About   Advertise   Archives   Education   Glenbrook   Jobs   Store   Views
Subscribe:

Data Security

Welcome to the News View for "Data Security".

Here, on these archive pages, you'll find all of the articles on Payments News for Data Security listed in date sequence beginning with the most recent article at the top of the page.

Click here for a complete listing of what's available in the Payments News Archive - organized by both posting date and subject category.

Subscribe to Payments News!

July 07, 2009

Lessons Learned from the Heartland Data Breach

Tags » Data Security, Heartland Payment Systems, PCI Compliance  » Comments (0)

HeartlandPayments_logo-140px.jpgBased on an interview with Heartland Payment Systems CEO Robert Carr, Rachael King writes for BusinessWeek about lessons learned during the Heartland data breach that began in 2008 and was discovered and announced in January 2009.

June 30, 2009

Heartland Completes First Phase of End-to-End Encryption Pilot

Tags » Data Security, End-to-End Encryption, Heartland Payment Systems, Merchant Acquirers, Security, Voltage Security  » Comments (0)

HeartlandPayments_logo-140px.jpgHeartland Payment Systems has announced that yesterday it successfully completed the first phase of its end-to-end encryption pilot project. According to the company, "this first step involved the transmission of live AES (Advanced Encryption Standard)-encrypted card transactions from a merchant to Heartland’s processing platform. AES is the highest level of encryption and is currently on track to replace DES (Data Encryption Standard) and Triple DES as the desired standard for sensitive data."

Earlier this month Heartland announced it was working with Voltage Security to develop its end-to-end encryption approach. READ MORE

June 24, 2009

Mercator Advisory Group Publishes End-to-End Encryption Report

Tags » Data Security, End-to-End Encryption, Mercator Advisory Group, Voltage Security  » Comments (0)

MercatorAdvisoryGroup_logo-140px.jpgMercator Advisory Group has published a new report, End-to-End Encryption: The Acquiring Side Responds to Data Loss and PCI Compliance that "explores end-to-end encryption (E2EE) in the hands of merchants, payment service providers and processors. In the face of the three bogies of PCI DSS compliance and penalties, reputational risk and direct financial loss, the acquiring half of the payments process is evaluating options for eliminating cleartext cardholder data from their systems. Tokenization (the subject of a recent Mercator report) and end-to-end encryption are the leading candidates. This report examines the complexity of E2EE within payments and enterprise security." READ MORE

June 22, 2009

Merchant Link, MICROS Extend Tokenization to Property Management

Tags » Data Security, Merchant Link, PCI Compliance  » Comments (0)

Merchant_Link_logo-140px.jpgMerchant Link has announced that it will offer later this year its TranactionVault hosted credit card security product and service to users of the latest version of the MICROS OPERA Property Management System (PMS). READ MORE

June 17, 2009

Heartland Selects Voltage Security for End-to-End Encryption

Tags » Data Security, Heartland Payment Systems, Merchant Acquirers, Security, Voltage Security  » Comments (0)

HeartlandPayments_logo-140px.jpgHeartland Payment Systems has selected Voltage Security as a partner to develop end-to-end encryption (E3) software specifically suited to payments processing.

“Heartland is developing a complete end-to-end encryption solution designed to protect cardholder data at all stages of a transaction – from card swipe through delivery to the card brands,” said Bob Carr, Heartland’s chairman and chief executive officer. “Together with Voltage, we are developing a comprehensive solution that currently does not exist.” READ MORE

June 16, 2009

"The Battle Over Personally Identifiable Information is Lost"

Tags » Banking Industry, Data Security, Privacy, TowerGroup  » Comments (0)

TowerGroup_logo-140px.jpgA new research report titled "Protecting Personal Information: We Lost the Battle, Can We Win the War?" by TowerGroup declares that the financial services industry has lost the battle to protect consumers' personally identifiable information (PII) data. TowerGroup's George Tubin points out that "in light of the loss or theft of hundreds of millions of data records containing PII, the financial services industry must consider the ramifications of past, present and future data losses." READ MORE

ThreatMetrix Tackles Mobile Commerce Security on Smartphones

Tags » Data Security, ECommerce Payments, Online Banking, ThreatMetrix  » Comments (0)

ThreatMetrix_logo-140px.jpgThreatMetrix has unveiled a new mobile security application for smartphone users called SafeAndSurf - a web browser that securely stores a smartphone user's personal data until he or she is ready to sign-on to a social network, execute an online banking transaction, or complete an ecommerce purchase. According to the company, "SafeAndSurf is the only mobile security application to safeguard a smartphone user's personal information and also allow the user to automatically insert that information to transaction data fields, a combination that allows consumers to shop, bank and play on their smartphones more safely and easily." SafeAndSurf is available today for use on the Apple iPhone. READ MORE

