1 / 2100%
Recently the Office of the Chief Financial Officer requested an external audit
on the financial operations of Padgett-Beale. The results of the audit revealed
some concerning practices performed by a number of offices and branches
within the Padgett-Beale family. It has been revealed that these locations and
offices have been utilizing third party mobile payment systems to pay
independent providers of services to Padgett-Beale guests. Examples include
tour guides, golf instructors, tennis instructors, and day care providers. While
these providers are approved to work with Padgett-Beale, the method used to
facilitate payment is not.
Mobile payments are enabled on the customer side by applications (or apps)
such as Apple Pay, Samsung Pay, and Google Pay (Square, 2017).
Companies such as Square enable the merchant to collect payment from these
apps, as well as standard credit cards (via chip reader, swiping, or Near Field
Communication). These services offer a level of convenience that make them
very popular, which is only amplified with the ubiquity of mobile devices.
Padgett-Beale is not against embracing new technologies, however when
dealing with PCI information, a plan needs to be developed by the Padgett-
Beale central offices to ensure proper compliance and implementation of said
technologies. Padgett-Beale can be subject to fines, which can reach hundreds
of thousands of dollars depending on the length of non-compliance, and other
litigation if non-compliance is discovered (Dwyer, 2019).
Naturally, with any information system or protocol there come a number of
security risks that the company needs to be aware of and mitigate in order to
protect the data entrusted to it. Mobile payments present a significant risk for
a data breach, as PCI information is highly sought after by bad actors.
Security risks stem from a number of sources when dealing with mobile
devices on both the merchant and the consumer sides. On the merchant side,
there is a risk of data being intercepted via skimmers placed on POS (Point
of Sales) devices and other methods of intrusion (Dwyer, 2019). On the
customer side risk comes in the form of mobile devices being infected with
malware, devices being lost or stolen, and attempts of phishing and social
engineering (ENISA, 2016). Any step between the consumer and the provider
of the Mobile Payment systems can be compromised, and while not all
threats can be prevented, there are steps that Padgett-Beale can take to ensure
that mobile payments are both secure and compliant.
The first step that Padgett-Beale needs to take is to have all branches and
offices utilizing mobile payment systems immediately cease operating such
devices and services. Since the exact details of these incidents are under
review, Padgett-Beale needs to assume that all devices and practices are non-
complaint with standards set forth by the PCI Security Standards Council
(PCISSC, the central authority for PCI compliance). When dealing with non-
compliance, time is a factor and thus all mobile payments need to be such
down. The next step is to have the Finance department and IT department
review the practices that these office and branches have been using. This
includes identifying the devices used to enable these transactions, what
networks those devices have been connecting to, and how the data has been
stored and transferred. According to the PCISSC, devices accepting mobile
payments need to have security hardening, be properly patched against
vulnerabilities, have proper access controls and logging, among other device
requirements (PCI Security Standards Council, 2017). At the present time,
Padgett-Beale needs to assume that the devices being used to facilitate mobile
payments are consumer off the shelf devices with absolutely zero hardening
requirements in place. After the cease and desist is issued, the central Finance
and IT departments can then cooperatively develop an implementation plan
based off of the requirements of the PCISSC in order to ensure compliance
and security requirements are maintained.
Padgett-Beale is open to embracing new technologies and solutions in order
to meet guest expectations and satisfaction. Part of this satisfaction comes
from the ease of being able to book and pay for varying services via mobile
payments. It is the responsibility of Padgett-Beale to provide a safe and
secure method of offering such services to guests. While the branches and
offices in question had the best intentions, their actions put Padgett-Beale at
risk for fines and litigation as a result of being non-compliant with PCI
standards. For the time being, Padgett-Beale needs to issue a formal cease
and desist to these offices and branches until a proper procedure can be
developed by the central office.
Students also viewed