Vector
Vector

Choose your topics

Blogs
3 Best Practices for Data Privacy

With more technology comes more data, and with that a greater need for data privacy enforcement. What best practices should you be following?

Data Privacy
Blogs
How to Prioritize Your Third-Party Risks

How can you prioritize effectively and enhance your organization’s security posture? Here are our top tips for setting up realistic, sustainable processes.

Third-Party Risk Management GRC
Blogs
Top Tips to Save Time When Assessing Third-Party Risks

Is assessing third-party risks taking up too much of your time? How can you make the process more effective and efficient? Find out in the latest post from SureCloud.

Third-Party Risk Management GRC
Blogs
The GRC Trends to Look Out for in 2024

Our GRC experts at SureCloud share their 2024 predictions for the world of governance, risk and compliance.

GRC
Blogs
The Top 5 Challenges of Third-Party Risk Management

With the supply chain now seen as a legitimate attack path, what can your organization do? Let’s explore 5 challenges of TPRM and how to overcome them.

Third-Party Risk Management GRC
Blogs
What is Third-Party Risk Management?

What is third-party risk management and how should you approach it? Find out in this post.

Third-Party Risk Management GRC
Blogs
The Top 4 Challenges of Risk Management

What are the top four challenges of risk management today and how can you overcome them? Find out in this post from SureCloud.

Third-Party Risk Management GRC
Blogs
Transform Compliance into Your Competitive Advantage

In GRC, compliance is often viewed as a cost that makes it harder to pursue growth. Here's how to make it your competitive advantage.

Compliance Management GRC
Blogs
Questions You Should Ask when Preparing For Your First Pen Test

Understand the processes that you and your chosen pentest provider will travel through for your first pen test, from the initial point to the day the test starts.

Penetration Testing
Vector (7)
Vector-1
Cyber Security

PCI London Report: Looking At The Bigger Picture

PCI London Report: Looking At The Bigger Picture
Written by

Anna

Published on

20 Jan 2020

PCI London Report: Looking At The Bigger Picture

 
 

PCI London held its 20th milestone event, attracting the best and brightest from the payments security, risk and compliance industry – including the SureCloud team. Presentations and seminars covered critical topics including third-party risk management, security as a continuous process, new trends in digital payments, and PCI DSS 4.0, including a seminar run by our own Risk Advisory Practice Director, Craig Moores. You can watch the presentation over on our webinar channel here.

 

So, what did we learn? What inspired us? And how is SureCloud responding to the latest trends and challenges in this dynamic industry?

Compliance in the mainstream – thanks to GDPR?

It might be nearly two years since the General Data Protection Regulation (GDPR)  came into force, but it remains a frequent topic of conversation. What has been so positive about GDPR, is how effective it has been on pushing the matter of compliance into mainstream consciousness (Amongst end-users as well as businesses).

Consumers now have a much better awareness of the responsibilities that organisations have in terms of protecting their data. Plus organisations, in turn, are recognising the value of making their position on compliance clear to their end-users. Forward-thinking approaches to compliance are not just about doing the work behind the scenes – they are about having clear and upfront communication of that work.

Read our blog on how to keep up the momentum with your GDPR program post the implementation date back in 2018 here.

The importance of data-based decision-making

Many of the discussions and seminars focused on the importance of using tangible business data to drive security decisions, rather than relying on a one-size-fits-all approach parachuted in from outside the organisation or reacting to the latest cyber threat headlines. 

As the cyber threat landscape becomes increasingly sophisticated, dynamic and complex, organisations must resist the temptation to panic, or to implement the latest cybersecurity tools and techniques without clear-headed consideration of their infrastructures and processes. Organisations’ abilities to accurately assess their own security and risk posture – and to implement protections accordingly – have never been more critical.

Thinking through the third-party chain of risk

As always, third-party risk management was a prominent topic. There was much discussion on overcoming one of today’s most common security and privacy challenges, underlining the importance of identifying priorities before, during and after vendor procurement.

After all, two-thirds of data breaches occur thanks to insecure or poorly managed third parties and vendors. Yet traditional third-party risk management methods are heavily reliant on spreadsheets, incorporating cumbersome and error-prone manual methods. As well as lacking the agility, which is essential as trends such as cloud computing, artificial intelligence and the Internet of Things dramatically extend the number of third parties to which organisations are connected. We expect to see even higher uptake of centralised, automated third-party risk management solutions over the coming months, as well as more considerable attention paid to processes such as effective information gathering from third parties.

Implementing a constructive PCI culture

Theo Botha, Head of Cyber Security and Information Security at Which? Consumer’s Association delivered a talk on PCI DSS and security strategy for a maturing estate, including the process of implementing a constructive PCI DSS culture. ‘Dejargonize, clarify and embed’ were his three key steps.

This talk resonated powerfully with us. The risk and compliance industry is saturated with acronyms and ever-evolving standards – many of which were key topics of discussion at PCI London! Technical language cannot be avoided when implementing security, risk and compliance tools and processes – but when it comes to communicating those processes to staff and building organisational awareness of compliance, discussions need to be centred on business goals and customer needs. Humanising compliance, in other words, is critical for organisations wanting to implement a genuinely constructive PCI culture. Again, we highly recommend watching Craig’s presentation on ‘How to Centre your PCI Programme Around your Business Objectives’ to explore this further.

Keeping up momentum with programs and processes

Perhaps above all, PCI London underlined the ongoing challenge for organisations of all sizes and sectors to keep up the momentum with compliance programs and operations. Standards are continually evolving – and rightly so – but this can be overwhelming – which is precisely why SureCloud aims to create a single, centralised cloud-based platform for all governance, risk and compliance processes. Momentum must be underpinned by technology which gives all stakeholders real-time visibility into the organisation’s risk and compliance posture. 

Check out a video of our PCI Compliance Management solution to see this in action here.