SlideShare a Scribd company logo
PCI FAQS AND MYTHS
Presented by BluePay
When your business — no matter its size — began accepting credit card payments, it
immediately became a potential target for data thieves.
Much more is at risk than your customers’ sensitive information, however. If you aren’t employing the best industry
practices to protect that data, your business could face fines, lose the ability to accept credit and debit card payments,
and jeopardize its credibility.
To help protect consumers’ credit card information from data thieves, the Payment Card Industry Security Standards
Council created data security standards that businesses must follow to be in compliance.
The cost of noncompliance can be staggering. The bank that processes your payments could be fined $5,000 to
$100,000 per month by the credit card companies — amounts likely to be passed along to you — until the business
is following the requirements. Your bank also could raise the fees it charges to process your business’s transactions,
or stop handling them altogether. (Check your account agreement with the bank.) Your business also might have to
cover the cost if the bank has to issue new cards to customers whose data has been compromised — and who could
become former customers if there has been a data breach. Finally, your business also may be liable for losses due to
fraud and other financial losses.
THE IMPORTANCE OF PCI COMPLIANCE
PCI FAQ’S AND MYTHS	 BLUEPAY | 2
TABLE OF CONTENTS
FAQ 1: 	 What are the PCI compliance levels and how are they determined?	 4
FAQ 2: 	My business has multiple locations; is each location required to validate PCI compliance?	 5
FAQ 3: 	 Am I PCI compliant if I have an SSL certificate?	 6
FAQ 4: 	 What is a vulnerability scan?	 7
FAQ 5: 	 Are debit card transactions in scope for PCI?	 8
MYTH 1: 	 I’m a small merchant who takes only a handful of cards, so I don’t need PCI.	 9
MYTH 2:	 PCI applies only to e-commerce companies.	 10
MYTH 3:	 I can wait until my business grows.	 11
MYTH 4:	 Outsourcing card processing makes us compliant.	 12
MYTH 5: 	 PCI compliance is an IT project.	 13
PCI FAQ’S AND MYTHS	 BLUEPAY | 3
FAQ 1:
WHAT ARE THE PCI COMPLIANCE LEVELS
AND HOW ARE THEY DETERMINED?
There are four levels of PCI compliance as determined by Visa and MasterCard. These levels are
based on the transaction volume (including credit, debit and prepaid) over a 12-month period.
Merchants that have been affected by a security breach that resulted in compromised card data
may be escalated to the next level.
Merchant Level Description
• Any merchant processing more than $6 million Visa and/or MasterCard transactions per year.
• Any merchant processing $1 million to $6 million Visa and/or MasterCard transactions per year.
• Any merchant processing $20,000 to $1 million Visa and/or MasterCard e-commerce transactions
per year.
• Any merchant processing less than $20,000 Visa and/or MasterCard e-commerce transactions per
year, and all other merchants processing up to $1 million Visa and/or MasterCard transactions per year.
PCI FAQ’S AND MYTHS	 BLUEPAY | 4
FAQ 2:
MY BUSINESS HAS MULTIPLE LOCATIONS; IS EACH
LOCATION REQUIRED TO VALIDATE PCI COMPLIANCE?
Best practices would be to certify each merchant ID (MID) number individually. Some
businesses choose to certify by multiple MID numbers under one entity. However, if multiple
locations are certified under one entity and a compromise were to occur, all MID numbers
are subject to forensic investigation (versus only the identified MID).
PCI FAQ’S AND MYTHS	 BLUEPAY | 5
FAQ 3:
AM I PCI COMPLIANT IF I HAVE AN SSL CERTIFICATE?
No. An SSL certificate is just one piece of the puzzle to becoming PCI compliant. You
must establish strong encryption of the cardholder’s data during transmission over open,
public networks. In addition, you need to validate that the website operators are a legitimate,
legal organization.
PCI FAQ’S AND MYTHS	 BLUEPAY | 6
A vulnerability scan is an automated tool that conducts a nonintrusive scan of a merchant or
service provider’s system to remotely review networks and Web applications based on the
external-facing Internet protocol (IP) addresses provided by the merchant or service provider.
The scan pinpoints vulnerabilities in operating systems, services and devices that could be
