Successful PCI Programs at Large Organizations

Listen to learn about the process of large-scale PCI DSS compliance from both a QSA and a client perspective.

Updated:  
October 12, 2023

SecurityMetrics Podcast | 17

Successful PCI Programs at Large Organizations

When your organization has 300 Merchant IDs (MIDs) in a multi-modality environment, leading a PCI DSS compliance program is no easy task.

Robbyn Lennon, Senior Merchant Services Program Coordinator at the University of Arizona sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA), along with SecurityMetrics Principal Analyst Michael Simpson to talk about large-scale PCI DSS compliance from both a QSA and a client perspective.

Robbyn explains in detail how she established a PCI DSS compliance program at the University of Arizona. With over 10 years of experience, she shares her three-part strategy: “Engagement, leadership, and encouragement.”

  • How to reduce scope in a large PCI DSS compliance program by organizing merchants into “pods.”
  • Why a focus on leadership as opposed to management helps employees take accountability for their job processes.
  • The tools, training, and documentation you need to empower merchants and improve your PCI program.

Resources:

Robbyn on LinkedIn

Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide

Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

Successful PCI Programs at Large Organizations Transcript

Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst here at Security Metrics. Very excited to for the topic today.

We're gonna be talking a little bit about higher education and how to set up a a PCI DSS, program at your universities, your colleges. And I have with me today two, great people on this topic. One is Michael Simpson. Mike, can you tell us a little bit about yourself and and and your relationship to this topic?

Yeah. For sure. Thanks, Jen. Yeah. So the my I'm Michael Simpson. I'm also a principal security analyst with Security Metrics.

I lead a team of assessors that work specifically with our higher education and our government, clients. And a lot of those are what I would call the multi mid environments where they have multiple merchant IDs that they're working with, and each of their merchant IDs could have their own independent way of processing credit card data. So it's a little different way to handle credit card information, and so auditing that environment is a little different as well. So I've been doing that for just under ten years now.

It's been great. And then I work very closely with Robin Lennon from the University of Arizona. Robin, did you wanna introduce yourself?

I'm Robin Lennon from university from the University of Arizona, and I am the merchant services program coordinator senior.

My job is to lead my merchant groups. We have quite a few over three hundred mids and what in a multi environment, multimodality environment, we actually have we're decentralized.

So as a result, we have quite a few different environments that Mike has to help us with all the time. The reality is is that starting in two thousand six is when I was voluntold to go into this area, we didn't really know what PCI was. All I knew is when I was talking to the bank is that we had to be PCI compliant.

So a lot of things have changed since two thousand and six. We have better guidance.

We have a organization that is mature. And hopefully, we can share some things that we have discovered on trying to handle. And I call it leading, not manage. I call it leading a group of people to make sure that we're all compliant and protect our merchants and our university.

Excellent. I'm so glad that you're available to talk to us about this. I was hoping that maybe, Michael, you could talk to us a little bit about, you you talked about multi mid. You talked about, multi mod modality came up.

Mike, can you tell us a little bit about, scoping? How is scoping in an environment like this different? What what do we need to know? There's a lot of people that are like, well, we do PCI all the time.

Why is it harder to do university? What makes it different? Can you speak to that a little bit?

Yeah. For sure. I mean, we we deal, even my team, we have a lot of assessments where we have merchants, sometimes level one merchants that have locations all across the nation. But kind of the difference that a lot of these higher education groups and the government groups deal with the other businesses might not not deal with is each of their merchant accounts or their MIDs may process differently. So the way that they receive credit card data, the way that they, enter that credit card data to be processed, it could be different for every single merchant ID. So those all have to be independently assessed.

A lot of organizations like, we also deal with a lot of parking entities that have multiple mids just to keep all the accounting separate between all of their locations.

