Payment card fraud – a radical but accessible approach to minimising risk 

Pete Woodward, Securious Cofounder and CEO, recently delivered a talk at the South West Fraud Forum Annual Conference about addressing payment card fraud. Read a summary of his session below.

Fraud usually isn’t random. It’s structured, scalable, and run like a business – and an increasingly slick one at that.  

And no longer is fraud just the work of lone hackers; it is dominated by well-organised criminal groups with hierarchies and specialised roles (like hackers, money mules, and social engineers). 

These cyber criminal organisations have websites, portals, supply chains, customer support, automation, loyalty programs, and even money-back guarantees on stolen card data. 

It’s effectively an industry worth billions. 

Within the overall universe of data breaches, payment card data is one of the biggest prizes .  

A successful breach might involve the card account numbers, the cardholder names, the expiration dates and the CVV codes. 

In addition, they might gain access to PIN numbers, billing addresses, account holder email addresses, phone numbers, transaction histories and much more. 

It doesn’t take much imagination to see why this kind of data, obtained at any scale, is so valuable and why there are thriving markets for it on the dark web. 

This is why there are special requirements for any organisation handling or storing payment card details, and that includes those that use a third party payment provider.  

So today I want to talk specifically about payment card data breaches, what the consequences are for any organisation that is responsible for a breach and, most importantly, what they can and should do to prevent it happening.  

Payment Card Fraud – the cost of being a breach point 

Ok, so we have a sense of the scale of payment card fraud – what I’d like to do now is switch the focus to the consequences for an individual organisation if they are the ones where the card data breach occurs. 

As you can probably imagine, it’s not pretty.  

I’m often called in to help organisations in this situation. 

From cold, hard shock at first to panic as the potential consequences become clear, I can assure you that it is normally a devastating and traumatic experience for all involved. 

You may be familiar with some of the major organisations that have suffered data breaches in recent years, including British Airways, Dixons Carphone Warehouse, Ticketmaster, and you’ll have heard about the multi-million pound fines and reputational damage that followed. 

But what you might be less familiar with is the impact a card data breach can have on much smaller organisations who might not get the media headlines but can suffer devastating consequences.  

These can be businesses, public sector organisations, healthcare providers, charities and basically anyonethat takes payment by card – trust me, the cyber criminals have no scruples. 

Let’s consider some of the consequences they have to deal with in the aftermath of a card data breach: 

If an organisation is named as a Point of Compromise, they will have to pay for forensic investigations, which can cost many tens of thousands of pounds.  

They will also have to pay fines if the breach occurred because they were not compliant with the mandatory Payment Card Industry Data Security Standard (PCI DSS), which I’ll come on to talk about in a moment.  

They will face increased processing fees due to chargebacks, and that’s not to mention the legal costs, regulatory scrutiny, and the sometimes irreparable reputational damage. 

And they have to deal with all this when they are normally completely unprepared, and while somehow trying to continue with business as usual at the same time. 

As I said before, you wouldn’t wish it on your worst enemy. 

So how should organisations minimise their risk: the real value of PCI Compliance 

So, what can organisations do to protect themselves and their customers’ data? 

That’s a huge question with a potentially massive scope.  

But I want to focus today on one area, and that’s the importance of good PCI DSS Compliance.  

Every business that takes card payment needs to be PCI compliant, but what I would like to stress is that effective PCI compliance should be far more than a box-ticking exercise – done well, it is probably the best thing you can do to mitigate the likelihood and risk of a data card breach. 

So what am I talking about?  

Well, it is critical to make sure that, if you process, store, or transmit cardholder data, you are compliant with the PCI DSS, which is a comprehensive set of requirements designed to increase data security and protect merchants, service providers, and customers when taking and making payments by debit or credit card. 

In the past, PCI DSS compliance for merchants of any significant size was often seen as a once a year assessment, a bit like a car MOT.  

But that’s a very dangerous approach and it is one the PCI Council is moving hard to change.  

Ultimately, it’s no good being in great shape and compliant once a year – you need to be compliant 24/7, 365 days a year to minimise the risk.  

And that means a different mindset and a different approach where you focus on pursuing continuous compliance rather than only having all your ducks in a row for the annual assessment.  

And while this can seem like an unwelcome complication, it’s actually very liberating for organisations.  

Not only do they avoid a massive panic for that once-a-year inspection, they also develop systems and processes that keep their barriers high all year round.  

And if something does go wrong – because it always can – then they are in the best possible place to limit the damage, both actually and reputationally. Why? Because it’s a proven fact that organisation who suffer a data breach but can show they had taken reasonable steps to avoid it bounce back far quicker than those who appear to have been unprepared. 

So I’m not suggesting PCI compliance is the be all and end all of security, but as a Qualified Security Assessor (QSA) and the founder of Securious, a cyber security company dedicated to helping organisations achieve and maintain PCI DSS compliance, I’ve seen first-hand how businesses can either make themselves a soft target or a hardened one.  

Compliance is not a box-ticking exercise; it’s a robust security framework that, when implemented properly, makes a real difference in reducing fraud risks. 

Final thoughts 

To sum this all up…

These days, cyber criminals operate like businesses, and extremely slick ones at that.  

Once they have a victim on the hook, they are shameless in their focus on doing all they can to extract as much money from that organisation as possible.  

Obviously avoiding a card data breach is easier said than done, because if enough resources are deployed, virtually any organisation can be vulnerable.  

But realistically, it is the weakest links that are the biggest risks and there is a very effective way of ensuring you aren’t the low hanging fruit – and that’s to ensure you are compliant with the PCI DSS on an ongoing basis. 

My recommendations therefore are:  

First, stop thinking about or treating the requirement to be PCI DSS compliant as a nuisance and embrace it as a way of staying safe and protecting your business (as well as your customers) 

Second, stop thinking of PCI DSS compliance as a once-a-year assessment that you can forget about for the next eleven months and instead adopt the mindset of continuous compliance, with robust processes and systems that minimise the risk every day all year. 

For more information about PCI DSS, check out our Ultimate Guide.