Thursday, September 10, 2009

Dynamic Duo(poly) Needs to be Challenged for SEPA Ration

10 September 2009 - 10:26

New schemes vital to Sepa for cards success - ECB's Tumpel-Gugerell

MasterCard and Visa need to be challenged by at least one new scheme if Sepa (Single euro payments area) for cards is to succeed, according to ECB executive board member Gertrude Tumpel-Gugerell.

In a speech at the EFMA conference on cards and payments, Tumpel-Gugerell says a single market for cards is the "missing piece in the Sepa puzzle" and warns Europe needs to overcome the "current stagnation".



Citing research from the ECB and De Nederlandsche Bank, she says a new Europe-wide card scheme could provide a "decisive impetus" to solving interoperability and overcoming fragmentation in the market, benefiting customers and merchants.



There are currently three scheme initiatives and Tumpel-Gugerell has called on those involved to "get down to business now"...



Continue Reading at Finextra 



Related:



Aug 13, 2009


MasterCard Inc. and Visa Europe could face competition in the coming years from new European-centered payment card networks such as Payfair and Monnet. Belgian retailer Colruyt Group is planning to begin testing the Payfair debit card ...


Jul 10, 2009


I would suspect that Monnetwould be based on the Chip and PIN system, which is more secure than what Visa and MasterCard have been pushing with their signature debit. I have long said that signature debit should be scrapped in it's



Jul 14, 2009


Several major French and German banking companies are said to be backing the Monnet debit card, and said last week that they expect to create a company then that would focus on building a payments network. See "Is Monnet Painting Visa into a corner?









Reblog this post [with Zemanta]

Happy Birthday ATM! Does Life Begin at 40?

09/09/09 was more than just a calendrical anomaly...



It was more than "A Day in the Life"



It was also the ATM's 40th birthday!




Wired put together the graphic on the left.  Here's a snippet from their posting:



"September 9 is the 40th birthday of the automated teller machine in the US. To celebrate the invention that spews twenties at two in the morning, we're spitting out some numbers of our own."



From: Wired.com



Interesting!  Yes?

Reblog this post [with Zemanta]
Is PCI DSS a Safe Investment?

By Robert Vamosi, Javelin Strategy & Research



Should merchants continue to invest in Payment Card Industry Data Security Standards (PCI DSS) in a down economy? Yes.



The losses—not just in fines and litigation, but also reputational damage—associated with the consequences of a data breach are astronomical when compared with the annual burden of maintaining compliance. PCI is an excellent baseline for cardholder security, but should PCI be made law? On this, there is plenty of room for debate...



Continue Reading at Bank Systems and Technology





Reblog this post [with Zemanta]

Trustwave Acquires VERICEPT









Data Loss Prevention Technology to be Integrated into Trustwave's Security and Compliance Suite




Chicago, Sept. 10, 2009 -(PIN Payments News Blog) – Trustwave, the leading provider of on-demand data security and payment card industry compliance management solutions to businesses and organizations throughout the world, has acquired Vericept, a leading provider of data loss prevention (DLP) and intellectual property protection solutions. The terms of the deal are confidential.



Data loss prevention solutions are most often used to monitor business processes in support of compliance mandates, to protect brand and reputation by enforcing customer data privacy and to defend strategic information and intellectual property against inadvertent and malicious loss. Leading organizations across multiple industries including financial services, healthcare, aerospace and defense, manufacturing, technology, education and retail utilize DLP solutions. With DLP, advanced content inspection is performed on data in use (e.g., endpoints), data in motion (e.g., network) and data at rest (e.g., data storage) to help detect and prevent the unauthorized use and transmission of confidential information. DLP is also used to demonstrate compliance across multiple standards and regulations, such as the PCI DSS and HIPAA, as part of a system of control over information.



The core of Vericept’s DLP solution is its patented Content Analysis Engine, which analyzes content against policy, helps detect and classify structured and unstructured content, as well as, text extraction of any file type. This patented detection and classification technology extends to data-in-motion to address Web 2.0 threats by identifying the use of applications such as blogs, social networking sites and Webmail to accurately identify and control sensitive data. Once data is classified, it can be managed consistently according to policy from the moment it is created.



