Merchant Services What You Need to Know. Agenda 6/5/2017. Overview of Merchant Services. EMV, Tokenization/Encryption, and PCI (Oh My!

Similar documents
PCI COMPLIANCE PCI COMPLIANCE RESPONSE BREACH VULNERABLE SECURITY TECHNOLOGY INTERNET ISSUES STRATEGY APPS INFRASTRUCTURE LOGS

C&H Financial Services. PCI and Tin Compliance Basics

The Changing Landscape of Card Acceptance

FIS Global Retail Payments. Centralize your enterprise with ONE trusted partner.

Semi-Integrated EMV Payment Solution

Payment Card Industry Compliance. May 12, 2011

EMV and Educational Institutions:

Top 5 Facts Merchants Need To Know About EMV

EMV Chip Cards. Table of Contents GENERAL BACKGROUND GENERAL FAQ FREQUENTLY ASKED QUESTIONS GENERAL BACKGROUND...1 GENERAL FAQ MERCHANT FAQ...

EMV THE DEFINITIVE GUIDE FOR US MERCHANTS AND POS RESELLERS

falanx Cyber PCI-DSS: How can your organisation achieve and maintain compliance?

EMV Just the Facts. Ozarks Association of Government Accountants

FOR A BARRIER-FREE PAYMENT PROCESSING SOLUTION

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services

Credit and Debit Card Fraud

Ignite Payment s Program on EMV

SAMPLE DATA FLOW DIAGRAMS for MERCHANT ENVIRONMENTS

EMV, PCI, Tokenization, Encryption What You Should Know for Presented by: The Bryan Cave Payments Team

Version 7.4 & higher is Critical for all Customers Processing Credit Cards!

Covering Your Assets: Payment Landscape and Technology

It s Not Too Late for EMV What You Need To Do Now!

Getting Out of PA-DSS Scope and Eliminating the High Cost of EMV: What you need to know

Straight Answers on PCI and EMV

Merchant Considerations for U.S. Chip Migration. EMV Migration Forum/National Retail Federation September 2014

Merchant Considerations for U.S. Chip Migration. EMV Migration Forum/National Retail Federation September 2014

Introduction. Scott Jerabek. The CBORD Group. Product Manager

Hot Topics in Payments Cornerstone CU League Small CU Committee July 9, 2014

Attachment 2: Merchant Card Services

Dates Visa MasterCard Discover American Express. Acquirers, subprocessors. support EMV. International ATM liability shift 2

Agenda. What is EMV. Chip vs Mag Stripe. Benefits of EMV. Timeframes & Liability Shift. Costs. Things to consider. Questions

PCI FAQS AND MYTHS. Presented by BluePay

Introduction to EMV BEYOND PAYMENT

PCI Toolkit

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD SELF-ASSESSMENT QUESTIONNAIRE (SAQ) A GUIDE

EMV FAQ S FROM A MERCHANT S PERSPECTIVE

EMV Terminology Guide

EMV Basics and the market

How EMV Compliance is Enhancing Self-Service Bill Payment

PROTECT AGAINST A DATA BREACH & ADDRESS PCI DSS COMPLIANCE WITH TRUSTCOMMERCE

Virtual Terminal User Guide

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 04/29/2016

Self-Assessment Questionnaire (SAQ) A and Attestation of Compliance Guidance Document. Self-Assessment Questionnaire A

PCI Information Session. May NCSU PCI Team

PCI DSS Security Awareness Training. The University of Tennessee and The University of Tennessee Foundation. for Credit Card Merchants at

Let s Talk about EMV. getnationwide.com

A CryptoCodex Ltd. Product

EMV Cards - Chipping Away at Fraud

COLUMBIA UNIVERSITY CREDIT CARD ACCEPTANCE AND PROCESSING POLICY

esocket POS Integrated POS solution Knet

International Operators Seminar. Bem-vindo! Bienvenidos! Bonjour! Croeso! Foon ying! Hujambo! Velkomen! Welkom! Welcome!

ATM Webinar Questions and Answers May, 2014

E M V O V E R V I E W. July 2014

FI0311 Credit Card Processing

PCI Gap Analysis 3/10/2014

Secure Remote Payment Council (SRPc) White Paper Discussion: EMV Enhancements Post Implementation September 13, 2016

Risk-based Approach to PCI DSS Validation

Crash Course: What are EMV and the EMV Liability Shift?

EMV & Fraud POS Fraud Mitigation Tips for Merchants First Data Corporation. All Rights Reserved.

Is Your Organization Ready for the EMV Challenge?

WHO, WHAT, WHY: PCI. Tess Casey Flanagan Senior Manager and Counsel, Global Compliance Operations

ILLINOIS COMMUNITY COLLEGE CFO CONFERENCE 2014

112 th Annual Conference May 6-9, 2018 St. Louis, Missouri

EMV Beyond October 1, Kristi Kuehn VP, Compliance Heartland

Receivables and Secure Payment Processing

EMV: The Next Generation of Payments

EMV: The Race Is On! September 24, 2013

Online Payment Services

PCI DSS SECURITY AWARENESS

The Small Business Guide to Mastering EMV

Tokenization: The Future of Payments

VARTECH NATION. EMV Certification for IT Professionals

EMV Migration Forum. How EMV Significantly Lessens the Impacts of Data Breaches. David Worthington, Principal Consultant// 12th March 2014

Business Administrator Forum

DIGITAL CREDIT for EMV QR Credit Card Apps

Evaluating Processing Infrastructure, Support & Costs

Payment Processing Solutions for MEDICAL OFFICES

Verifone MX 915/925 Payment Devices. with KWI 6.x POS Registers: What s New?