But the difference that they have is a lot of times they'll use the same systems at each location. So when we're doing an audit for a multilocation environment, similar to, like, we do a lot of restaurant chains, they use, you know, the same point of sale systems everywhere. They have the same process and procedures so we can sample. Instead of seeing every single one of their locations, we can take a sample of them and verify that, yes, they do have good centralized controls, and all of them are following those controls based on the sample that we've selected.

With our our university and our government entities, because each of their merchant IDs may process very differently, it's hard to to sample and to group those into, sampleable, environments. So we we tend to have to look at each individual merchant account and scope that individually. So as we're looking at each merchant account on campus, we're looking at, you know, how are they receiving data, whether that's in person, you know, card present transactions, if it's over the phone, if it's ecommerce transactions. And then once they receive that data, how is it being processed?

What types of systems are they using? Are they storing any credit card data either electronically or on file?

How is that transmitted to whatever entities they're using to to authorize the transaction and to process that?

So for for scoping one of these multi mid environments that universities typically have, it just tends to be a much broader, effort because each one has to be individually scoped instead of grouping them all together as as one whole.

So, Robin, you said you started this in two thousand six. How did you get your arms around the different the three hundred did you say three hundred plus merchants?

We have three hundred plus. Yes.

So the interesting thing is is because of the situation, and I tend to group the group things and try to make things as simple as possible. We had to figure out, first of all, what we had to do. And back then, if anybody wasn't part of the PCI then, it was not as the guidance wasn't out there. There was a lot of things that were a little differently, or one place would say one thing and another place would say another.

And especially in a decentralized environment, which really is in a, we're a group of mom and pops of different storefronts, right? Because one area may just they may just sell crickets for research. Another area like our bookstore is more like a major store. And so what we were trying to do is figure out what we had on campus.

Well, we went, we knew we had to do this, but all of a sudden we got the level two letter from our bank. You are now level two, and you have to actually file the, the assessment.

And then later on, we had to make sure that we had a, an assessment by QSA once a year, a validated, assessment.

So what we did was start just visiting. I became a credit card, and I I knew who the merchants were, actually talk to each one of them. And we would go into it. If it was a point of sale, I would go there.

And I'd go, okay, I'm a credit card. Where do I go? And something as simple as that, you know, make me understand what's going on. Because a lot of it is just process.

It's it's figuring out what the process is because, you know, process.

It's it's figuring out what the process is, because if you ask questions, it sometimes processes change, and the people you're asking questions to don't know that that someone has tried to improve the system and is doing something different. So what we did was go around, and I established relationships with all the merchants. And because we had three hundred, different kinds, then what we did was create groups. So we had you know, parking might have forty mids.

Right? Well, it'd be silly for them to do forty FAQs, right, or forty look at each one of them. So we created these pods, and, we we started creating these groups so that we could handle them like that. The other piece of it was is that, I firmly believe that you go to where the action is.

And so we started on ground. The people who actually were handling the credit cards. Right?

They're the ones that really have control, and they are our strongest and weakest links. So we started there, just on the floor, and then we started moving up and making people in the organization responsible for their group. Because I couldn't be responsible.

Right? I couldn't say, oh, I'm responsible for you guys taking your cards and your compliance because it's totally impossible that they had to have ownership.

So we started going in there and talking to people about just the processes, what was PCI, and actually determining what they were doing in each one of the entities and grouping it, and grouping the mids so that it was manageable. So we went from instead of over three hundred, we went down to about a hundred groups. Right? And that way, it became a little bit more manageable.

Nice. So, you've we've said a couple of of phrases now that, maybe some of our listeners are unfamiliar with. Most people understand PCI means credit card security. And if if if you didn't know that, I apologize for not saying that earlier.

PCI is the standard for credit card security. Right? So an SAQs is something that's that's a a type of you know what? I'm gonna have Michael talk about that.

Can you talk a little bit about what an SAQ is and maybe some of the common ones that you would see at a university or government or, you know, some of these these grouped ones?

Yeah. For sure. Yeah. So the PCI DSS, the payment card data security standard, it's a set of approximately three hundred and thirty security controls that are designed to protect credit card data. What they've found and what they've done to make it easier for merchants to assess is they've created these self assessment questionnaires.