Specifically, Vericept’s leading DLP solutions help address multiple requirements of the Payment Card Industry Data Security Standard (PCI DSS) version 1.2. PCI DSS is the payment card industry security requirement for entities that process, transmit and/or store cardholder data, which has been endorsed by all the major card brands – Visa Inc., MasterCard Worldwide, Discover Network, American Express and JCB. Using DLP technology, businesses can meet the following seven of the 12 requirements, further strengthening Trustwave’s position as a leading provider of PCI DSS services and solutions:
  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters


  • Requirement 3: Protect stored cardholder data


  • Requirement 4: Encrypt transmission of cardholder data across open, public networks


  • Requirement 6: Develop and maintain secure systems and applications


  • Requirement 8: Assign a unique ID to each person with computer access


  • Requirement 9: Restrict physical access to cardholder data


  • Requirement 10: Monitor all access to network resources and cardholder data




“We’re very excited to offer our customers a leading DLP solution that can manage sensitive data, scale to meet expanding business requirements and maintain high performance as business continues in real time,” says Robert J. McCullen, chairman and CEO of Trustwave. “Vericept’s DLP technology complements our current portfolio of security solutions offered to our global customer base.”



“The 451 Group believes concerns about data security and leak prevention are central to both regulatory compliance and network security,” says Paul Roberts, senior analyst for enterprise security at The 451 Group. “Trustwave’s acquisition of Vericept will allow it to marry Vericept’s expertise in inspecting data flows to and from the endpoint and on the network with Trustwave’s broad portfolio of managed security products and compliance offerings.”



Vericept’s DLP solutions help customers streamline and demonstrate compliance. With pre-defined compliance categories that specifically address standards such as PCI DSS, HIPAA and GLBA, Vericept’s patented DLP classification technology precisely monitors data to ensure compliance with company policy.



“We’ve developed a leading DLP technology for scanning and detecting sensitive information and mitigating risk based on policy requirements. Our DLP solutions ensure that a business’ sensitive data or competitive intelligence is not lost or leaked, compliance is enforced and brand equity is protected,” says Dave Parkinson, former CEO of Vericept, who will become Trustwave’s general manager of security services.



About TrustwaveTrustwave is the leading provider of on-demand and subscription-based information security and payment card industry compliance management solutions to businesses and government entities throughout the world. For organizations faced with today’s challenging data security and compliance environment, Trustwave provides a unique approach with comprehensive solutions that include its flagship TrustKeeper® compliance management software and other proprietary security solutions. Trustwave has helped thousands of organizations—ranging from Fortune 500 businesses and large financial institutions to small and medium-sized retailers—manage compliance and secure their network infrastructure, data communications and critical information assets. Trustwave is headquartered in Chicago with offices throughout North America, South America, Europe, Africa, China and Australia. For more information, visit https://www.trustwave.com .









PULSE and TRIONIS Sign Long-Term European ATM Acceptance Agreement



Houston and Brussels, Belgium -PIN Payments News Blog— PULSE, the Discover Financial Services business unit responsible for expanding global cash access for the company, has signed a long-term ATM acquiring agreement with TRIONIS, a European interbank processing network. TRIONIS is jointly owned by retail banks from nine European countries, the European Savings Banks Group and First Data.



Under terms of the agreement, when fully implemented, more than 74,000 TRIONIS ATMs across Europe will be able to process ATM transactions for Diners Club International® and Discover® cards.



“Since acquiring Diners Club, one of Discover’s priorities has been to strengthen global acceptance,” said Dave Schneider, PULSE president. “Our agreement with TRIONIS is a significant multi-country acquirer agreement to further European acceptance of Diners Club and Discover cards and an important step in helping reach that goal.”



The service went live in several countries on July 1, with acceptance of Diners Club cards at the ATMs of banks in Austria, Switzerland, Portugal, Spain, Luxembourg and Belgium. Discover cards are expected to be accepted at TRIONIS European ATMs beginning in October 2009.



“TRIONIS is pleased to be able to facilitate broader card acceptance at European cash access machines,” said Ernst Verbeek, TRIONIS managing director. “Acceptance of Diners Club and Discover cards will allow us to serve more cardmembers, while giving ATM operators access to additional ATM transactions.”



About PULSE



PULSE is one of the leading U.S. ATM/debit networks, currently serving more than 4,500 banks, credit unions and savings institutions across the United States. PULSE is owned by Discover Financial Services (NYSE: DFS). The network links cardholders with more than 289,000 ATMs, as well as POS terminals at retail locations in the U.S. The company is also a valued resource for industry research related to electronic payments and is committed to providing its participants with education on evolving products, services and trends in the payments industry. For more information, visit www.pulsenetwork.com .



