PCI

  • PDF
  • Print
  • E-mail

N2NetSecurity, Inc. is proud to be certified as a PCI Qualified Security Assessor (QSA).

pci_ssc_qsa-sm

Download our PCI Services Brochure

PCIServicesBrochure-thumb

Does your company store, transmit, or process credit cards or debit cards from Visa, MasterCard, American Express, JBC, or Discover?  If so, you have a PCI compliance requirement and we would love to help you get peace of mind and get back to doing what you do, business.

With decades of experience, our team members draw from experience gained at Bridgestone, Home Depot, and other Fortune 250 Companies to save you time and money.  N2NetSecurity, Inc. has been certified by the PCI Security Standards Council (SSC) to perform PCI Services as a Qualified Security Assessor (QSA).  As shown in the following diagram, we have developed a broad range of PCI services including our Gap Assessment, Remediation, Formal QSA Assessment, and Maintenance services.

PCI_Services

When it comes to protecting your reputation and customer data, we understand that the utmost care must be given.  At the same time, we understand that in this economy, companies face daily challenges and often have to choose between function and security.  We believe you can do both.  We do not believe in chasing technologies or standards, we believe in getting to the root of the problem and fixing it right, the first time.

We will start by performing a gap assessment.  This process normally takes a couple of days and includes time for us to train your personnel on PCI compliance, get to know about your environment, and perform the actual gap assessment, which is derived from the PCI Data Security Standard (DSS).  Then, we will deliver a quality report with findings and recommendations for remediation and compliance.

Next, if required, we can assist you with the remediation.  We will assist you with both your policy and technical controls.  We will follow the PCI SSC recommended milestone program to PCI compliance.  We will provide the necessary guidance and experience to help you achieve PCI compliance.  If necessary, we will assist you in completing a Self Assessment Questionnaire (SAQ).

We provide formal QSA assessments to include the Report of Compliance (ROC), as required by the PCI SSC.

PCI requirements change from time to time and we can help you remain compliant and meet your regular obligations.  It is important to realize the cost of being non-compliant.

Cost of being non-compliant:

 

PCI Classification

Card

Provider

Cost for Non Compliance

Prior to Breach

Cost for Non-Compliance after a Breach (same for all)

Level 1 Merchants

(6 Million Cards/year)

Visa

Up to $25k/mo

  • Up to $500k fine from each of the 5 card brands (Up to $2.5M)
  • Losing the ability to process cards in the future
  • Mandated on-site audits with QSA
  • Cost for re-issuing cards
  • Unlimited liability for all fraudulent charges (easily $500k per card brand)
  • Possible class-action law suits
  • Possible Federal investigation
  • Additional Potential Fines:
    • Egregious violation ($500k)
    • Failure to report ($100k)
    • Storing full track data
    • $50k initial fine
    • $100k monthly

MasterCard

  • $25k 1st quarter
  • $50k 2nd quarter
  • $100k 3rd quarter
  • $200k 4th quarter

Level 2 Merchants

(1-6 Million Cards/year)

Visa

Up to $5k/mo

MasterCard

  • $25k 1st quarter
  • $50k 2nd quarter
  • $100k 3rd quarter
  • $200k 4th quarter

Level 3 Merchants

(20k-1 Million Cards/year)

Visa

Up to $5k/mo

MasterCard

  • $10k 1st quarter
  • $20k 2nd quarter
  • $40k 3rd quarter
  • $80k 4th quarter

Level 4 Merchants

(less than 20k/year)

Visa

None at this time

MasterCard

None at this time

 

We can help you avoid these cost!  We look forward to earning your business.

Contact us now to schedule your PCI Gap Assessment.

 

Data Breach News

Imprisoned “Greenpoint Crew” member hit with new ID theft charges

MA: Town of Essex Legal Notice About “Potential” Breach Involving Youth Commission Records

Malware used in Jason’s Deli showing up elsewhere

CT: Hacker stole $87,000 from Putnam school account

UK: Council data leak sparks fraud fears

College Data Breaches Underscore Higher Ed Security Challenges

Investigators Find Famous DJ’s Credit Card Details for Sale

UK: Confiscated blacklist leaked back into market

KCI working to contain employee data breach

Faculty, staff ID threatened

West Virginia accounting firm employee sentenced for ID theft

Nine Former Cell Phone Company Employees with Stealing Customer Information in $15 Million Cell Phone Cloning Scheme (updated)

NZ: Card security breached in Qtown

Cyber Thieves Steal Nearly $1,000,000 from University of Virginia College

MO: Union pension mailer reveals recepient’s Social Security numbers

Delaware government: State retiree sues over Aon data leak

MN: Metro restaurant workers indicted in credit card scam

Email remains a major vector of enterprise data loss

Swiss: No assistance in stolen bank data cases

Heartland Payment Systems, Discover Agree To $5 Mln Intrusion Settlement

(Follow-up) Secret Service: Computer virus to blame for Jason’s Deli thefts

Miami man pleads guilty in ID theft case

MO: Military social security cards & other papers found in dumpster

AIB tells tribunal employee dismissed for accessing accounts

FL: Laptop theft results in data breach for P.K. Yonge employees, students

N2NetSecurity, Inc. News

WALTHAM, MA - February 19, 2010 - N2NETSECURITY, INC. has been certified as a Top 20% Performer based on the Past Performance Evaluation survey responses of its reference customers. N2NETSECURITY, INC.'s PPE score of 98/100 demonstrates outstanding overall customer satisfaction relative to similar companies.  Open Ratings, Inc.

Report can be downloaded here.