Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Top Vulnerabilities Call Centres Must Manage for PCI Compliance
News & Analysis

Top Vulnerabilities Call Centres Must Manage for PCI Compliance

ISBuzz TeamBy ISBuzz TeamJanuary 12, 2015Updated:January 12, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
pci
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A major concern for any organisation that routinely processes customer card transactions is the risk of fraud or cybercrime. With PCI DSS 3.0 compliance top of mind, call centres go to great lengths to protect online card payments. Experienced at delivering vulnerability testing at call centre sites over the years, I’ve listed the top vulnerabilities to look out for – some old, some relatively new – as a lapse in managing these will leave you vulnerable and therefore pose a serious barrier to PCI compliance.

1. Gaps in Physical Security

A common feature of call centres is high staff turnover making it almost impossible for staff to keep track. To counter this, call centres use a variety of methods including infrared barriers, photo ID cards, and security staff to control access to the building. Even so, it can be relatively easy for determined individuals to trick their way past security.

Free Cyber Security Training! Join the revolution, today!

Once inside, there may be ample opportunity to come across invoices, credit card transaction slips, or Post-it note password reminders left lying around. Simple measures include appointing someone to stay with the visiting group, questioning hot desk visitors, and encrypting devices and network access controls. Also, a casual observer shouldn’t be able to see full credit card information either in emails or on a screen.

2. Plausible Phishing Scams

Constant handling of customer cardholder data makes call centres a regular target for spammers. A classic tactic is to send an email pretending to be from inside the company. A particular favourite and effective phishing attack is the “planned outage.” A spoof email invites the recipient to click a link and log on for further details. Our experience shows the success rate of this simple technique can be as high as 75%. A spear phishing attacks are even more convincing.

To minimise damage from these scams a company should implement tight email filtering controls, use SMTP authorisation to block external emails that pretend to come from inside the organisation, and equally educate staff about the dangers of phishing and tell-tale signs such as links to external websites.

3. Unauthorised USB Devices

Staff often bring their own USB devices in the office from home. Sometimes these devices unwittingly introduce viruses such as Gameover Zeus and Conficker into the network. USB keys can also be used to copy files and take them from the building without authorisation.

Having a combination of good, up-to-date antivirus software and some form of USB device control technology will mitigate these risks, along with some form of USB device control technology.

4. Unauthorised Access Points

Often call centres sensibly insist on a ‘no wireless’ policy. But it doesn’t necessarily stop staff from setting up their own wireless access point. If they only have basic protection in place, outsiders can use these rogue points as a way to hack into the company network. This is where you need to deploy rogue access point protection which scans for rogue access points and alerts IT if one is discovered. Equally manual checks for unauthorised access points is also advisable.

5. Unsecured Bluetooth and DECT Headsets/Phones

Call centre staff may bring their own Bluetooth and DECT headsets or digital mobile radio (DMR) devices into work. These are insecure, and if the Bluetooth is left switched ‘on’ then the device will constantly be broadcasting without anyone realising. Nowadays Software Defined Radio (SDR), capable of eavesdropping on Bluetooth and other devices, only costs around £100. An outsider sniffing for Bluetooth and DECT calls can collect all the cardholder information needed to commit fraud. The remedy is to impose policies that strictly prohibit unauthorised use of Bluetooth or DECT headsets and phones. The policy should be supported by instructing security staff to make regular physical sweeps of the offices to look for unauthorised devices.

6. Insufficient Staff Background Checks

Call centres make attractive targets for criminals. Working in a call centre gives them ready access to credit card and other valuable customer information. Minimise this risk by undertaking thorough background checks when recruiting and note that the PCI SSC also recommend practices such as masking primary account numbers, USB device control and training staff to be alert to suspicious behaviour.

7. Telephone-Based Social Engineering

Anyone can call a call centre pretending to be a customer and attempt to extract valuable personal information about a target individual. Rigorous training in the correct procedures to follow and how to handle a variety of challenging call scenarios is the best way to counter this. It should also be policy that the customer only receive limited personal information over the telephone.

8. IT Administrative Errors

Finally, call centres are no different from any other workplace when it comes to common IT errors. Common IT administration lapses include infrequent software patch management, incorrect server permissions, and ordinary users being given administrator privileges for their desktops as a short-cut to fixing problems. All of these issues can be solved using IT best practices such as regular patch application, regular permissions checks, log management and so on.

To sum up, most of the vulnerabilities covered by PCI DSS 3.0 will already be familiar. Strong encryption and a programme of regular checks can help detect and eliminate configuration or rogue systems issues – both old and new.

By Toby Scott-Jackson, Senior Security Consultant, SureCloud

toby scott-jacksonBio: Toby has accumulated a vast amount of experience in his 15 years in the security industry, and is now viewed as an industry authority by both peers and clients alike. Toby began his career as a successful consultant with assignments at Sybase, SBC Warburg, and many other well respected commercial organizations. UK and US Government work has exposed Toby to information security on a global level, which has resulted in him developing a unique set of skills.

Toby’s specialist interest is Internet infrastructure, and complex attacks and network weaknesses originating from outside the organizations perimeter.He works closely with a number of ISPs to mitigate serious threats such as distributed denial of service, DNS poisoning and routing/tunneling attacks.

In 2000, Toby founded AIL, a boutique penetration test company servicing the security needs of a growing number of City based companies. After a successful trade sale of AIL in 2005, Toby co-founded SureCloud in March 2006. Toby is responsible for security research and development, and heads up the SureCloud consulting division.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}