June 09, 2009

NACS, Merchant Groups Ask PCI Council to Lead Collaborative Effort

Tags » Data Security, Merchants, PCI Compliance, PCI Security Standards Council  » Comments (2)

The Payment Card Industry (PCI) Security Standards Council must take the lead in developing a collaborative approach with merchants in defining more open standards for future PCI Data Security Standard (DSS) requirements, stressed NACS (the National Association of Convenience Stores) and several other trade associations in a June 8 letter to the Council. READ MORE

May 29, 2009

Voltage Security Introduces Data Breach Index

Tags » Data Security, Security, Voltage Security  » Comments (0)

Voltage Security has introduced the Voltage Data Breach Index, a single at-a-glance view into the state of national and global data breaches.

According to Voltage, "the visual map brings data breach reporting to life, summarizing historical and real-time breaches, size and scope, types of records, regions affected, industry and more. Perhaps most interesting is that patterns in the data enable the creation of a predictive data breach model. This model predicts, for example, that 14 data breaches will, over the next year, each expose 1,000,000 or more records to potential use by criminals. And, at least one breach of over 10,000,000 records will affect nearly 5 percent of the U.S. population." A white paper is also available.

April 22, 2009

Hypercom, Ingenico, VeriFone Launch SPVA Payment Security Alliance

Tags » Data Security, Hypercom, Ingenico, PCI Compliance, PCI Security Standards Council, Point of Sale (POS), Verifone  » Comments (0)

Hypercom, Ingenico, and VeriFone have announced the formation of the Secure POS Vendor Alliance - SPVA, a non-profit business organization chartered with implementing common payment security standards among vendors of secure point-of-sale (POS) devices used by retailers, acquirers and cardholders alike. READ MORE

April 15, 2009

Verizon Business 2009 Data Breach Study

Tags » Data Security, PCI Compliance, Security  » Comments (0)

More electronic records were breached in 2008 than the previous four years combined, fueled by a targeting of the financial services industry and a strong involvement of organized crime, according to the "2009 Verizon Business Data Breach Investigations Report" released today. Full press release here. READ MORE

March 31, 2009

Do the Payment Card Industry Data Standards Reduce Cybercrime?

Tags » Data Security, Financial Regulators, PCI Security Standards Council  » Comments (1)

The US House of Representatives Subcommittee on Emerging Threats, Cybersecurity and Science and Technology is holding a hearing today on the subject: "Do the Payment Card Industry Data Standards Reduce Cybercrime?". Witnesses include representatives from the US Department of Justice, the Payment Card Industry Data Security Standards Council, Visa Inc., Michaels Stores, and the National Retail Federation. A webcast is available.

March 25, 2009

Bank Fraud Forum Blog Launched

Tags » Banking Blogs, Banking Industry, Card Fraud, Data Security, Security  » Comments (0)

The Bank Fraud Forum Blog has been launched by Memento Security.

Fraud is a serious issue that deserves serious discussion. The Bank Fraud Forum℠ has two primary objectives: 1) to convey insights, opinions and comments on the world of financial crime, and 2) to serve as an open, albeit virtual, forum for the fraud fighting community. Our goal is to offer intelligent, timely and thought-provoking analysis of trends, news, best practices and more.

March 19, 2009

Visa Holds Global Security Summit

Tags » Data Security, PCI Compliance, Security, Visa  » Comments (1)

Visa chief enterprise risk officer Ellen Richey told security experts today that payment card data fraud rates remain near historic lows despite economic woes and high-profile compromises, and called for continued industry investment, collaboration and innovation, three key components in keeping the electronic payment system secure in the future. She made her comments to a gathering of business, government, academic and law enforcement officials at Visa's Global Security Summit, its third cross-functional symposium on payment security, held in Washington, DC. READ MORE

February 12, 2009

Voltage SecureData Provides End-to-End Encryption of Data

Tags » Data Security, PCI Compliance, Security, Voltage Security  » Comments (0)

Voltage Security has announced major enhancements to Voltage SecureData, supporting more environments and platforms, including end-to-end encryption across distributed environments such as those used by retail and payment processors. "Voltage customers are finding it easier to protect their data end-to-end, comply with regulations and protect sensitive customer information from the moment it is collected." READ MORE

February 06, 2009

Data Breaches: What the Underground World of “Carding” Reveals

Tags » Card Fraud, Data Security, Financial Regulators, Security  » Comments (0)

