{"id":1811,"date":"2023-10-02T14:00:00","date_gmt":"2023-10-02T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/making-sense-of-todays-payment-cybersecurity-landscape"},"modified":"2023-10-02T14:00:00","modified_gmt":"2023-10-02T14:00:00","slug":"making-sense-of-todays-payment-cybersecurity-landscape","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/10\/02\/making-sense-of-todays-payment-cybersecurity-landscape\/","title":{"rendered":"Making Sense of Today&#8217;s Payment Cybersecurity Landscape"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"48.964362081254\">\n<div readability=\"45.124019957234\">\n<p>The surge in cybercrime activity since the outbreak of the COVID-19 pandemic has been tough to ignore. This is particularly true for &#8220;high-value&#8221; sectors such as finance \u2014 especially the payments industry.<\/p>\n<p>Cybercriminals have <a href=\"https:\/\/www.darkreading.com\/risk\/cyberthreats-regulations-mount-for-financial-industry\" target=\"_blank\" rel=\"noopener\">continuously targeted the financial sector<\/a>, not only because of the cache that comes with compromising a high-profile finance name but also because of the allure of a potentially lucrative payday. In fact, more than <a href=\"https:\/\/www.contrastsecurity.com\/cyber-bank-heists-report\" target=\"_blank\" rel=\"noopener\">60% of global financial institutions<\/a> with over $5 billion in assets were hit by cyberattacks in 2022. And with the number of non-cash transactions hitting a record of <a href=\"https:\/\/www.federalreserve.gov\/paymentsystems\/fr-payments-study.htm#:~:text=With%20157.0%20billion%20payments%20in,all%20card%20payments%20in%202021.\" target=\"_blank\" rel=\"noopener\">157 billion in 2021<\/a> in the US alone, the highly disruptive payments sector has emerged as a foremost threat target.<\/p>\n<p>To combat this, the PCI Standards Security Council \u2014 which sets industrywide cybersecurity standards and is led by major players in the payments card space \u2014 has unveiled its newest version of its <a href=\"https:\/\/blog.pcisecuritystandards.org\/pci-dss-v4-0-resource-hub\" target=\"_blank\" rel=\"noopener\">Data Security Standards (DSS) v4.0<\/a>. With current guidance \u2014 DSS v3.2.1 \u2014 set to sunset in 2024, the payment card industry and vendors that accept card payments have been working diligently to make sure they hit the March 2025 compliance deadline for v4.0. However, with so many new technologies and threats to contend with, and more than five years elapsing since the debut of v3.2.1, getting up to speed with the expectations of v4.0 is proving to be easier said than done.<\/p>\n<h2 class=\"regular-text\">What&#8217;s New in PCI DSS v4.0?<\/h2>\n<p>Originally set to be updated every three years, v4.0 guidance has been long awaited, to say the least. At over <a href=\"https:\/\/docs-prv.pcisecuritystandards.org\/PCI%20DSS\/Standard\/PCI-DSS-v4_0.pdf\">350 pages<\/a>, <a href=\"https:\/\/www.darkreading.com\/edge-articles\/what-s-new-in-pci-dss-4-0-for-authentication-requirements-\" target=\"_blank\" rel=\"noopener\">4.0 features numerous new best practices<\/a>, as well as enhancements on existing guidelines, including requiring businesses to implement multifactor authentication on all accounts that access cardholder data and new mandates for providing employee cybersecurity training. That said, when combining the legwork of meeting new compliance requirements and double-checking compliance against the rest of the guidance, the process of adopting v4.0 can seem like a highly daunting process \u2014 especially for businesses seeking to become DSS compliant for the first time. Here are three of the foundational steps that businesses can use to become compliant:<\/p>\n<ol readability=\"9.8464223385689\">\n<li><strong>Establish a baseline and review guidance pillars: <\/strong>This may seem like a no-brainer, but with such a dense piece of guidance \u2014 <a href=\"https:\/\/www.nashvillepost.com\/genesco-to-book-9m-gain-from-visa-settlement\/article_e7d9efcf-160e-5d1e-919b-0ea8d7c9f5d4.html\" target=\"_blank\" rel=\"noopener\">fines that can be in the millions of dollars<\/a> for noncompliance \u2014 having a firm grasp of your end-to-end compliance from the start is pivotal. Much like previous versions of PCI DSS guidance, v4.0 is composed of a comprehensive list of 12 pillars that aim to provide the most comprehensive security for the industry and cardholders themselves \u2014 tackling things like network security to the cryptography used to transmit cardholder data. In tandem with familiarizing themselves with these pillars and seeing how they stack up, businesses need to determine which PCI DSS level they fall under to determine the exact specifics they are required to adhere to in terms of the rollout of their PCI DSS compliance.