Net at Work is hiring!
Grow your career with us.   Apply Now X
Need Help?
  • Application Remote Support
  • Infrastructure Remote Support
  • Sage HRMS Remote Support
  • Helpdesk
  • General Inquiry
1-800-719-3307
Net at Work Net at Work
  • Solutions & Services
    • ERP/Accounting
      Software & Vendor Selection
      ERP Implementation Services
      ERP Migration Services
      Acumatica
      NetSuite
      Sage X3
      Sage Intacct
      SDMO
      Sage 100 ERP
      Sage 300 ERP
      Sage 500 ERP
      CRM
      Strategic Advisory Services
      CRM Training Camp
      Creatio
      Sage CRM
      Employee Experience
      Sage HRMS
      Rippling
      Workforce Go
      Criterion
      Miviva
      Enterprise Content Management
      Imaging / Scanning
      Document Management
      Workflow Automation
      Solutions
      Nonprofit Solutions
      Abila by Community Brands
      NetSuite
      Sage
      Salesforce
      IT and Security Services
      Managed IT Services
      Fractional CIO Services
      Cloud Services
      Cloud at Work Sage Hosting
      DR/Business Continuity Planning
      Compliance & Security
      Storage & Recovery
      Networking
      IT Security Services
      Communications
      Web Solutions
      Services Overview
      B2B Technology Suite
      Magento eCommerce
      WordPress CMS
      Systems Integration
      Website Managed Services
      Online Marketing & SEO
      ERP eCommerce Integration
      Additional Solutions
      Enterprise Business Intelligence
      Avalara Automated Tax Solutions
      Fortis Payments
      Sage Fixed Assets
      Vertex SMB Sales and Use Tax
      Prime Foodservice Software
      Rental 360
  • Industries
    • Industries
      Chemicals
      Construction
      Discrete Manufacturing
      Field Service
      Food & Beverage
      Healthcare
      Industrial Manufacturing & Equipment
      Medical Devices
      Nonprofit
      Private Equity
      Retail
      Wholesale Distribution
  • Learning Center
    • Online Resources
      Recorded Webinars
      Whitepapers
      Ebooks
      Success Stories
      Upcoming Events
      Live Webinars
      Seminars
      Virtual Training Courses
      Training Courses
      View all available training course options
  • Company
    • Why Us
      Who We Are
      Management
      Our Partners
      Locations
      Careers
      News
      Press Releases
      Success Stories
      Net at Work Blog
      Contact Us
      1.800.719.3307
      Email Us
      Programs
      Alliance Partnership Program
      Women at Work
      Diversity and Inclusion
  • Blog
  • Contact Us
  • Contact Us

Home » Newsletters » Sage 300 Newsletter – Q2 2020 » COVID-19 Related Cybercrime and PCI Compliance: The Importance of Securing Credit Card Data

Sage 300

Sage 300 Newsletter – Q2 2020

Keeping You Up-To-Date With Information About Sage 300

COVID-19 Related Cybercrime and PCI Compliance: The Importance of Securing Credit Card Data

By: Net at Work Team

COVID-19 (Coronavirus) has caused all of us to rethink and revise the way we do business and the way we live in general. In the new environment where a majority of the workforce is working remotely, and businesses and consumers are making purchases online versus in a store, the opportunity for cybercriminals looking to phish, attack, scam and steal money or data increases.

For some businesses, accepting credit cards as a form of payment from their customers is now a necessity. Whether you are new to accepting credit cards, or it’s always been a natural part of your business, keeping cardholder data secure should be a top of mind priority. This means being PCI Compliant.

What is PCI Compliance?

The Payment Card Industry Data Security Standards (PCI DSS) is a set of regulations created by the major card brands to make transactions more secure and to protect them against identity theft and fraud.

Any merchant that wants to process, store or transmit credit card data is required to be PCI compliant, according to the PCI Compliance Security Standards Council.

There are 12 main PCI DSS requirements that all merchants must meet, regardless of their size or the number of transactions they process.

GOALS PCI DSS REQUIREMENTS
Build and Maintain a Secure Network 1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data 3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program 5. Use and regularly update anti-virus software or programs
6. Develop and maintain secure systems and applications
Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need-to-know
8. Assign a unique ID to each person with computer access
9. Restrict physical access to cardholder data
Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
Maintain an Information Security Policy 12. Maintain a policy that addresses information security for employees and contractors

Source: https://www.pcisecuritystandards.org

Additional regulations may be required depending on the number of transactions that are processed annually, but generally, most small-to-medium sized businesses fall under Level 4 which is less than 20,000 transactions per year, and the largest merchants fall under Level 1, processing more than 6 million transactions per year.

Level 4 merchants (processing less than 20,000 transactions annually) must complete a Self-Assessment Questionnaire (SAQ) through a Qualified Security Assessor. Most often, this service is offered through a partnership with your credit card processor at a significantly reduced cost. There are many advantages to going through the processor preferred vendor.

What if I’m not PCI Compliant?

PCI Compliance is not a law; however, it is a universally required set of regulations that all card brands mandate that you follow in order to avoid financial penalties. Most processors will tack on non-compliance fees to your merchant statement for not becoming compliant.

