About   Advertise   Archives   Education   Glenbrook   Jobs   Store   Views   Subscribe:

Mercator Advisory Group Publishes End-to-End Encryption Report

Tags » Data Security, End-to-End Encryption, Mercator Advisory Group, Semtek, Voltage Security  » Comments (0)

MercatorAdvisoryGroup_logo-140px.jpgMercator Advisory Group has published a new report, End-to-End Encryption: The Acquiring Side Responds to Data Loss and PCI Compliance that "explores end-to-end encryption (E2EE) in the hands of merchants, payment service providers and processors. In the face of the three bogies of PCI DSS compliance and penalties, reputational risk and direct financial loss, the acquiring half of the payments process is evaluating options for eliminating cleartext cardholder data from their systems. Tokenization (the subject of a recent Mercator report) and end-to-end encryption are the leading candidates. This report examines the complexity of E2EE within payments and enterprise security."

"End-to-end encryption's beauty is very much in the beholder's eye. If you're a Tier one merchant in no mood to risk the reputational crisis of a data breach, using E2EE to rid your network of card data is a good move," George Peabody, Director of Mercator Advisory Group's Emerging Technologies Advisory Service and principal analyst on the report.

"E2EE also reduces the scope of PCI compliance audits and remediation costs but the beauty of encryption and card security will likely be lost on millions of Tier 4 merchants. Strong sales incentives and messaging will be required to have them join in the data protection fight."

  • End to end encryption (E2EE) is a long forestalled rational reaction to data breaches and PCI DSS audit costs.
  • The advantages to merchants of getting out from under a large set of PCI compliance burdens may make E2EE worthwhile.
  • Defining the "ends" in E2EE is a key step for every deployment.
  • The encryption zones under a processor's control - from the merchant's magstripe reader to the interconnection point with card brand or issuer - appear to be a manageable domain where the burdens of key management and new POS gear equal the benefits.
  • Standards development is in early days. A new working group under ASC X9 has brought together the key stakeholders, some of whom have sharply diverging goals.

    Companies and programs mentioned in this report include: Hypercom, VeriFone, Ingenico, MagTek, Magensa, Heartland Payment Systems, Visa, MasterCard, RBS Worldpay, RSA, Prime Factors, Verizon Business, Voltage Security, Semtek, Futurex, SafeNet, Transaction Network Services (TNS), Thales, Atos wordlwide, HP Attala, Banco de Credito e Inversiones, Propay, Fifth Third Bancorp, and EMVCo.

    Members of Mercator Advisory Group have access to these reports as well as the upcoming research for the year ahead, presentations, analyst access and other membership benefits. Please visit us online at http://www.mercatoradvisorygroup.com.



  • Add your comment... (note that all comments are reviewed before they're published)

    Feed You can follow this conversation by subscribing to the comment feed for this post.

    If you have a TypeKey or TypePad account, please Sign In

    Sponsors

    News View

    Payments Consultants

    Subscribe

    Search

    Languages



    Glenbrook Partners

    PAYMENTS NEWS IS PRODUCED BY AND IS A SERVICE MARK OF GLENBROOK PARTNERS, LLC
    ISSN 1556-4487

    Glenbrook's Consulting Services

    • Innovation and Strategy
    • Payments Product Development
    • Payments Market Assessments
    • Payments Vendor Selection
    • Merchant Payments Optimization
    • Payments Risk Management
    •  
    • To discuss how Glenbrook can
      help you
      , email us:

    Glenbrook's Payments Education

    • Payments Boot Camp
    • Emerging Payments Roundtables
    • Special Focus Workshops
    • Private Payments Workshops
    •  
    •  
    •  
    • For more information on Glenbrook's payments education, email us:

    Tools for Payments Professionals

    • Glenbrook Writings
    • Payments News
    • Payments Jobs
    • Payments Education
    • Payments Bookstore
    • Payments Glossary
    •  
    • To send us news that you'd like us to cover on Payments News, email us:

    Contacts:                        
    Compilation Copyright © 2002 - 2009 Glenbrook Partners LLC. All Rights Reserved.
    Terms of Use        Privacy Policy        RSS Feed        Payments News RSS Feed

    Subscribe to Payments News   

    Follow Payments News on Twitter for Real-Time Updates