used by hackers to target the company’s private network. Approved Scanning Vendors (ASVs),
such as ControlScan, do not require the merchant or service provider to install any software on
their systems, and no denial-of-service attacks will be performed.
FAQ 4:
WHAT IS A VULNERABILITY SCAN?
PCI FAQ’S AND MYTHS	 BLUEPAY | 7
Any debit, credit and prepaid cards branded with one of the five card association/brand
logos that participate in the PCI SSC — American Express, Discover, JCB, MasterCard and
Visa International — are within scope.
FAQ 5:
ARE DEBIT CARD TRANSACTIONS IN SCOPE FOR PCI?
PCI FAQ’S AND MYTHS	 BLUEPAY | 8
Merchants are divided into four categories based on the number of card transactions handled in
a 12-month period, but all must meet PCI requirements regardless of their size-level designation.
Smaller merchants do face fewer validation requirements, however. For a Level 4 merchant
(processing fewer than 20,000 e-commerce transactions or up to 1 million transactions overall),
an annual self-assessment questionnaire is recommended and a network scan by an approved
vendor is to be performed quarterly if applicable, but the requirements of the bank handling the
merchant’s transactions still must be met for the business to be in compliance.
MYTH 1:
I’M A SMALL MERCHANT WHO TAKES ONLY A HANDFUL
OF CARDS, SO I DON’T NEED PCI
PCI FAQ’S AND MYTHS	 BLUEPAY | 9
MYTH 2:
PCI APPLIES ONLY TO E-COMMERCE COMPANIES
Whether your business handles one transaction or hundreds of credit/debit card purchases
per day, it is subject to the PCI Data Security Standards regardless of whether the transactions
are electronic, in person or by phone. The requirements apply to your business if any customer
ever pays you directly using a debit or credit card.
PCI FAQ’S AND MYTHS	 BLUEPAY | 10
MYTH 3:
I CAN WAIT UNTIL MY BUSINESS GROWS
As previously noted, a business of any size that processes a credit or debit card transaction
is subject to PCI compliance. If you think your business is too small to attract a hacker,
consider this: About 60 percent of cyber attacks in 2015 targeted small and medium-sized
businesses, which in general have smaller or less sophisticated IT security staffs and
resources than big corporations.
Overall, 42 percent of small businesses surveyed by the National Small Business Association
reported experiencing a cyber attack. Among types of attacks, the theft of credit card
information was second behind a general computer hack. The firms whose business bank
accounts were hit suffered an average of more than $32,000 in losses, and 42 percent of small
businesses said it took them more than three days to resolve a cyber attack issue.
PCI FAQ’S AND MYTHS	 BLUEPAY | 11
Relying on an outside vendor does not ensure that your business is PCI compliant.
Outsourcing could reduce your risk and make it easier to prove that your business
is compliant, but much like with paying your taxes to the IRS, relying on an external
“expert” does not relieve your accountability.
MYTH 4:
OUTSOURCING CARD PROCESSING MAKES US COMPLIANT
PCI FAQ’S AND MYTHS	 BLUEPAY | 12
Any temptation to shift the entire burden of PCI compliance onto the IT staff could prove costly.
While IT can set up, run and test programs, compliance is an ongoing task. Rules change
and regular assessments are needed, and with so much at stake from financial and reputation
standpoints, your entire organization is affected.
MYTH 5:
PCI COMPLIANCE IS AN IT PROJECT
PCI FAQ’S AND MYTHS	 BLUEPAY | 13
BluePay, Naperville, IL
(Note: BluePay has multiple offices nationwide and in Canada; corporate headquarters is in Naperville)
www.bluepay.com
866-495-0423 (sales, toll free)
866-739-8324 (U.S. merchant support, toll free)
BluePay is a leading provider of technology-enabled payment processing for merchants and suppliers of any size in
the United States and Canada. Through physical POS, online, and mobile interfaces, as well as CRM and ERP software
integrations, BluePay processes business-to-consumer and business-to-business payments while providing real-time
settlement, reporting, and reconciliation, along with robust security features such as tokenization and point-to-point
encryption. BluePay is headquartered in Naperville, Illinois, with offices in Chicago, Maryland, New York and Toronto.
THIS PRESENTATION IS BROUGHT TO YOU BY BLUEPAY

