Please do not leave this page until complete. This can take a few moments.
If you’re in charge of payment card data at your company, you’ve probably come across the term PCI DSS. No, it’s not some secret code; it stands for Payment Card Industry Data Security Standard. Basically, it’s a set of rules designed to keep your customers' card info safe from cyber crooks.
Here to tackle today's cyber threats head-on is the latest version of this standard called PCI DSS 4.0. But here's the catch: there's a deadline looming. By April, companies must be in compliance with 4.0 mandates or risk fines of up to $100,000 a month, depending on volume of transactions.
Keeping things simple and in plain English, below are the six essential things businesses need to implement before the deadline hits.
1. Web application firewall: Web applications can be a goldmine for hackers if not properly protected. That’s the job of a web application firewall. It acts as a shield, inspecting all traffic to block any malicious intruder targeting your web apps.
2. Anti-phishing tools: Phishing is still the oldest trick in the cybercriminal playbook. Threat actors often send scams by email in hopes of snaring victims into giving up their login credentials, financial details, or personal info.
To combat this, you need serious anti-phishing measures, which include domain-based message authentication (DMARC), sender policy framework (SPF), DomainKeys Identified Mail (DKIM) to prevent spoofing, the use of link scrubbers, and server-side anti-malware tools. PCI DSS recommends regular security awareness training to help employees identify and report phishing attacks.
3. Penetration testing: Requirement 11.4 of PCI DSS 4.0 specifies organizations must perform penetration testing at least annually and after any significant change to the network.
This includes testing from both inside and outside the business to identify vulnerabilities and ensure security of cardholder data.
4. Multi-factor authentication: Not all MFA is created equal. Make sure you have a system that can’t be tricked by replay attacks, where hackers intercept and reuse authentication messages.
5. Tougher passwords: Businesses need to encourage staff to use long and complex passwords using at least 12 alphanumeric characters. Given how the average internet user has 100 apps and online accounts, the only way to generate, store, and recall passwords is by using a commercial password manager.
6. Automated log analysis: Digging through endless logs looking for troublemakers is a job for automation. Businesses must have log analysis tools such as a security info event manager, which simply collects data from various sources to detect and respond to security threats.
The above list is not the comprehensive set of requirements. Version 4.0 puts great emphasis on periodic risk assessments.
Abiding by PCI DSS 4.0 rules may seem like a big hassle, but look on the bright side: Complying will not only prevent being fined by regulators but also make your business less vulnerable to scams and cyberattacks.
Stay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Sign upWorcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
SubscribeWorcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
See Digital EditionStay connected! Every business day, WBJ Daily Report will be delivered to your inbox by noon. It provides a daily update of the area’s most important business news.
Worcester Business Journal provides the top coverage of news, trends, data, politics and personalities of the Central Mass business community. Get the news and information you need from the award-winning writers at WBJ. Don’t miss out - subscribe today.
Worcester Business Journal presents a special commemorative edition celebrating the 300th anniversary of the city of Worcester. This landmark publication covers the city and region’s rich history of growth and innovation.
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
This website uses cookies to ensure you get the best experience on our website. Our privacy policy
To ensure the best experience on our website, articles cannot be read without allowing cookies. Please allow cookies to continue reading. Our privacy policy
0 Comments