As digital payments boom, here’s how small-sized retailers can meet cybersecurity threats
Even without dedicated IT teams or advanced cybersecurity, SMEs can take practical steps to reduce the risks they face
A COMMON misconception among small and medium-sized enterprises (SMEs) is that they are too small to be of interest to cybercriminals. The reality is the opposite: they are prime targets.
Unlike banks or large corporates, SMEs lack the resources for dedicated IT teams or advanced security infrastructure, making them vulnerable to increasingly sophisticated fraud schemes.
But SMEs can dramatically reduce the risk of fraud and breaches by aligning with international data security standards.
One global standard for protecting payment systems is set by the Payment Card Industry Security Standards Council (PCI SSC), an international body originally founded by five credit card companies.
The Payment Card Industry Data Security Standard (PCI DSS) sets requirements on access control, encryption and vulnerability management – areas where SMEs often fall short.
The Council also has a dedicated webpage that provides guidance to merchants, such as recommending that they make use of resources that are already available.
For instance, SMEs should approach their existing payment vendors or service providers to maximise the features that they offer.
Simple steps
Some cybersecurity areas that may be more challenging for SMEs are remote access, password management and patching vulnerabilities.
Payment solution vendors often support or troubleshoot merchants’ payment systems from their own offices, and not from the business location. They do this using what are known as “remote access” software products.
However, some of these vendors use commonly known default passwords for remote access, making it much too easy for hackers to access merchants’ systems.
Such hackers scan the Internet for businesses with vulnerable remote access systems and use malware to steal valuable payment card data.
Merchants should ask their vendors how to change the default passwords; how to enable remote access only when specifically requested; and how to disable it when not needed. They should also require multi-factor authentication before granting access.
If remote access use is unavoidable, SMEs should make sure that vendors use remote access credentials that are unique to the business, and that are not the same ones used for other customers.
Aside from limiting the use of remote access as much as possible, the best line of defence is to make “passphrases” rather than passwords, and change them often. This means using a sentence for a stronger password, instead of a single word.
Meanwhile, SMEs may also face software vulnerabilities. To fix these vulnerabilities, payment service providers will send updates – known as “patches” – to payment systems.
Installing these in a timely manner will help fix known issues, closing any doors that criminals could use to access a merchant’s system and steal customers’ data.
Reducing data exposure
Ultimately, the best way to protect against data breaches is for SMEs to simply not store card data at all, by outsourcing their card processing.
When setting up payment systems, SMEs should ask their service provider or in-house IT teams whether they truly need to store card data.
They should also discuss tokenisation technologies, which ensure that card data is useless even if it is stolen.
For instance, PCI offers point-to-point encryption solutions for merchants that can help make data less valuable to attackers even if compromised in a breach.
Apart from providing strong encryption protections – so that payment card data is protected – it makes it easier for a merchant’s cardholder data environment to be validated against the PCI data security standards.
As payments evolve, so too do the methods of fraudsters. SMEs cannot afford to assume they are beneath attackers’ notice.
By understanding the latest threats, shoring up fundamental defences and aligning with PCI DSS, smaller firms can strengthen their resilience without incurring unsustainable costs.
The writer is regional vice-president for the PCI Security Standards Council
TRENDING NOW
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
HDB reviewing ‘jumbo’ flat scheme after Telok Blangah unit listed for sale at S$2.18m
What role can Japan play in Asean’s future?