The importance of PCI Compliance

Before the PCI DSS was established, various card brands set up their own security programmes in order to protect card holder data and identity theft due to ongoing data compromises occurring at numerous levels.

In 2006, the five major card brands (Visa, MasterCard, American Express, Discover Card and JCB) then decided to unify their policies and procedures under one universal standard that was called the Payment Card Industry Data Security Standard (PCI DSS). The PCI council governs the payment industry and ensures that all entities accepting, storing or transmitting credit card data adhere to the PCI DSS. The aim is to reduce the number of security breaches and protect the card brands.

PCI DSS can help organisations to;

• protect valuable customer information including payment card details
• protect against the loss of valuable business information and the cost associated with data compromise
• protect against the negative publicity associated with a data breech
• ensure continued customer confidence in the use of payment cards

How does an organisation attain PCI compliance?

An organisation can attain PCI compliance by conforming to the 12 security requirements set out within the PCI DSS. Depending on their merchant level an organisation that is accepting, storing or transmitting card data can become PCI DSS compliant by either submitting a validated Self-Assessment Questionnaire (SAQ) or by undergoing an onsite assessment with a Qualified Security Assessor (QSA).

The merchant level depends on the volume of transactions that they are handling per annum. An organisation that is handling 6 million transactions or more must have an onsite assessment carried out each year by a QSA as well as quarterly network scans.
However, an organisation that is handling 20,000 to 6 million transactions per year can fill out an SAQ but must also undergo quarterly scans of their external network in order to conform to PCI compliance. For organisations handling less than 20,000 transactions per year, they must also undergo quarterly scans on their network and complete an SAQ.

If an organisation that is handling card data from one of the PCI council member brands falls victim to a security breach, they can incur a significant fine and be banned from handling future credit card payments for any of the five major card brands.

For further information on our PCI compliance services, please contact one of our Sales representatives by calling +353 (0)1 495 1300 or by completing our Online Enquiry Form or Request a Call Back Form.

Sysnet appoints new Sales Director

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced the appointment of Paul McNamara as Sales Director with immediate effect.

Paul McNamara brings a wealth of experience and knowledge to Sysnet, having spent more than 14 years in sales roles with companies such as Google and BT. At Sysnet, Paul will be responsible for overseeing regional sales activity and for the achievement of the company’s global sales objectives.

“We are very pleased to welcome Paul to the company, his experience and expertise will drive the consolidation of our global sales effort as the business continues to enjoy a considerable level of growth across all regions.” said Gabriel Moynagh, General Manager at Sysnet Global Solutions.

“I am delighted to join Sysnet and I look forward to getting to know our clients and their businesses. As Sales Director, my responsibility is to ensure our clients continue to receive the most appropriate and best value information security compliance and risk mitigation solutions” said Paul McNamara, Sales Director at Sysnet Global Solutions “I am also looking forward to the challenge of ensuring that the business continues to enjoy in the future, the success it has experienced to date.”

Paul holds a BSc. in Management from Trinity College, Dublin and an Advanced Diploma in Marketing from the Dublin Institute of Technology.

For further information, please visit our website at www.sysnetglobalsolutions.com

Sysnet appoints new Head of Professional Services

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced the appointment of Andrew Dalrymple as Head of Professional Services with immediate effect.

Andrew has gained significant experience within the information security industry having held a number of senior roles with organisations such as NCC Group Plc, Global Secure Systems Ltd, Dimension Data Plc and Computer Associates (CA) Inc in the UK and South Africa. He has significant experience in the audit and assurance space with an emphasis on PCI-DSS, IS0270001 and Data Privacy and has consulted across a wide range of industry sectors.

“Following our recent announcement regarding the appointment of a new Chief Technical Officer, we are pleased to advise that we have now further strengthened our core management team with the appointment of Andrew Dalrymple as Head of Professional Services.” said Gabriel Moynagh, General Manager at Sysnet Global Solutions. “Andrew is a highly qualified, experienced professional and we are very pleased to welcome him to the company.”

“I’m very happy to have this opportunity to join Sysnet and I look forward to working with such a highly skilled and dedicated professional service team.” said Andrew Dalrymple, Head of Professional Services at Sysnet Global Solutions.

