Payment Security Opportunities for Leadership & Growth Jeff Wakefield.

Slides:



Advertisements
Similar presentations
CONFIDENTIAL 1 Preparing for & Maintaining PCI Compliance.
Advertisements

Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Microsoft Mobile Service Platform Empowering The Agile Service Provider Ronald Chan Business Development Manager Network Service Providers Microsoft Greater.
Zenith Visa Web Acquiring A quick over view. Web Acquiring Allows merchants to receive payments for goods and services through the Internet Allows customers.
1 U.S. EMV Migration Update and Best Practices Hap Huynh, Senior Director Risk Products April 2015.
Contactless Payment. © Family Economics & Financial Education – January 2007 –– Financial Institution Unit – Contactless Payment - 2 Funded by a grant.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
Creating a Winning E-Business Second Edition
Creating a Winning E-Business Second Edition Operating Your E-Business Chapter 5.
Credit / Debit Card Electronic Payments Industry Update on Convenience Fees, Utility Program and More! Presented by: Presented by: Michael Hodge, Regional.
Electronic Commerce Semester 1 Term 1 Lecture 22.
Visa Europe Implementing PCI DSS Requirements Within Your Organisation September 2008 Simon Breeden.
Jeff Williams Information Security Officer CSU, Sacramento
Principles and Learning Objectives
WHY POS?  Streamline operations  Track inventory  Control cash  Spend more time with your customers  Increase your profitability The easiest way.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Mobile POS & Fuel.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
Why Comply with PCI Security Standards?
PCI and how it affects College Stores… ROBIN MAYO | PCIP ECOMMERCE MANAGER EAST CAROLINA UNIVERISTY.
“Electronic Payment System”
SMARTER. TOGETHER. Skimming Prevention: Overview of Best Practices August 5, 2014.
Security & PCI Compliance The Future of Electronic Payments Security & PCI Compliance Greg Grant Vice President – Managed Security Services.
Mr. Stasa – Willoughby-Eastlake City Schools ©. Essential Question #8  In your opinion, how has technology improved and/or damaged the banking industry?
THE TRANSFORMATION OF PAYMENTS. NFC Hosted Payments EMV in the US End-to-End Encryption Mobile POS.
Intercard The Right System March 6, 2012 Alberto Borrero Vice-President, Int´l Marketing & Sales Intercard Mobile: Skype: aborrero
Payments technology and security
HOW TO SELL HARBORTOUCH AND MAKE MONEY.  Devalued terminal market creates opportunities in valued POS market  Higher acquisition cost and market saturation.
Academy of Risk Management | Innovate. Collaborate. Educate. Fraud Management Solutions Innovative Products & Thought Leadership.
Protecting Customer Websites and Web Applications Web Application Security.
Our Portfolio Reflects Our Expanding Possibilities
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
EUROCON “Computer as a Tool”, Belgrade, 24 th November 2005 (1) Paul Killoran EUROCON 2005 Paul Killoran, Fearghal Morgan & Michael Schukat National.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
© Copyright SmartCentric Technologies International Ltd (2003 – 2005). All rights reserved. No part of this document may be reproduced, stored or transmitted.
Creating a Winning E-Business Second Edition Operating Your E-Business Chapter 5.
Dell Connected Security Solutions Simplify & unify.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
VirtualMerchant Secure Hosted Software Solution. Introducing VirtualMerchant  Complete hosted payment solution that instantly transforms PCs into “virtual”
The next generation of payments is here. Is your business ready?
What you need to know about PCI-DSS Jane Drews Chief Information Security Officer Information Security & Policy Office
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
e-Learning Module Credit/Debit Payment Card Acceptance and Security
RiTA Server A New Era in Payment Processing!. 2 Mission Statement  To strengthen and defend our position as the trusted worldwide leader of the electronic.
Groupon Training June 2011.
VeriShield Protect Revolutionary technology that simplifies PCI DSS compliance with no system upgrades Now available on V x Solutions!
INTRODUCTION TO SIM.DLL AGENDA SIM.DLL Overview and Features SIM.DLL Requirements Supported Terminals Transaction Flow Benefits.
Integrated Systems Selling Payment Solutions to Retailers Jennifer Miles General Manager, Retail Systems.
Global Product Marketing
PAYWARE SIM Secure Integration Method. WHY PAYWARE SIM? PAYware SIM provides a single interface to simply and securely integrate Windows-based POS systems.
E-Commerce & M-Commerce. Introduction Electronic commerce, commonly known as e- commerce, It is a type of industry where buying and selling of product.
Global Digital Security Market WEBSITE Single User License: US$ 2500 No of Pages: 60 Corporate User License: US$ 4000.
What does Chip offer Banks today?. CARD TYPES CREDIT DEBIT CHARGE PRIVATE LABEL PRE-PAYMENT MULTI FUNCTION.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
The simplest way to mobilize POS system. TABLE OF CONTENTS  What is SimiPOS  Why SimiPOS  Features  Screenshots/logo  About us.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
A Brief Introduction Radiant Pay, a global provider of payment processing services to all kinds of business, Radiant Pay Services.
Commercial Card Expense Reporting (CCER) The Trustees of Roanoke College An internet solution Accessed via Wells Fargo’s secure Commercial Electronic Office.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
EMV.
Payment Card Industry (PCI) Rules and Standards
Presented By: Mark Jordan
Payment Card Industry (PCI) Rules and Standards
Undeniably Advanced PC-based Payment Solution
Consider cards over cash
Consider cards over cash
FORECASTED ONLINE GROWTH VS IN STORE GROWTH
Consider cards over cash
New Jersey Gasoline C-Store Automotive Association
Presentation transcript:

