About   Advertise   Archives   Education   Glenbrook   Jobs   Store   Views   Subscribe:

Top Five Causes of Data Security Compromises

Tags » Data Security, PCI Compliance, Security, Visa  » Comments (0)

Visa USA and the U.S. Chamber of Commerce have announced their assessment of the five leading causes of data security breaches and offered immediate, specific prevention strategies for each.

"The single, most effective weapon in the battle against today's data theft is education," said Sean Heather, executive director, U.S. Chamber of Commerce. "We're very pleased to stand with Visa to bring vital, timely information from the front lines of fraud to companies across the country so they can take steps to reduce the threat to their own businesses."

The findings, which are described in a comprehensive security alert from Visa, came from a detailed review of the card security environment, including common fraud techniques, potential areas of weakness by card-accepting merchants, and emerging threats.

As outlined today, the five leading causes of card-related data breaches are:

  1. Storage of Magnetic Stripe Data -- The most common cause of data breaches occurs when a merchant or service provider stores sensitive information encoded on the card's magnetic stripe in violation of the PCI Data Security Standard. This can occur because a number of point- of-sale systems improperly store this data, and the merchant may not be aware of it.
  2. Missing or Outdated Security Patches -- In this scenario, hackers are able penetrate a merchant or service provider's systems because they have not installed up-to-date security patches, leaving their systems vulnerable to intrusion.
  3. Use of Vendor Supplied Default Settings and Passwords -- In many cases, merchants receive POS hardware or software from outside vendors who install them using default settings and passwords that are often widely known to hackers and easy to guess.
  4. SQL Injection -- Criminals use this technique to exploit Web-based applications for coding vulnerabilities and to attack a merchant's Internet applications (e.g. shopping carts).
  5. Unnecessary and Vulnerable Services on Servers -- Servers are often shipped by vendors with unnecessary services and applications that are enabled, although the user may not be aware of it. Because the services may not be required, security patches and upgrades may be ignored and the merchant system exposed to attack.
As part of its effort to help businesses keep their data secure, the U.S. Chamber is distributing the Visa security alert to its full membership of small and mid-sized businesses nationwide. In addition, the Chamber will also be working with its national network of local chambers of commerce to further ensure this valuable information reaches as many businesses as possible. The Visa alert along with helpful answers to data security questions can be found at the Chamber's web page http://www.uschamber.com/sb/security.

"The bottom line is that there are a number of relatively simple things any merchant can do to reduce their threat of fraud significantly," said Michael E. Smith, senior vice president, Enterprise Risk and Compliance at Visa USA. "Visa is committed to doing all we can to get this information out to those who need it most. We look forward to working with the U.S. Chamber to continue this effort in the months ahead." More information is available at http://www.uschamber.com/sb/security, http://www.visa.com/cisp (see alerts and bulletins) and http://www.visa.com/merchant.



Add your comment... (note that all comments are reviewed before they're published)

Feed You can follow this conversation by subscribing to the comment feed for this post.

If you have a TypeKey or TypePad account, please Sign In

Sponsors

News View

Payments Consultants

Subscribe

Search

Languages



Glenbrook Partners

PAYMENTS NEWS IS PRODUCED BY AND IS A SERVICE MARK OF GLENBROOK PARTNERS, LLC
ISSN 1556-4487

Glenbrook's Consulting Services

  • Innovation and Strategy
  • Payments Product Development
  • Payments Market Assessments
  • Payments Vendor Selection
  • Merchant Payments Optimization
  • Payments Risk Management
  •  
  • To discuss how Glenbrook can
    help you
    , email us:

Glenbrook's Payments Education

  • Payments Boot Camp
  • Emerging Payments Roundtables
  • Special Focus Workshops
  • Private Payments Workshops
  •  
  •  
  •  
  • For more information on Glenbrook's payments education, email us:

Tools for Payments Professionals

  • Glenbrook Writings
  • Payments News
  • Payments Jobs
  • Payments Education
  • Payments Bookstore
  • Payments Glossary
  •  
  • To send us news that you'd like us to cover on Payments News, email us:

Contacts:                        
Compilation Copyright © 2002 - 2009 Glenbrook Partners LLC. All Rights Reserved.
Terms of Use        Privacy Policy        RSS Feed        Payments News RSS Feed

Subscribe to Payments News   

Follow Payments News on Twitter for Real-Time Updates