SecureConnect Logo
Phone: 888-949-7328 | mySecureConnect Login
 
pci-compliance.jpg

Serious Texas Suffers Data Breach

Customers at the Serious Texas Bar-B-Q restaurant were subjected to debit card fraud from a nationwide security breach earlier this year. Around 200 to 300 customers got their card information stolen from one of the four restaurant locations due to a breach in the credit-card payment system.

Serious Texas Bar-B-Q has assured guests that the problem was immediately fixed and they were not at fault, but unfortunately if the restaurant had maintained PCI compliance and implemented additional security services, it would have minimized the risk to the brand and its customers.

A solution such as SecureConnect not only protects your business and reputation but can also save owners the devastating costs associated with a data breach that can reach up to over a million dollars and ultimately harm a business and its future growth. SecureConnect is a full-service solution that offers PCI compliance, numerous security features and piece of mind to merchants at a fixed monthly rate.

As breaches like this happen to businesses similar to yours, it is imperative to not only take notice but to take action. To learn more about SecureConnect and receive a free PCI consultation, contact us today!

Spot Critical Holes in your Infrastructure with a Vulnerability Assessment

Contrary to popular belief, it really isn’t enough to become secure. If you are serious about maintaining your business for the long run, you will have to maintain security — something that is completely different. Maintaining security can get complicated in a world where new security threats are on the horizon all the time, but it’s something that can get easier if you have the right tools.

If you’re serious about securing the important assets of your business, you will need to first start by using a vulnerability assessment to spot critical holes in your infrastructure. From there, you will be able to see exactly what is insecure at the moment, and then fix those problems.

Naturally, you can also take a different approach with a vulnerability assessment by contracting an outside company to not just run the vulnerability assessment for you, but also to generate an action plan based on the report generated from the assessment. This is a great way to delegate your security tasks without worrying about having an insecure system.

No matter what path you ultimately choose, you will need to get started today by getting the vulnerability assessment and seeing if there are any critical holes in your infrastructure. Contact us today!

PCI Compliance for the QSR Industry

Without solid compliance, the systems that a QSR-oriented business relies on to process payments and other tasks for customers could be at risk for a security breach. If a breach were to occur and it was found that the proper QSR PCI compliance principles weren’t being practiced, stiff fines and other consequences could result.

At this point, the goal is to effectively implement PCI compliance solutions for the unique network environment in your store. Security isn’t something that should be complicated, especially if you have many employees that will need to be educated and trained on proper security procedures.

The key is to practice smart delegating measures. If security is not your strong suit, it may be best to bring in a company that specializes specifically in helping companies manage their QSR PCI compliance needs in a way that just makes sense. The best way to move forward is to make sure that you get started right away — don’t delay! Contact SecureConnect today!

Passwords and Pepperoni

Hell Pizza, a New Zealand based pizza chain, recently sent out an email to its 230,000 customers to change their passwords. They believe that they have suffered a breach, but cannot yet identify the attack vector (this could be a rogue employee or poorly designed website).

While I applaud Hell Pizza for notifying their customers, since web users typically use the same email and password for websites they authenticate to, they didn’t adequately protect the information to begin with. According to sources at risky.biz, the hackers have obtained private information including passwords, email and home addresses and phone numbers, in addition to order information. Apparently, no cardholder data was obtained.

Merchants are continually trying to enhance the user experience by offering such services as online ordering. However, this can be a disservice to your customers if not properly implemented, as in the case of Hell Pizza. Developing a web site with insecure coding is a poor way to conduct business.

While representatives from Hell Pizza indicated that cardholder data wasn’t breached, it would seem likely that the online payment card flow would put their servers in scope for PCI. Vulnerability scanning, as conducted by an ASV (of which BHI SecureConnect is one) should have shown the SQL injection vulnerability (as reported by risky.biz). In addition, validation by completing the Self Assessment Questionnaire would indicate that one cannot provide direct database access from the internet (mySQL was reportedly listening on the public side), among many other violated requirements.

Hell Pizza should have conducted due diligence in assessing their security posture, and if in scope for PCI, have a contractual obligation to fulfill the PCI requirements.

This should also serve as a lesson for consumers to not use the same password for the websites that you access. A breach could potentially allow access to online banking and other personal records. Use a password databases, such as the open source (ie free) KeePass Password Safe, to keep your passwords safe and straight.

Better Merchant Compliance without Stress

Whether you’ve been in business for a little while or you’re just getting started, there’s one area that you probably already find a bit frustrating: PCI compliance. It is a topic that tends to get ignored because many business owners feel that it takes too long to really achieve compliance and have the misconception that it’s an extremely costly venture. However, this isn’t the case at all — it’s quite possible to achieve compliance without incurring all the stress and debt that have become misconstrued throughout the retail industries.

The best way to achieve better merchant compliance is to see what areas need to be fixed in the first place. Completing a vulnerability assessment and looking at any problems within your current system is the best way to make sure that you have a better grasp on any problems already present in the system.

From there, you can apply comprehensive solutions that cover the basic components of great security, such as round-the-clock monitoring as well as strong firewall protection.

So, if you really want to achieve better merchant compliance, you would do well to pay attention to the advice offered here — contact an expert like SecureConnect who can provide you with the foundation of security and the assurance of compliance.




 
 
Learn More
Why SecureConnect
Packages
Managed Firewall
PCI Compliance
Archived Webinars
SecureConnect Blog
Case Studies
FAQs

SecureConnect Scoop
About Us
Approved Scanning Vendor
Careers
Press Releases
Terms of Use
Privacy Policy
Site Map
Next Steps
Send Informational Packet
Get a Free PCI Scan
Receive Communications from us
Request a Free PCI Consultation
Launch the PCI Wizard
Email Us
Sign Up
mySecureConnect Login
Call Direct: 888.949.7328

Follow SecureConnect
Follow us with RSS feed Subscribe to our RSS feed
Follow us on Twitter Follow us on Twitter
Follow us on Facebook Become a Facebook fan
Follow us on Facebook See our events on Flickr
Visit our profile on Linkedin Join us on Linkedin
© 2010 BHI Advanced Internet, Inc. Provider of SecureConnect®. All Rights Reserved.