Digital technology continues to emerge in different sectors of
everyday life. With it; of course, comes concerns for privacy and
security. And nonetheless, companies such as Padget-Beale can
absolutely skyrocket in performance, net worth, sales, you name it, all
aspects. However, not with the help of rogue shadow IT systems.
These systems negatively affect the companies worth and operations.
It also opens vulnerabilities that Padgett-Beale could be responsible
for in the event of a data breach and goes beyond simply terminating
employees.
Before we can begin, it is ok to have a misunderstanding between
shadow IT and corporations. End users or people on the front lines are
in a more fast paced environment than managers and corporate
meetings. In a festival environment if needs aren’t met or objects in
place to make employees jobs a life easier, it is understandable that
they feel their voice may not be heard due to slow support from upper
staff who call the shots. Which leads to shadow IT.
For example, mobile payments made through the independent
provider situation. These workers are trying to make their lives easier
and not necessarily maliciously opening the company to data breaches.
They may not know that magnetic card swipes are more prone to
being breached. They are simply trying to work more efficiently which
employees look for.
To that note, payments through magnetic strip swipe should be ceased
due to the lack of security with magnetic swipe. Magnetic swipe has a
huge vulnerability that leads to it being breached easier. Hackers know
about this vulnerability and has been exploited. The data in the
magnetic strip is static so can easily be copied and used without the
owners knowing. If the system that is being used to book services
through the concierge are hacked, the customers data credit card
information can be breached leading to malicious purchases. The
payments are processed through a magnetic swipe reader on the
providers cell phone. Without direct assistance from authorized IT, the
cell phone is deemed a vulnerability as there is no security or known
protection of the devices. How do we know if its encrypted? Software
versions, and application bugs are all risk to being compromised which
can lead to data breach. If data is breached this way, customers data is
available in plain text.
d d According to the American Bar Association, “if a merchant is
the victim of a data breach because of PCI DSS noncompliance,
penalty costs can range between $5000 to $500,000 per month. If
breaches continuously occur, card brands can revoke merchants right
to process transactions” (Wills, 2019). The method the company is
using directly violates the standard. We do not know if these POS
devices comply with PCI Security Standards Council or if they have
been notified. “When you change payment processors, upgrade your
POS to accept mobile and contactless payments, you must notify the
PCI Security Standards Council which will validate the end-2-end
security of your payment processing system” (Dwyer, 2019).
d d Another way payments are transacted are through mobile
payments such as Apple pay, or Google pay through customers cell
phones. This method is OK. NFC or “near field communication” is the
method of using mobile payments through mobile applications such as
Apple pay or Google pay. The NFC acts as an RFID reader which is
one of the PCI DSS recommendations for the highest security in
contactless payments. These payments are encrypted and are
impossibly harder to duplicate or crack. Although, utilizing this method
alienates customers as everyone does not have these applications set
up, cell phones die faster, and are more risker and expensive if lost or
stolen while being used in a fast pasted environment such as a festival
(Bennett, 2013.)
d d Radio Frequency Identification would be the most secure
method of accepting contactless payments. The RFID are the chips
embedded into credit and debt cards. This method is the most secure
because it creates an encrypted code for each transaction. The data
cannot be duplicated and cannot be read in plain text. The data is
constantly changing. This can make productivity faster and secure.
Customer information is collected through a secure database allowing
data to be collected about customers location, activities, and
controlling what areas customers have access to. If one is lost or
stolen it can be deactivating using robust RFID software platforms
(2018, Token Team.) Although, privacy is a concern as the data
collected to the RFID chips is transferred back to a cloud. Usually, of
the software vendor’s commercial cloud. (Gettoken.com).
Sources
Wills, Leonard. 2019. The Payment Card Industry Data Security
Standard. American Bar Association.
https://www.americanbar.org/groups/litigation/committees/minority-
trial-lawyer/practice/2019/the-payment-card-industry-data-security-
standard/
Dwyer, Ben. 2019. PCI Compliance for Mobile Devices. Card Fellow.
Security Risks of the Digital Age.
https://www.cardfellow.com/blog/pci-compliance-for-mobile-devices/
Bennett, Craig. 2013. RFID wristbands VS NFC apps: What’s winning
the contactless battle? Tech Radar. What about using NFC
smartphones instead? https://www.techradar.com/news/world-of-
tech/rfid-wristbands-vs-nfc-smartphones-what-s-winning-the-
contactless-battle-1167135
Token Team. 2018. The Beginner’s Guide to RFID Technology for
Events. Gettoken.com https://www.gettoken.com/beginners-guide-
rfid-technology-events/