All businesses have the responsibility to protect customer data from bad actors – and they certainly can’t afford to lose time, resources or valuable information to data security threats. But where to begin?
For most small businesses, data security pertains to three main areas – operational cybersecurity, continuity plans for disruptions and transaction security for customer payments. Let’s break these down.
- Cybersecurity in business operations
Small businesses are often targeted by cybercriminals because they may have fewer security resources than larger organizations. Protecting small business IT systems* from cyber threats is essential for maintaining business operations, safeguarding sensitive data and preserving customer trust. A successful cyberattack can lead to data breaches, financial losses, operational downtime, and reputational damage. By implementing strong cybersecurity measures such as firewalls, antivirus software, employee training, and regular system updates, you can reduce risk and ensure long-term stability and growth.
For businesses with informational websites or ecommerce operations, it is also critical to implement strong data security measures and invest in the right tools. Online stores collect valuable data such as customer names, addresses, payment details, and account credentials, making them attractive targets for bad actors.* Investing in cybersecurity not only protects your assets but also helps create a safe shopping environment that encourages customer confidence and long-term growth.
- Business continuity plans for disruptions to systems and data
Whether disruptions occur due to random chance or cyber attacks, it is essential to have business continuity plans ready. These ensure that critical IT systems and sensitive data stay protected and accessible, via procedures for data backup, system recovery, incident response, and communication. For small businesses, even short bouts of downtime from software outages, hardware failures and other disruptions can cause financial losses, reputational damage and unforeseen costs. By proactively identifying risks and implementing recovery strategies, business continuity planning strengthens resilience, safeguards customer and business information, and supports your ability to continue serving customers during and after unforeseen incidents.
- Payment security in customer transactions
Protecting payment security is essential for small businesses to safeguard sensitive customer information, financial operations and uphold ethical businesses practices – especially in an increasingly digital landscape for retailers, restaurants and service providers. Any business that processes, stores, or transmits cardholder data must validate and comply with the Payment Card Industry Data Security Standard (PCI DSS),* regardless of which provider you use for payments processing. While these standards are put in place to help protect you and your customer’s payment data, for some, validating and maintaining PCI DSS compliance can be costly, complex and time-consuming.
But it doesn’t have to be. We’ve put together this helpful guide that highlights the need-to-know of validating PCI DSS compliance and how you can protect your business and customer payment data today and in the future.
Understanding the basics of payment security standards
To help businesses of all sizes minimize the risks associated with security and data protection, the payments industry created the PCI Security Standards Council, established by Visa, Mastercard, American Express, Discover and JCB International – the five major card brands worldwide. This council created the Payment Card Industry Data Security Standard (PCI DSS), a global set of security requirements with actionable best practices for payment data security. These standards ensure robust controls are in place across the entire payment ecosystem, including:
- Point-of-sale devices
- Mobile devices, personal computers and servers
- Wireless hotspots
- Web-shopping applications
- Paper-based storage systems
- Transmission of cardholder data to service providers
- Remote access connections
These standards apply to all merchants who store, process or transmit payment data – making it critical for small businesses to understand and act on PCI DSS best practices to protect customer card data and personal information.
Why your business needs to maintain PCI DSS compliance
Most businesses that accept payment cards have to validate their compliance with PCI DSS requirements on an annual basis. Those who do not meet payment security requirements can receive hefty fines and assessments from the payment card brands. Even worse, a cybersecurity event or fraud incident could result in negative brand perception and even the loss of your business. Payment security requirements vary by business type and processing volume – making it a little harder to understand how to maintain compliance.
The four merchant levels for PCI DSS compliance
The first step in validating PCI DSS compliance is to understand which requirements apply to your business. Non-merchant participants in the payments lifecycle – like payment processors, card issuers, and technology vendors – have their own compliance standards under the PCI DSS framework.
For merchants, there are four PCI compliance levels* – based on the annual number of transactions a business accepts and processes:
- Level 1
Merchants processing more than 6 million Visa or Mastercard credit or debit card transactions annually. Report of compliance must be conducted by an authorized Qualified Security Assessor (QSA) and must undergo an internal audit once a year. Additionally, once a quarter, they must submit to a network scan by an Approved Scanning Vendor (ASV).
- Level 2
Merchants processing between 1 and 6 million Visa or Mastercard card-present credit or debit card transactions annually. They’re required to complete an assessment once a year using a Self-Assessment Questionnaire (SAQ). Additionally, a required quarterly network scan must be provided by an ASV.
