close up of used credit car
Technology

CARD SECURITY: LEADING FROM THE FRONT IN THE DIGITAL AGE

Published by Gbaf News

Posted on March 27, 2015

3 min read
Add as preferred source on Google

The Rising Threat of Card Encryption Hacks

The alleged hacking of SIM Card encryption keys has once again highlighted the importance for card manufacturers to have in place advanced data encryption processes and robust security handling policies to mitigate the risks of serious breach, writes Marshall Haldane, allpay Card Services Director.

With technology evolving in sophistication, it has never been more important to ensure security products are upgraded, best practice is followed and – just as importantly – staff understand their roles and responsibilities around data handling, production processes and audit trails.

Comprehensive Security Approaches in Card Manufacturing

As a global card supplier – certified to manufacture both MasterCard and Visa Cards – allpay takes a three-pronged approach to security handling through physical and logical access, staff vetting and training and third-party audits to meet PCI Security Council compliance standards.

Doing battle against sophisticated fraud and theft techniques means getting the basics right on physical access – ID authentication, CCTV, physical security checks/searches, tandem access requirements, etc

Network Architecture and Physical Security Enhancements

Having recently expanded our UK operation – subsequently introducing new service lines in all areas of card production – the design of our network architecture as a whole was reviewed and strengthened to exceed industry standards.

Marshall Haldane

Marshall Haldane

Construction plans, facility layout, implementation of the access control system, intrusion detection systems and CCTV cameras all combine to create a resilient and safe environment for manufacturing cards. Combined with the use of state of- the-art EMV encoding, data encryption, laser, printing, colour and embossing technologies, they work to assure a secure operation at every inch of the site.

Data Protection and Workforce Vigilance

However, just as important as the physical nature of security is the effective protection of data, and, crucially, regular attention of those in the production environment who work around it. Building protections around stored and moving data (across a number of networks), needs to be rigorous.

While we invest heavily in advanced data encryption techniques to protect client data in the event of

a breach, it comes to nothing if the personnel are not acutely aware of their responsibilities within security policies and procedures.

Staff Training, Vetting, and Security Procedures

At allpay, pre-employment and ongoing screening of staff remains key – as does staff knowledge of the production process, site security and logical security procedures.

Due to continuous investment in technology, protocols and guidance needs to be frequently updated, requiring staff to carry out regular security awareness training.

At allpay, for example, staff are required to sit regular security awareness training via online tutorials which is logged centrally. They’re also regularly issued with updated guidance should protocols be enhanced or changed.

Key to any safe environment ensures that:

  • Guidance, training and processes are not static, but evolving;
  • Enforcement of security policies is strict, not merely satisfied
  • Security audits and awareness training is regular, not infrequent; and that
  • Prevention of viruses is automated, not manual, and systems are updated regularly with the latest security patches for operating systems.

Robust implementation of the above is imperative for card issuers to reduce the risk of fraud and theft, while maintaining a high-level of security for their customer information.

Key Takeaways

  • Allpay employs a three‑pronged security strategy: physical/logical access control, staff vetting and training, and third‑party PCI audits.
  • Physical security measures include facility layout design, intrusion detection, CCTV, and tandem access systems.
  • Advanced EMV encoding, data encryption, and secure production technologies are integrated into card manufacturing.
  • Staff are continuously vetted and undergo regular, logged security awareness training with updated protocols.
  • Enforcement of evolving security guidance, automated virus protection, and regular patching are essential.

References

Frequently Asked Questions

What prompted allpay to reinforce security measures?
Alleged hacking of SIM card encryption keys highlighted risks, prompting upgrades to encryption, physical security, and staff procedures.
What are the three core security pillars at allpay?
They are physical and logical access control, staff vetting and training, and third‑party PCI Security Council audits.
How does allpay ensure employee security awareness?
Through pre‑employment screening, regular online security training, centrally logged, with updated guidance as protocols evolve.
What technologies are used to secure card production?
Allpay uses EMV encoding, data encryption, laser, colour and embossing technologies, along with intrusion detection and CCTV.
Why is automated virus protection stressed?
Because prevention must be proactive; ensuring systems are regularly patched and protected minimizes human error risks.

Tags

Related Articles

More from Technology

Explore more articles in the Technology category