Think your data is safe with PCI? Think Again.
You know your payment systems need to be PCI DSS compliant, but will that really keep your card information safe? Unfortunately, the answer is no.
PCI compliance is a great first step since it requires credit card numbers to be encrypted when stored or before being transmitted over public networks. However, beyond securing your network from outside intruders in general, there aren’t any regulations requirements specifically for:
- Securing communication between POS hardware and peripherals
- Encrypting credit card data before an authorization is obtained
- Encrypting credit card data transmitted across a private network
In other words, savvy thieves can find ways to steal your unencrypted data while it is still within the store’s private networks. In fact, many of the breaches that occur today are perpetrated on PCI compliant merchants.
Here is the problem:
You can see the obvious vulnerability inherent in even PCI complaint POS systems. MerchantWARE encrypts the data at the card reader, completely eliminating this vulnerability. With MerchantWARE, merchants never actually store or transmit any unencrypted credit card information.