Quote:
|
Originally Posted by MichelH
It is rumoured that MasterCard is currently investigating PaySystems and other payment processing companies to investigate if they comply with their new rules. It is even rumoured that PaySystems has been shut off by MasterCard...
|
This is true but possibly exaggerated. All the card companies are implementing new security rules and HIGHLY recommending compliance and even threatening fines and shut-offs. The card companies are starting at the top with the banks, processors, gateways and third-party processors and then work their way down.
The problem is that there is a disconnect between the persons that make the rules and the persons that enforce the rules within these companies. The people that make the rules are thinking about fraud liability; the people enforcing the rules are thinking lost revenue if they piss too many merchants off. Because of this, enforcement of these rules, thus far, are just idle threats. I've heard that Verisign has as much as told VISA and MasterCard to go piss up a rope yet I have not heard any rumors that Verisign is going to be fined or shut off.
Most likely, enforcement of these new rules will somehow be rolled up into the fees the merchant pays – if you, as a merchant, comply with CISP and the other mandates, and you only use compliant systems between the cardholder and the bank, then you will pay a slightly lower rate that the merchants and systems that don't comply.
Until some sort of consistent enforcement structure is adopted (fees or otherwise), the enforcement will be limited to saber rattling and possibly fines for merchants, third-party processors, gateways or banks that actually get hacked and it can be determined that non-compliance to these new security rules attributed to the event.
BTW, I'm not advocating non-compliance with these new regs and mandates, quite the opposite; I advocate immediate compliance regardless of the enforcement methods or threat of fines. Lack of security is not just a black eye to the payment industry; it is a black eye to the entire Internet e-commerce community.