Mobile Payment Presentation for IT Governance board
Mobile payments can refer to any payment that is made using a
mobile device. Mobile wallets and mobile money transfers are
included in the category of mobile payments. The two types of
mobile payments are online or in-app purchases and using a POS
(point-of-sale) terminal in person. It is expected that “the worldwide
mobile payment revenue is to hit $12.06 trillion by 2027, with a
CAGR (compound annual growth rate) of 30.1% from 2020 to 2027”
(CardConnect, n.d.). This major growth in the mobile payments
market is caused by the popularity of smartphones. Mobile payment
methods may actually be safer and more secure than a physical card.
The way consumers are capable of utilizing mobile payments is by
using NFC, or Near-Field Communication. NFC “transmits data
through electromagnetic radio fields to enable two devices to
communicate with each other. To work, both devices must contain
NFC chips, as transactions take place within a very short distance”
(Tardi, 2020). The connection must be established between the
mobile device and the POS terminal. This technology allows
customers and businesses to make and accept contactless payments.
Apple and Google Pay is a type of service that utilizes NFC
technology. This uses “radio frequency identification within close
proximity, payment data is sent from the phone to the card reader
and, once the consumer has validated their identity either via a
passcode or fingerprint, money is transferred from the account”
(CardConnect, n.d.). No cardholder data is taken from the card
because tokenization (tokens) is used to replace sensitive data,
compared to using the regular credit card payment method.
Electronic or mobile payments made to businesses using a linked
credit card, debit card, or a “payment processor like Paypal or Stripe
are reported to the IRS separately using Form 1099–K. These are
informational returns used to report income to the IRS” (Derus,
2021). Each state has its own reporting requirements.
The sensitive data or information involved with credit/debit and
mobile card payments is protected by the PCI-DSS. PCI-DSS is the
Payment Card Industry Data Security Standard. This set of security
standards is “designed to ensure that ALL companies that accept,
process, store or transmit credit card information maintain a secure
environment” (ComplianceGuide, 2017). The PCI-DSS is led by the
PCI SSC (security standards council), which focuses on improving
payment account security throughout the entire transaction process.
PCI DSS applies to any and all organizations that utilize major
payment card brands such as Visa, Mastercard, AMEX, and Discover
Card). PCI compliance levels are determined based on the volume of
Visa transactions over the calendar year, “any merchant that has
suffered a breach that resulted in an account data compromise may
be escalated to a higher validation level” (ComplianceGuide, 2017).
The following are security issues/concerns that may arise while
utilizing Mobile Payments. Unfortunately, data breaches still occur
and hackers are constantly finding ways around IT security. The
better educated the consumer is, the better protected their
information is from the following scenarios.
• Lost or stolen devices - Applications on devices, require the
input of different forms of sensitive data. If the device is
stolen, so is all of the data. Utilizing two-factor authentication
which requires two forms of id in order to unlock the device.
Since mobile payments use tokens, “tokenization ensures that
your card information is never seen by merchants when a
randomly generated payment token is created in place of
sensitive card details” (Cardconnect, n.d).
• Phishing - Take precautions when responding to messages or
downloading apps from unknown sources, to avoid being
subject to a phishing scam.
• Weak passwords - Weak passwords can be subject to easy
hacking. Password complexity is one of the important rules of
cybersecurity.
• Public WiFi - Risks such as evil-twin attack. Use a VPN or
trusted network.
• Human error - Stay educated and aware to not become victim
to any of the mentioned threats/attacks.
While technology continues to develop every day and with the
growth of emerging technologies, there are always going to be risks
involved. Introducing and using Mobile Payments at Padgett-Beale
can help improve processing within the hotel. Providing training and
creating policies to keep devices and software virus free can mitigate
security issues as well.
References:
CardConnect. (n.d.).
How to solve mobile payment security concerns
.
CardConnect. Retrieved April 22, 2022, from
https://cardconnect.com/launchpointe/payment-security/mobile-
payment-security
Derus, C. (2021, January 7).
Do I have to file form 1099-NEC?
Brightwater Accounting. Retrieved April 22, 2022, from
https://brightwateraccounting.com/forms-1099-nec-1099-
k/#:~:text=Electronic%20payments%20made%20to%20businesses%20
using%20a%20credit,you%20can%20see%20a%20summary%20of%20
them%20here.
PCI Compliance Guide Frequently Asked Questions: PCI DSS faqs
.
PCI Compliance Guide. (2017, September 5). Retrieved April 22,
2022, from https://www.pcicomplianceguide.org/faq/
Tardi, C. (2021, May 19).
Near Field Communication (NFC) definition
.
Investopedia. Retrieved April 22, 2022, from
https://www.investopedia.com/terms/n/near-field-communication-
nfc.asp