SlideShare a Scribd company logo
Copyright© 2018 Sucuri. All Rights Reserved.
Copyright© 2018 Sucuri. All Rights Reserved.
Ecommerce Risks & Threats
Copyright© 2018 Sucuri. All Rights Reserved.
According to Trustwave
research, 90% of data
breaches impacted
small merchants
1. Retail - 45%
2. Food & Beverage - 24%
3. Hospitality - 9%
Top 3 Compromised Industries
Data Breaches
Copyright© 2018 Sucuri. All Rights Reserved.
Average cost of a data
breach for small business
$36K+
Copyright© 2018 Sucuri. All Rights Reserved.
Merchants need to
consider a multi-layered
approach for protecting
sensitive customer data.
Serious data breaches can
happen even you do not
store cardholder data.
Copyright© 2018 Sucuri. All Rights Reserved.
Data BreachCost Factors
Mandatory Forensic
Examination
Notification of Customers Affected Customer Credit
Monitoring
PCI Compliance Fines
Liability for Fraud Charges Credit Card Replacement
Costs
POS System Improvements Reassessment for PCI
Compliance
Copyright© 2018 Sucuri. All Rights Reserved.
Non-monetarydamages are painfultoo
57%
31%
75%
of people lost trust and
confidence in the
organization
of people terminated
their relationship with
the organization
of executives said the
data breach had an
impact on the business’
reputation
Ponemon Institute Study Ponemon Institute Study Ponemon Institute Study
Copyright© 2018 Sucuri. All Rights Reserved.
Non-monetarydamages are painfultoo
Bad Press Loss of Payment
Card Privileges
Your Time
Copyright© 2018 Sucuri. All Rights Reserved.
What is PCI Compliance?
Copyright© 2018 Sucuri. All Rights Reserved.
PCI Compliance
In 2006, American Express, Discover, JCB International, MasterCard and Visa Inc.
founded the Security Standards Council (PCI SSC) in order to maintain a
comprehensive and evolving set of standards to help vendors protect their
payment systems.
PCI = Payment Card Industry
Copyright© 2018 Sucuri. All Rights Reserved.
BuildandMaintaina SecureNetwork
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Protect Cardholder Data
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Maintaina VulnerabilityManagement Program
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Implement Strong Access Control Measures
•
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
RegularlyTest andMonitor Networks
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Maintainan InfoSecPolicy
•
Copyright© 2018 Sucuri. All Rights Reserved.
Website Security
Copyright© 2018 Sucuri. All Rights Reserved.
How Websites Get Hacked
•
•
•
•
•
•
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
SSL Certificate= Secure?
•
•
•
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Website ApplicationFirewalls
•
•
•
•
•
•
Copyright© 2018 Sucuri. All Rights Reserved.
Post Breach PCI Protocol
Copyright© 2018 Sucuri. All Rights Reserved.
Mandatory Forensic Examination
• PCI DSS require merchants that are
suspected of having a data breach to have
a mandatory forensic examination.
• According to Verizon Business, a small
business examination may cost between
$20,000 to $50,000.
Copyright© 2018 Sucuri. All Rights Reserved.
Notificationof Customers
• If financial information is suspected of
being compromised, most states require
that customers be notified.
• University of North Carolina at Chapel Hill
said a 2013 data breach of just 6,000
records has cost the school nearly $80,000
in working with affected parties.
Copyright© 2018 Sucuri. All Rights Reserved.
Affected Customer Credit Monitoring
• If you experience a breach you may
be required to produce up to a
year’s worth of credit monitoring
and/or counseling services to
customers affected by your breach.
Copyright© 2018 Sucuri. All Rights Reserved.
PCI ComplianceFines
• In 2011, 96% of the merchants experiencing a
data breach had not complied with the PCI
DSS.
• If the forensic investigation shows that your
business was not in compliance heavy fines
could be levied against you. These fines can
range from $5,000 to $50,000 or more.
Copyright© 2018 Sucuri. All Rights Reserved.
Liability for Fraud Charges
• Many merchants assume they have no
liability after a data breach.
• This is not necessarily the case; lawsuits
may claim liability on merchants for security
breaches.
Copyright© 2018 Sucuri. All Rights Reserved.
Credit Card ReplacementCosts
• Merchants may be required by card issuers to
pay the cost of reissuing cards to customers.
• These fees can range from $3 to $10 per card.
Copyright© 2018 Sucuri. All Rights Reserved.
POS System Improvements
• Depending on the source of the breach, you
may have to invest in upgrading or replacing
your POS system, including servers, software
and/or card swipe devices.
Copyright© 2018 Sucuri. All Rights Reserved.
Reassessment for PCI
Compliance
• In order to qualify to accept cards again,
a complete PCI assessment by an
external Qualified Security Assessor
(QSA) must be performed.
Copyright© 2018 Sucuri. All Rights Reserved.
Thank You!
Alycia Mitchell

