opinion

Keeping Cardholder Data Safe, Secure

Keeping Cardholder Data Safe, Secure

Congratulations. It is 2021 and, so far, your business has survived the Great Culling of 2020, the global pandemic of COVID-19

Just as some people found ways to improve themselves while quarantined by learning to bake bread or brew beer, or taking up reading or yoga, some businesses thrived under quarantine protocols. Whether your business thrived or struggled to survive, it is safe to say that the phrase “adapt or die” truly showed its relevance in 2020 — especially for small businesses.

More credit card transactions mean more opportunities for them and more security obligations for you.

If your business is web-based, like Amazon or DoorDash, these may be bonanza times for you. If you run a brick-and-mortar business, then depending on the state you live in, you may have had to modify your business model, at least temporarily, in ways that had never before crossed your mind. Restaurants and auto-parts stores adopted curbside pickup, for instance, or became cash-free environments. Suddenly, you found yourself taking orders and billing information over the telephone.

Regardless, it is great that your business has found a way to make it in this year of the new normal, but survival means new responsibilities because, as you are likely aware, legitimate business owners are not the only ones adapting to this new world; cybercriminals love it. More credit card transactions mean more opportunities for them and more security obligations for you.

You may believe your primary obligation is getting your product to your customer, but in the grand scheme of things, protecting your customers' personal information and cardholder data is more important. While ensuring your customer receives what they paid for is important, hard goods can easily be replaced, whereas a security breach that reveals your customer’s personal information and cardholder data can result in such problems as identity theft, and there is a great chance that your failure to provide adequate protection will result in the permanent loss of that person as a customer in the future.

It is pretty easy to figure out what a customer’s personal information consists of; the obvious elements like name, address, telephone number and date of birth certainly fall under the category of personal information, but what else does cardholder data encompass?

Cardholder data, for the purpose of this article, is the Personal Identifiable Information (PII) that is kept on the magnetic strip found on the back of any credit, debit or ATM card. The cardholder data stored is typically the account number, cardholder name and expiration date, as well as the service code, also known as the CVV or CVV2, depending on the bank issuing the card.

Fortunately, for consumers and merchants alike, there is the Payment Card Industry Security Standards Council, hereafter referred to as the PCI SSC.

The PCI SSC was created in 2006 by American Express, Discover, JCB International, MasterCard and Visa, and its mission is to enhance credit card data security by developing standards, practices and services. Part of this was accomplished with the establishment of the PCI Data Security Standard (PCI DSS).

The PCI DSS lists 12 requirements for a merchant to become PCI-compliant. These requirements range from the basics such as using a proper firewall to protect unauthorized access to the servers that store and transmit your customer’s cardholder data, and not using default passwords provided by any third-party vendors you might use. Additionally, updating anti-virus software, testing your security systems and establishing a policy that addresses information security for employees and any relevant contractors is required.

Whether your business is face-to-face with your customers inserting their credit card into a terminal, or your business is entirely web-based and you never interact with the customer or their credit card information, if you accept any credit or debit card as a means of payment, you have an obligation to be PCI-compliant to some degree.

Failure to be PCI-compliant can be expensive as the penalties levied by the credit card company on the acquiring bank (credit card bank) can range from $5,000 to $100,000 per month, in addition to possible legal action, loss of revenue and the inevitable loss of consumers' trust.

Fortunately, becoming PCI-compliant does not have to be as difficult as it might seem on the surface. You will have to fill out a self-assessment questionnaire and the associated Attestation of Compliance annually, but the technical portion is easy and usually free as most merchant service providers have partnered with certified PCI vendors and assessors.

Jonathan Corona has 15 years of experience in the electronic payments industry. As MobiusPay’s EVP, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards set forth by the card associations. MobiusPay specializes in merchant accounts in the U.S., EU and Asia. Follow them @MobiusPay on Twitter, Facebook and IG.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Complying With New Age Assurance and Content Moderation Standards

For adult companies operating in today’s increasingly regulated digital landscape, maintaining compliance with card brand requirements is essential — not only to safeguard your operations but also to ensure a safe and transparent environment for users.

Gavin Worrall ·
opinion

Understanding the FTC's New 'Click to Cancel' Rule

The Federal Trade Commission’s new “Click to Cancel” rule has been a hot topic in consumer protection and business regulation. Part of a broader effort to streamline cancellation processes for subscription services, the rule has sparked significant debate and legal challenges.

Corey D. Silverstein ·
opinion

Key Factors for Choosing a Merchant Services Partner

Running a successful adult business requires more than just delivering alluring and cutting-edge products and services. Securing the right payment processing partner is essential to maintaining a steady revenue stream.

Jonathan Corona ·
opinion

Identifying and Preventing Transaction Laundering

Recently, a few merchants approached me after receiving compliance notifications from their acquirer about transaction laundering. They were unsure what it meant, and unsure how to identify and fix the problem.

Cathy Beardsley ·
profile

WIA: Alexis Fawx Levels Up as Multifaceted Entrepreneur

As more performers look to diversify, expanding their range of revenue streams and promotional vehicles, some are spreading their entrepreneurial wings to create new businesses — including Alexis Fawx.

Women In Adult ·
opinion

Navigating Age-Related Regulations in Europe

Age verification measures are rapidly gaining momentum across Europe, with regulators stepping up efforts to protect children online. Recently, the U.K.’s communications regulator, Ofcom, updated its timeline for implementing the Online Safety Act, while France’s ARCOM has released technical guidance detailing age verification standards.

Gavin Worrall ·
opinion

Why Cyber Insurance Is Crucial for Adult Businesses

From streaming services and interactive platforms to ecommerce and virtual reality experiences, the adult industry has long stood at the forefront of online innovation. However, the same technology-forward approach that has enabled adult businesses to deliver unique and personalized content to consumers worldwide also exposes them to myriad risks.

Corey D. Silverstein ·
opinion

Best Practices for Payment Gateway Security

Securing digital payment transactions is critical for all businesses, but especially those in high-risk industries. Payment gateways are a core component of the digital payment ecosystem, and therefore must follow best practices to keep customer data safe.

Jonathan Corona ·
opinion

Ready for New Visa Acquirer Changes?

Next spring, Visa will roll out the U.S. version of its new Visa Acquirer Monitoring Program (VAMP), which goes into effect April 1, 2025. This follows Visa Europe, which rolled out VAMP back in June. VAMP charts a new path for acquirers to manage fraud and chargeback ratios.

Cathy Beardsley ·
opinion

How to Halt Hackers as Fraud Attacks Rise

For hackers, it’s often a game of trial and error. Bad actors will perform enumeration and account testing, repeating the same test on a system to look for vulnerabilities — and if you are not equipped with the proper tools, your merchant account could be the next target.

Cathy Beardsley ·
Show More