Sett opp kontoen din

Beskytt din bedrift

Som en bedrift som tar kortbetalinger, har du et ansvar for å holde kundenes kortinformasjon trygg. Dette er tett regulert av Payment Card Industry Data Security Standards (PCI DSS) og påvirker alle virksomheter som godtar kortbetalinger. Hvis du vil finne ut mer om hvorfor og hvordan dette påvirker deg, kan du ta en titt i vår Guide for PCI DSS.

For spesifikke sikkerhetsrelaterte problemer kan du sende en e-post til fraud.norway@elavon.com, og vi vil svare innen en virkedag.

PCI DSS Compliance

 

Hos Elavon har vi betalingssikkerhet som vår første prioritet. Derfor opprettet vi Secured by Elavon, et enkelt sikkerhetsprogram som gir deg alt du trenger for å holde virksomheten din beskyttet - fra å oppnå PCI DSS (Payment Card Industry Data Security Standards) til å sikre kundenes data gjennom transaksjoner.

PCI DSS er et sett med krav for å forbedre datasikkerhet for betalingskontoer. Disse standardene ble utviklet av PCI Security Standards Council, som ble grunnlagt av Visa®, MasterCard®, JCB®, Discover® og American Express® på global basis.

Dette gjelder alle virksomheter som tar kreditt- og debetkort, uavhengig av størrelse eller transaksjonsvolum. Enhver virksomhet som er involvert i lagring, behandling og / eller overføring av betalingskortnummer må overholde disse.

Fraværet av manglende overholdelse kan ha en dominoeffekt på virksomheten din, da de økonomiske implikasjonene av et regelbrudd kan ødelegge kunder av alle størrelser. Du kan redusere risikoen ved å overholde og verifisere sertifiseringen som kreves av bransjen. Ved å følge standardiserte PCI DSS prosedyrer, kan du:

 

1. Beskytte kundenes personopplysninger

2. Øke kundenes tillit gjennom et høyere datasikkerhetsnivå

3. Beskytt organisasjonen din mot økonomiske tap og utbedringskostnader

4. Opprettholde kundenes tillit og ivareta omdømmet til merkevaren din

Lær mer om produktene våre rundt PCI Compliance  

Velkommen til Secured by Elavon

Som ny kunde blir virksomheten din automatisk registrert i Secured by Elavon. Dette gjør at du kan få din PCI DSS-sertifisering, samt administrere ditt pågående compliance-program.

Virksomheten din holder deg opptatt nok, så om du ønsker å spare tid, la Elavon administrere PCI-compliance for deg. Hvis du gjør det, er Secured Pro det riktige alternativet for deg.

Secured Pro, administrert av Elavon, tilbyr deg forbedret beskyttelse mot svindel og brudd på betalingssikkerhet, og sørger for at bedriften din ivaretar kundene og omdømmet. Enten du er kunde for første gang eller fornyer, betyr Secured Pro at vi administrerer complianceprosessen for deg, kontakter deg når en handling skal utføres og samarbeider for å fullføre den. Du trenger ikke å bekymre deg mer for at sertifiseringen går ut eller at svindelprosessene ikke oppdateres.

Med Secured Pro drar du også fordel av vårt PCI Waiver-program. Avhengig av nivået av PCI-overholdelse, kan ansvar for bøter unngås.

Secured Pro i detalj

Et virksomhet som ikke overholder betalingsbehandlingen er mottakelig for sikkerhetsbrudd, for eksempel at en hacker stjeler kundenes betalingskortinformasjon. Secured Pro inkluderer en rekke skanningkontroller som sikrer at betalingsmiljøet ditt holder skurkene ute og beskytter bedriften din mot potensiell risiko for svindel:

Network Perimeter Scan

Denne skanningen vurderer sikkerhetsposisjonen til systemene som er kopplet mot internett for eventuelle sårbarheter, og gir deg en rapport som identifiserer mulige sikkerhetsbrister, slik at du kan ta nødvendige tiltak.

