Site icon IT World Canada

When it comes to cyber security, it’s always busy season

By Cheryl McGrath
Vice President and Country General Manager – Canada
Optiv Security

Where has the year gone? The temperature is dropping, the leaves are turning, and the busy holiday shopping season is rapidly approaching. In some stores, it’s already here! For those of us in the world of cyber security, this means one thing: a significant amount of hype and stress around holiday security threats. Spend a little time reading the news and you’ll come across story after story warning consumers about being distracted and vulnerable to attackers and alerting retailers to the impending doom lurking behind a wave of new cyber-attacks designed to steal customer data.

There is an element of truth behind both of these “hype tracks.” But the reality is if you’re a retailer or any other business accepting credit cards and electronic payments, the holiday shopping season should not matter. Just as retailers tend to fully test and lock down their holiday websites in October in preparation for the big rush, payment security should not only be implemented well in advance of the holidays, it should be a standard 365-days-per-year discipline, just like managing inventory or staffing check-outs.

The Payment Card Industry Data Security Standard (PCI DSS) has done a satisfactory job at setting minimum standards relating to payment security, but many organizations incorrectly use it as an entire security framework. Any security framework should be customized to a merchant’s specific risk profile – the business it’s in, the data it stores, the countermeasures it has in place, and the enemies who are most likely to attack. Complying to PCI standards is simply not enough in this threat landscape. Sure, your organization may achieve a minimal level of security by following PCI and similar guidelines, but the truth is this is not enough to secure the very complex world of monetary transactions in today’s connected world.

So, how should merchants go about implementing true payment security in their organizations? In most cases, this requires four steps:

With these steps, merchants can go a long way to improve payment security. However, these are not discrete steps – they are ongoing and interrelated, which is why the shopping season really should not be any different from any other time of year. Regardless of the season, you need to understand your constantly evolving risk profile; your points of sale; the state of your operational efficiency and effectiveness; and your internal security.

It’s all-too-easy to get caught in the holiday crush. But if your organization takes security seriously year-round, the holidays should be nothing to fear.

Exit mobile version