Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Businesses Don’t Have to Walk it Alone
Articles

Why Businesses Don’t Have to Walk it Alone

ISBuzz TeamBy ISBuzz TeamFebruary 15, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Why Businesses Don’t Have to Walk it Alone
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Payment Card Industry Data Security Standard (PCI DSS) is intended to help organisations ensure the safe handling of sensitive payment card data. But it can also present significant (and potentially expensive) regulatory hurdles. Matthew Bryars, CEO of Aeriandi explains what PCI DSS means to businesses and the various ways in which compliance can be achieved, without breaking the bank in the process.

PCI DSS was originally conceived by the world’s major payment card brands (Visa, Mastercard, American Express) as a way to standardise security practices across all organisations that take, process and store sensitive payment card data. It has come a long way since its first appearance in late 2004 and the latest version – PCI DSS 3.0 – sets out 12 very clear requirements that all relevant organisations must adhere to in order to be deemed PCI compliant. Perhaps unsurprisingly, PCI DSS is often met with mixed reactions. Many see it as an unnecessary bureaucratic exercise or an annual check box task. However, these organisations are missing the point entirely. PCI DSS is not about bureaucracy, it is about the safety of highly sensitive customer data. Irrespective of PCI DSS, if organisations aren’t doing their utmost to keep this data safe, they need to take a good hard look at themselves. Whilst heavy fines can be levied against organisations who suffer data breaches and are found to be non-compliant, the monetary loss usually pales into insignificance compared to the reputational damage sustained as the result of a high profile breach.  As such, PCI DSS compliance should be considered a by-product, rather than a primary driver, of securing customer data within an organisation.

PCI DSS covers all forms of payment collection, processing and storage. For many businesses, the telephone remains one of the primary channels for taking customer payments, usually via dedicated customer contact centres. But they can be noisy and chaotic places, where data security often slips down the list of priorities. So how can PCI compliance be achieved (and importantly, maintained) in this kind of environment?

Choosing the path that’s right for your business

The good news is that there are a number of different paths to compliance, offering something for nearly every scenario. Some organisations choose to receive, process and store sensitive card data in-house. This can be a good option for those that have already made significant internal security infrastructure investments. However, for those that haven’t already got the necessary infrastructure in place, dealing with it in-house can be a costly exercise, carrying a great deal of ongoing (and unnecessary) risk to the organisation. An alternative way to achieve PCI compliance is to utilise specialist technology to ensure the sensitive data never enters the contact centre environment in the first place. If it’s never there, it can’t be breached or stolen, meaning any risk to the security of the data is immediately minimised.

Taking the contact centre out of  scope for PCI-DSS

In this scenario, when a customer comes to make a phone payment, rather than divulge the card details directly to a contact centre agent, they are routed through an external secure payment platform. The customer then enters their payment details via the telephone keypad to complete the transaction. The contact centre agent can see the transaction taking place and can still engage with the customer if required, but they have no visibility of the sensitive card data at any stage. This further reduces overall risk to data by removing the agents themselves from the security equation. Furthermore, when there’s no payment data on site, the contact centre’s obligations with regard to PCI-DSS are significantly reduced, leaving just one of the 12 requirements for PCI DSS in scope; Requirement 12 – ‘Maintain a policy that addresses information security’.

Achieving and maintaining PCI compliance can be painful at times, but organisations should focus less on the pain points, and more on the bigger picture, which is keeping customer data (and company reputation) safe. For an industry so reliant on phone payments, securing this channel should be a top priority for all collections agencies. Furthermore, there are a host of third party experts out there who can all but remove the stress of PCI compliance, and boost the quality of collections services offered to customers. So what are you waiting for?

[su_box title=”About Matthew Bryars” style=”noise” box_color=”#336588″]Matthew BryarsMatthew Bryars, CEO at Aeriandi, Shortly after completing a Masters degree in physics from University College London, Matthew was one of the first to see the potential for highly secure, cloud-based business services – and promptly co-founded Aeriandi. Matthew quickly applied his problem solving skills to the business world and has been responsible for building the company from a start-up to a well renowned business – running services for some of the world’s largest banks and contact centres.

Although the business has grown substantially, Matthew still takes a hands-on approach and remains actively involved in the development process, getting most fulfilment from delivery of high quality, relevant solutions based on the company’s hosted multi-channel platform.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}