More Related Content

What's hot

Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSteve Abrams
 
MTBiz May-June 2019
MTBiz May-June 2019 MTBiz May-June 2019
MTBiz May-June 2019
Mutual Trust Bank Ltd.
 
When does a company need to be PCI compliant
When does a company need to be PCI compliantWhen does a company need to be PCI compliant
When does a company need to be PCI compliantDivya Kothari
 
Everything You Need to Know About Taking Plastic
Everything You Need to Know About Taking PlasticEverything You Need to Know About Taking Plastic
Everything You Need to Know About Taking Plastic
Business.com
 
Introduction to B2B Electronic Payments
Introduction to B2B Electronic PaymentsIntroduction to B2B Electronic Payments
Introduction to B2B Electronic Payments
Griffin McGahey
 
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial OrganizationsLeveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
Ricardo Ponce
 
Business Identity Theft
Business Identity TheftBusiness Identity Theft
Business Identity Theft
- Mark - Fullbright
 
Economic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds DissectedEconomic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds Dissectedamiable_indian
 
Seamless payment integration with shopify (1)
Seamless payment integration with shopify (1)Seamless payment integration with shopify (1)
Seamless payment integration with shopify (1)
ThinkTanker Technosoft PVT LTD
 
Factors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway ProviderFactors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway Provider
Alaina Carter
 
Report on Online Banking for Women
Report on Online Banking for WomenReport on Online Banking for Women
Report on Online Banking for Women
Rahul Shah
 
Data Security: A field guide for franchisors
Data Security: A field guide for franchisorsData Security: A field guide for franchisors
Data Security: A field guide for franchisors
Grant Thornton LLP
 
Btl mastercard
Btl mastercardBtl mastercard
Btl mastercard
btlcoin token
 
07 factors to consider while choosing an ecommerce payment gateway
07 factors to consider while choosing an ecommerce payment gateway07 factors to consider while choosing an ecommerce payment gateway
07 factors to consider while choosing an ecommerce payment gateway
SnehaDas60
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCIKelly Lam
 
Artificial Intelligence in Banking
Artificial Intelligence in BankingArtificial Intelligence in Banking
Artificial Intelligence in Banking
Khawar Nehal khawar.nehal@atrc.net.pk
 
Understanding the Card Fraud Lifecycle : A Guide For Private Label Issuers
Understanding the Card Fraud Lifecycle :  A Guide For Private Label IssuersUnderstanding the Card Fraud Lifecycle :  A Guide For Private Label Issuers
Understanding the Card Fraud Lifecycle : A Guide For Private Label Issuers
Christopher Uriarte
 

What's hot (20)

Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_Payments
 
MTBiz May-June 2019
MTBiz May-June 2019 MTBiz May-June 2019
MTBiz May-June 2019
 
When does a company need to be PCI compliant
When does a company need to be PCI compliantWhen does a company need to be PCI compliant
When does a company need to be PCI compliant
 
Everything You Need to Know About Taking Plastic
Everything You Need to Know About Taking PlasticEverything You Need to Know About Taking Plastic
Everything You Need to Know About Taking Plastic
 
MensWearhouse_3728
MensWearhouse_3728MensWearhouse_3728
MensWearhouse_3728
 
Introduction to B2B Electronic Payments
Introduction to B2B Electronic PaymentsIntroduction to B2B Electronic Payments
Introduction to B2B Electronic Payments
 
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial OrganizationsLeveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
 
09Feb2012ISOAgent[1]
09Feb2012ISOAgent[1]09Feb2012ISOAgent[1]
09Feb2012ISOAgent[1]
 