More Related Content

PDF
Preventing P2P Fraud with Aite Group
PPTX
Preventing Fraud with a Multi-Channel Approach
PDF
Digital banking Account Take Over
PDF
Same day ach bec fraud detection prevention webinar 3 1-18
PPTX
Guardian analytics vs. actimize 2016
PDF
Behavioral Analytics for Preventing Fraud Today and Tomorrow
PPT
New fraud protection solutions
PDF
New Requirements of Fraud Prevention
Preventing P2P Fraud with Aite Group
Preventing Fraud with a Multi-Channel Approach
Digital banking Account Take Over
Same day ach bec fraud detection prevention webinar 3 1-18
Guardian analytics vs. actimize 2016
Behavioral Analytics for Preventing Fraud Today and Tomorrow
New fraud protection solutions
New Requirements of Fraud Prevention

What's hot (20)

PPTX
Stop wire fraud aug 2016
PDF
Business Email Compromise Scam
PDF
Preventing Business Email Compromise Fraud with Guardian Analytics Real-Time ...
PPTX
ISMG - Fighting Business Email Compromise
PDF
Same Day ACH: The Face of Faster Payment
PDF
Blockchain and it’s importance on Insurance Industry
PDF
IBM Smarter Analytics Signature Solution for healthcare
PPTX
How to fight chargebacks. part 1
PDF
Intelligent underwriting workbench
PDF
Preventing Tax Evasion & Benefits Fraud Through Predictive Analytics
PDF
Adoption of Technologies for Claims Management in the Health Insurance Sector.
PDF
IBM Smarter Analytics Solution for insurance
PPTX
Fraud Prevention Strategies to Fight First-Party Fraud and Synthetic Identity...
PDF
Case study Big Data Insurance
PPTX
Big Data in Insurance Industry
PDF
Preventing Tax Evasion & Combating Fraud through Predictive Analytics
PDF
KYC automation using artificial intelligence (AI)
 
PDF
Accenture Insurance Data Capture
PDF
Data Driven Tax Administration - new strategy for big data, BI and analytics ...
PPTX
Cybersecurity-Anforderungen in IT-Sourcing-Projekten meistern – Ein Leitfaden...
Stop wire fraud aug 2016
Business Email Compromise Scam
Preventing Business Email Compromise Fraud with Guardian Analytics Real-Time ...
ISMG - Fighting Business Email Compromise
Same Day ACH: The Face of Faster Payment
Blockchain and it’s importance on Insurance Industry
IBM Smarter Analytics Signature Solution for healthcare
How to fight chargebacks. part 1
Intelligent underwriting workbench
Preventing Tax Evasion & Benefits Fraud Through Predictive Analytics
Adoption of Technologies for Claims Management in the Health Insurance Sector.
IBM Smarter Analytics Solution for insurance
Fraud Prevention Strategies to Fight First-Party Fraud and Synthetic Identity...
Case study Big Data Insurance
Big Data in Insurance Industry
Preventing Tax Evasion & Combating Fraud through Predictive Analytics
KYC automation using artificial intelligence (AI)
 
Accenture Insurance Data Capture
Data Driven Tax Administration - new strategy for big data, BI and analytics ...
Cybersecurity-Anforderungen in IT-Sourcing-Projekten meistern – Ein Leitfaden...
Ad

Similar to Ecommerce Website Security (20)

PPTX
Payment gateway
PDF
Treasury in a Time of Crisis
PDF
Combating Fraud: Six Principles for Security
PDF
Transform Your Financial Crime Detection with Advanced Graph Analytics
PPTX
Leverage Gartner’s Insight for Assessing the Total Cost of Fraud in Your Paym...
PDF
RPA case study for claims processing
PDF
Protecting Against Payment Fraud in SAP S/4HANA
PPTX
Fast- Track Data Processing with Automation in Claims Processing
PDF
Payment Processing and Compliance Challenges
PPTX
2020 i gaming report webinar
PPTX
Relying on Data for Strategic Decision-Making--Financial Services Experience
PDF
Master Data in the Cloud: 5 Security Fundamentals
PDF
Pros and Cons of a Digital Payment System
PDF
How Credit Card Processing Works
PPTX
AI in Banking - What it can do & its benefits | Virtue Analytics
PDF
Securter Systems
PDF
Understanding the impact of your fraud strategy
PPTX
Digital Transformation in Insurance Operations
PDF
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
PPT
Ibm odm fraud detection & management system
Payment gateway
Treasury in a Time of Crisis
Combating Fraud: Six Principles for Security
Transform Your Financial Crime Detection with Advanced Graph Analytics
Leverage Gartner’s Insight for Assessing the Total Cost of Fraud in Your Paym...
RPA case study for claims processing
Protecting Against Payment Fraud in SAP S/4HANA
Fast- Track Data Processing with Automation in Claims Processing
Payment Processing and Compliance Challenges
2020 i gaming report webinar
Relying on Data for Strategic Decision-Making--Financial Services Experience
Master Data in the Cloud: 5 Security Fundamentals
Pros and Cons of a Digital Payment System
How Credit Card Processing Works
AI in Banking - What it can do & its benefits | Virtue Analytics
Securter Systems
Understanding the impact of your fraud strategy
Digital Transformation in Insurance Operations
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Ibm odm fraud detection & management system
Ad