Not being PCI Compliant could potentially open your systems to a data breach. In 2019, the average cost per data breach in the U.S. was just over $8 million*. For most small businesses that means shutting the doors. Yes, that is the extreme, however there are also additional fines from the card brands that can reach $100,000 per incident. The fine amount depends on a company’s transaction volume, the number of PCI DSS requirements violated, and other factors. And you will need to pay it until you address the issue.

Being out of compliance can also be damaging to your brand. Data breaches can take years to recover from, if you recover at all. It’s better to comply with PCI standards.
*Source: https://www.ibm.com/security/data-breach

Staying Out of The Scope of PCI Compliance?

PCI Compliance is more than just the system you are using to process credit cards.

You will often hear credit card processors or software vendors say their system will keep you out of the scope of PCI Compliance. In my opinion, this is dangerously misleading. Remember, all merchants are required to be PCI Compliance. Yes, their system may be certified, it may keep cardholder data secure when it’s being used, but what’s to stop someone from writing a credit card number down on a sticky note or keeping an unencrypted spreadsheet full of credit card numbers?

To stay assured that PCI compliance is handled properly and that both yours and your customers’ data is safeguarded against potential breaches, pick a payment provider that meet all the PCI Level 1 compliance standards — the highest PCI level with the strictest requirements.

Conclusion

PCI DSS for merchants can be an extremely technical subject, but don’t get frustrated or give up. We are here to help. We have resources to guide you through the PCI certification process and a payment processing partner with PCI Level 1 compliance standards.

If you’re concerned or unsure about not being compliant or have questions about how to become compliant, reach out to us to setup a conversation.

« Return to Newsletter
  • This field is for validation purposes and should be left unchanged.
In This Issue
  • From the Desk of the Sage 300 Practice Director
  • Announcing the Release of Sage 300 v2020.2
  • Predict or Pray, You Know the Better Way: Business Intelligence Tools for Sage 300
  • Complimentary Virtual Sage 300 Training Courses
  • Sage 300 + Sage CRM: Quick Start/Pilot Programs
  • Don’t Let This Happen to Your Business: Taking Cyberthreats Seriously
  • The New Remote Workforce & The Case for Hosting Your Sage 300 Solution in the Cloud
  • COVID-19 Related Cybercrime and PCI Compliance: The Importance of Securing Credit Card Data
  • Sage 300 Support

    Helpdesk:
    P: 888.494.9479
    E: helpdesk@netatwork.com

    Upcoming Live Webinars

    Sage 300 Virtual Educational Courses – See Dates/Times

    Supercharge Sage 300 with Fortis Payments
    October 8 | 2pm ET
    Register Here

    Year End CRM Evaluation: 2025 Platform Comparison Guide
    October 8 | 2pm ET
    Register Here

    Stop Microsoft 365 Attacks Before They Hit
    October 14 | 2pm ET
    Register Here

    Popular Recorded Webinars

    The Case for Hosting Sage 300 in the Cloud

    Sage 300 & Finance Leadership in Action: Outpace the Competition for Top Talent

    Extend the Power of Sage 300 with Seamless eCommerce Integration

    Sage + DocLink – Document Management, Less Paper, and Smarter Workflow

    Sage 300 Webinar Archive

    View our library of on-demand recorded webinars.

    Newsletter Archive

    Read our previous Sage 300 Newsletters here

    Connect With Us

    Business Applications

    • Overview
    • Software & Vendor Selection
    • ERP Implementation Services
    • ERP Migration Services
    • Cloud ERP
    • CRM
    • Employee Experience
    • ECM
    • Nonprofit Solutions

    Learning Center

    • White Papers & Guides
    • Ebooks
    • Training Courses
    • Virtual Training Courses
    • Success Stories
    • Live Webinars
    • Recorded Webinars
    • Trials

    Infrastructure Solutions

    • Managed IT Services
    • Fractional CIO & Advisory Services
    • Cloud Services
    • Cloud at Work Sage Hosting

    Support

    • Application Remote Support
    • Infrastructure Remote Support
    • Sage HRMS Remote Support
    • General Inquiry
    • Helpdesk

    Web Development

    • Services Overview
    • Magento eCommerce
    • WordPress CMS
    • Systems Integration
    • Website Managed Services
    • ERP eCommerce Integration

    Company Information

    • Why Us
    • Alliance Partnership Program
    • Women at Work
    • Diversity and Inclusion
    • Partners
    • Careers
    • News
    • Blog
    • Privacy Policy
    • Contact Us

    Additional Solutions

    • Enterprise Business Intelligence
    • Avalara Automated Tax Solutions
    • Fortis Payments
    • LeaseQuery Lease Accounting
    • Sage Fixed Assets (Sage FAS)
    • Vertex SMB Sales and Use Tax
    • Prime Foodservice Software
    • Rental 360
    • SDMO

    Industries

    • Chemicals
    • Construction
    • Discrete Manufacturing
    • Field Service
    • Food & Beverage
    • Healthcare
    • Industrial Manufacturing & Equipment
    • Medical Devices
    • Nonprofit
    • Private Equity
    • Wholesale Distribution
    Net at Work
    Net at Work (HQ)
    575 8th Ave
    New York, NY 10018

    P: (800) 719-3307
    info@netatwork.com
    Locations Across North America »
    Visit our sister companies:
    Cloud at Work - Sage Application Hosting
    Pixafy - An eCommerce Agency
    Docutrend
    WordPress Image Lightbox Plugin


    Our website uses cookies to ensure you get the best experience. Learn more.

    I Understand