Andrew, who studied at Rhodes University in South Africa, is an IS0270001 Lead Auditor and holds the CITP, CISA, CISM and CGEIT certifications.

For further information, please visit our website at www.sysnetglobalsolutions.com

Call Recording, PCI DSS & the Pitfalls

Many organisations that use voice recordings within the Contact Centre do so because it is required for business reasons, such as agent training or confirmation of verbal contractual agreements that are carried out over the telephone channel when selling services.

Depending upon the transaction type, regulatory requirements to keep any recordings (for varying periods of time) for playback apply. For businesses, particularly in the financial services and retail sectors, further requirements apply due to the fact that when purchase transactions are completed over the telephone using payment cards, certain data needs to be protected.

For organisations that are required to record telephone conversations and also take payment card details over the phone the recording and storage of this data can become a PCI compliance issue.

Typically the call recording will record the whole conversation including the Primary Account Number (PAN) and the three or four digit security code (CAV2, CVC2, CVV2 or CID). In addition to the considerations required around the call recordings, enhanced processes and procedures are required for all of other stages involved in and around the initial call.

There are many things to be considered when recording a call containing cardholder data, it is vital to quickly determine what data needs to be protected, for what length of time and depending upon what analytical tooling is in place within your business; the appropriate management and protection of this information is paramount. It is worth noting that some of the largest fraudulent activities that occur are often from within the organisation, so it is imperative to ensure that voice recording is looked at from both a technology and a user process perspective, as they go hand in hand.

Some things to consider

1. Is a formal Security Awareness Training programme in place and being maintained?
2. Have you developed and implemented a set of PCI DSS compliant Policies?
3. Are the call recordings stored securely?
4. Is your network securely maintained and protected against attack?
5. Do you maintain and secure a detailed set of auditable logs?

Where technology exists to prevent recording of these data elements, such technology should be enabled. If these recordings cannot be data mined, storage of CAV2, CVC2, CVV2 or CID codes after authorisation may be permissible as long as appropriate validation has been performed. This includes the physical and logical protections defined in PCI DSS that must still be applied to these call recording formats.

What this means:
Essentially, the Card Verification Value (CVV) must not be retained post authorisation. In any event, and only as a last resort, where a CVV is retained it must be held subject to additional security controls to meet the intent of the Standard, but always via a compensating control.

Before any such compensation control can be implemented it must be verified by a Qualified Security Assessor (QSA) in turn approval must be obtained for the compensation control from the acquiring bank.

How can Sysnet help you?
Sysnet Global Solutions is a QSA providing a range of services and solutions that enable organisations to become and remain compliant with the standard. We have developed tailored packages to address the specific requirements of organisations who must comply with the requirements discussed in this document.

For further information on our Information Security Services, please contact one of our Sales representatives by calling +353 (0)1 495 1300 or by completing our Online Enquiry Form or Request a Call Back Form.

Alternatively, for a full list of contact details for our worldwide offices and Business Development Managers, please click here.

Sysnet appoints new Chief Technical Officer

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced the appointment of Gabriel McDermott as Chief Technical Officer with immediate effect.

Gabriel McDermott brings a wealth of experience and knowledge to Sysnet having worked with companies at varied stages of development from start-ups to established businesses across a variety of sectors. Gabriel’s strengths lie in his ability to provide leadership both managerial and technical to cross function teams with specific product targets. As CTO, Gabriel will oversee the next phase of Sysnet’s technology platform development that will future proof the company’s ability to consistently deliver unrivalled service to its existing client base and greatly enhance the speed to market for new clients.

“We have created a number of senior management roles due to the exceptional growth experienced in recent times.” said Gabriel Moynagh, General Manager at Sysnet Global Solutions “This appointment is essential to our strategic development and we are very happy to welcome Gabriel to the company.”

“I’m very excited about working with the new product development team at Sysnet and I look forward to further developing the company’s long term technical strategy in line with the strategic business development objectives.” said Gabriel McDermott, Chief Technical Officer at Sysnet Global Solutions.

Gabriel holds an honours BSc. Degree and PhD in Computer Science from University College Dublin.

For further information, please visit our website at www.sysnetglobalsolutions.com

Sysnet announce appointment of new Regional Manager for Africa

Sysnet today announced that they have appointed Angie Marriner as their new African Regional Manager due to phenomenal growth within this region over the past 12 months.