More from Sucuri (20)

PPTX
Logs: Understanding Them to Better Manage Your WordPress Site
PPTX
Webinar: Personal Online Privacy - Sucuri Security
PPTX
Why Do Hackers Hack?
PPTX
What Are the Most Common Types of Hacks?
PPTX
Steps to Keep Your Site Clean
PPTX
2018 Hacked Website Trends
PPTX
Sucuri Webinar: What is SEO Spam and How to Fight It
PPTX
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
PPTX
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
PPTX
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
PPTX
Sucuri Webinar: Leveraging Sucuri's API
PPTX
Sucuri Webinar: Website Security Primer for Digital Marketers
PPTX
Sucuri Webinar: Sucuri Introduces the Sales Enablement Department
PPTX
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
PPTX
Sucuri Webinar: Simple Steps To Secure Your Online Store
PPTX
Sucuri Webinar: Getting Started with Sucuri
PPTX
Sucuri Webinar: Is SSL enough to secure your website?
PPTX
Sucuri Webinar: Preventing Cross-Site Contamination for Beginners
PPTX
Webinar: CWAF for Mid Market/Enterprise Organizations
PPTX
Webinar: eCommerce Compliance - PCI meets GDPR
Logs: Understanding Them to Better Manage Your WordPress Site
Webinar: Personal Online Privacy - Sucuri Security
Why Do Hackers Hack?
What Are the Most Common Types of Hacks?
Steps to Keep Your Site Clean
2018 Hacked Website Trends
Sucuri Webinar: What is SEO Spam and How to Fight It
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
Sucuri Webinar: Leveraging Sucuri's API
Sucuri Webinar: Website Security Primer for Digital Marketers
Sucuri Webinar: Sucuri Introduces the Sales Enablement Department
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: Simple Steps To Secure Your Online Store
Sucuri Webinar: Getting Started with Sucuri
Sucuri Webinar: Is SSL enough to secure your website?
Sucuri Webinar: Preventing Cross-Site Contamination for Beginners
Webinar: CWAF for Mid Market/Enterprise Organizations
Webinar: eCommerce Compliance - PCI meets GDPR

Recently uploaded (20)

PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Cloud computing and distributed systems.
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Electronic commerce courselecture one. Pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
cuic standard and advanced reporting.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Approach and Philosophy of On baking technology
PDF
Encapsulation theory and applications.pdf
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Cloud computing and distributed systems.
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Building Integrated photovoltaic BIPV_UPV.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
Encapsulation_ Review paper, used for researhc scholars
Diabetes mellitus diagnosis method based random forest with bat algorithm
Electronic commerce courselecture one. Pdf
Programs and apps: productivity, graphics, security and other tools
cuic standard and advanced reporting.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Understanding_Digital_Forensics_Presentation.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Network Security Unit 5.pdf for BCA BBA.
Agricultural_Statistics_at_a_Glance_2022_0.pdf
MYSQL Presentation for SQL database connectivity
Approach and Philosophy of On baking technology
Encapsulation theory and applications.pdf