So and those self assessment questionnaires are a subset of those three hundred and thirty security controls that are designed to protect specific types of payment channels.

So we have and it's kind of like an alphabet. There's the SAQ a and the SAQ b and the SAQ c and the CBT. There's just there's a handful of these self assessment questionnaires.

One example would be like the SAQ b is designed for people who are taking payments usually either in person or over the phone, and then they're entering that data into, you know, their bank provided analog connected terminal. So since that bank terminal is connected to an analog connection, there's no need for firewall. So a lot of the PCI controls surrounding how to configure your firewalls and your network security, those don't apply, so they're not in the SAQB.

The same with, antivirus. You're not gonna install antivirus on one of these bank terminals. It doesn't have that type of an operating system.

So what the council has done to make it easier, if if you have a very simple payment flow like the SAQB, where you're just taking credit card data and processing it on an analog terminal, instead of having three hundred and thirty secondurity controls you're looking at, there's more like thirty secondurity controls. And they're all designed on how to protect the paper that or the the credit card data that you're collecting. If you're destroying anything on on file, there's security controls around that and security controls around the physical security of your terminal to make sure that that doesn't get tampered with. Similar to, like, the SAQA, that's designed for merchants who are outsourcing all of the payment collection and processing to a PCI compliant third party provider.

Usually, this is ecommerce, and they have you know, they're using Authorized on Ad or PayPal or, you know, there's a host of ecommerce providers who will take the security burden and the compliance burden away from the merchant by collecting and processing that data themselves.

So, again, instead of three hundred and thirty controls that people have to manage, there's, you know, just a handful, a couple of dozen controls that they're, that they need to validate to make sure that the way that they send customers to that third party is done in a secure manner and to validate that they're keeping an eye on their third parties to make sure that they maintain compliance.

So there's there's a lot of different SAQ types, those self assessment questionnaires, and they're all designed to protect specific types of payment channels.

So part of the scoping is understanding what type of payment channel a merchant has. And then each of the self assessment questionnaires has, this section is called the eligibility to complete Completely. Section. And there there's usually, like, five or six statements that you that all have to be true for you to use that self assessment questionnaire to validate your compliance instead of validating against the full set of, you know, the PCI DSS controls.

So, Robin, you mentioned, something about having different FAQ types. Do you wanna speak a little more to this topic and and how you figure it out and help people figure out what FAQs they should be taking care of?

The FAQs are a great learning tool, to give you an example. And right now, we have in the last couple years, we've actually did Mike has, actually did little classes on each essay queue because it really our, our basically focus is is the more they know and understand, the more they're engaged and the more they can find their own issues. To give you an example, when we first started this, the FAQs, I would use that as a learning tool, and we would start going through everything. And we had a lot of different modalities.

At that point, when we originally originally, we had a couple of, of merchants that actually retained credit card numbers. So with that, the whole three hundred and was it thirty questions were applicable. And so we would have to go through it and use it as a uni a learning tool to make sure that they understood what's going on. It's a great way to discover what we would do at first when we first started into this.

We would go when we do our process, be the credit card, be either coming across a point of sale or through ecommerce. We would discover what's going on. Where do I go now? Oh, I'm sitting on the server in clear text.

You know? You're like, no. No. No. No. No. We can't do that. Right? Or gee whiz.

We need to make sure that we are not we're encrypting correctly and we have the right firewalls.

What we discovered at that time using this tool in the self assessment questionnaire and all all through it is that sometimes people didn't understand.

And, I mean, we would go or they would answer it, like, it doesn't happen anymore because our program is very mature. But it originally, we'd say, do you have firewalls? And they go, yes. Well, I learned I would actually have to say, is it turned on?

You know, because Yes. Because then we would find, Oh, no, it's not, because it was interfering with our application. Now, this is very old stuff. Right now, we've got firewalls that's really changed.