Business Identity Theft
Business Identity TheftBusiness Identity Theft
Business Identity Theft
 
Economic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds DissectedEconomic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds Dissected
 
Seamless payment integration with shopify (1)
Seamless payment integration with shopify (1)Seamless payment integration with shopify (1)
Seamless payment integration with shopify (1)
 
Factors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway ProviderFactors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway Provider
 
Report on Online Banking for Women
Report on Online Banking for WomenReport on Online Banking for Women
Report on Online Banking for Women
 
Data Security: A field guide for franchisors
Data Security: A field guide for franchisorsData Security: A field guide for franchisors
Data Security: A field guide for franchisors
 
Btl mastercard
Btl mastercardBtl mastercard
Btl mastercard
 
Requirement of PCI DSS in India.
Requirement of PCI DSS in India.Requirement of PCI DSS in India.
Requirement of PCI DSS in India.
 
07 factors to consider while choosing an ecommerce payment gateway
07 factors to consider while choosing an ecommerce payment gateway07 factors to consider while choosing an ecommerce payment gateway
07 factors to consider while choosing an ecommerce payment gateway
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCI
 
Artificial Intelligence in Banking
Artificial Intelligence in BankingArtificial Intelligence in Banking
Artificial Intelligence in Banking
 
Understanding the Card Fraud Lifecycle : A Guide For Private Label Issuers
Understanding the Card Fraud Lifecycle :  A Guide For Private Label IssuersUnderstanding the Card Fraud Lifecycle :  A Guide For Private Label Issuers
Understanding the Card Fraud Lifecycle : A Guide For Private Label Issuers
 

Viewers also liked

White paper everything your business needs to know about chargebacks
White paper everything your business needs to know about chargebacksWhite paper everything your business needs to know about chargebacks
White paper everything your business needs to know about chargebacks
PerformanceCardService
 
A Guide to Employee Recognition
A Guide to Employee RecognitionA Guide to Employee Recognition
A Guide to Employee Recognition
RPGCardServices
 
JWT: The Future 100 (December 2014)
JWT: The Future 100 (December 2014)JWT: The Future 100 (December 2014)
JWT: The Future 100 (December 2014)
J. Walter Thompson Intelligence
 
10 Ways to Make Your Lead Generation Website Convert On the First Visit
10 Ways to Make Your Lead Generation Website Convert On the First Visit10 Ways to Make Your Lead Generation Website Convert On the First Visit
10 Ways to Make Your Lead Generation Website Convert On the First Visit
StraightNorthIM
 
First Year of Business Survival Guide
First Year of Business Survival GuideFirst Year of Business Survival Guide
First Year of Business Survival Guide
expresstradecapital
 
Digital in 2017 Global Overview
Digital in 2017 Global OverviewDigital in 2017 Global Overview
Digital in 2017 Global Overview
We Are Social Singapore
 

Viewers also liked (6)

White paper everything your business needs to know about chargebacks
White paper everything your business needs to know about chargebacksWhite paper everything your business needs to know about chargebacks
White paper everything your business needs to know about chargebacks
 
A Guide to Employee Recognition
A Guide to Employee RecognitionA Guide to Employee Recognition
A Guide to Employee Recognition
 
JWT: The Future 100 (December 2014)
JWT: The Future 100 (December 2014)JWT: The Future 100 (December 2014)
JWT: The Future 100 (December 2014)
 
10 Ways to Make Your Lead Generation Website Convert On the First Visit
10 Ways to Make Your Lead Generation Website Convert On the First Visit10 Ways to Make Your Lead Generation Website Convert On the First Visit
10 Ways to Make Your Lead Generation Website Convert On the First Visit
 
First Year of Business Survival Guide
First Year of Business Survival GuideFirst Year of Business Survival Guide
First Year of Business Survival Guide
 
Digital in 2017 Global Overview
Digital in 2017 Global OverviewDigital in 2017 Global Overview
Digital in 2017 Global Overview
 

