Overview: PBI requested an external audit of financial operations. A
preliminary report has been provided which has identified an
unknown and significant finding that must be addressed. The audit
identified a “Shadow IT” network of unauthorized and unapproved
cashless payment technologies at several locations throughout PBI
properties. The primary focus of this summary is to outline the use
of mobile payments currently in use through the concierge desk from
an authorized independent provider. Services provided in which
these mobile payments are being used include private tennis and golf
lessons, childcare, and tours. The medium used for these mobile
payments is a cell phone with a payment application system like
Apple Pay capable of either a contactless payment or through an
attached credit card reader device. c c c c c c c c
Mobile Payment Systems: A mobile payment is a regulated
transaction through a mobile wallet or device in which a money
transfer or transaction occurs that is linked to a credit or debit card
or a bank account and processed to and through a point-of-sale
device (What Are Mobile Payments? And How to Use Them, 2017).
Third party mobile payment systems such as Apple Pay, Android Pay,
Samsung Pay, and Square are designed to create point-of-sale
locations and opportunities where traditional brick-and-mortar sales
cannot exist. Such locations and opportunities may include pool-side
food and beverage services, on-site tours, or with tennis and golf
coaches. A typical mobile payment transaction is a quick and
effortless process between a customer and the merchant. Ideally,
the customer will have a choice to use a smartphone with a mobile
wallet app linked to a credit card or bank account or a physical
credit or debit card. The customer will present the smartphone or
physical card to the merchant who will receive the payment through
a smartphone or other mobile device with a contactless payment app
or an attached card reader. This transaction is possible by Near
Field Communication (NFC) technology that uses a secure, dynamic
encryption process that enables two devices do communicate
wirelessly when within a proximity of 2 inches or less (What Is NFC?
All You Need to Know About Near Field Communication, 2022).
PCI-DSS Compliance: PCI-DSS compliance is the Payment Card
Industry Data Security Standard all businesses involved with the
processing, storing, or transmittal of credit card data are required to
ensure compliance (Dwyer, 2019). Mobile technology involved with
any credit card data is included in this requirement. Compliance is
not backed by the government in the way that the Federal Trade
Commission (FTC) is. Instead, banks and credit card companies work
together to support PCI-DSS compliance. The cost of non-
compliance can include being fined or blacklisted. Fines have the
potential to range from $5,000 to $100,000 per month of non-
compliance. In the event of a data breach other possible
consequences include suspension of credit card processing privileges,
civil litigations, additional fines, and a possible damaged business
reputation.
The use of mobile devices requires an added level of compliance.
Consumer versions of many mobile devices do not come with the
same inherent privacy standards as a mobile device intended for
commercial use. Privacy standards of commercial mobile devices will
be required to maintain end-to-end or point-to-point encryption,
meaning encryption is happening at every level from the device all
the way to the network processing the transaction (Dwyer, 2019).
Privacy and Security: Credit cards automatically come with many
built-in security features to ensure the protection of the user’s
information. Europay, Mastercard and Visa (EMV) cards, use an
electronic chip that generates a unique transaction code every time
it is used, which makes it very difficult to duplicate. The card
verification value (CVV) is a 3- or 4-digit pin that provides an added
layer of security to verify a transaction. This number is also not
allowed to be stored by a retailer. Additionally, credit cards have
the capability to be frozen or locked in the event a possible theft is
suspected to prevent additional unauthorized transactions. Lastly,
authorization limits can be established by the user to prevent high
dollar transactions from occurring without prior consent (Ladika,
2021).
When a credit card is linked to a user’s mobile device intended to
function as a mobile wallet, it is critical the user keeps their device’s
operating system up to date. Additionally, the user should only
download apps from their device’s official app store. These apps
should also be kept up to date. Keeping software and operating
systems up to date will be essential to reduce the potential theft of
any personal data. In the event of a lost or stolen mobile device,
the user should ensure the device is able to be remotely deactivated
to prevent the thief from keeping or maintaining unfettered access
to their stolen information.
Recommendations/Summary: The use of a “Shadow IT” system is
alarming and must be promptly removed from all PBI systems.
However, this system also has demonstrated a valid need to adopt a
mobile payment system to better serve the guests and customers
using services at PBI properties. While there are inherent security
and privacy risks, PBI can adopt industry standard practices to
ensure this system is managed properly. Adopting and promoting
this new system will allow PBI and the applicable departments to
manage the mobile payment system in a way that will ensure
profitability occurs, security and privacy is maintained, and
compliance with PCI-DSS is adhered to.
References:
Dwyer, B. (2019, November 7). PCI Compliance for Mobile Devices.
CardFellow Credit Card Processing Blog. Retrieved April 30, 2022,
from https://www.cardfellow.com/blog/pci-compliance-for-mobile-
devices/
Ladika, S. (2021, November 16). Credit card security guide.
CreditCards.Com. Retrieved May 1, 2022, from
https://www.creditcards.com/statistics/credit-card-security-guide/
What Are Mobile Payments? And How to Use Them. (2017, April
24). Square. Retrieved April 30, 2022, from
https://squareup.com/us/en/townsquare/mobile-payments
What Is NFC? All You Need to Know About Near Field
Communication. (2022, January 12). Square. Retrieved April 30,
2022, from https://squareup.com/us/en/townsquare/nfc