Kimberly Kiefer Peretti of the Computer Crime and Intellectual Property Section of the US Department of Justice has authored a paper titled "Data Breaches: What the Underground World of “Carding” Reveals" icon_PDF_small.gif to be published in the Santa Clara Computer and High Technology Journal. READ MORE

January 27, 2009

Heartland Says It Accelerates Development of End-to-End Encryption

Tags » Data Security, Heartland Payment Systems, Merchant Acquirers, PCI Compliance, PCI Security Standards Council, Processors  » Comments (2)

Heartland Payment Systems has announced that "it has formed an internal department dedicated exclusively to the development of end-to-end encryption to protect merchant and consumer data used in financial transactions. For the past year, Robert O. Carr, Heartland's chairman and chief executive officer, has been advocating for payments industry adoption of this technology - which will protect data at rest as well as data in motion - as an improvement for payment transaction security." READ MORE

January 24, 2009

New Books on PCI-DSS Compliance

Tags » Books, Data Security, PCI Compliance, PCI Security Standards Council, Security  » Comments (0)

With all of the news this week surrounding the payment card data breach at Heartland Payments Systems, we've added a new section to the Payments News Bookstore with several new books covering the topic of PCI-DSS (Payment Card Industry-Data Security Standard) compliance. If you're aware of any we've missed, please send us Feedback and we'll add them to the bookstore.

In addition to these books about the subject, the PCI Security Standards Council website is a great starting point for learning more about PCI-DSS.

January 23, 2009

Heartland CEO Calls for Industry Cooperation to Fight Criminals

Tags » Data Security, Heartland Payment Systems, PCI Compliance, Security  » Comments (0)

Heartland Payment Systems issued a press release today saying that it had "added more than 400 merchants to its client base in the past few days - exceeding results for the same period from last year" - and including a statement from founder, chairman and CEO Robert O. Carr on the response his organization has made to the announcement earlier this week of a payment card data breach at Heartland. READ MORE

January 21, 2009

More on the Heartland Payment Systems Card Data Breach

Tags » Data Security, Heartland Payment Systems, Merchant Acquirers, PCI Compliance, Security  » Comments (1)

Eric Dash and Brad Stone report for the New York Times on the payment card data breach announced yesterday by Heartland Payment Systems. The compromise may have occurred as early as last May but wasn't detected until late last fall.

The Heartland breach also showed that in spite of the adoption of more stringent standards and tougher oversight by banks and credit card companies, consumers are still vulnerable."
You can follow the discussion about the Heartland card data breach among Twitter users and on our Other Blogs page.

January 20, 2009

Heartland Payment Systems Announces Major Card Data Breach

Tags » Data Security, Heartland Payment Systems, Merchant Acquirers, PCI Compliance, Security  » Comments (0)

Heartland Payment Systems has announced it has learned it was the victim of a security breach within its processing system in 2008. Heartland says it "believes the intrusion is contained." The company has created a website for "to provide information about this incident and advises cardholders to examine their monthly statements closely and report any suspicious activity to their card issuers."

Brian Krebs reports for the Washington Post that the breach "may have led to the compromise of more than 100 million credit and debit card transactions."

The data stolen includes the digital information encoded onto the magnetic stripe built into the backs of credit and debit cards. Armed with this data, thieves can fashion counterfeit credit cards by imprinting the same stolen information onto fabricated cards.

January 12, 2009

Fireman's Fund Offers First Payment Card Security Insurance

Tags » Data Security, Merchants, PCI Compliance  » Comments (0)

Fireman’s Fund Insurance Company has announced the introduction of what it's calling "the first coverage for retailers that experience a breach of their payment card security system." READ MORE

January 11, 2009

Peter Wayner's New Editions

Tags » Data Security, PCI Compliance, Privacy, Security  » Comments (0)

[Reposted from my personal blog: www.sjl.us]

I happened to hear from Peter Wayner that he's got new editions of both his Disappearing Cryptography (third edition) and Translucent Databases (second edition) now available.

Disappearing Cryptography is available from Amazon while it looks like Translucent Databases, for the moment anyway, is only available on the publisher's web site.