But those were the kind of things that we would have to do in our discovery phase and really use it. I like it on the self assessment questionnaires because it keeps us fresh, and it keeps us engaged, and it keeps us away of it's an excellent tool to keep us centered.

So, when we have all these different things, I mean, these tools, which is the the PCI Council has provided us, a lot of people think of it as just paperwork or check the box, but it is they are really good security tools to kinda keep us in the now. Right.

One thing too I wanted to mention quick, Jen. With with the self assessment questionnaires, like, the bank, when they're asking these merchants to assess, they don't want a hundred FAQs turned in. They want one self assessment validated FAQ, and it's usually the SAQD that they want. So the instead of having all hundred merchant groups fill out an SAQD, we have them fill out the SAQ that applies to their payment channels, and then we can take all of the information that we glean from all, you know, hundred or hundred plus FAQs, and that all gets rolled up into one SAQD that then gets turned into the bank. So that's kinda how that assessment process works.

So what's going on there is this has worked very well for us. So we have all these pods or groups, that are responsible for their little store for their store, either their big store or a little store. And so they may have three different environments. They may have, ecommerce.

They may have point of sale. They may have, virtual terminals. So what we do is we have them complete those three type of essay self assessment questionnaires so that they they hand those to us. We review them.

I should say, Mike and I and anyone else. Jen, you've reviewed them before. And then what that will becomes the documentation to, underscore, I should say, or the documentation to document my greater our greater SAQ, which is usually a d at the end. And then we just complete all that information.

So we have a question of saying, hey. You've got all these merchants. We have the documentation underneath there to support, our SAQD.

It's just an easier way to handle this the large, different modalities.

I agree. And and I liked what you said about having even if you have a single merchant that has different flows, they're doing a different SAQ for the different flows, and it helps get in their minds, some clarity around how they're taking these these credit cards. And and with that clarity, do you believe that you have reduced scope?

Oh, definitely. And I I have to say, it's not about me. I mean, I'm just leading them. I can't you know, all we can do is really engage them.

I call it the three pieces, is engagement, management, and encouragement.

The engagement is the teaching piece, right? Letting them know what they have to what's the responsibility.

The management piece is giving them the tools to be successful and to make sure that they have the things. We have templates, the support to choose the right application because things have changed over the years. So what they have is there's a lot of third party applications now where it used to be we would have to create them. Right? And then encouragement is really the piece that keeps them engaged because we all, time flies, especially right now, you know, things are crazy. And so you have this constant cycle of engagement, the management, and the encouragement.

So when you have this many people, even if it's a small entity, it's a small group, you have a lot of people involved.

So it allows you to have a touchstone, so to speak, to go back. And, again, like, I I repeat, you know, something to pull back on when things may feel a little out of, sync like it's like, currently with COVID. Right?

Sure.

So, Michael, she mentioned some of the tools that that, get offered some some of her merchants on, knowing how to fill out those FAQs and and really get on the on the same page. Because I've noticed there is some turnover. You you new people coming in, they might not always know, or it's been a whole year. And I don't focus on this. And and how am I supposed to remember it from the year before? So, Michael, what are some of the the the training and and support that that you have been part of that that is helpful to to these types of groups?

Yeah. I there's a couple of things. And one of them, I think, was really pushed by Rob on which has helped a lot is each of these groups create their own merchant manual or or binder. And it has all of their policies and procedures that describe how they secure credit card data and what steps have to be done to make sure that they maintain a secure environment.

The thing that that helps at this type of an institution is if there is turnover, instead of all that knowledge being lost, there's something that's still there. And then to help reinforce that, usually, as part of the annual assessment as we're getting ready to do an assessment, we'll spend some time having webinars with the different merchant groups. We'll explain what PCI is. We'll explain what the different, SAQ types are and what payment flows they apply to.

