Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How to Retain Customer’s Trust : The Importance of Compliance
Articles

How to Retain Customer’s Trust : The Importance of Compliance

ISBuzz TeamBy ISBuzz TeamSeptember 11, 2015Updated:July 8, 20248 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
The Importance of Compliance
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Consumer trust in a business has never been so critical. Take, for example, the recent hack on Ashley Madison which saw customer data stolen from its 37 million users, leaving patrons details exposed and the businesses reputation in tatters. This news demonstrates the need for customers to feel confident that their financial and sensitive details are safe when parting with them over the phone and online. The bottom line is, if the public does not trust your brand, they aren’t going to give you their custom.

Coupled by the fact that upcoming changes to the European General Data Protection Regulation will provide uniformity of data protection laws across all 27 EU states, businesses need to act now to educate customers on the security surrounding remote payments. They also need to review their PCI compliance in order to protect consumer data and avoid fines of up to $100,000 per month[1] under the new EU Data Protection Law set to arrive in 2017[2]. Those that fail to do so could cause irreversible damage to brand reputation and result in loss of customer trust, halting the growth of the entire business. As you can imagine this is the absolute worst case scenario and can certainly be avoided. Looking at the industry today, it appears some businesses still have a long way to go to gain this trust.

In fact, according to a recent survey of 2,000 UK consumers by Elitetele.com, ninety-seven per cent don’t know what happens to sensitive information they give to call centre operatives over the phone. When asked to describe what happens, over a third (36 per cent) stated they had no idea and almost two thirds (61 per cent) incorrectly identified what information operatives have access to and how it is stored.

Consumers also have significant insecurities about how financial information is handled, despite technology existing to guard against criminals online. Forty per cent stated they are not confident their payment details are secure from being hacked by cyber criminals, and 30 per cent are scared operatives can secretly record their information elsewhere. Which is just another reason for customer’s to not want to hand over sensitive financial information.

But where do these insecurities derive from? The simple answer is a lack of compliancy. With a widespread adoption of compliance put in place, it would provide a more transparent and trustworthy relationship between brands and customers.

More so, the scale, frequency and evolution of security threats mean that consumer confidence in the ability of businesses to store their data securely has taken a huge hit. However, this does not need to be the case. By seeking specialist advice and guidance, organisations can ensure PCI compliance and thus the security of customer’s information.

So how can businesses do their bit to make customers more receptive, while building long lasting and trusting relationships?

While there is no one size fits all solution, the following steps will help any business to ensure they are PCI compliant ahead of these changes, an in turn create a safe and transparent environment for customers: 

  1. PCI DSS Compliance Call Recording

PCI compliance is mandatory for any business taking payments over the internet or on the phone to minimise the risk of fraud – otherwise it’s the customer’s word against the businesses, or vice versa. In fact, the Financial Services Authority (FSA) requires all financial companies to record and store their telephone conversations. However, it is a violation to store any sensitive authentication data including card validation codes and values after authorisation, even if encrypted. Should companies be found to violate this, penalties and fines could be enough to close a business down.

To safeguard against this, businesses must have in place a fully compliant PCI call recording system that satisfies all criteria outlined in the PCI DSS, as well as regulations from the Financial Services authority. By doing so, agents don’t hear or see any sensitive information provided by the customer and the information remains missing from stored or archived call recordings. The solution increases trust between the business and the customer, as well as improving call handling and customer experience overall by combining an intuitive IVR (Interactive Voice Response) system which provides an automatic call journey for card payments, freeing up agent time for other tasks, thus increasing business efficiency.

  1. Interactive Voice Response Payment System

Research has found that 75% of consumers prefer talking to a customer service representative over the phone rather than online[3]. This makes perfect sense; for customers a quick phone call eliminates waiting time and solves the problem there and then. However, with this comes the need for increased customer support and, with more agents involved in the payment process, the worry of non-compliance.

Using a state of the art IVR payment system enables customers to make payments without the need for an agent, or the need to store credit card details, making the transaction 100 per cent PCI compliant. It also provides a competitive advantage with the ability to take 100s of payments an hour, 24/7, making the business more accessible to existing or potential customers with lower overall costs to the business. This again frees up call centre staff to focus on other servicing issues, eliminating on-hold times and reducing staff errors.

  1. PCI Compliant Hosting

When making payments over the phone, understandably safety and trust is a top priority to consumers. This means a data breech can be catastrophic to a business’ reputation. Imagine calling a company, handing over your details, and having those details stolen. You would feel it was the businesses duty to help. However, with no record of the conversation, you could be left to pick up the pieces.

In this way, when becoming PCI Compliant, businesses must protect not only credit card data, but also sensitive customer data in general. A recent example of this is cyber criminals targeting Apple Pay call centre operatives in an attempt to commit fraud[4].

To combat this, a Unified Threat Management security platform can protect any distributed network with the fastest security technology on the market, including next generation firewalling, IPS, Data Loss Prevention, app control and vulnerability management, ensuring the business isn’t a target for cyber criminals. Customers can then spend confidently and the business can keep its reputation intact.

  1. PCI – Data Governance

A Data Governance solution allows organisations to be able to keep pace with data, manage access entitlements efficiently and effectively, audit access to every file and email event, identify and involve data owners and find and classify sensitive and business critical data. This ensures Data Governance policies are in place and adhered to.

In the case of PCI, it is important to protect not only databases, but file shares as well. Customers can then rest easy that their details are secure, and out of reach of curious members of staff. When file shares contain any of the PCI-designated sensitive information, organisations need to audit access to these shared networked resources as part of their PCI compliance efforts.

Understandably, there is no one size fits all solution. Compliance levels depend on the size and nature of a business, and knowing where to start can prove a daunting task due to ever changing rules and regulations. What is clear is businesses need to seek expert advice on deploying the right solution ahead of the new EU legislation, helping them become and remain PCI compliant. By doing so, they can have the peace of mind that they will not be handed a fine which will halt future business growth, not to mention the irreversible damage it can do to a brand’s reputation.[su_box title=”About Elitetele.com” style=”noise” box_color=”#336588″]Elitetele.comAt Elitetele.com, our mission is to help businesses grow and improve performance through the powerful provision of bespoke technology and communication solutions. Our vision is to be the communications supplier and employer of choice.As one of the fastest growing privately owned technology businesses in the UK, we will continue to accelerate our growth by bringing together the best technical minds in the marketplace with unrivalled and innovative unified communications solutions and internet services for businesses.We are the only unified communications provider to be featured four times in the Sunday Times Tech Track 100, which recognises the fastest growing technology companies in the UK. Elitetele.com is aSwyx Gold Partner, and the first unified communications provider to be presented with Swyx’s International Partner of the Year Award 2013.We employ over 100 staff members across six offices, including a European arm in Madrid. Customers include, Merlin Entertainments Group, P&O Ferries, American Airlines, Yo! Sushi and one third of the Premier League football clubs.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}