Payment Security Opportunities for Leadership & Growth Jeff Wakefield

VeriFone Security Opportunities Pre-PED Product Market ChurnPre-PED Product Market Churn Reposition VeriFoneReposition VeriFone Sell Broader Array of SolutionsSell Broader Array of Solutions Become a ‘Trusted Advisor’Become a ‘Trusted Advisor’ Dominate the CompetitionDominate the Competition ProblemOpportunityProblemOpportunityProblemOpportunityProblemOpportunity

VeriFone PCI Solutions PIN PadsPIN Pads CountertopCountertop PortablePortable Multi-LaneMulti-Lane POSPOS UnattendedUnattended SoftwareSoftware

VeriFone PCI Product Dominance

Why VeriFone Supports Standards? VeriFone Has Resources to Support StandardsVeriFone Has Resources to Support Standards Industry BenefitsIndustry Benefits –Enables Better Overall Solution Development –Reduces Overall Implementation Industry Costs –Provides Confidence in the Payment Chain Retailer BenefitsRetailer Benefits –Reduces Integration Costs –Provides Higher Value Solutions –Reduces Proprietary Solutions –Reduces Risk of Data Breaches –Eases Payment Standards Compliance VeriFone Standards Participation PCI Security Standards Council IFSF PCATS: Chair – Payment Systems X9: ANSI Committee W3C: XML Schema Working Group XML Forms Initiative EBT, WIC, ECC

Why VeriFone Supports Standards? VeriFone BenefitsVeriFone Benefits –Raise Barrier to Market Entry –R&D Investment Builds Portfolio Advantages –Provides Opportunity to Become Security Vendor –Raises the Competitive Bar –Establish & Maintain Payment Leadership Position

VeriFone Security Leadership As Industry Leader It Is Our Responsibility to Solve Industry ProblemsAs Industry Leader It Is Our Responsibility to Solve Industry Problems –Member of PCI Security Standards Council Board of Advisors –Published PIN PAD Security Best Practices –Secure Retail Payments Website –Payment Security Newsletter –Retail Payments Security Conference –New Products & Services

PIN Pad Security Best Practices PIN PAD Security Best Practices 1.Weekly Visual Terminal Inspections 2.Serial Number Validation 3.Monitor Pin Pad Problems 4.Secure Terminal Storage 5.Terminal Asset Tracking 6.Repair Technician Verification & Log 7.Mount PIN Pads Securely to Counter 8.Electronic Serial Number Validation 9.Change Default PIN Pad Password 10.Purchase From Authorized Sources 11.Use Authorized Repair Centers 12.Develop a Response Plan! There is a Gap in PIN Pad SecurityThere is a Gap in PIN Pad Security Need Better PIN Pad ControlsNeed Better PIN Pad Controls –Physical Control –Logical Control –Access Control

VeriFone Secure Retail Payments

to Secure Retail Payments Newsletter

Retail Payments Conference

New Security Products & Services Compliance Reporting - TrustwaveCompliance Reporting - Trustwave Compliance Monitoring - ArcSightCompliance Monitoring - ArcSight Secure Terminal RetirementSecure Terminal Retirement Terminal Security AuditTerminal Security Audit Tamper Resistant ShippingTamper Resistant Shipping Locking PIN Pad StandLocking PIN Pad Stand Payment ProductPayment Product $

Need To Eliminate Skimming Consumers Handing Their Cards to Clerks & Waiters Remains a ProblemConsumers Handing Their Cards to Clerks & Waiters Remains a Problem As An Industry We Need to Either:As An Industry We Need to Either: –Develop Solutions and Operating Rules to Eliminate Card Handover Or Or –Make The Information Obtained by Criminals Not Valuable

Degree of Security RetailRestaurantPetro Fuel Dispenser Organized Crime Focus 0% 100% “Using a credit card at a gas station could pose more of a risk for data theft than shopping online, as point-of-sale (POS) terminals at the pump have emerged as a weak link in the security chain” - Gartner Group Fuel Pump Fraud Increases

“Secure PumpPAY” Launch at NACSLaunch at NACS OP4100 & PrinterOP4100 & Printer Retrofit Kits for PumpsRetrofit Kits for Pumps PAYware Device & ContentPAYware Device & Content 900,000 Million Fuel Points900,000 Million Fuel Points TDES by 2010TDES by 2010