We'll help them understand what security controls the assessors are gonna be looking for to make sure that they're securing that data. So we kind of really, every year, start from ground one to help bring those new people up to speed so that they know what's expected of them and when, you know so when the assessment comes, it's not some scary thing. It's just an opportunity that they have to show that, yes, I have been maintaining the compliant environment. So we try to make sure there's no surprises.

Exactly. This is not we're we're we're helping. We're not, what shall we say? What we always say, we're we're helping.

We're part of the solution. We're not just trying to create another problem for them. Because they have all different type of things that they're worried about. Right?

And, so compliance is big at a university and anywhere, and we want them to be, again, part of the solution so that the learning and the providing that learning is really important. I wanna say something about what Mike was talking about. We started out everybody would have to have these binders, And it really followed everything except for, it included everything on their SAQ so that they were able to make sure they had the documentation, plus additional things. Long time ago, we for all the third party, the the self assessment ecommerce's SACAs, I keep wanting to put in thing terminology, but for the ecommerce, the third parties really didn't have to have the scans, the external scans and the internal scans.

But we as a campus decided that, with our assessors, that that would be really a good line of defense. So we we make them or we we provide that information to them, and they have scans if they have if they jump to a, if they have one jump to a payment gateway.

So they would have to have that in their binder. They would have to have their policies and their processes and their procedures and their incident response.

Well, that's a lot saying that that has saved a lot of departments' problems when they had somebody who just left, that someone could actually pull down the binder and actually start looking at it, and we could use that as a as a basis for learning and to bring them into the fold, so to speak. Well, lately, there's been a lot of of wanting to make sure we go paperless.

And, unfortunately, I find that that is not as as, not as good a tool as actually having the binder. Something different than having and flipping a binder versus actually seeing it electronically. Right? So we're working on that.

How do we make sure that everybody has the access to the electronic version of it on the, on the on their server? Because that happens too. We don't know where it is. They might have put it in their personal, and they no longer have access or whatever.

So that binder has really saved our behinds at a couple times or my what we call the merchant responsible person, because each department group has a has a individual who is my contact and is responsible for the documentation of their group, when somebody leaves.

I too have found that the the binders are very important. I had a an experience last year where, like you said, somebody had left and somebody was new and was expected to respond to the assessment. She she was very new and hadn't had any of the trainings, and there was no binder for her to look at. And when I showed up to talk to her, she burst into tears.

And I I felt horrible because, I mean, basically, all I said was, hey. Let's get started on your assessment. Where's your binder? And and just it was so overwhelming for her.

And I wasn't quite sure how to to to help her in that moment because she didn't have the tools that she needed to really feel confident to to answer. And I don't also, I I don't make a habit of making people cry in assessments.

It was really not a good moment.

But if she had had a binder, something to look at.

The the PCI compliance, especially when you have maybe, for for your SAQ b where you just have a swiper, you know, some of these this is not a lot. It's not complex.

And people are are absolutely capable of stepping up and doing it, but they need a place to start from.

Right. Right. And it's really important. So the biggest thing I have to say is that anybody who's in charge of their their PCI compliance or it's it's supporting those that are on the feet's on the ground, the boots on the ground.

Because they are your they are the whole picture, actually. It doesn't matter if it's in your IT department. Actually, even in accounting because they see what's coming through. Or the people that are actually in front of the point of sales.

Or the managers who are in who are in charge of the processes and the procedures. Because how many of us have always been, we don't find it as much now, but we used to have people come in and go, well, why do we have to do all of this? Right? Because they didn't have the tools or they didn't have the knowledge to know we have to do that because of security, because of compliance, and then we would change things.

But, yes, that's that's where the little binder is. We have found even though the procedures the procedures on how you do something, maybe one only one person did it, right, for three different entities or whatever, and they just and they had been doing it for so long and doing it so well, no one even knew what went on behind the scenes Right. Until they left. You know?

And then they might be in the beaches of Hawaii and can't get ahold of them. Right? Or whatever. So no.

