants at risk!
What if a Security Loss Occurs? • If a loss is suspected, a forensics audit is done at merchant’s cost • Forensics report can expose reseller deficiencies • If a loss did occur, fines will be assessed • The merchant is responsible but may be able to successfully sue other service providers
In addition to the upgrade, what is needed? • Other Actions: • Internet connected sites should have a properly configured firewall protecting them from unsolicited external connections • Remote access software should be turned off when not in use • All passwords should be complex and not shared among sites or users • Updated anti-virus software and OS patches • Always be aware of changes to your POS environment!
Disclosure Data Security Disclosure - Notify your merchants - Completely customizable - Send by certified mail or in person to ensure delivery
Mercury Payment Systems Questions?