Are You Protecting Customers’ Credit and Debit Card Data?

It’s hard to ignore the fact that data security breaches seem to be increasing in frequency and severity, particularly those involving credit and debit card data. Just ask Home Depot, Michaels Stores, Neiman Marcus, or their 50+ million customers whose payment card data may have been compromised in 2014. To reduce the chances of making the list in 2015, preventative measures must be taken by every business that accepts credit and debit card payments.

The PCI Security Standards Council developed the Payment Card Industry Data Security Standard (PCI DSS) to encourage and enhance cardholder data security. This standard includes 12 requirements.

Build and Maintain a Secure Network and Systems

  • Install and maintain a firewall to protect cardholder data.
  • Do not use defaults for system passwords or security parameters.

Protect Cardholder Data

  • Protect stored cardholder data.
  • Encrypt transmission of cardholder data.

Maintain a Vulnerability Management Program

  • Protect systems against malware and regularly update anti-virus software.
  • Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

  • Restrict access to cardholder data to those who need to know.
  • Identify and authenticate system access.
  • Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

  • Track and monitor all access to networks and cardholder data.
  • Regularly test security systems and processes.

Maintain an Information Security Policy

  • Maintain a policy that addresses information security for all personnel.

The PCI Security Standards Council also provides a number of tips and strategies to increase the security of payment card data, such as:

  • Never store Sensitive Authentication Data, such as the full track contents on the magnetic stripe or chip, card verification codes/values, or PINs.
  • Ask point-of-sale vendors about the security of payment card systems.
  • Do not store cardholder data that is not needed.
  • Consolidate and isolate cardholder data that is needed.

The Council notes that the PCI DSS provides minimum security requirements that may be enhanced by additional controls and practices. Various laws, rules or regulations may also require enhanced security measurers. For example, under the Fair and Accurate Credit Transaction Act (FACTA), electronically printed credit and debit card receipts given to customers cannot include a card’s expiration date or more than the last five digits of the card number.

Sometimes security measures aren’t enough to prevent a data security breach, so businesses should use insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Protecting Against Emerging Data Security Threats

Cyber threats continue to top the list of concerns for individuals and businesses alike. With breaches becoming more common and more expensive, businesses are now discovering that steps must be taken to protect against data security breaches. Since understanding the risk is the first step to controlling it, let’s take a look at some observations made by Georgia Institute of Technology’s Information Security Center and Research Institute in their 2015 Emerging Cyber Threats Report.

Users are the greatest weakness to information security.

  • Though software vulnerabilities continue to be exploited, users remain the link most often exploited in attacks as cybercriminals continue to successfully abuse their trust.
  • Users often allow attackers to circumvent security measures.
  • Social engineering, which is also known as hacking humans, is a common and extremely effective way to attack systems. Sixty-seven percent of cyber attacks start with a phishing electronic communication sent by an attacker posing as a trustworthy person or business.
  • Training is an important piece of the security puzzle and one that businesses do not employ often enough. Forty-nine percent of businesses that do not perform employee security-awareness training pay the price — their annual losses are four times greater than those with a training process in place.

Attackers are increasingly targeting mobile devices.

  • As consumers and employees increasingly rely on mobile devices, their phones and linked cloud repositories have become treasure troves of information.
  • Increasing mobile app popularity and the proliferation of free apps relying on advertising for revenue have driven many developers to use vulnerable code that can be exploited. According to the report, in 2014, 91% of the top 200 iOS apps and 83% of the top 200 Android apps had some risky behavior.
  • Attackers follow the money, so the increasing use of mobile devices to make payments will draw their attention.
  • Android devices continue to bear the brunt of attackers’ focus. Since Android devices are targeted by malware 99% of time, users of these devices require better security measures and increased education about the risks.
  • Apple’s iOS ecosystem is not a safe haven. Researchers at Georgia Tech note that attackers have found ways around security measures, and that additional attacks should be expected.

Rogue workers can cause significant damage to a business.

  • The involvement of an insider causes the costs of data breaches to rise quickly.
  • Companies generally require more time to detect and respond to insider attacks, nearly 260 days, compared to 170 days for other attacks.
  • Incidents involving malicious insiders cost an average of $210,000 more to resolve.
  • Businesses should focus on protecting their “crown jewels” before expanding data-protection programs to cover broader kinds of information.
  • Businesses face a significant challenge looking for behavioral indicators that could detect the activities of a rogue insider.
  • Outreach to employees and access restrictions, such as splitting access rights to valuable data between two or more people, can make it much less likely for a single rogue insider to cause damage.

According to the report, the growing ‘Internet of Things’, which is the interconnection of uniquely identifiable devices (phones, tablets, etc.) to the Internet, will only make security issues more important in the future. By 2020, there could be 50 billion interconnected devices, so securing these devices and the data passed between them will be an ongoing challenge.

Since the risk of suffering a data security breach is likely to continue in the foreseeable future, businesses should consider insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against cyber risks, contact us.

If you’d like to subscribe to our weekly newsletters please click here.