opinion

Unpacking the Payment Card Industry's Latest Data Security Standard

Unpacking the Payment Card Industry's Latest Data Security Standard

The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements and guidelines that apply to all businesses that accept credit card payments, and is designed to ensure the security of those transactions. Created in 2004 by Visa, Mastercard, Discover and American Express, the PCI DSS has evolved over the years to ensure that online sellers have the systems and processes in place to prevent data breaches.

The PCI DSS Version 4.0 officially became the new standard on April 1. Coming at a critical time when cyber threats are increasingly sophisticated, this update emphasizes the need for stronger safeguards to protect sensitive cardholder data.

One of the most notable updates is the increased focus on authorization mechanisms, encouraging the use of multifactor authentication and stronger password requirements.

PCI DSS 4.0 introduces several key changes and enhancements aimed at improving the overall security posture of companies that handle payment card data. One of the most notable updates is the increased focus on authorization mechanisms, encouraging the use of multifactor authentication and stronger password requirements.

Additionally, the new standard places a greater emphasis on monitoring and logging practices, ensuring that businesses have the necessary tools and processes in place to detect and respond promptly to security incidents.

PCI compliance can sometimes seem overwhelming to the average business owner, since achieving it requires educating yourself on a variety of security protocols and processes. Fortunately, with a bit of help, you can successfully navigate these waters and achieve compliance in no time.

Businesses can use various tools to achieve PCI compliance, but a well-structured compliance checklist is critical and makes the process much easier. Here are eight mandates that every merchant should be familiar with.

Firewall: Protect cardholder data with a firewall. Every device interacting with cardholder data must have a firewall installed, protecting your network from outside attacks. This will ensure all transactions happen safely. Buy and use only approved PIN entry devices at your POS. Buy and use only validated payment software at your POS or website shopping cart.

Passwords: Immediately change default passwords on hardware and software as soon as you receive them from vendors. That includes your wireless router. For strong and unique passwords, use password management software to generate a random password or use the “three random words” method.

Data Protection: Both physical and digital cardholder information must be strictly guarded. Physical access to cardholder information should be restricted and monitored. Remember to log out when leaving a terminal and add a timeout after a short period of inactivity is detected. Digital data must be protected using firewalls. 

Encryption: PCI-compliant encryption is essential. It prevents data and information from being stolen during the transfer between the issuing bank and acquiring bank, encrypting cardholder data that passes through open, public networks and confirming POS encrypts this data. Ensure peer-to-peer encryption. Make sure your wireless router uses encryption.

Antivirus Software: Install antivirus software, be sure to update it with the latest versions and regularly run a virus scan. Set up a monthly checklist/process where you download or patch your software, so you know you are up to date. Otherwise, new vulnerabilities will not be patched.

Secure Systems: Implement a security checklist that employees must follow to protect data and ensure the security of systems and applications. This checklist should address any vulnerabilities and keep all your software up to date, including firewalls, apps and POS. Test security processes and systems frequently to make sure they are still working and improve where needed. Regularly check PIN entry devices and PCs to ensure no one has installed rogue software or “skimming” devices.

Cardholder Data Access: To reduce the chance of a breach, minimize the number of employees who have access to cardholder data. Only those who need such access in order to perform their jobs should have it. 

Permission ID: Assign unique IDs to each employee or user with access to cardholder details and network resources. This enables you to track precisely who logs in and when. Consider surveillance for fraudulent activity.

Develop clear information security policies in order to implement the above guidelines, and to prove and track compliance. Policies and procedures should identify how standards are maintained so that auditors can verify your compliance. Teach your employees about security and your policies.

PCI DSS 4.0 represents a significant step forward in the fight against cybercrime, providing your business with a comprehensive framework to protect payment card data and maintain the trust of your new and existing customers. Whatever the size of your business, PCI compliance is a must.

Jonathan Corona has two decades of experience in the electronic payments processing industry. As chief operating officer of MobiusPay, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards mandated by the card associations, including, but not limited to, maintaining a working knowledge of BRAM guidelines and chargeback compliance rules defined in both Visa and Mastercard operating regulations.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Breaking Down HB 805 and How it Affects the Adult Industry

North Carolina House Bill 805 was enacted July 29, after the state legislature overrode Governor Josh Stein’s veto. The provisions that relate to the adult industry, imposing requirements for age verification, consent and content removal, are scheduled to become effective Dec. 1. Platforms have until then to update their policies and systems to comply with the new regulations.

Corey D. Silverstein ·
opinion

Staying Compliant With Payment Standards Across Europe and Australia

So, you’ve got your eye on international growth. Smart move. No matter where adult-industry merchants operate, however, one requirement remains consistent: regulatory compliance. This isn’t just a legal checkbox — it’s a critical component of keeping payments flowing and business operations intact.

Jonathan Corona ·
opinion

How to Avoid Copyright Pitfalls When Using Music in Adult Content

When creating an adult video, bringing your vision to life often means assembling just the right ingredients — including the right music. However, adding music to adult content can raise complex legal and ethical issues.

Lawrence G. Walters ·
opinion

New Visa Rules Adult Merchants Need to Know

In December 2024, I shared an update on the upcoming rollout of Visa’s Acquirer Monitoring Program, also known as VAMP. The final version went into effect in June, and enforcement will begin in October. With just a month to go, now is the time to review what’s changing and how to stay compliant.

Cathy Beardsley ·
opinion

WIA Profile: Lainie Speiser

With her fiery red hair and a laugh that practically hugs you, Lainie Speiser is impossible to miss. Having repped some of adult’s biggest stars during her 30-plus years in the business, the veteran publicist is also a treasure trove of tales dating back to the days when print was king and social media not even a glimmer in the industry’s eye.

Women in Adult ·
opinion

Fighting Back Against AI-Fueled Fake Takedown Notices

The digital landscape is increasingly being shaped by artificial intelligence, and while AI offers immense potential, it’s also being weaponized. One disturbing trend that directly impacts adult businesses is AI-powered “DMCA takedown services” generating a flood of fraudulent Digital Millennium Copyright Act (DMCA) notices.

Corey D. Silverstein ·
opinion

Building Seamless Checkout Flows for High-Risk Merchants

For high-risk merchants such as adult businesses, crypto payments are no longer just a backup plan — they’re fast becoming a first choice. More and more businesses are embracing Bitcoin and other digital currencies for consumer transactions.

Jonathan Corona ·
opinion

What the New SCOTUS Ruling Means for AV Laws and Free Speech

On June 27, 2025, the United States Supreme Court handed down its landmark decision in Free Speech Coalition v. Paxton, upholding Texas’ age verification law in the face of a constitutional challenge and setting a new precedent that bolsters similar laws around the country.

Lawrence G. Walters ·
opinion

What You Need to Know Before Relocating Your Adult Business Abroad

Over the last several months, a noticeable trend has emerged: several of our U.S.-based merchants have decided to “pick up shop” and relocate to European countries. On the surface, this sounds idyllic. I imagine some of my favorite clients sipping coffee or wine at sidewalk cafés, embracing a slower pace of life.

Cathy Beardsley ·
profile

WIA Profile: Salima

When Salima first entered the adult space in her mid-20s, becoming a power player wasn’t even on her radar. She was simply looking to learn. Over the years, however, her instinct for strategy, trust in her teams and commitment to creator-first innovation led her from the trade show floor to the executive suite.

Women in Adult ·
Show More