Even though we love to go paperless, there is something that we really train on is saying it it might be a really good way to make sure that you have some sort of continuity, where in case, even if someone surprised an audit, we have that our internal auditors and our external state auditors got to the point they would ask for the binder. You know? Oh, you take credit cards. Can I see your binder? It takes off the pressure from the entities who are being auditors, the audit I mean, who are being audited, the auditors. And it brings it full circle. So it really does help the whole, sit the whole auditing situation.

So so so you you spoke a little bit about, spreading that ownership. Right? Because you don't man it. You don't you know, you're not the one in control of this process.

Different merchants are. How have you been able to spread that ownership and help people understand that they are responsible for their own, section of that compliance? So get the where I'm getting at is anybody at a that has a lot of mids that that they try and do all the work, it's just overwhelming. It's just too much.

Well, and even the smaller organizations because we're not boots on the ground. We're we are back here. We're their support and their resource.

So the people that are actually doing the work have to be there so they can see. They can see the stickies on the they can see the stickies on the, on the screens if people are taking mail ins, right? Or they oh, that's another one that's changed. We don't take mail ins anymore, right?

Remember when we first all started, it was fun. People had the forms that had, you know, this is my credit card number, and they put it in the in basket. Right? And then the front counter.

You don't do that anymore. I know. But when we walk around and going, oh, no. You know, because you have this basket full of credit card numbers, you know, that went went away a long time ago.

And I'm sure it still happens, you know, but we we really be careful of that. But those, but those are the kind of things because you we can't be there. We need to have that education out there to people so they can seek it. I have a lot of things that we started with assigning each group a merchant responsible person.

And this was our contact. This was the person who had created the team within their their area. Right? Their their PCI pod, their little tribe.

I actually call them my my whole campus as my you know, my tribe. And, they they would create that so that they understood who was involved, what were the processes. They would have the meetings with them because I can't have continual meetings. They would talk about it in their meetings and trainings.

When they'd meet, like, hey, does anyone have any questions? This is a great way to do instant response training. So each one of these individuals would have their group, and that would keep their group fresh. Plus, I would be able to contact that person instead of trying to find who's the job it is at that time to manage the front desk or the ecommerce or whatever. I'm a keep it simple person, and that was a lot easier for everybody to to, disseminate information and create that energy.

So so we've talked a lot about the decentralized approach, getting responsibility out to the to the the merchants.

But there's always that piece. And, Michael, I was hoping you would speak to this, that the central IT functions that that span all of it. And how does that fit? What have you seen, and how do you make that piece successful?

Yeah. So that that one can be challenging, because a lot of especially with our higher education, groups and even our our state government groups. They they tend to there's a certain point when you need more technical skill than one individual department may have access to. So they rely on some central, IT group or some central IT security group to help manage firewalls or to help, install networks and provide the appropriate network segmentation for a PCI environment.

There are some groups also that they have, you know, a centralized group that manages all of their ecommerce sites that are redirecting out to these third party gateways.

So if if you have a third party IT organization, it's really important that you have buy in from upper management so they understand the importance of of PCI compliance. Because for a lot of these groups, you know, they're not the merchant. They're they're not accepting credit card payments. Sometimes it's hard to get them to understand why it's so important that they are following these payment card industry, security requirements on their firewalls or or or how they manage their servers if they're following these, requirements from the payment card industry.

Once you get that buy in, though, they can be a really helpful tool to, in your merchant compliance program.

There's a lot of there's some groups that we use where they'll you know, their central IT group has templates. So if they have a merchant that wants to have a kiosk, where people can make payments, they have they know exactly, okay. This is how we're gonna implement the network in there. Here's some documentation to help you with your, you know, deployment of your kiosk. So they can kinda be there to guide them, on those really hard technical questions that that a lot of these people that are responsible for the merchant account may not have the technical knowledge they would need to to implement those types of controls.

So a lot of times, you you will have to rely on a central IT group, that isn't always necessarily as plugged into the audit as as your merchant would be because they're not dealing with credit cards directly. They're just helping to support that environment.

