PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Trustwave Exec Opines on PCI Mobile Guidance

By Mercator Advisory Group
October 29, 2012
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

In an online Op-Ed in SC Magazine UK, David Froud, Global Director of Practice Development at Trustwave, suggests the recent guidance on mobile payment security from the Payment Card Industry Security Standards Council will need to keep pace with market demands for evolving mobile technology. Froud identifies a “shift away from the credit card paradigm,” and points to Visa’s recent moves to incentivize EMV compliance through the Technology Innovation Program and secure more of the payment process through Point-to-Point Encryption as indicators of this shift.

…[N]ear field communication (NFC) and mobile payments (m-payments) have…opened the door for not only a more risk-based approach to PCI DSS, but for a total shift away from the credit card paradigm. Everyone from smartcard vendors, to mobile network operators (MNOs), to payment service providers (PSPs) and existing payments networks all want their piece of the pie. Combine this with the launch of services such as Google Wallet, the EU’s imminent approval of a mobile payment hub, and the raft of new handsets featuring NFC, and the question of how to protect the consumer from a security standpoint is brought into sharp focus.

Due to the nature of mobile devices today, any threat that exists for a computer will exist for a mobile device, resulting in a vastly increased exposure to data theft.

If m-payments are to take off as forecasted, the development focus needs to change so that security is ultimately part of the initial requirements analysis and that the use of customers data is either minimised, adequately encrypted or (preferably) both. This oversight needs to be addressed on two levels:

  • With the PCI SSC leading the charge with a series of best practice guidelines and enforcing regulations (something that would be difficult to do and achieve).
  • By educating and training developers on fundamental secure coding principles.

Ultimately, Froud echoes what seems to be the prevailing attitude among payment security experts, (and how Mercator concluded a recent report on Mobile Payment Security), when he says:

Currently there are few, if any, standard measurements for benchmarking application security during development. With the exception of the new, and granted, somewhat immature PCI SSC mobile recommendations, these will struggle to keep up with the developments in technology and security threats. The industry needs to come together to ensure that security is at the forefront of the development process with recommendations on topics such as outsourcing and controls to ensure that the authentication for transactions is secure.

Click here to read more from SC Magazine.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    payment gateways

    How Payment Gateways for Businesses Can Help You Offer Your Customers More Options

    February 10, 2026
    Reserve Bank of India (RBI) Extends Mandate for Tokenization to June '22

    Late Payments? Governments Are Taking Action

    February 9, 2026
    ai phishing

    The Fraud Epidemic Is Testing the Limits of Cybersecurity

    February 6, 2026
    stablecoins b2b payments

    Stablecoins and the Future of B2B Payments: Faster, Cheaper, Better

    February 5, 2026
    Payment Facilitator

    The Payment Facilitator Model as a Growth Strategy for ISVs

    February 4, 2026
    Simplifying Payment Processing? Payment Orchestration Can Help , multi-acquiring merchants

    Multi-Acquiring Is the New Standard—Are Merchants Ready?

    February 3, 2026
    ACH Network, credit-push fraud, ACH payments growth

    What’s Driving the Rapid Growth in ACH Payments

    February 2, 2026
    chatgpt payments

    How Merchants Should Navigate the Rise of Agentic AI

    January 30, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result