Ecommerce Website Security

  • 1. Copyright© 2018 Sucuri. All Rights Reserved.
  • 2. Copyright© 2018 Sucuri. All Rights Reserved. Ecommerce Risks & Threats
  • 3. Copyright© 2018 Sucuri. All Rights Reserved. According to Trustwave research, 90% of data breaches impacted small merchants 1. Retail - 45% 2. Food & Beverage - 24% 3. Hospitality - 9% Top 3 Compromised Industries Data Breaches
  • 4. Copyright© 2018 Sucuri. All Rights Reserved. Average cost of a data breach for small business $36K+
  • 5. Copyright© 2018 Sucuri. All Rights Reserved. Merchants need to consider a multi-layered approach for protecting sensitive customer data. Serious data breaches can happen even you do not store cardholder data.
  • 6. Copyright© 2018 Sucuri. All Rights Reserved. Data BreachCost Factors Mandatory Forensic Examination Notification of Customers Affected Customer Credit Monitoring PCI Compliance Fines Liability for Fraud Charges Credit Card Replacement Costs POS System Improvements Reassessment for PCI Compliance
  • 7. Copyright© 2018 Sucuri. All Rights Reserved. Non-monetarydamages are painfultoo 57% 31% 75% of people lost trust and confidence in the organization of people terminated their relationship with the organization of executives said the data breach had an impact on the business’ reputation Ponemon Institute Study Ponemon Institute Study Ponemon Institute Study
  • 8. Copyright© 2018 Sucuri. All Rights Reserved. Non-monetarydamages are painfultoo Bad Press Loss of Payment Card Privileges Your Time
  • 9. Copyright© 2018 Sucuri. All Rights Reserved. What is PCI Compliance?
  • 10. Copyright© 2018 Sucuri. All Rights Reserved. PCI Compliance In 2006, American Express, Discover, JCB International, MasterCard and Visa Inc. founded the Security Standards Council (PCI SSC) in order to maintain a comprehensive and evolving set of standards to help vendors protect their payment systems. PCI = Payment Card Industry
  • 11. Copyright© 2018 Sucuri. All Rights Reserved. BuildandMaintaina SecureNetwork • •
  • 12. Copyright© 2018 Sucuri. All Rights Reserved. Protect Cardholder Data • •
  • 13. Copyright© 2018 Sucuri. All Rights Reserved. Maintaina VulnerabilityManagement Program • •
  • 14. Copyright© 2018 Sucuri. All Rights Reserved. Implement Strong Access Control Measures • • •
  • 15. Copyright© 2018 Sucuri. All Rights Reserved. RegularlyTest andMonitor Networks • •
  • 16. Copyright© 2018 Sucuri. All Rights Reserved. Maintainan InfoSecPolicy •
  • 17. Copyright© 2018 Sucuri. All Rights Reserved. Website Security
  • 18. Copyright© 2018 Sucuri. All Rights Reserved. How Websites Get Hacked • • • • • • • •
  • 19. Copyright© 2018 Sucuri. All Rights Reserved. SSL Certificate= Secure? • • • • •
  • 20. Copyright© 2018 Sucuri. All Rights Reserved. Website ApplicationFirewalls • • • • • •
  • 21. Copyright© 2018 Sucuri. All Rights Reserved. Post Breach PCI Protocol
  • 22. Copyright© 2018 Sucuri. All Rights Reserved. Mandatory Forensic Examination • PCI DSS require merchants that are suspected of having a data breach to have a mandatory forensic examination. • According to Verizon Business, a small business examination may cost between $20,000 to $50,000.
  • 23. Copyright© 2018 Sucuri. All Rights Reserved. Notificationof Customers • If financial information is suspected of being compromised, most states require that customers be notified. • University of North Carolina at Chapel Hill said a 2013 data breach of just 6,000 records has cost the school nearly $80,000 in working with affected parties.
  • 24. Copyright© 2018 Sucuri. All Rights Reserved. Affected Customer Credit Monitoring • If you experience a breach you may be required to produce up to a year’s worth of credit monitoring and/or counseling services to customers affected by your breach.
  • 25. Copyright© 2018 Sucuri. All Rights Reserved. PCI ComplianceFines • In 2011, 96% of the merchants experiencing a data breach had not complied with the PCI DSS. • If the forensic investigation shows that your business was not in compliance heavy fines could be levied against you. These fines can range from $5,000 to $50,000 or more.
  • 26. Copyright© 2018 Sucuri. All Rights Reserved. Liability for Fraud Charges • Many merchants assume they have no liability after a data breach. • This is not necessarily the case; lawsuits may claim liability on merchants for security breaches.
  • 27. Copyright© 2018 Sucuri. All Rights Reserved. Credit Card ReplacementCosts • Merchants may be required by card issuers to pay the cost of reissuing cards to customers. • These fees can range from $3 to $10 per card.
  • 28. Copyright© 2018 Sucuri. All Rights Reserved. POS System Improvements • Depending on the source of the breach, you may have to invest in upgrading or replacing your POS system, including servers, software and/or card swipe devices.
  • 29. Copyright© 2018 Sucuri. All Rights Reserved. Reassessment for PCI Compliance • In order to qualify to accept cards again, a complete PCI assessment by an external Qualified Security Assessor (QSA) must be performed.
  • 30. Copyright© 2018 Sucuri. All Rights Reserved. Thank You! Alycia Mitchell