But once once we find once we get that support in place and that and that understanding in place, then they can really be a a great asset to the organization.

Our administration is fantastic, and it really is it is really important. I think that the change in the industry, allowing people to, the administration to really take notice. And it was a long time ago, but the Target and Home Depot reach really started bringing, it was easier to bring people involved and hires because we just the, because that was the first time in a long time that I had actually had the higher administration give miss a call and say, are we okay?

So, you know, yes, we are. We've been working very hard on this for a long time. So yeah. And it they are amazing to work with. So it's really important to get your higher admin and involved.

So, in in addition to that, getting that that admin involvement, if if there's another higher education group that's just starting their journey down PCI, what were some potential gotchas or some some of the biggest pieces of of advice that you could offer to them?

Well, first of all, I would I would say collect the information on all of your the who who who's what's going on? What are the procedures?

And on every one of your groups and understand who is who the players are. We really need and get start getting them engaged so they understand that you're not being you're not picking on them. You're creating relationships.

The strongest compliance programs and security programs is really that you created this big relationship that we're all part of the solution.

I think that's the biggest piece. I find that a lot of people that call me and say, what are you doing? What's going on? And how did you do this? Is basically I go begin with relationships, and really working on each one of the levels.

We really are truly in it all together, and especially in a campus environment.

The reality is, if one little sac one sac a I won't call them little because some of them are huge, right? But, or a point of sale, if they get breached, the whole campus gets breached.

I don't know how the, the industry, how the card brands are going to say to us, like, oh, no. We're just going to isolate and do forensics for here. Right? It may affect the whole entire campus.

And I tell them that. They go, really? Do you think that would happen? I go, I can't read their minds.

I don't know. And it depends. So we truly are in it all together.

And I think that is the thing I would first say. And the second thing that you were talking about is that you can't do it. Whoever is in charge of it, we can't do it. We can't do it without them. We are just a resource. We are leading the charge. We are helping them.

We're we have their back.

And creating that environment that if something goes wrong, they have no fear of giving you a call. I tell you, I've had people call me and just say, hey. Guess what? And tattletale on other people or tattletale on themselves.

Right? And just say, hey. I don't this is what happened. We had a new person.

What do you think? And this is the environment you want. You want to be able to know that people will be able to tell you if they've discovered a weak point or a an issue that needs to be solved.

I think that's the greatest piece. And the other the third, I would have to say, is create your create your resources, procurement, and in an environment because they are doing all the different contracts and agreements that they may not know might have a credit card piece of it, right, or a payment piece of it. So develop relationships with your procurement and contracting. Develop and they're part of your team.

You were saying campus IT. It is great. Our campus IT a long time ago said, no. We don't have any PCI. We don't want any credit cards on our servers. And this is long time ago because our program has been, you know, is years old. And I said, well, unfortunately, that's not the case.

So, you know, and so is bringing them in, and they're part of it. And I our IT people are unbelievable, all over the campus, be it in the individual departments as well as the central IT. Mike has been great with them, and, they really have come along over the years.

So it would be your security people, your information security people. They're part of what you're training.

And it is just like this. Right? And we're even finding now that even the people that are involved with HIPAA and all the other compliance areas are a great a great resource, and they help because they're out there as well. And you're auditing your internal auditing individuals.

They are, they're, very valuable in allowing you if they're out there saying, Hey, I think this group might need help, or if they're out there saying, hey, I think you need to contact your the program coordinator. Or they just say, Robin, but I you know, program coordinator to help you with this piece. So that developing that team, again, it's relationships. Developing that team and that just piece is really invaluable to your security program.

That that is such excellent advice. Michael, from your perspective, do you have anything to to add on that for for groups like this?

Yeah. I mean, I think you need a kind of a balanced approach. It is important that you have ownership, distributed to all the merchants. So the I'm you know, I've seen some groups like this multi mid environments that are really small where they may only have, you know, fifteen, twenty merchant accounts that they're dealing with.

