News Archives - Blogs / News

22 posts

HostedPCI

2021: Record-Breaking Hacking Attacks

A company’s worst nightmare consists of potential malicious threats and breaches to its customer database. Zero-day hacking attacks are done by outside parties by discovering and exploiting vulnerable software malfunction of which a vendor and his development team may not be aware.

HostedPCI

PCI DSS Mobile Payment

PCI DSS has announced that it will be improving its security standards concerning payments done through mobile devices. Currently, there are two separate standards mandates, the first being software-based and working around PINprotection (SPoC)

HostedPCI

Target Release Date set

The PCI council has been working hard to update and deliver a new version of the PCI DSS standard. Currently, the target date for the PCI DSS v4.0 release is estimated to be March 2022. This revision will be requesting for industry professionals to review and provide feedback about the draft before the final version is released in March.

HostedPCI

8 Digit BIN implementation

The PCI Software-Based PIN Entry on COTS (SPoC) Standard provides requirements for developing secure solutions that enable EMV contact and contactless transactions with PIN entry on the merchant’s consumer device using a secure PIN entry application in combination with a Secure Card Reader for PIN (SCRP).

HostedPCI

security requirements for PIN Entry

The PCI Software-Based PIN Entry on COTS (SPoC) Standard provides requirements for developing secure solutions that enable EMV contact and contactless transactions with PIN entry on the merchant’s consumer device using a secure PIN entry application in combination with a Secure Card Reader for PIN (SCRP).

HostedPCI

Payment security for small businesses

Payment Card Industry Security Standards Council (PCI SSC) has introduced a new payment security tool for small businesses. The payment security tool will protect the card data of PCI SSC customers.

HostedPCI

5 updates from PCI SSC you need to know

The PCI P2PE standard has for sometime governed security requirements for technologies and services that organizations use for end-to-end encryption of cardholder data. The goal is to ensure that no sensitive cardholder data passes in unencrypted form through a merchant's point of sale system.

HostedPCI

Network Segmentation

Earlier this month the PCI SSC released a memo referring to their network segmentation guidelines, while network segmentation is not part of PCI scope, it seems that most breaches happen from systems that were deemed not in scope, and companies were unaware that their data was even being accessed by these systems.