Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > FIVE REASONS WHY EVERY CONTACT CENTRE SHOULD HAVE A PCI DSS COMPLIANCE PROGRAMME IN PLACE
    Technology

    FIVE REASONS WHY EVERY CONTACT CENTRE SHOULD HAVE A PCI DSS COMPLIANCE PROGRAMME IN PLACE

    FIVE REASONS WHY EVERY CONTACT CENTRE SHOULD HAVE A PCI DSS COMPLIANCE PROGRAMME IN PLACE

    Published by Gbaf News

    Posted on November 10, 2015

    Featured image for article about Technology

    BY ROB CRUTCHINGTON AT ENCODED

     With Christmas fast approaching, contact centres are preparing for an escalation in calls and transactions that the festive season brings.  However with payment card fraud continuing to rise and data theft constantly in the news, just look at the recent cyber attack on the Talk Talk consumer website, non-PCI DSS compliant contact centres could be risking more than just a fine.

     1)         News travels fast

    Survey findings from the Contact Babel, The UK Contact Centre Decision-Maker’s Guide 2015, worryingly revealed that almost a third of medium sized organisations have no compliance programme in place.  With several versions of the standard now available via SAQ (Self Assessment Questionnaire) there is little argument as to why a programme shouldn’t be at least road mapped.

    In the age of social media, where good news travels fast and bad news even faster can a brand afford for clients’ card data to be lost with the resulting PR backlash?

    Referring to the downloadable PDF of the VISA Merchant Agents List to engage with a trusted advisor is a useful first step to vetting vendors and avoiding fines and lawsuits, in the event of the unthinkable happening and customer card data being stolen.

     2)         The buck stops with the merchant

    Delivering a good customer experience is about more than swift call response times.  Paying for goods and services remotely is the norm for consumers and they expect their personal card account information to be kept safe.  Every contact centre that accepts credit and debit card payments over the telephone is responsible for safeguarding their customer’s information and can be held liable for security compromises.

    The Payment Card Industry Data Security Standard (PCI DSS) is intended to protect cardholder data wherever it resides and failure to comply with PCI DSS can result in hefty fines, not to mention the damage to reputation and lost sales.  By complying with PCI DSS, merchants and service providers meet their obligations to the payment eco-system and build a culture of security that benefits everyone.

     3)         PCI DSS Compliance is not a one off exercise

    PCI DSS is a change in mind-set, a change in attitude towards the handling of card data.  It’s not like other industry accreditations where organisations can prepare the night before an audit and scrape a pass.  It is the implementation of security procedures that will underpin the company’s behaviour when dealing with payments as well as how networks are designed, plus how access is granted and logged.

     PCI DSS compliance must be revisited every year and that takes time and resource, it is effectively a full time job.  Employing a compliance officer, who has the complete support of the contact centre management and the authority to update the status quo, ensures the required changes are driven through.

     4)         Awareness is increasing

    The Payment Card Industry Data Security Standard (PCI DSS) was originally the brainchild of the world’s five largest payment card providers VISA, MasterCard, American Express, Discover and JCB International. Today, it is a global framework that provides guidance on how to process, store and transmit information about payment cards and their owners, with the aim of reducing the incidence of card fraud and promoting best practice in information security.

      In the event of a loss of data or cards being used fraudulently, fines are passed down the chain from VISA and MasterCard at the top to the merchant/retailer at the bottom.  The consumer doesn’t suffer financially as measures are in place and assurances given to prevent this happening.  However, if something goes wrong, consumer brand loyalty can quickly fade.

    Customers transact with an organisation because they feel confident that their payment cards will not be compromised, their personal details are secure and their identities cannot be stolen.

    In the event of a security breach individuals will be inconvenienced and could suffer emotional distress at the thought of their details being stolen and used fraudulently.  This could lead to a reduction in customer confidence in both the method of payment and the retailer who caused the problem.  Reactive contact centres could find themselves quickly playing catch up as their customers vote with their feet.

     5)         Becoming and remaining PCI DSS compliant

    Every contact centre that accepts credit and debit card payments over the telephone needs to be PCI DSS compliant.  However, what many contact centres don’t realise is that PCI DSS covers the entire trading environment, meaning all third-party partners and vendors that handle card data on their behalf or supply services where card data is transmitted, must also comply before full PCI DSS compliance is achieved.

     The latest version of PCI DSS introduced a new requirement compelling service providers to supply a “Responsibility Matrix” which defines who is responsible for each of the 300+ PCI controls; namely the client, the supplier or both. It is worth stating at this point that PCI is not intended to trip up organisations or waste time; it is intended to secure cardholder data.  Achieving PCI DSS compliance increases trust between an organisation and its partners and suppliers and boosts customer confidence.

     The best way to minimise future costs as the standard evolves is to take good advice in the first place.  Minimise exposure to the primary risk areas such as staff and infrastructure.  Invest in training and education on the PCI DSS standard in order to have the talent in house and work with payment organisations that are themselves Level 1 PCI DSS compliant.  Remember there is no such thing as a compliant software solution.

     The moral of the story is – put a checklist in place, work with the right payment solution provider, get a compliance programme underway and have a safe, secure and profitable Christmas.

    Related Posts
    Treasury transformation must be built on accountability and trust
    Treasury transformation must be built on accountability and trust
    Financial services: a human-centric approach to managing risk
    Financial services: a human-centric approach to managing risk
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Technology

    Explore more articles in the Technology category

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Compliance Has Become an Engineering Problem

    Why Compliance Has Become an Engineering Problem

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    View All Technology Posts
    Previous Technology PostBLOCK CHAIN TECHNOLOGY: THE FINANCIAL SERVICES IT ENTERPRISE AWAITS?
    Next Technology PostSECURE CHIP TECHNOLOGY INDUSTRY ACHIEVES INTEROPERABILITY MILESTONE