Thursday, October 1, 2009
How Compliance Affects You
Did you know that 92% of card data compromises take place in small businesses with low volume? Many merchants think that the majority of data compromises take place utilizing internet transactions. In fact, 70% of the compromises take place at brick and mortar businesses rather than on the internet. As a business owner, you absolutely need to make certain that you are compliant with PCI DSS standards. Just because your credit card processor is billing you for PCI compliance fees, does not certify that you are specifically compliant.
The opportunity to process credit/debit cards is a great way to grow your business and give your customers the payment options they have become accustomed to. In order to make the most of this opportunity, your customers have to trust that their card information will be handled in a responsible manner and that they can safely utilize these cards for purchases. We all share in the opportunity to demonstrate that credit/debit cards are a safe and convenient way to pay.
Merchants today are at risk for lawsuits and fines from the card associations for any type of data breach. In addition, the reputation of your business can be placed at serious risk if it becomes publicly known that your customers’ card information has been compromised."
Do yourself, and your customers a favor and CLICK HERE to get compliance facts. There you will find a checklist that will guide you thru important issues that you need to be aware of and will point you to specific corrective actions that you should take.
Monday, September 28, 2009
PCI Compliance…Are you at risk?
AS A MERCHANT, HAVE YOU EVER...
- Processed a credit card transaction at your business and noticed the receipts contained the full credit card number and the expiration date? How about your copy of the receipt? If so, you are NOT COMPLIANT AND AT RISK.
- Stored credit card numbers in a binder or on your computer in a spreadsheet for recurring billing? NON-COMPLIANT!!!
- Configured your router or computer and used a easy, generic password such as 1-2-3-4? HACKERS LOVE THIS….YOU, AND YOUR CUSTOMERS ARE AT RISK. Create your own password and never use default passwords.
- Had your terminal go down and started keeping credit card data written in a spreadsheet on your computer to charge the client later?
- Imprinted a card and written down the CVV data (3-digit security code on back or 4-digit code on the front of the card)?
- Not renewed your anti-virus software on your computer?
- Spent years storing your receipts in a shoe box in your back office?
You may have seen in the news in recent months of the huge data breaches that took place which resulted in millions of credit card numbers being compromised. A couple huge payment processors and a major retailer were hacked into. You would think that these types of entities are the main targets of these international fraudsters. However, due to increased security being put into place, hackers and thieves are beginning to focus their attention on small, local, mom and pop type organizations. Consequently, you absolutely need to be aware and alert for the safety of you, your business and your customers.
PCI DSS is the real buzz phrase in the payments industry these days. It stands for Payment Card Industry Data Security Standards. Compliance is a standard of security established for any business that processes credit cards. Whether you have a computerized POS system, process over a phone and do manual imprints, process through a credit card terminal or have an e-commerce website taking orders, PCI establishes a series of best practices and minimum security protocols that must be observed for your business type.
Through the Fair and Accurate Credit Transactions Act of 2003, Public Law 108 to 159, the U.S. congress preempted what some individual states mandated on credit and debit card truncation to set a national standard. Under Title 1, Section 113 of the act, only the last five digits of the card account number can be printed on electronically printed receipts provided to the customer. The laws vary by state regarding truncation of the merchants copy. Some states carry it even further and say that the expiration date can't appear on receipts either. To be on the safe side, I would suggest that you make certain that both copies are truncated totally. If your receipts are showing more than is allowed, contact your processor, or POS vendor, immediately and have them assist you in becoming fully compliant.
While you're at it, ask your processor about any PCI compliance fees they may now, or in the future, be charging you. Some are using this as a new revenue stream and charging excessive monthly, annual or a combination of both, fees with no corresponding benefits.
Friday, January 30, 2009
Check your statement monthly
If you feel that it is near impossible to really understand your statement, and all it's various charges, you need to ask the questions. You could contact your rep, if they're still around. The Customer Care department of your service provider, would be another suggestion, and they should be happy to walk you thru it, line by line. Or, you could contact me and with my years of experience, and I'll be able to help you figure it all out.
Often, you will see at the top of your monthly statement, something called "Important Notice" or "Statement Messages". Here is typically where you will see notes on upcoming changes to your statement and subsequently, your processing costs.
Here's an example of what I'm talking about. With the increased credit card fraud and data breaches of late, most processors are passing on some sort of "fee" to you to help "protect" you and your business. Typically, they will notify you in the Statement Message section of your statement of upcoming charges. One processor I know of, notified their merchants of a monthly $9.99 Data Breach Service fee that was going to be charged to them. They gave merchants a couple months for free with the opportunity to call in and opt out if they didn't want it. However, the majority of merchants never read those little notes and months later, some of them start calling in asking what the fee is and who authorized it.
I've also seen merchants that are still getting statements from processors that they previously did business with, and are still paying monthly minimum fees to because they never cancelled the agreement. This, of course, is just money being thrown away.
Probably the most disturbing thing I find is that, over time, a merchants rates have continued to rise, without the knowledge of the merchant because they haven't looked at their statement in detail each month. Or, there are services they are paying for, but not utilizing and therefore costing them unnecessarily.
So, the bottom line here is....how is this affecting your bottom line? Let me urge you, please, please, please, take the time, each and every month, to look at your statement in detail. Make certain that you fully understand every charge and why you're paying it. If, when you make your call, you feel as if you're getting the runaround, please don't hesitate to contact me utilizing any of the contact methods found on this blog.
Thanks for taking the time to check out my blog. Be blessed and be a blessing.
