Why Merchants Keep Failing to Protect Card Data Fines
Total Page:16
File Type:pdf, Size:1020Kb
May/June 2018 www.isoandagent.com Why merchants keep failing to protect card data Fines. Bad publicity. Class actions. Are any of these penalties severe enough to stop data breaches? 001_ISO050618 1 4/24/18 4:16 PM Your Payment Partner of Choice E800 E500 E600 A920 Smart Retail Solutions Introducing PAX’s new Smart Retail Solutions. Sleek designs that make them look more like a tablet than a payment terminal. PAX has launched an application management platform for resellers and partners to manage applications with the PAX Smart Retail Solutions. US Headquarters: Regional O ce: 4901 Belfort Road, Suite 130 40 West Baseline Road, Suite 210 Jacksonville, FL 32256 Tempe, AZ 85283 +1-877-859-0099 | [email protected] +1-877-859-0099 | [email protected] © 2017 PAX Technology Limited. All Rights Reserved. PAX’s name and PAX’s logo are registered trademarks of PAX Technology Limited. All other products or services mentioned in this advertisement are trademarks, service marks, registered trademarks or registered service marks of their respective owners. pax-smart-retail-iso&agent.indd002_ISO050618 2 1 4/23/20184/23/18 5:10:10 8:02 AMPM Contents 10 Why merchants fail to protect data Are the incentives for protecting card data so lopsided that merchants feel little need to do more? Or is it wrong to ask merchants to fix the faults in a payment card ecosystem they had little hand in creating? Processing Cards Processing 04 14 20 An African startup builds on bitcoin A cryptocurrency debit card looks Why Verifone needs to be taken Bitpesa’s founder saw bitcoin as the next past the card networks’ limits private, despite its turnaround big thing, and stuck with her plan even The idea of a crypto debit card has been Verifone has worked hard to recover as the craze around cryptocurrencies done before — and in some cases, has from its self-inflicted wounds. But the started to fade. been shut down by the major card net- market it serves has also come a long works. MoxyOne has a new approach. way in recent years. Technology Technology Processing 06 Do B2B payments need a Venmo? 16 22 Bill.com sees its future in taking the les- Asian gig innovator Grab pulls Why merchants won’t care about sons of successful P2P apps like Venmo ahead of Uber the signature waiver rule and applying them to B2B payments. Uber has a well-deserved reputation The card networks have chosen to for payments innovation, but Grab has eliminate the signature requirement. But been far more ambitious. merchants may not rush to make any Compliance changes. 08 Processing U.K. fintechs try to offset Brexit disaster 18 U.K. fintech companies have two A London processor targets the U.S. choices: flee the country, or try to Checkout.com has big plans for ‘Brexit-proof’ their operations expansion, but wants to keep its target audience narrowly defined isoandagent.com May/June 2018 ISO&AGENT 1 001_ISO0518 1 4/25/2018 10:57:34 AM Editor’s View isoandagent.com 1 STATE STREET PLAZA, 27TH FLOOR NEW YORK, NY 10004 • (212) 803-8200 EDITOR Daniel Wolfe Do retailers strive 212-803-8397 [email protected] CONTRIBUTING EDITOR David Heun for security? ART DIRECTOR Robin Henriquez Data security is as important to merchants as ever, but GROUP EDITORIAL DIRECTOR, BANKING Richard Melville a growing number of breaches keep making headlines. [email protected] VP, RESEARCH Dana Jackson NATIONAL SALES MANAGER, ADVERTISING It’s fair to question whether merchants care enough Megan Downey 212-803-6092 about security, or whether they have the right tools in [email protected] place, or if they are not compliant with the expectations VP, CONTENT OPERATIONS AND CREATIVE SERVICES Paul Vogel of the payment card industry. But sooner or later, that DIRECTOR OF CREATIVE OPERATIONS Michael Chu blame has to get shared with the issuers and processors DIRECTOR OF CONTENT OPERATIONS that put merchants on the front lines of protecting their Theresa Hambel MARKETING MANAGER own card data. Deborah Vanderlinder If a merchant is breached, it suffers bad publicity, fines, FULFILLMENT MANAGER Christopher Onyekaba legal settlements and other consequences. But none of CUSTOMER SERVICE these are enough to put the company out of business. A few executives may lose 212-803-8500 [email protected] their jobs, but no one seriously expected the likes of Home Depot, Target and others to go out of business after being breached. And perhaps that’s the right outcome — these companies are victims, after all — but they may not have the right incentives in place. We all have locks on our doors, but do we all need a security alarm as well? Many merchants may not think so until it’s too late — they see themselves as low-risk because they have smaller CHIEF EXECUTIVE OFFICER ....................................Gemma Postlethwaite ticket prices or don’t sell luxury goods. But the card data they handle is every bit CHIEF FINANCIAL OFFICER ..................................................Robert Dennen EVP & CHIEF CONTENT OFFICER .................................David Longobardi as valuable as the card data handled by the giants of retail. CHIEF MARKETING OFFICER............................................... Matthew Yorke CHIEF SUBSCRIPTION OFFICER ........................................... Allison Adams The merchant acquiring industry can address this problem by educating SVP, CONFERENCES & EVENTS........................................... John DelMauro merchants and providing the appropriate tools and resources to better protect SVP, HUMAN RESOURCES ............................................................. Ying Wong payment card data. If the penalties aren’t harsh enough to scare merchants into doing more, there must be other ways to improve their approach to security. © 2018 ISO&Agent and SourceMedia, Inc. and ISO&Agent. ISO&Agent is published 6 times a year by SourceMedia, Inc., One State Street Plaza, 27th Floor New York, NY —Daniel Wolfe 10004. For customer service contact us at (212) 803-8500; email: [email protected]; or send correspondence to Customer Service, ISO&Agent, One State Street Plaza, 27th Floor New York NY 10004. For more information about reprints and licensing content from ISO&Agent, please visit www.SourceMediaReprints. com or contact PARS International Corp. (212) 221-9595. Those registered with the Copyright Clearance Center (222 Rosewood Drive, Danvers, Mass., 01923) have permission to photocopy articles. The fee is $10 per copy. Copying for other than personal use or internal reference is prohibited without express permission. This publication is designed to provide accurate and authoritative information regarding the subject matter covered. It is sold with the understanding that the publisher is not engaged in rendering financial, legal, accounting, tax, or other professional service. ISO&Agent is a trademark used herein under license. 2 ISO&AGENT May/June 2018 002_ISO050618 2 4/24/2018 6:08:09 PM Your attitude almost always determines your altitude in life. So does a direct relationship to upper management and excellent residual reporting tools. Soar away, my friends. Soar away. No one provides better training, tools, and support to grow and succeed. To start your journey to become an EMS agent, visit emsagent.com or call 866-211-0738. 003_ISO050618 3 4/23/2018 5:10:12 PM PROCESSING Bitcoin BitPesa’s niche sets it apart from pure bitcoin operations, by offering a range of options for cross-border pay- ments, accepting bank transfers and funds from licensed money transfer op- erators, in addition to bitcoin. Its plat- form blends mobile money, blockchain technology and bitcoin acceptance for cross-border business-to-business transactions. In certain cases, bitcoin offers an elegant solution for businesses in Africa making purchases from foreign suppliers in their own currency with its blockchain approach cutting out sever- al intermediaries, Rossiello explained. One example she gave is an African company that wants to import Jap- anese car parts from a vendor that Elizabeth Rossiello, founder of Nairobi-based BitPesa wants to get paid in yen. “Typically you’d need a foreign counterparty to assist in that kind of An African startup transaction, but BitPesa lets businesses use bitcoin or another currency to buy those supplies and avoid going through builds on bitcoin a foreign cash window,” Rossiello said. Bitpesa’s founder saw bitcoin as the next big thing, and “Customers can now do large trans- stuck with her plan as crypto’s power crumbled actions during African trading hours, where previously they had to operate on the schedule of brokers in other By Kate Fitzgerald countries, which also don’t recognize African holidays.” When jobs in banking dried up after the bitcoin’s reputational wounds as the BitPesa’s cloud-based API enables global economic crash in 2008, Eliza- cryptocurrency faces more regulatory seamless integration with partners, and beth Rossiello went to work in Africa at backlash and pricing volatility. with a U.K.- authorized payment insti- several microfinance operations, where “It can be frustrating, because this tution license since 2015, the company she saw firsthand how Kenya’s recently technology is new and the media is has the flexibility to take funds from launched M-Pesa mobile money service riding the waves of excitement and licensed money transfer operators in was transforming payments. collapsing optimism based on its price, bitcoin or hard currencies and pay out Then, Rossiello heard that cryptocur- while every day we’re over here demon- through a network