And at that size, yes, you could have one person that's kind of in charge of it if they have the the political authority to go into each of the groups and say, hey. This is how you have to deal with credit card data, but it doesn't scale well. So so you do need to have that merchant buy in from from all of the people that are accepting and processing credit card payments, so that they can help to hold some of that burden. It allows you to scale.

But you also do need to have that central, you know, people at the top of the organization. They need to understand PCI compliance, and they need to support your PCI compliance efforts. If you have a merchant account, like Robin was saying, if you have one merchant account that's not compliant, your whole organization is not compliant. So if if you have one of your merchant groups that just refuses to to to join in the group and, you know, put those necessary controls in place to protect not only their organization, but the the university or campus as a whole, then you need someone to be able to step in and say, hey. You know, you either do it securely or you don't do it at all. So you kinda need a a combination approach where you do have, buy in at the executive level, and then you also have that responsibility distributed to each of the merchants. So everyone is working together to secure the data.

Well, this has been a lot of really actionable, information. Robin, go ahead, please.

Oh, I was just going to say what Mike was talking about. You do have to have the ability to say, that may be so if they don't wanna do compliance, but these are your options. And we've had to shut people down. They have decided that it was a joint effort because we work every everything we can to make sure that they're successful.

And to provide and to work with the application to do what they want to. But they have to do it within certain options. But we have had individual departments that have said that it was not worth it to do the compliance piece that they, that we were requiring. So they we found a different way for them to utilize credit card payments.

And most of those were small. We find that you really have to weigh it because if you don't have a lot of transactions, but you then there's other way and you don't want the compliance and there's other ways that we can support you to maybe, like, we rent out little point of sale terminals or we can do some other things.

We have some new newer processes, which is really great. We're working through p two p e and so through some of the, card, some of the card payment gateways that allow them to pretty much move remove most of it, if not, all of it. So to allow them to do what they need to do. But the reality is is that they're at the bottom line. You have to say, you know, I don't think this is going to work for you.

Well, this has really been a a great, session talking to both of you. I wanna give each of you a chance for last words of advice first, Michael. And then, Robin, we'll let you have the the final word on things so that, Michael, any last pieces of advice that that we haven't quite touched on yet?

I I would just say, you know, the importance of annually scoping your environment. So whether you have a single merchant account or you have three hundred merchant accounts, things change. The way that you process credit card data changes. It's something that we've seen especially this year with COVID nineteen and the lockdowns and a lot of people working from home. Sometimes you're processing from home. So it's important every year to just kinda go through all of your documentation, make sure that you understand how credit card is data is being processed today and not how it was processed last year to make sure that you have the appropriate security controls in place to protect the data.

Because while compliance sometimes can feel like a burden, it's really there to help your organization reduce risk so that you don't have, you know, a much worse event happen to you that you don't wanna have happen.

Right. Right. Robin, last words.

Engage, engage, engage.

I think and keep in the encouragement. I use well, I feel as though we use the documentation as part of the encouragement as well, as far as the management tools and the engagement tools. We do a hundred percent documentation review and we have found and discovered that that is the better way to keep everybody engaged.

I cannot emphasize enough that every year your different modalities should do the documentation, even if you don't have to submit to a bank.

What we did find in the past is if they were passed over and didn't have that documentation review, they may not even look at it, you know, for a year because they just didn't have time or they didn't feel it was as important. So having the hundred percent documentation review with all of your merchants is really important. And that does keep you them encouraged.

You you hone your management, your what you provide them, and it keeps them engaged.

Thank you so much for coming and talking to me today, Robin and Michael, you as well.

Some super great information and and I hope that it's, helpful to to our listeners. Thank you for joining us once again here at Security Metrics podcast.

If you find this useful, please share it out to some of your friends. I know that this is some some really great information that that Michael and Robin brought to us today, and I hope that that you find it useful as well. Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.