Angie will oversee all business activity in Africa on behalf of Sysnet. Angie has a strong project management background in the Information Security Assurance industry, having worked within the industry for a number of years.

“We are delighted that Angie is joining Sysnet’s South African office as our new Regional Manager. We believe that Angie’s experience and skill set will be beneficial to Sysnet in gaining a stronger foothold within the African region” said Tom Moynagh, Managing Director at Sysnet.

“I am delighted to be joining a company that is rapidly expanding globally and one that is targeting Africa” said Angie Marriner. “As a native South African, I believe that there is a lot of potential within the African region for Sysnet to expand further”.

“As a result of economic growth within the African region, there has been a significant increase in the number of business transactions which has led to more sensitive information being stored, processed and transmitted by organisations. This has inevitably led to an increased demand for Information Security Assurance related services such as Documentation Review, PCI DSS audits, PCI DSS training etc. I believe that Sysnet Global Solutions are well positioned to deliver a high quality level of information security services to African organisations in the future” said Angie Marriner.

Sysnet have also appointed a number of Qualified Security Assessors for South Africa and are in the final stages of recruiting a Business Development Manager who will work closely with Angie in her role as Regional Manager. Further key hires are expected in the near future as Sysnet continues to expand in this region.

For further information, please visit our website at www.sysnetglobalsolutions.com

Sysnet expands Dublin Office following two major Banking wins

Sysnet Global Solutions today announced that they hope to increase their support staff by up to 35 people following the acquisition of two major banking clients in recent months. Sysnet will deliver PCI DSS merchant portfolio compliance validation for both clients.

PCI DSS is a set of comprehensive requirements for enhancing the security of payment account data, transactions and processing systems. It was developed by the founding payment brands of the PCI Security Standards Council, and has been adopted by third party processors and merchant acquirers globally to combat cardholder data fraud.

The PCI DSS programme the banks will implement provides a complete suite of services including an online portal, merchant helpline and associated services supported by a clear compliance policy and charging structure.

“This is another very significant achievement for Sysnet, the company has grown rapidly in the last year and these latest client acquisitions will most likely see us add another 35 support people to our staff base.” said Tom Moynagh, Managing Director at Sysnet Global Solutions.

For further information, please visit our website at www.sysnetglobalsolutions.com

Veracity Payment Solutions partners with Sysnet to provide PCI DSS compliance programme for merchants

Veracity Payment Solutions, headquartered in Atlanta, Georgia, has partnered with Sysnet Global Solutions, offering merchants a single solution for PCI DSS compliance. Veracity Payment Solutions offers full service point-of-sale solutions, web-based reporting and management tools to the merchant community, trade associations, community banks and Affinity partners. Sysnet Global Solutions is a worldwide provider of information security assurance and payment card industry compliance services.

“In selecting Sysnet, we were looking for an industry leading partner that would allow Veracity not only to deliver an all encompassing PCI DSS compliance solution, but a company that mirrors Veracity’s commitment to helping our customers achieve every aspect of their compliance requirements. We are fast becoming the experts in the field of PCI DSS compliance due to our relationship with Sysnet” says Grant Putre, Chief Information Officer with Veracity.

Veracity’s customers have the advantage of updating their PCI DSS compliance on an annual basis utilising Sysnet’s user friendly, web-based Securus portal. This solution supports all requirements for PCI DSS compliance with simple wizard-tools, regardless of merchant size or processing volume. Additionally, Veracity now has an in-house helpdesk to provide merchants with the expertise required to complete the PCI DSS certification process.

“As Sysnet expands its global footprint we are delighted to partner with an innovative organisation such as Veracity. Veracity’s commitment to assisting their merchants achieve PCI DSS compliance is substantial and Sysnet is confident that this will be achieved in the most optimum way utilising Sysnet’s Securus technology.” said Colum Rafferty, Business Development Director at Sysnet.

For further information, please visit our website at www.sysnetglobalsolutions.com

Sysnet Global Solutions launch ‘Make the Right Move’ campaign, offering savings of up to 20% on PCI services

Sysnet Global Solutions, a leading international provider of information security and assurance solutions, today announced the launch of ‘Make the Right Move’ campaign that offers up to 20% savings on PCI DSS (Payment Card Industry Data Security Standard) services.