Similar to PCI FAQs and Myths - BluePay

PCI Compliance Process
PCI Compliance ProcessPCI Compliance Process
PCI Compliance Process
BluePayProcessing
 
Pci compliance
Pci compliancePci compliance
Pci compliance
pcihghg23
 
PCI Compliance for Payment Security
PCI Compliance for Payment SecurityPCI Compliance for Payment Security
PCI Compliance for Payment Security
PaymentAsia
 
PCI_Presentation_OASIS
PCI_Presentation_OASISPCI_Presentation_OASIS
PCI_Presentation_OASISDermot Clarke
 
How Credit Card Processing Works
How Credit Card Processing WorksHow Credit Card Processing Works
How Credit Card Processing Works
Business.com
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1wardell henley
 
Merchant Services Audit 03 2011
Merchant Services Audit   03 2011Merchant Services Audit   03 2011
Merchant Services Audit 03 2011
carolta555
 
Evolution Pci For Pod1
Evolution Pci For Pod1Evolution Pci For Pod1
Evolution Pci For Pod1
Amanda Squires@Pod1
 
PCI compliance
PCI compliancePCI compliance
PCI compliance
UnitedThinkers
 
Reduce PCI Scope - Maximise Conversion - Whitepaper
Reduce PCI Scope - Maximise Conversion - WhitepaperReduce PCI Scope - Maximise Conversion - Whitepaper
Reduce PCI Scope - Maximise Conversion - WhitepaperShaun O'keeffe
 
Introduction To SAQ 4 U
Introduction To SAQ 4 UIntroduction To SAQ 4 U
Introduction To SAQ 4 U
RAlcala65
 
CSI-globalVCard-Whitepaper-Whats-holding-your-business-back
CSI-globalVCard-Whitepaper-Whats-holding-your-business-backCSI-globalVCard-Whitepaper-Whats-holding-your-business-back
CSI-globalVCard-Whitepaper-Whats-holding-your-business-backDavid Disque
 
How fraud and chargeback prevention works
How fraud and chargeback prevention worksHow fraud and chargeback prevention works
How fraud and chargeback prevention works
Ikajo International
 
Symbiotic Consulting Group LLC - PCI Compliance Overview
Symbiotic Consulting Group LLC - PCI Compliance OverviewSymbiotic Consulting Group LLC - PCI Compliance Overview
Symbiotic Consulting Group LLC - PCI Compliance OverviewRosy Kaur
 
Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link businessMike Shelah
 
PCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should carePCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should care
Sean D. Goodwin
 
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSSWhat Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
London School of Cyber Security
 
Adventures in PCI Wonderland
Adventures in PCI WonderlandAdventures in PCI Wonderland
Adventures in PCI Wonderland
Michele Chubirka
 
How to setup credit card merchant account?
How to setup credit card merchant account?How to setup credit card merchant account?
How to setup credit card merchant account?
itio Innovex Pvt Ltv
 
Top-KYC-AML-Providers-for-startups-and-small-business.pdf
Top-KYC-AML-Providers-for-startups-and-small-business.pdfTop-KYC-AML-Providers-for-startups-and-small-business.pdf
Top-KYC-AML-Providers-for-startups-and-small-business.pdf
KYCAMLGuide
 

Similar to PCI FAQs and Myths - BluePay (20)

PCI Compliance Process
PCI Compliance ProcessPCI Compliance Process
PCI Compliance Process
 
Pci compliance
Pci compliancePci compliance
Pci compliance
 
PCI Compliance for Payment Security
PCI Compliance for Payment SecurityPCI Compliance for Payment Security
PCI Compliance for Payment Security
 
PCI_Presentation_OASIS
PCI_Presentation_OASISPCI_Presentation_OASIS
PCI_Presentation_OASIS
 
How Credit Card Processing Works
How Credit Card Processing WorksHow Credit Card Processing Works
How Credit Card Processing Works
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
 
Merchant Services Audit 03 2011
Merchant Services Audit   03 2011Merchant Services Audit   03 2011
Merchant Services Audit 03 2011
 
