Blog

  • Which Industries Are Most Affected By GDPR?

    Which Industries Are Most Affected By GDPR?

    Since the General Data Protection Regulation (GDPR) was enforced on May 25, 2018, many have complied with it lest they face unprecedented non-compliance fines and other consequences. GDPR, at its core, is the new set of rules designed for EU individuals to give them more control over their data. Its objective is to make the regulatory environment simple so that both businesses and their customers in the EU can ultimately benefit from the digital economy. 

    In this article, we’ll be tackling the top industries affected by GDPR, the challenges that they face since the regulation has come into effect over a year ago, and the benefits they receive from this data privacy law. These industries are the following: social media, online retail, digital banking, cloud computing, and healthcare. 

    (more…)

  • BYOD Security Checklist & Best Practices

    BYOD Security Checklist & Best Practices

    Cybersecurity owns the headlines on a weekly basis and for good reason. Data theft shows no signs of stopping, making security paramount. Cybersecurity extends beyond your mainframe, including mobile and employees alike. Read on to check out our Bring Your Own Device (BYOD) security checklist and best practices.

    (more…)

  • Is Stripe PCI Compliant?

    Is Stripe PCI Compliant?

    Is Stripe PCI Compliant? If you implement it properly, the answer is yes, Stripe is completely PCI compliant!

    Stripe is a popular platform that makes it easy for businesses to accept credit and debit cards over the internet quickly and securely. Ridesharing company Lyft uses Stripe to power its payment solution for 700,000 drivers around the world, and that’s just one company. This payment service moves billions of dollars a year and is used by tens of thousands of companies around the world, from small scrappy startups to established Fortune 500s.

    You don’t become a leading plug-and-play payment solution provider by accident. You do it by making it quick and painless for companies to accept credit card payments at scale. It’s not always easy for companies to meet the stringent security standards for processing online payments, let alone other personally identifiable information like birthdays and addresses.  This requires a lot of technical expertise, expensive hardware, and active attention for companies to achieve that on their own.

    (more…)

  • How To Perform A PCI Vulnerability Scan

    How To Perform A PCI Vulnerability Scan

    Wherever people are legally transacting money for goods, there are going to be bad guys in search of a score. It’s just the unfortunate reality of our world increasingly moving to the internet for its needs — wherever the good guys go to transact and do business, the bad guys will follow them in an effort to manipulate and rip off.

    As the American e-commerce industry grew by 14.2% in 2018 to total more than $517 billion in transactions, you can be sure that cybercriminals are at work to con people out of their money and personally identifiable information. Consumers can take certain steps to establish their own security, but they must fundamentally share some of this information in order to complete transactions online. They can’t be responsible for protecting information that they necessarily part with.

    The burden to protect this information — we’re talking about credit card numbers, security codes, and the like — lies with the businesses that process it. The best of these businesses pursue PCI compliance because they know that it’s an important feather in their cap for retaining consumer trust and pushing back against any would-be cybercriminals.

    For those businesses that don’t know where they stand on the PCI compliance front, they only need to conduct a vulnerability scan.

    (more…)

  • PCI Expert Summit 2019: Event Recap

    PCI Expert Summit 2019: Event Recap

    RSI Security’s first-ever PCI Expert Summit is in the books, and we couldn’t be happier about how things turned out!

    Marina Village Conference Center – San Diego, California

    On October 2nd we were joined by four speakers, a number of sponsors, an expert panel, and over 70 attendees to begin the process of building a strong, vibrant PCI compliance community in the Southern California area. The event took place at the beautiful Marina Village Conference Center in San Diego.

    “I found the event to be very informative. It was also nice to be around other folks I’ve worked with previously but haven’t actually met in person. It was definitely worth the time coming down for what I hope to be the first of many future RSI Summits,” said Gurpal Singh, head of compliance at Finix Payments. 