<\/li>\n<li readability=\"9\">\n<p><strong>Determine the role of technology in your compliance efforts: <\/strong>One of the most interesting aspects of v4.0 is the latitude that is given to businesses to use technology to achieve and demonstrate their compliance. The compliance technology industry has come a long way since v3.2.1 was introduced. Moreover, the posture within the compliance community toward technology has shifted dramatically \u2014 with regulators now expecting, rather than encouraging, that technology be a part of an organization&#8217;s compliance mix. With that, businesses now have greater latitude to deploy emerging technologies like the cloud and different SaaS tools to help meet their ongoing compliance needs \u2014 from network monitoring to vulnerability testing \u2014 including when it comes to meeting v4.0 expectations. Thus, in addition to identifying existing gaps or weaknesses in meeting v4.0 oversight expectations, businesses also need to think about how they are going to fill them, and how and when to use technology tools to help them do so.<\/p>\n<\/li>\n<li readability=\"11\">\n<p><strong>Embrace flexibility and dynamism: <\/strong>The rapid pace of innovation by well-funded cybercriminals means it is highly likely cybersecurity guidance will be coming at a much greater frequency from PCI in the years ahead. This means businesses need to begin building enabling cybersecurity strategies to be both flexible and adaptable as new payment technology and related threats become realized.&nbsp; Meeting the compliance standards of today is great. However, as the payments world becomes more complex, global, and interconnected, businesses simply do not have the luxury of waiting around for new guidance to come out before they update their practices. Cybersecurity is a living, breathing ecosystem, and payment stakeholders that prioritize both robust preventative and detectable cybersecurity measures, like anti-malware software and threat hunting and penetration testing, stand a much better chance of not only remaining compliant, but delivering a more secure and enjoyable experience for their customers.<\/p>\n<\/li>\n<\/ol>\n<p>PCI DSS v4.0 is a major marker for the future of cybersecurity health and performance of the payments card industry. However, in addition to meeting this compliance threshold, businesses must continue to look beyond this immediate guidance and engage in proactive cybersecurity strategies that continuously push the boundaries of their own security. If they can do this successfully, the payments card space stands a much greater chance of remaining one step ahead of adversaries and can establish greater trust with consumers for years to come.<\/p>\n<\/div>\n<\/div>\n<div id=\"articleFooter-newsletterSignup\" readability=\"10.473404255319\">\n<p>Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.<\/p>\n<p><a class=\"subscribe-btn dr-btn\" href=\"https:\/\/darkreading.tradepub.com\/c\/pubRD.mpl?secure=1&amp;sr=pp&amp;_t=pp:&amp;qf=w_defa3135&amp;ch=dr_eoa\" title=\"Subscribe\" target=\"_blank\" rel=\"noreferrer noopener\">Subscribe<\/a><\/div>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/making-sense-of-todays-payment-cybersecurity-landscape\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The surge in cybercrime activity since the outbreak of the<\/p>\n","protected":false},"author":12,"featured_media":1812,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1811","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1",310,310,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?resize=310%2C310&ssl=1",310,310,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?resize=310%2C310&ssl=1",310,310,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/making-sense-of-todays-payment-cybersecurity-landscape.png?fit=310%2C310&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1811","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1811"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1811\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1812"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1811"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1811"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}