Evolution Pci For Pod1
Evolution Pci For Pod1Evolution Pci For Pod1
Evolution Pci For Pod1
 
PCI compliance
PCI compliancePCI compliance
PCI compliance
 
Reduce PCI Scope - Maximise Conversion - Whitepaper
Reduce PCI Scope - Maximise Conversion - WhitepaperReduce PCI Scope - Maximise Conversion - Whitepaper
Reduce PCI Scope - Maximise Conversion - Whitepaper
 
Introduction To SAQ 4 U
Introduction To SAQ 4 UIntroduction To SAQ 4 U
Introduction To SAQ 4 U
 
CSI-globalVCard-Whitepaper-Whats-holding-your-business-back
CSI-globalVCard-Whitepaper-Whats-holding-your-business-backCSI-globalVCard-Whitepaper-Whats-holding-your-business-back
CSI-globalVCard-Whitepaper-Whats-holding-your-business-back
 
How fraud and chargeback prevention works
How fraud and chargeback prevention worksHow fraud and chargeback prevention works
How fraud and chargeback prevention works
 
Symbiotic Consulting Group LLC - PCI Compliance Overview
Symbiotic Consulting Group LLC - PCI Compliance OverviewSymbiotic Consulting Group LLC - PCI Compliance Overview
Symbiotic Consulting Group LLC - PCI Compliance Overview
 
Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link business
 
PCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should carePCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should care
 
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSSWhat Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
 
Adventures in PCI Wonderland
Adventures in PCI WonderlandAdventures in PCI Wonderland
Adventures in PCI Wonderland
 
How to setup credit card merchant account?
How to setup credit card merchant account?How to setup credit card merchant account?
How to setup credit card merchant account?
 
Top-KYC-AML-Providers-for-startups-and-small-business.pdf
Top-KYC-AML-Providers-for-startups-and-small-business.pdfTop-KYC-AML-Providers-for-startups-and-small-business.pdf
Top-KYC-AML-Providers-for-startups-and-small-business.pdf
 

Recently uploaded

April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
NathanBaughman3
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
Operational Excellence Consulting
 
BeMetals Presentation_May_22_2024 .pdf
BeMetals Presentation_May_22_2024   .pdfBeMetals Presentation_May_22_2024   .pdf
BeMetals Presentation_May_22_2024 .pdf
DerekIwanaka1
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
Ben Wann
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
my Pandit
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Jos Voskuil
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback Analysis
Safe PaaS
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
seri bangash
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
Naaraayani Minerals Pvt.Ltd
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
usawebmarket
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
BBPMedia1
 
Filing Your Delaware Franchise Tax A Detailed Guide
Filing Your Delaware Franchise Tax A Detailed GuideFiling Your Delaware Franchise Tax A Detailed Guide
Filing Your Delaware Franchise Tax A Detailed Guide
YourLegal Accounting
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
awaisafdar
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
fakeloginn69
 

Recently uploaded (20)

April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
 
BeMetals Presentation_May_22_2024 .pdf
BeMetals Presentation_May_22_2024   .pdfBeMetals Presentation_May_22_2024   .pdf
BeMetals Presentation_May_22_2024 .pdf
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
 
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdfDigital Transformation in PLM - WHAT and HOW - for distribution.pdf
Digital Transformation in PLM - WHAT and HOW - for distribution.pdf
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback Analysis
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
Role of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in MiningRole of Remote Sensing and Monitoring in Mining
Role of Remote Sensing and Monitoring in Mining
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 
Filing Your Delaware Franchise Tax A Detailed Guide
Filing Your Delaware Franchise Tax A Detailed GuideFiling Your Delaware Franchise Tax A Detailed Guide
Filing Your Delaware Franchise Tax A Detailed Guide
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptxCADAVER AS OUR FIRST TEACHER anatomt in your.pptx
CADAVER AS OUR FIRST TEACHER anatomt in your.pptx
 

