cybersecurity

Retailers must upgrade authentication, encryption and pen testing

The PCI Security Standards Council now requires better authentication, encryption and penetration testing by companies that accept consumer payments, improvements lauded by security experts.

“There are a lot of people who consider compliance to be policy for policy sake,” said Ryan O’Leary, vice president of the threat research center at WhiteHat Security. “But with these three recommendations, it is really security-industry standards that are finally being forced upon companies. I would say, absolutely, it will move the bar forward as far as security goes.”

Administrators with access to card data must now have two-factor authentication when they log in, either locally or remotely.

To read this article in full or to leave a comment, please click here

Retailers must upgrade authentication, encryption and pen testing Read More »

Protecting data wherever it lives

Data encryption addresses four major areas: data in motion, data stored on user devices, data stored on servers and data that is currently being used. Today, most encryption efforts focus on data stored on servers because that is where the majority of big breaches take place. “There are lots of different challenges,” said Sol Cates,

Protecting data wherever it lives Read More »