    (more…)

  • How To Avoid PCI Noncompliance Fees

    How To Avoid PCI Noncompliance Fees

    Just as professional athletes or motorists pay fines when they break certain rules, the same applies to companies doing business online. But the rules governing these companies’ behavior goes beyond “unsportsmanlike conduct” or “following the speed limit.” When they collect and process payment information for debit and credit cards, they must adhere to a number of rules in the process. If they break those rules, then they’re on the line to pay a penalty for it.

    If it’s expensive to ignore the rules, why are an increased number of companies doing so? Verizon’s 2018 Payment Security Report reveals a drop in PCI compliance, which are the standards that companies have to stick to in order to process payment information online. Where 55.4 percent of companies were compliant in 2017, that number shrank to 52.5 percent in 2018. Chalk it up to lack of awareness or other shortcomings, but companies leave themselves and their customers exposed to bad actors when they shun this kind of compliance.

    Beyond merely leaving themselves and their customers vulnerable to data breaches and cyberattacks, this decreased regard for the best practices pertaining to collecting payment card data and other personally identifiable information leaves these companies on the hook for noncompliance fees. It might not be as exciting or interesting as a professional athlete paying his or her commission for uttering an expletive during a game, but it can still be just as expensive.

    (more…)

  • What Does PCI Stand For, And What Does It Mean For My Business?

    What Does PCI Stand For, And What Does It Mean For My Business?

    PCI compliance” might sound boring and technical, but it’s a major focal point for any business that handles online credit or debit card payments. In 2019, that’s most businesses! 

    The internet has completely changed the way we shop and transact — where we used to go to brick and mortar stores in order to spend cash or swipe a card in exchange for the goods we want, this entire experience can now happen from the comfort of your home.

    (more…)

  • How To Become PCI Compliant — A Step by Step Guide 

    How To Become PCI Compliant — A Step by Step Guide 

    In times of widespread concern about cyberattacks and phishing attempts, it turns out that there’s a clear roadmap to protect your business from malicious hackers — your business only needs to pursue PCI compliance. But what is this term, and what is it all about?

    Payment card industry (PCI) compliance refers to the standards that companies have to stick to in order to process payment information online. These best practices are collectively known as the Payment Card Industry Data Security Standard (PCI DSS), and they were created by the PCI Security Standards Council (PCI SSC). This set of best practices works to increase controls and protection around cardholder data while simultaneously reducing credit card fraud.

    Just as you might see homes advertising the security systems they’ve installed (“protected by Brinks,” for example), PCI compliance is a similar demonstration that a company has taken steps to protect its systems and infrastructure. When you make your business PCI compliant, it represents major progress toward protecting your customers from data breaches and protecting your business against cyberattacks. It’s completely in your interest if your company processes payments online.

    (more…)

  • How Can Healthcare Organizations Leverage HITRUST Framework?

    How Can Healthcare Organizations Leverage HITRUST Framework?

    Healthcare organizations not only have to be HIPAA and HITECH compliant, but they also have to ensure that their business associates are compliant as well. Which makes sense; if electronic health records (EHRs) are being passed from one healthcare organization to another company, the information is still private and needs to be secured. To ensure this is the case, many organizations are requiring business associates to adopt HITRUST’s data and data security framework, while implementing it internally themselves.

    To what degree these business associates are mandated to adopt the HITRUST security framework depends on the healthcare organization. Although leveraging the framework to some degree will significantly protect both the healthcare organization and the associate in the case of an audit.

    To understand why organizations are leveraging the HITRUST framework and how it can help, read ahead.

    (more…)

  • How HITRUST Is Growing It’s Privacy Controls For Greater Security

    How HITRUST Is Growing It’s Privacy Controls For Greater Security

    There are plenty of industries with which government intervention plays a necessary role. Unarguably, they provide for national defense, a platform for international relations and foreign policy, and they ensure minimum basic dignity to citizens within their borders. Then — some might say “unarguably” again — there are the sectors with which government intervention lends a less helpful hand. To get specific, today we’re talking about data security in the healthcare industry.

    To learn about how and why the private sector has increased the demands for security and how HITRUST, a data security platform, is growing its privacy controls, read ahead.

    (more…)