PCI FAQs and Myths - BluePay

  • 1. PCI FAQS AND MYTHS Presented by BluePay
  • 2. When your business — no matter its size — began accepting credit card payments, it immediately became a potential target for data thieves. Much more is at risk than your customers’ sensitive information, however. If you aren’t employing the best industry practices to protect that data, your business could face fines, lose the ability to accept credit and debit card payments, and jeopardize its credibility. To help protect consumers’ credit card information from data thieves, the Payment Card Industry Security Standards Council created data security standards that businesses must follow to be in compliance. The cost of noncompliance can be staggering. The bank that processes your payments could be fined $5,000 to $100,000 per month by the credit card companies — amounts likely to be passed along to you — until the business is following the requirements. Your bank also could raise the fees it charges to process your business’s transactions, or stop handling them altogether. (Check your account agreement with the bank.) Your business also might have to cover the cost if the bank has to issue new cards to customers whose data has been compromised — and who could become former customers if there has been a data breach. Finally, your business also may be liable for losses due to fraud and other financial losses. THE IMPORTANCE OF PCI COMPLIANCE PCI FAQ’S AND MYTHS BLUEPAY | 2
  • 3. TABLE OF CONTENTS FAQ 1: What are the PCI compliance levels and how are they determined? 4 FAQ 2: My business has multiple locations; is each location required to validate PCI compliance? 5 FAQ 3: Am I PCI compliant if I have an SSL certificate? 6 FAQ 4: What is a vulnerability scan? 7 FAQ 5: Are debit card transactions in scope for PCI? 8 MYTH 1: I’m a small merchant who takes only a handful of cards, so I don’t need PCI. 9 MYTH 2: PCI applies only to e-commerce companies. 10 MYTH 3: I can wait until my business grows. 11 MYTH 4: Outsourcing card processing makes us compliant. 12 MYTH 5: PCI compliance is an IT project. 13 PCI FAQ’S AND MYTHS BLUEPAY | 3
  • 4. FAQ 1: WHAT ARE THE PCI COMPLIANCE LEVELS AND HOW ARE THEY DETERMINED? There are four levels of PCI compliance as determined by Visa and MasterCard. These levels are based on the transaction volume (including credit, debit and prepaid) over a 12-month period. Merchants that have been affected by a security breach that resulted in compromised card data may be escalated to the next level. Merchant Level Description • Any merchant processing more than $6 million Visa and/or MasterCard transactions per year. • Any merchant processing $1 million to $6 million Visa and/or MasterCard transactions per year. • Any merchant processing $20,000 to $1 million Visa and/or MasterCard e-commerce transactions per year. • Any merchant processing less than $20,000 Visa and/or MasterCard e-commerce transactions per year, and all other merchants processing up to $1 million Visa and/or MasterCard transactions per year. PCI FAQ’S AND MYTHS BLUEPAY | 4
  • 5. FAQ 2: MY BUSINESS HAS MULTIPLE LOCATIONS; IS EACH LOCATION REQUIRED TO VALIDATE PCI COMPLIANCE? Best practices would be to certify each merchant ID (MID) number individually. Some businesses choose to certify by multiple MID numbers under one entity. However, if multiple locations are certified under one entity and a compromise were to occur, all MID numbers are subject to forensic investigation (versus only the identified MID). PCI FAQ’S AND MYTHS BLUEPAY | 5
  • 6. FAQ 3: AM I PCI COMPLIANT IF I HAVE AN SSL CERTIFICATE? No. An SSL certificate is just one piece of the puzzle to becoming PCI compliant. You must establish strong encryption of the cardholder’s data during transmission over open, public networks. In addition, you need to validate that the website operators are a legitimate, legal organization. PCI FAQ’S AND MYTHS BLUEPAY | 6
  • 7. A vulnerability scan is an automated tool that conducts a nonintrusive scan of a merchant or service provider’s system to remotely review networks and Web applications based on the external-facing Internet protocol (IP) addresses provided by the merchant or service provider. The scan pinpoints vulnerabilities in operating systems, services and devices that could be used by hackers to target the company’s private network. Approved Scanning Vendors (ASVs), such as ControlScan, do not require the merchant or service provider to install any software on their systems, and no denial-of-service attacks will be performed. FAQ 4: WHAT IS A VULNERABILITY SCAN? PCI FAQ’S AND MYTHS BLUEPAY | 7