Leveraging Data Security Technology. October 19 th 9:15 AM

North America Terminal Brochure Guide

Heartland Payment Systems

EMV for Merchants and Merchant Acquirers: U.S. Migration Considerations. Smart Card Alliance Webinar October 6, 2011

EMV is coming. Here s how to stay ahead of the trend. Presented by CO-OP Financial Services

EMV Adoption in the U.S.

THE ADOPTION OF EMV TECHNOLOGY IN THE U.S. By Guy Berg Global Industry Sales Consultant Datacard Group

What Do Merchants Need to Be Successful Online?

Payment Gateway Overview. Get familiar with credit card processing & our platform

Payment Card Industry Data Security Standard Self-Assessment Questionnaire B Guide

Understanding the 2015 U.S. Fraud Liability Shifts

EMV: GET READY. Michelle Thornton, CO-OP Financial Services

EMV Implementation Guide

Datacap s Guide to EMV in the US

TAS FOCUS ON. The absolute framework for electronic payment management. cashless 3.0: the ultimate. payment experience IN THIS DOCUMENT

Card Payment acceptance at Common Use positions at airports

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Onsite Assessments Service Providers. Version 1.

Adding Business Value with Integrated Payment Solutions

EMV Frequently Asked Questions for Merchants May, 2015

The State of EMV Harland Clarke Card Services

Protecting Payments Throughout the Ecosystem. Emma Sutcliffe Senior Director, Data Security Standards PCI Security Standards Council

Accepting EMV Chip Cards at the Fuel Pump. September 20, 2017

ACCEPTANCE BREAKING THROUGH THE DIGITAL AGE TO EXPAND TRANSACTIONS FOOTPRINT

Transcription:

Merchant Services What You Need to Know Heather Nowak VP, CPP Senior Product Manager Agenda Overview of Merchant Services Why accept cards? What you need to know/consider Capabilities/Pricing/Contract Hardware/Software Ongoing Support EMV, Tokenization/Encryption, and PCI (Oh My!) What s the difference? PCI - Let s take a closer look 2 1

Overview of Merchant Services 3 Why Accept Cards? - 83% of consumers prefer to pay via card (credit card or debit card) - Customer convenience - Security for entity (no cash handling) - Increases cash flow timeframe for merchant/business - Multiple ways to accept cards (terminal, tablet, phone, website) 4 2

What You Need to Know/Consider: - Capabilities Is integration needed with internal systems? Reporting Requirements? Card only solution or other capabilities needed (check, ACH) - Pricing Various pricing models exist will depend on your card volume, types of cards accepted, average ticket Other Fees: Association Fees (MasterCard/Visa) Tokenization/Encryption costs Non PCI- Compliant - Ongoing Support Understand the support model and ensure it aligns with your expectations Sales representative? Call Center? Relationship Manager? Hardware/Gateway support 5 EMV, Tokenization/Encryption, and PCI (Oh My!) 6 3

What s the Difference? - EMV Fraud liability shift to all point-of-sale devices (except Automated Fuel Dispensers) took effect October 2016 Liability for counterfeit fraud transactions shifts to merchant if cardholder presents and EMV capable card but the merchant does not have the technology to accept the EMV card - Tokenization/Encryption Tokenization protects cardholder data after authorization so it can only be used on the processors network (changes card information into random digits worthless to hacker) Encryption protects cardholder data from point of swipe, at a terminal, until it reaches the processors network for authorization (end to end encryption) PCI (Payment Card Industry Data Security Standard) https://www.pcisecuritystandards.org Certification required by Associations (MasterCard/Visa) Questionnaire completion and scans of websites Submission of certification Annual process 7 PCI A Few Fun Facts PCI DSS compliance has increased by 167% since 2012 69% of consumers would be less inclined to do business with a breached organization 8 4

PCI Let s Take a Closer Look PCI Data Security Requirements (applicable to anyone who accepts or processes cards) Build and Maintain a strong network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy 9 PCI Let s Take a Closer Look How to protect your business: Buy and use only approved PIN entry devices at your points-of-sale. Buy and use only validated payment software at your POS or website shopping cart. Do not store any sensitive cardholder data in computers or on paper. Use a firewall on your network and PCs. Make sure your wireless router is password-protected and uses encryption. Use strong passwords. Be sure to change default passwords on hardware and software most are unsafe. Regularly check PIN entry devices and PCs to make sure no one has installed rogue software or skimming devices. Teach your employees about security and protecting cardholder data. * - https://www.pcisecuritystandards.org/pci_security 10 5

PCI Let s Take a Closer Look The PCI 3-Step Process* Assess. Identifying cardholder data, taking an inventory of IT assets and business processes for payment card processing, and analyzing them for vulnerabilities. Remediate. Fixing vulnerabilities and eliminating the storage of cardholder data unless absolutely necessary. Report. Compiling and submitting required reports to the appropriate acquiring bank and card brands. * - https://www.pcisecuritystandards.org/pci_security/how 11 Contact Information: Heather Nowak Phone: 419-720-7708 Email: Heather.Nowak@Huntington.com 12 6