READ MORE

January 08, 2009

Ingenico Protects Payment Card Data from Terminal to Host

Tags » Data Security, Ingenico, Point of Sale (POS)  » Comments (0)

Ingenico has announced a new open architecture security enhancement, the Ingenico On-Guard solution, that the company says "will encrypt cardholder data from the transaction terminal to the merchant host, thus adding a significant security layer to card transactions that used to communicate in the clear. The new solution will be available on the Ingenico terminals sold in North America." READ MORE

December 23, 2008

RBS WorldPay Announces Compromise of Data Security

Tags » Data Security, Merchant Acquirers, Payroll Cards, Prepaid Cards and Stored Value Cards, RBS Lynk  » Comments (0)

In a press release titled "RBS WorldPay Announces Compromise of Data Security and Outlines Steps to Mitigate Risk", RBS WorldPay (formerly RBS Lynk), the U.S. payment processing arm of The Royal Bank of Scotland Group, announced that its computer system had been improperly accessed by an unauthorized party in early November.

According to more information provided on the RBS Worldpay web site, "the issue affected pre-paid cardholders and other individuals. Approximately 100 payroll cards have been used in a fraudulent manner and those cards have been de-activated. Our internal security professionals and outside experts are working with federal and state law enforcement authorities in an investigation of this event."

Legislative Responses to Data Breaches, Information Security Failures

Tags » Data Security, Financial Regulators, Privacy, Security  » Comments (0)

The Payment Cards Center of the Federal Reserve Bank of Philadelphia has published a new discussion paper titled "Legislative Responses to Data Breaches and Information Security Failures" icon_PDF_small.gif by Philip Keitel. READ MORE

December 08, 2008

Securing Cyberspace for the 44th Presidency

Tags » Data Security, ECommerce Payments, Mobile Banking, Mobile Payments, Online Banking  » Comments (0)

The Center for Strategic & International Studies (CSIS) Commission on Cybersecurity for the 44th Presidency has released its final report, "Securing Cyberspace for the 44th Presidency" icon_PDF_small.gif. "The Commission’s three major findings are: cybersecurity is now one of the major national security problems facing the U.S.; decisions and actions must respect American values related to privacy and civil liberties; and only a comprehensive national security strategy that embraces both the domestic and international aspects of cybersecurity will improve the situation."

November 17, 2008

PCI Security Standards Council Introduces Assessor QA Program

Tags » Data Security, PCI Compliance, PCI Security Standards Council  » Comments (1)

The PCI Security Standards Council (PCI SSC) has announced that it has launched a quality assurance program for Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs). According to the PCI SSC, "the new program was designed to provide QSAs and ASVs with a set of requirements that helps ensure they provide consistent, quality validation and assessment services to merchants and service providers." READ MORE

November 12, 2008

Understanding PCI DSS Version 1.2

Tags » Data Security, PCI Compliance, PCI Security Standards Council  » Comments (0)

The PCI Security Standards Council, the standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), has announced it will be offering a complimentary webinar, "Understanding PCI DSS Version 1.2,” to be held on Tuesday Nov. 25, 2008 at 11:30 a.m. EST and at 7:30 p.m. EST. The session will be repeated on Wednesday Dec. 17, 2008 at 10:30 a.m. EST and 8:30 p.m. EST. READ MORE

August 18, 2008

PCI Security Standards Council Issues Summary of Changes

Tags » Data Security, PCI Compliance, PCI Security Standards Council  » Comments (0)

The PCI Security Standards Council (PCI SSC) has announced the availability of a summary of forthcoming changes to PCI DSS as it moves from version 1.1 to the previously announced version 1.2 in October. READ MORE

Sponsors

News View

Payments Consultants

Subscribe

Search

Languages



Featured in Alltop
Glenbrook Partners

PAYMENTS NEWS IS PRODUCED BY AND IS A SERVICE MARK OF GLENBROOK PARTNERS, LLC
ISSN 1556-4487

Glenbrook's Consulting Services

  • Innovation and Strategy
  • Payments Product Development
  • Payments Market Assessments
  • Payments Vendor Selection
  • Merchant Payments Optimization
  • Payments Risk Management
  •  
  • To discuss how Glenbrook can
    help you
    , email us:

Glenbrook's Payments Education

  • Payments Boot Camp
  • Emerging Payments Roundtables
  • Special Focus Workshops
  • Private Payments Workshops
  •  
  •  
  •  
  • For more information on Glenbrook's payments education, email us:

Tools for Payments Professionals

  • Glenbrook Writings
  • Payments News
  • Payments Jobs
  • Payments Education
  • Payments Bookstore
  • Payments Glossary
  •  
  • To send us news that you'd like us to cover on Payments News, email us:

Contacts:                        
Compilation Copyright © 2002 - 2009 Glenbrook Partners LLC. All Rights Reserved.
Terms of Use        Privacy Policy        RSS Feed        Payments News RSS Feed

Subscribe to Payments News   

Follow Payments News on Twitter for Real-Time Updates