Sikkerhetsskanning

Beskytt datamaskiner og mobiler med denne skanningen - den oppdager lagret kundekortinformasjon og analyserer systemet for aktuelle cyber-trusler, virus og skadelig programvare for at du skal være trygg på at enhetene dine er sikre. Det er mulig å skanne en eller tusenvis av enheter på få sekunder.

Kortholder Data Skanning

Protect your computers and mobiles by running this scan. It helps you find and remove any unencrypted credit card numbers on your network. By identifying where you store payment card data you can securely remove it, dramatically reducing the scope of your PCI DSS assessment.

Antivirusbeskyttelse

Bekjemp hackere og sørg for at enhetene dine ikke er infisert med virus og annen skadelig programvare, som kan forstyrre og potensielt skade bedriften din.

PCI DSS External Vulnerability Scan

En kvartalsskanning av alle IP-områder og domener for å identifisere eventuelle svakhetsområder.

POS Application Discovery Scan

Det er viktig å sjekke og bekrefte POS-søknaden din regelmessig mot PCIs sikkerhetsråds liste over godkjente POS- applikasjoner for å sikre at du overholder kravene.

      Guide til PCI DSS by Elavon             

Ofte stilte spørsmål

  • To make the process of becoming PCI DSS compliant as easy as possible, we have developed a simple three-step process to get you certified.

    Step 1 – Register at elavonsecuritymanager.com

    You’ll receive two login emails from Secured by Elavon with your username and password for registration.

    Elavon Security Manager   

    Step 2 – Complete PCI DSS questionnaire

    Once registered, you will be guided through the compliance validation process to achieve certification straight away, certainly no later than 90 days from the date your account is opened to avoid the PCI non-compliance fee.

    Step 3 – Receive PCI DSS certification

    After successfully confirming your business is processing card payments in a secure manner, we will send you your PCI DSS certification.

    Benefits of becoming PCI compliant:

    • Keeps your customer card data secure to industry regulations
    • Reduces the risk of card fraud
    • Avoid non-compliance fees, as you no longer pose a risk
    • Avoid reputational damage in the event of a breach
  • The Payment Card Industry Data Security Standards (PCI DSS) is a set of requirements for enhancing payment account data security.

    These standards were developed by the PCI Security Standards Council, which was founded by Visa®, MasterCard®, JCB®, Discover® and American Express® to facilitate industry-wide adoption of consistent data security measures on a global basis.

  • Yes. Regardless of size, all businesses that store, process or transmit cardholder data must comply with the PCI DSS. The requirements apply to all acceptance channels including retail (bricks and mortar), mail/telephone order (MOTO) and eCommerce.

    Data security is vital for any business that accepts credit and debit card payments, especially for small business merchants, which make up 91% of those affected by a data breach. This is an industry-wide problem, which the PCI DSS was designed to combat. No business is without risk.

  • The PCI DSS requirements for security management, policies, procedures, network architecture, software design and other critical protective measures is intended to proactively protect customer account data.

  • No. Merchants have been advised to take the PCI Self-Assessment Questionnaire (SAQ) to identify potential security risks in order to achieve PCI compliance since 2010. The framework of the PCI Data Security standards is not new and has been required in different forms for some time now and continues to evolve.

  • All entities, merchants and service providers that store, process or transmit cardholder data must meet PCI DSS requirements. Requirements for certification vary, depending on the number of transactions an entity processes and the manner in which they are processed.

  • Elavon has partnered with leading PCI DSS compliance service providers to help you evaluate the status of your account, to assist with any necessary remediation efforts and to certify your account's PCI compliance.

    If you have any queries regarding your merchant account or general PCI questions, please contact Elavon Customer Service: +44 (0) 345 850 0195 (select 'Option 2').

  • No. There are many qualified security assessors (QSAs) and approved scanning vendors (ASVs). You are free to choose to certify with any vendor you like. If you choose to use a third-party QSA/ASV, you must upload your compliance certificate via our PCI portal.