- Level 3
Merchants processing between 20,000 and 1 million Visa or Mastercard ecommerce transactions annually. They must complete an annual assessment using the relevant SAQ. Additionally, a required annual network scan must be provided by an ASV.
- Level 4
Merchants processing fewer than 20,000 Visa or Mastercard ecommerce transactions annually, or those that process up to 1 million transactions. An annual assessment using the relevant SAQ must be completed, or other alternative validation exercise as defined by the acquirer and a quarterly network scan may also be required from an ASV.
The best way to figure out your compliance level is to consult with your payment processing provider. This is critical for ensuring your business maintains the correct documentation and procedures.
Mastering the 12 PCI DSS requirements
Once you have determined your business’s level of compliance, there are 12 core requirements* to protect payments data.
- Install and maintain a firewall configuration to protect cardholder data.
- Do not use vendor-supplied defaults for system passwords and other security parameters.
- Protect stored cardholder data.
- Encrypt transmission of cardholder data across open, public networks.
- Use and regularly update anti-virus software or programs.
- Develop and maintain secure systems and applications.
- Restrict access to cardholder data by business need to know.
- Assign a unique ID to each person with computer access.
- Restrict physical access to cardholder data.
- Track and monitor all access to network resources and cardholder data.
- Regularly test security systems and processes
- Maintain a policy that addresses information security for all personnel.
Each of these builds a strong foundation of data security practices to protect business operations and customer information. These requirements tend to overlap with cybersecurity best practices as well, underscoring the interconnected nature of business IT systems and customer payment interactions.
Steps to ensure payment security compliance
Every year, all businesses that accept card payments must evaluate and attest to their compliance with PCI DSS requirements. This includes assessments of security infrastructure, solutions for identified vulnerabilities, and submissions of remediation details and compliance reports.
Merchants should validate compliance using the following steps:
- Scope: determine which system components and networks are in scope for PCI DSS analysis and compliance.
- Assess: examine the compliance of system components in scope following the testing procedures for each PCI DSS requirement.
- Report: assessor and/or entity completes required documentation (e.g., Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC)), including documentation of all compensating controls.
- Attest: complete the appropriate Attestation of Compliance (AOC).
- Submit: submit the SAQ, ROC, AOC and other requested supporting documentation such as ASV scan reports to the acquirer (for merchants) or to the payment brand/requestor (for service providers).
- Remediate: if required, perform remediation to address requirements that are not in place, and provide an updated report.
Understandably, these steps can be time-consuming and resource-intensive for small business owners juggling numerous responsibilities. Rather than trying to tackle these independently, it is helpful to partner with a payments processor to validate PCI DSS compliance each year.
Partner with your payments processor on PCI DSS compliance
Your payments processor can be an invaluable resource to boost payment security, follow industry requirements and save time and money for other operational needs. It is important to choose a holistic PCI DSS compliance and validation solution – fragmented or budget approaches can result in assessment gaps and payment security vulnerabilities.
A strong PCI DSS compliance solution from a provider like Elavon should include:
- Security software and tools
Look for state-of-the-art security technologies like encryption and tokenization that protect sensitive payment data both “in-transit” and “at rest.” Cybersecurity software adds an extra layer of support to protect your devices against malware and cybercriminals. And lastly, many providers will offer online PCI DSS compliance validation tools, including help with the PCI Self-Assessment Questionnaire (SAQ) and network vulnerability scanning (if applicable).
- Breach assistance
While every business that processes credit cards must validate PCI DSS compliance annually, data breaches can still occur. In the event of an incident, a breach assistance program can provide your business with financial assistance and help reimburse financial costs associated with forensic investigations, any card replacement costs, fines, fees, or assessments from the payment card networks affected by the breach.
- Comprehensive support
Your provider should offer comprehensive and ongoing support when you need it and should be accessible via online help, email, and phone. Since PCI DSS compliance is not a single task but an ongoing process, your provider should reach out to you throughout the year if anything needs to be done to maintain compliance or if your compliance needs to be renewed.
- Education and training resources
The world of PCI DSS compliance is complex. Look for a provider that offers access to valuable tips, information and best practices that make it easy for you to understand how you can safeguard your business and your customer payment data.
Ready to improve your data security and validate your PCI DSS compliance? As your trusted payments partner, Elavon is committed to providing payment security solutions you and your business can rely on. From payment security and fraud mitigation to PCI DSS Compliance Validation, we offer data security and risk reduction expertise so you can focus on growing your business, increasing your revenue, and building customer trust.