PCI’s Biggest Shortcoming Our System Requires Sensitive DataOur System Requires Sensitive Data We Are Building Higher Walls & Wider MoatsWe Are Building Higher Walls & Wider Moats As Long As The Gold is There, Criminals Will Target Retail LocationsAs Long As The Gold is There, Criminals Will Target Retail Locations An Industry-wide Initiative is Required to Eliminate Data That Has Criminal ValueAn Industry-wide Initiative is Required to Eliminate Data That Has Criminal Value

Merchant Compliance Issue Store Back Office Payment Processor In-store LAN Home Office WAN Consumer Facing Devices POS Local Area Network POS Cash Register Home office Server Enterprise Wide Area Network Store Back Office Server Must Protect:

Retailer’s PCI DSS Challenge PCI DSS compliance issues will continue to evolve and as such, represent an ever-increasing cost for Retailers to remain compliant with current industry standards.PCI DSS compliance issues will continue to evolve and as such, represent an ever-increasing cost for Retailers to remain compliant with current industry standards. As long as Consumer Card data resides in Retail Systems, organized crime will continue to focus their data breach efforts on Retailers to obtain that valuable Card data.As long as Consumer Card data resides in Retail Systems, organized crime will continue to focus their data breach efforts on Retailers to obtain that valuable Card data. The solution lies in protecting Consumer Card data before it enters the Retailers payment systems for processing.The solution lies in protecting Consumer Card data before it enters the Retailers payment systems for processing.

PCI Compliance: The Elusive Goal Successful compromises of customer card data are increasing.Successful compromises of customer card data are increasing. The costs associated with these compromises are extremely highThe costs associated with these compromises are extremely high Retailers have the responsibility to protect critical consumer data and are dependent on a number of disparate systems for their POS and EFT solution.Retailers have the responsibility to protect critical consumer data and are dependent on a number of disparate systems for their POS and EFT solution. Costs associated with the changes to these disparate payment systems required to protect this data impact the retailer several ways:Costs associated with the changes to these disparate payment systems required to protect this data impact the retailer several ways: –Certification Cost –Manpower –Opportunity Cost (usurp other projects) Certification costs associated with PCI DSS compliance are expensive and very time consuming and resource intensive.Certification costs associated with PCI DSS compliance are expensive and very time consuming and resource intensive.

The VeriShield DSS™ Solution VeriShield DSS™protects Retailers by encrypting Consumer Card data before it enters the Retailers pos & payment systems Encrypt critical card data in the PIN Pad/TerminalEncrypt critical card data in the PIN Pad/Terminal Completely “cloaks” critical information that protects Mag Stripe data, even if it ends up in the wrong handsCompletely “cloaks” critical information that protects Mag Stripe data, even if it ends up in the wrong hands No changes required at the POS … transaction “Looks” exactly the same to POS but Consumer Card data is completely protected.No changes required at the POS … transaction “Looks” exactly the same to POS but Consumer Card data is completely protected. Few (if any) changes are required at the Retailers host for decryption, depending on the Retailers environmentFew (if any) changes are required at the Retailers host for decryption, depending on the Retailers environment Solution supports cost savings measures offered by PIN encouragement/BIN Management without compromiseSolution supports cost savings measures offered by PIN encouragement/BIN Management without compromise

How it works in the terminal When a card is read, unique algorithms encrypt card data while preserving essential portions for specific purposesWhen a card is read, unique algorithms encrypt card data while preserving essential portions for specific purposes –ISO Prefix for PIN Encouragement –Last 4 digits for receipt printing –DUKPT V eri- S hield

VeriShield DSS™ Magstripe Encryption Store Back Office Payment Processor In-store LAN Encryption Gateway WAN VeriShield™ DSS VeriShield™ Encrypted Cardholder Information Outside of Merchant Enterprise Responsibility to Manage Secret Keys Outside of Retailers Enterprise

VeriShield DSS™ Benefits VeriShield easily secures critical Consumer Card data even if compromisedVeriShield easily secures critical Consumer Card data even if compromised No changes required to the Retailer POS for easy and quick implementationNo changes required to the Retailer POS for easy and quick implementation Instantly achieves a higher standard of security with little if any developmentInstantly achieves a higher standard of security with little if any development Reduces efforts to become and maintain for PCI DSS complianceReduces efforts to become and maintain for PCI DSS compliance Positions VeriFone as the Leader in Secure Payment SolutionsPositions VeriFone as the Leader in Secure Payment Solutions

VeriFone As A Trusted Advisor Recurring Business Increasing Margins Sales Level Commodity-Based Project-Based Consultation-Based Trusted Advisor

Thank You

PAY at the Table Mobile Payments America’s Growth Opportunities WirelessSecurity PCI Compliance Contactless Contactless is paving the road for Mobile Phone Payments and Consumers will finally “get it” VeriFone is already delivering this infrastructure Bringing secure payments & PIN debit to the table has real benefits VeriFone has solutions at the ready for any size restaurant Security is an enormous issue for issuers, acquirers and merchants VeriFone is taking on the role of Trusted Advisor and is delivering comprehensive products and solutions