  • 8. Any debit, credit and prepaid cards branded with one of the five card association/brand logos that participate in the PCI SSC — American Express, Discover, JCB, MasterCard and Visa International — are within scope. FAQ 5: ARE DEBIT CARD TRANSACTIONS IN SCOPE FOR PCI? PCI FAQ’S AND MYTHS BLUEPAY | 8
  • 9. Merchants are divided into four categories based on the number of card transactions handled in a 12-month period, but all must meet PCI requirements regardless of their size-level designation. Smaller merchants do face fewer validation requirements, however. For a Level 4 merchant (processing fewer than 20,000 e-commerce transactions or up to 1 million transactions overall), an annual self-assessment questionnaire is recommended and a network scan by an approved vendor is to be performed quarterly if applicable, but the requirements of the bank handling the merchant’s transactions still must be met for the business to be in compliance. MYTH 1: I’M A SMALL MERCHANT WHO TAKES ONLY A HANDFUL OF CARDS, SO I DON’T NEED PCI PCI FAQ’S AND MYTHS BLUEPAY | 9
  • 10. MYTH 2: PCI APPLIES ONLY TO E-COMMERCE COMPANIES Whether your business handles one transaction or hundreds of credit/debit card purchases per day, it is subject to the PCI Data Security Standards regardless of whether the transactions are electronic, in person or by phone. The requirements apply to your business if any customer ever pays you directly using a debit or credit card. PCI FAQ’S AND MYTHS BLUEPAY | 10
  • 11. MYTH 3: I CAN WAIT UNTIL MY BUSINESS GROWS As previously noted, a business of any size that processes a credit or debit card transaction is subject to PCI compliance. If you think your business is too small to attract a hacker, consider this: About 60 percent of cyber attacks in 2015 targeted small and medium-sized businesses, which in general have smaller or less sophisticated IT security staffs and resources than big corporations. Overall, 42 percent of small businesses surveyed by the National Small Business Association reported experiencing a cyber attack. Among types of attacks, the theft of credit card information was second behind a general computer hack. The firms whose business bank accounts were hit suffered an average of more than $32,000 in losses, and 42 percent of small businesses said it took them more than three days to resolve a cyber attack issue. PCI FAQ’S AND MYTHS BLUEPAY | 11
  • 12. Relying on an outside vendor does not ensure that your business is PCI compliant. Outsourcing could reduce your risk and make it easier to prove that your business is compliant, but much like with paying your taxes to the IRS, relying on an external “expert” does not relieve your accountability. MYTH 4: OUTSOURCING CARD PROCESSING MAKES US COMPLIANT PCI FAQ’S AND MYTHS BLUEPAY | 12
  • 13. Any temptation to shift the entire burden of PCI compliance onto the IT staff could prove costly. While IT can set up, run and test programs, compliance is an ongoing task. Rules change and regular assessments are needed, and with so much at stake from financial and reputation standpoints, your entire organization is affected. MYTH 5: PCI COMPLIANCE IS AN IT PROJECT PCI FAQ’S AND MYTHS BLUEPAY | 13
  • 14. BluePay, Naperville, IL (Note: BluePay has multiple offices nationwide and in Canada; corporate headquarters is in Naperville) www.bluepay.com 866-495-0423 (sales, toll free) 866-739-8324 (U.S. merchant support, toll free) BluePay is a leading provider of technology-enabled payment processing for merchants and suppliers of any size in the United States and Canada. Through physical POS, online, and mobile interfaces, as well as CRM and ERP software integrations, BluePay processes business-to-consumer and business-to-business payments while providing real-time settlement, reporting, and reconciliation, along with robust security features such as tokenization and point-to-point encryption. BluePay is headquartered in Naperville, Illinois, with offices in Chicago, Maryland, New York and Toronto. THIS PRESENTATION IS BROUGHT TO YOU BY BLUEPAY