“We are delighted to announce the launch of ‘Make the Right Move’ campaign that extends the great service we currently provide to our existing clients, to our competitor’s clients – providing a superior service and up to 20% savings.” said Gabriel Moynagh, General Manager at Sysnet Global Solutions.

Why Choose Sysnet?

• Market leaders in PCI DSS & ISO 27001 services, vulnerability management and audit & assessment consultancy.
• An extensive range of PCI DSS services.
• Over 20 years experience in multiple IT environments.
• Expert engineering and consultancy teams that are certified to the highest standards.
• More than 300 clients in over 35 countries worldwide.
• Tailored service packages to meet the unique requirements of a broad range of customer groups.
• PLUS up to a 20% saving on QSA service costs

Sysnet offer an extensive range of information security consultancy services including;

Gap Analysis
Remediation Plan
On-site Assessment
Web Application Vulnerability Assessment
Payment Application Data Security Standard (PA DSS) Assessment
Risk Assessment
Security Awareness Programmes
Incident Response Services
• Network Scanning
Penetration Testing

The offer is available to all organisation types and sizes including banks, acquiring institutions, Payment Service Providers, Payment Application Providers, government departments and merchants. Organisations interested in this limited offer can call +353 (0)1 409 8309 or visit our website to complete our call back request form.

Apani sign Sysnet Global Solutions as Premier Integration Partner

May 26, 2010

Apani sign Sysnet Global Solutions as Premier Integration Partner

26th May 2010 – Apani UK Limited, a leading provider of identity-aware network solutions, today announced that it has signed a partnership with Sysnet Global Solutions to enable its clients to rapidly reduce Audit scope and safeguard critical data as it traverses the corporate network. Sysnet Global Solutions is a leading international provider of information security and assurance solutions. Sysnet offers a range of information security & assurance services and managed security services, to a wide variety of businesses including acquirers, international banks and government departments.

“We are delighted to be working with Sysnet. Our software-only approach to segmentation and encryption provides a more logical approach to securing key business systems and critical data-in-motion in alignment with regulatory requirements and industry standards such as PCI DSS, Data Protection Act and ISO 27001” said Allen Wise, UK Managing Director at Apani.

“Sysnet Global Solutions have significant experience in assisting large enterprises to reduce the scope of regulatory and compliance projects through the implementation of network segmentation solutions” said Gabriel Moynagh, General Manager at Sysnet. “We are delighted that Apani have chosen to partner with Sysnet to provide these solutions to our clients.

For further information, please visit our website at www.sysnetglobalsolutions.com

Sysnet Launch new Services, Solutions & Brand

March 26, 2010, Dublin

Sysnet Launch new Services, Solutions & Brand

Friday, March 26, 2010 – Sysnet Global Solutions, a leading international provider of information security and assurance solutions, today announced the launch of a range of new services and solutions to assist organisations in protecting their vital information assets and in achieving and maintaining compliance with best practice and compliance regulations such as ISO 27001 and PCI DSS. To coincide with the launch, Sysnet have redesigned their brand and have re-launched their website at www.sysnetglobalsolutions.com

“We are delighted to announce the launch of our innovative range of professional security services and the addition of an array of managed security services, that better position us to offer a more complete information security and assurance service to our clients.” said Gabriel Moynagh, General Manager at Sysnet. “We have also undertaken a re-brand of our business, which we envisage will assist us in executing our global strategy.”

Some of the new information security consulting services include Information Security Strategy, Policy & Procedure Development, Information Security Awareness solutions and training, PCI DSS Training and a Periodic On-site Compliance ‘Health Check’.

Sysnet is also delighted to announce a suite of managed security services which will include Log Monitoring, Firewall Management and Log Retention as well as many more. Sysnet’s clients will also be able to purchase specially tailored packages to meet their needs which contain combinations of our new services and solutions.

“We have significantly extended the range of services in order to offer even greater assistance to our clients, in analysing the validity of their organisation’s security posture” said Paul Prior, Senior Product Manager at Sysnet “The introduction of our managed security services means we can now offer our customers tailored solutions to assist them in managing their information security environment.”

For further information, please visit our website at www.sysnetglobalsolutions.com