opinion

Keeping Cardholder Data Safe, Secure

Keeping Cardholder Data Safe, Secure

Congratulations. It is 2021 and, so far, your business has survived the Great Culling of 2020, the global pandemic of COVID-19

Just as some people found ways to improve themselves while quarantined by learning to bake bread or brew beer, or taking up reading or yoga, some businesses thrived under quarantine protocols. Whether your business thrived or struggled to survive, it is safe to say that the phrase “adapt or die” truly showed its relevance in 2020 — especially for small businesses.

More credit card transactions mean more opportunities for them and more security obligations for you.

If your business is web-based, like Amazon or DoorDash, these may be bonanza times for you. If you run a brick-and-mortar business, then depending on the state you live in, you may have had to modify your business model, at least temporarily, in ways that had never before crossed your mind. Restaurants and auto-parts stores adopted curbside pickup, for instance, or became cash-free environments. Suddenly, you found yourself taking orders and billing information over the telephone.

Regardless, it is great that your business has found a way to make it in this year of the new normal, but survival means new responsibilities because, as you are likely aware, legitimate business owners are not the only ones adapting to this new world; cybercriminals love it. More credit card transactions mean more opportunities for them and more security obligations for you.

You may believe your primary obligation is getting your product to your customer, but in the grand scheme of things, protecting your customers' personal information and cardholder data is more important. While ensuring your customer receives what they paid for is important, hard goods can easily be replaced, whereas a security breach that reveals your customer’s personal information and cardholder data can result in such problems as identity theft, and there is a great chance that your failure to provide adequate protection will result in the permanent loss of that person as a customer in the future.

It is pretty easy to figure out what a customer’s personal information consists of; the obvious elements like name, address, telephone number and date of birth certainly fall under the category of personal information, but what else does cardholder data encompass?

Cardholder data, for the purpose of this article, is the Personal Identifiable Information (PII) that is kept on the magnetic strip found on the back of any credit, debit or ATM card. The cardholder data stored is typically the account number, cardholder name and expiration date, as well as the service code, also known as the CVV or CVV2, depending on the bank issuing the card.

Fortunately, for consumers and merchants alike, there is the Payment Card Industry Security Standards Council, hereafter referred to as the PCI SSC.

The PCI SSC was created in 2006 by American Express, Discover, JCB International, MasterCard and Visa, and its mission is to enhance credit card data security by developing standards, practices and services. Part of this was accomplished with the establishment of the PCI Data Security Standard (PCI DSS).

The PCI DSS lists 12 requirements for a merchant to become PCI-compliant. These requirements range from the basics such as using a proper firewall to protect unauthorized access to the servers that store and transmit your customer’s cardholder data, and not using default passwords provided by any third-party vendors you might use. Additionally, updating anti-virus software, testing your security systems and establishing a policy that addresses information security for employees and any relevant contractors is required.

Whether your business is face-to-face with your customers inserting their credit card into a terminal, or your business is entirely web-based and you never interact with the customer or their credit card information, if you accept any credit or debit card as a means of payment, you have an obligation to be PCI-compliant to some degree.

Failure to be PCI-compliant can be expensive as the penalties levied by the credit card company on the acquiring bank (credit card bank) can range from $5,000 to $100,000 per month, in addition to possible legal action, loss of revenue and the inevitable loss of consumers' trust.

Fortunately, becoming PCI-compliant does not have to be as difficult as it might seem on the surface. You will have to fill out a self-assessment questionnaire and the associated Attestation of Compliance annually, but the technical portion is easy and usually free as most merchant service providers have partnered with certified PCI vendors and assessors.

Jonathan Corona has 15 years of experience in the electronic payments industry. As MobiusPay’s EVP, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards set forth by the card associations. MobiusPay specializes in merchant accounts in the U.S., EU and Asia. Follow them @MobiusPay on Twitter, Facebook and IG.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

Segpay Marks 20 Years of High-Risk Triumphs

Payment processors are behind-the-scenes players in the world of ecommerce, yet their role is critical. Ensuring secure, seamless transactions while navigating a rapidly changing regulatory landscape requires both technological expertise and business acumen.

Jackie Backman ·
opinion

The SCREEN Test: How to Prepare for Federal Age Verification

For those who are counting, there are now 20 enacted state laws in the United States requiring age verification for viewing online adult content, plus numerous proposed laws in the works. This ongoing barrage has been exhausting for many in the adult industry — and it may be about to escalate in the form of a potential new AV law, this time at the federal level.

Corey D. Silverstein ·
opinion

How to Master Team Dynamics for Business Success

Having the right team in place is everything. Whether getting a startup off the ground and thriving, or safeguarding an established company, the right — or wrong — people can mean the difference between a successful venture and a failed dream.

Juicy Jay ·
opinion

Eight Steps to Fast-Track AI Site Approval for Processing

Artificial intelligence is a hot topic these days. AI technology is speeding up the way we do business across all industries and offers numerous benefits, from automating processes to increasing efficiency and scalability.

Cathy Beardsley ·
opinion

How to Secure High-Risk Transactions With Network Tokenization

Ensuring the security of data as it moves through digital channels is the foundation of safe transactions, and crucial for your success. If your business can’t secure transactions, you’re exposed to myriad processing traumas.

Jonathan Corona ·
profile

WIA Profile: Reba Rocket

As chief operating officer and chief marketing officer of Takedown Piracy, long at the forefront of intellectual property protection in adult entertainment, Rocket is dedicated to safeguarding the livelihoods of content creators and producers while fostering a more ethical and sustainable industry.

Women In Adult ·
opinion

Protecting Content Ownership Rights When Using AI

In today’s digital age, content producers have more tools at their disposal than ever before. Among these tools, artificial intelligence (AI) content generation has emerged as a game changer, enabling creators to produce high-quality content quickly and efficiently.

Corey D. Silverstein ·
opinion

How Payment Orchestration Can Help Your Business

An emerging payment solution is making waves in the merchant world: the payment orchestration platform (POP). It’s quickly gaining traction as a powerful tool for managing online payments — but questions abound.

Cathy Beardsley ·
opinion

Fine-Tuning Refund and Cancellation Policies

For adult websites, managing refunds and cancellations isn’t just about customer service. It’s a crucial factor in maintaining compliance with the regulations of payment processors and payment networks such as Visa and Mastercard.

Jonathan Corona ·
profile

WIA Profile: Laurel Bencomo

Born in Cambridge, England but raised in Spain, Laurel Bencomo initially chose to study business at the University of Barcelona simply because it felt familiar — both of her parents are entrepreneurs. She went on to earn a master’s degree in sales and marketing management at the EADA Business School, while working in events for a group of restaurants in Barcelona.

Women In Adult ·
Show More