Skip to content
The Cyber Security Place

Expert Articles

Why PCI Compliance Should Remain a Priority, Even in a Pandemic

Reported by cybera.com

By Rob Chapman, Director of Security Architecture at Cybera

No one would blame you if you have a few priorities beyond PCI compliance right now. After all, the COVID-19 pandemic is leaving a giant footprint across the business world. And many companies have enlisted their IT security teams to focus on keeping their systems up and running or directly supporting remote employees and end-user customers.

But if you’re an IT security professional, you simply can’t relegate your cybersecurity and compliance responsibilities to the back burner—despite the massive disruption to “business as usual.” Why? It’s all about managing risk.

To Reduce Risk, Stay Focused on PCI Compliance

If your experience is like many other IT security professionals’ right now, you’re probably being pulled in five different directions and directed to “think about the big picture.” Well, there’s no bigger picture than protecting the financial interests of your company and its customers.

For highly distributed enterprises with many remote sites (and remote employees), security should be an even greater concern right now. A key part of that security includes payment card transactions and the ability to meet your company’s PCI compliance obligations. Simply put, maintaining PCI compliance can greatly reduce business risk and save money.

Why Compliance Matters More Than Ever

If the pandemic has revealed anything, it’s that companies must have a solid IT foundation that can adapt quickly to a flurry of unanticipated market demands. Part of that foundation involves locking down your regulatory and compliance processes so they remain a priority rather than an afterthought.

So, what’s the upside to spending valuable time and resources on PCI compliance right now? It starts with three key areas where you can:

Limiting the Potential for Cybercrime

By now, it’s clear that cybercriminals aren’t taking any breaks during the pandemic. In fact, the scams seem to be accelerating as hackers take advantage of confusion and lax security protocols with a variety of phishing and social engineering schemes. Remote site environments without dedicated IT staff are especially at risk from these types of attacks.

Because cybercrime is such a clear threat, it’s imperative that you do whatever you can to prevent it. Start by following the core PCI-DSS compliance guidelines to take actions such as:

Tightening Security to Prevent Theft

Especially in retail environments, there’s always the potential for both internal and external theft, which tends to rise during challenging economic times. By adhering closely to the PCI-DSS guidelines, you can better control both your physical environment and your online systems.

One of the best ways to prevent theft is to make sure all store video cameras are doing what they’re supposed to. Position your cameras to cover your POS systems, back-office computers, and any devices used to access the network. Doing so will serve as a strong deterrent and a reliable record of nefarious activities.

Another proven theft prevention method is to limit access to your POS systems, back-office computers, and corporate network. You can start by implementing least-privilege access protocols and extending full admin rights only to those employees who absolutely need it. The more effective you are at restricting access to systems within the scope of PCI compliance, the more secure you’ll be.

Avoiding Regulatory Fines and Card Processor Fees

Beyond the obvious security-related reasons to meet your PCI compliance objectives, you can also gain significant financial benefits. First of all, filling out your PCI self-assessment questionnaire (SAQ) should reveal whether you have any compliance gaps or missing information.

These gaps can lead to possible fines and higher transaction fees when it comes to processing card payments. Even worse, non-compliance could expose your business to a wide range of expensive legal fees. That’s why achieving PCI compliance simply makes good financial sense.

Make PCI Compliance a Priority

Yes, it might be difficult to focus on anything beyond basic IT requirements right now. But you’re doing your company a disservice if you don’t treat PCI compliance as a fundamental requirement—pandemic or not. The good news is the PCI-DSS guidelines provide some relatively fast and easy steps you can take right now to help keep your business secure.

About Rob Chapman

As Director of Security Architecture at Cybera ( www.cybera.com ), Rob Chapman is responsible for the company’s overall cybersecurity architecture and PCI compliance initiatives. During his career, he has focused on areas ranging from academic and enterprise technologies to big data and audiovisual systems. Chapman has a Masters in Educational Leadership and Instructional Technology from Tennessee Technological University. He currently resides in Columbia, TN.

Read the full article at cybera.com