PCI Compliance

PCI Compliance



  •  
  •  







Did You Know…

If you don’t secure your customer’s sensitive card data you will be hit with a fine of up to £300,000*.

If you lack data security and suffer a breach, you will have to reimburse customers.

If your customer’s card data is stolen, you may not be allowed to process card payments again, destroying your business.

If, after all this, your card data still isn’t secure, you will be forced to pay £15,000* per month.

If you enjoy running a successful business…you will want to think about protecting your data.

Call centres are easy targets for fraudsters because card data is seen and heard by your call centre staff and it can also be gleaned from call recordings. According to recent statistics, the black market for card data is a huge business – and it’s still growing. Card data is now more valuable than ever.

According to recent information¹, 97% of businesses retain sensitive card details on call recordings and only 3% of UK call centres comply with PCI Guidelines. This puts the financial details of millions at risk.

The Solution? CardGuard

CardGuard from elitetele.com is the solution. CardGuard is the only way to securely accept card payments over the phone.

This is how CardGuard works:

-the customer phones your call centre to make a payment

-the agent has the payment verification screen open in CardGuard mode

-the customer is asked to enter their card details into the telephone keypad

-CardGuard hides the card numbers on the payment screen so they cannot be seen

-CardGuard masks the DTMF² so the numbers tones cannot be heard

-with CardGuard in place, no card details are spoken

See no details. Hear no details. Speak no details.

Key Features of CardGuard

-CardGuard is completely PCI Compliant

-CardGuard enables you to allow all of your call centre staff to take card payments over the phone, rather than a trusted few

-With CardGuard there is no need for additional staff training for the handling of sensitive data

-With CardGuard you have no need of a ‘clean room’ as the agent is never in possession of sensitive data

-You have no need to switch off or alter call recordings with CardGuard as no sensitive data is spoken

The Low Down on PCI Compliance and PCI DSS

PCI DSS stands for Payment Card Industry Data Standard Security. At the end of 2004, Visa and MasterCard aligned to improve card security at an industry level and created the Payment Card Industry Data Security Standard, soon joined by other major brands such as American Express. Being PCI Compliant as it is called, is mandatory and applies to all commercial operations that store, process or transmit cardholder data both manually and electronically.

PCI DSS is a set of principles and requirements around which businesses need to base their data security to become PCI Compliant:

Build and Maintain a Secure Network

Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

Protect Cardholder Data

Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks

Maintain a Vulnerability Management Program

Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications

Implement Strong Access Control Measures

Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data

Regularly Monitor and Test Networks

Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes

Maintain an Information Security Policy

Requirement 12: Maintain a policy that addresses information security

(PCI Security Standards Council (2006), About the PCI Data Security Standard (PCI DSS), Retrieved 14 September 2009 from  www.pcisecuritystandards.org)

If your business accepts card payments then you must be PCI Compliant. This is where CardGuard from elitetele.com can help you.

The Benefits of CardGuard

The reputation of your company depends upon how customers perceive you. So if your business gains bad publicity for card data fraud, you could face a serious loss of business. Customers will not want to hand their sensitive data over to a company that has negligently lost card data in the past. So, to protect your brand, you need to protect your customers and to do that you need to be PCI Compliant. You need CardGuard.

Customers often have ‘card anxiety’ whilst paying by card over the phone, mostly due to negative press regarding card data fraud. If you make your customers aware that their card details are protected by CardGuard, they will be reassured.

As stated before, using CardGuard means that all of your agents can deal with card payments and without the need for a clean room too. Add this to still being able to use call recording and you really are on to a winner.

And once again let’s reiterate that with CardGuard you are PCI Compliant – which means no massive fines!


Sources of Information obtained from the following websites;

*RBS WorldPay – RBS WorldPay show a list of Fines on their PCI Compliance site which are imposed by the Card Providers
¹CallCentre.co.uk
²Dual Tone Multi Frequency

Please note the above websites are not in any way associated with Elitetele.com

UK Telecoms News | Phone System News | 08 Number News » PCI-Compliance