  • If you do not comply with the security requirements of the card associations, you put your organisation at risk of payment card compromise. You will also be liable for the cost of the required forensic investigations, fraudulent purchases and the cost of re-issuing cards. You may also lose your credit card acceptance privileges.

    Elavon might impose additional fees for each month that your account has not been validated as PCI compliant or in any given month your account is deemed non-compliant. You must maintain your compliant status once it is obtained in order to prevent this fee in the future.

  • The minimum requirement for a level 4 merchant is to complete a PCI DSS Self-Assessment Questionnaire (SAQ) on an annual basis and achieve a passing score. If you electronically store cardholder information or if your processing systems have any internet connectivity, a quarterly network vulnerability scan by an approved scanning vendor is also required.

  • It depends how complex your card handling environment is, but on average completion takes 20 minutes. 

  • A vulnerability scan is an automated, non-intrusive scan that assesses your network and web applications from the internet (on the external-facing IPs).

    The scan will identify any vulnerabilities or gaps that may allow an unauthorised or malicious user to gain access to your network and potentially compromise cardholder data. The scans will not require you to install any software on their systems, and no denial-of-service attacks will be performed.

  • For merchants who require quarterly scans, any associated cost will be built into the price quoted upon in our PCI Programme. If additional IP addresses are added to your business between scans, there may be additional costs.

  • If you fail the network vulnerability scan, this means that the scan discovered areas of vulnerability in your network of high severity. These vulnerabilities should be remediated and another scan should be performed to ensure there are no further vulnerabilities. We will help guide you to remediate a failed scan and work toward achieving compliance.

    First, you will want to login to our PCI Portal to review the scan results. The report will provide a description of the identified issues and resources to begin fixing the problems. You will need to address each of the problems and then schedule a directed scan to ensure your remediation of the problem meets the PCI DSS.

  • As part of becoming PCI compliant, you may be required to upgrade your equipment and/or software to a PCI DSS certified version. You must contact your equipment and/or software vendor to discuss what options may be available and the costs associated with those options, if any. The cost associated with any equipment and/or software upgrade will not be covered by Elavon.

  • If your business locations process under the same tax ID, location address and IP addresses, you are only required to certify once for all locations. Please contact our customer assisstance team via 'Contact Details' on the PCI Portal. If your business locations have different tax IDs, you will need to certify once per tax ID, location address and IP address.

  • The length a PCI compliance certificate is valid depends on whether your business requires a questionnaire or scan.

    If your business only requires the annual questionnaire, PCI certification is valid for one year. If your business requires quarterly scans, PCI certification is valid for three months, at which time your next quarterly scan will be due.

    If you change the manner in which you store, process or transmit cardholder data, you may increase the vulnerability of your business and you must contact your PCI portal customer assistance team for re-certification.

  • If you have been PCI DSS certified within the past several months, through another approved scan vendor, please submit all of your certification documentation to us so that we know that your account is currently PCI compliant. Access our PCI Portal and upload your PCI certificate.

  • If time isn’t on your side, for an extra £5 per month you can opt to hand the PCI compliance process over to us to manage for you.

    Secured Pro offers a dedicated account management and enhanced protection against fraud and payment security breaches including:

    • A committed team to help you through the certification process
    • Notifications to when you’re due for renewal or need to action anything – no need to remember dates and details
    • Extensive system security scan checks to find any vulnerabilities
    • If you are breached and compliant, you will have access to our PCI waiver programme to cover any costs (depending on your level of PCI compliance)

    For more information, visit: www.elavon.co.uk/securedpro  

Ring oss gjerne – vi er her for å hjelpe deg

Kundeservice

+47 24 15 99 19 / brukersted@elavon.com

Man-fre 8:00 til 16:00

Sørg for å ha Merchant ID-nummeret (MID) klart når du ringer oss

Ta kontakt