About TRIONIS



TRIONIS offers the issuers of 165 million cards access to cash at more than 74,000 ATMs across Europe. TRIONIS provides processing services to its users for switching POS and ATM card payment transactions on EUFISERV and all other payment card brands. TRIONIS is a Brussels-based company owned by retail banks from nine European countries, the European Savings Banks Group and First Data. Its mission is to develop, maintain and operate international payment services for the financial industry. More on www.trionis.com .



Source: Company press release.





Reblog this post [with Zemanta]

InnerCircle for Powerful Women in Banking

New Professional Network for Women in Banking

US Banker  |  September 2009


The editors of American Banker and its sister publication US Banker are proud to announce the launch of a professional peer-networking site for senior-level and aspiring women in banking and financial services.

The new network — called the Inner Circle — is designed to extend the dynamic community that has developed around the 25 Most Powerful Women in Banking event program and rankings. Its goal is to identify, support, and connect top-performing women in financial services.



The Inner Circle will include blogs, discussions, and online events on topics of interest to the community. It will also serve as an up-to-the-minute one-stop shop for information about the 25MPWIB rankings and program.



Please visit www.25mpwib.com/InnerCircle to find out more.

Reblog this post [with Zemanta]

Lack of Online Banking Security Causing Customer Churn - Gartner


Financial fraud affects consumer bank behavior, Gartner Finds - (PDF)

By Marcia Savage, Features Editor, Information Security magazine

A new report released by Gartner Inc. Wednesday shows the impact of data breaches and financial fraud on consumers' behavior, including their banking activity. About 7.5% of U.S. adults lost money due to some type of financial fraud, mostly due to data breaches, according to a survey of 5,000 Americans conducted by the research firm last September.

Of the respondents, 14% said they were victims of credit card fraud and 7% said a thief used their debit or ATM card to make purchases or withdraw cash. Six percent said they were victims of new account fraud, where a thief opened an account in their name, while 5 % said a criminal stole money out of their existing checking or savings account and 4 % said a thief forged checks on their account.

Compared to the average consumer, nearly twice as many people who lost money to fraud changed their shopping, payment and e-commerce behavior, according to Avivah Litan, vice president and distinguished analyst at Gartner.

"We all read about the data breaches. This survey certainly proves they're having an impact in terms of spooking customers," Litan said.

Victims of electronic checking and/or savings account transfer fraud were almost five times more likely to change banks due to security concerns, compared to the average consumer, according to the report.


"From a bank point of view, this is really causing customer churn," she said. "It's costing them customers."

Consumer security concerns have a big impact on online banking, she said, with 20% of survey respondents worried about security, saying they stopped or won't start transferring money between accounts. The percentage doubled among fraud victims. While only 6% of the consumers surveyed said they changed banks due to security concerns, the number jumps to 28% among checking/savings account transfer fraud victims, according to the report.

Thirty-five percent of survey participants said security was an important factor in their decision to bank online or do more business with their bank online, but security isn't as important to consumers as bank fees and customer service, the Gartner survey showed.

Security, however, becomes much more important for consumers who have been victims of a financial account takeover, according to the report. Litan advised financial institutions that have implemented strong security to publicize that fact to their customers to gain their confidence. They should also engage customers to participate in security; an example would be to sign up for a service that alerts them to suspect transactions, she said.
"There's a lot of value in (banks) advertising your security," Litan said. Right now, banks aren't using security as a customer retention tool, she added.



Reblog this post [with Zemanta]

How Big of a Problem is SQL Injection?

From NetSecurity.org:



Exactly how big of a problem is SQL injection? Can you provide a rough picture to our readers not familiar with the issue?




SQL injection is a HUGE problem.



It is both fairly common, as well as having the potential to be a huge risk to a business either directly or indirectly.



A good example of the risk of SQL Injection is the recent revelation that SQL injection was a key part in a number of the recent large credit card data breaches - Heartland, Hannaford, TJX and others.



In these cases, SQL injection was used in order to get further into an organization and do something else, however in a lot of cases SQL injection can be serious enough all on its own.



I've seen examples such as a small US bank that had over 5,000 mortgage applications stolen from an application via SQL Injection, and hence all of the information needed to steal all of those people's identities.



For those not familiar with SQL injection, it occurs when unvalidated user input is included within Structured Query Language (SQL) statements that are dynamically assembled within the application. For example, say the application is assembling a query for product information with a “productid” variable supplied by the user with a query something like this:



string query = "SELECT * from products WHERE productid =" + productid



Read in it's entirety at NetSecurity.org

Heartland Breach Update on Class Action Lawsuits

Heartland Update: Judge to Hear Motions to Dismiss Class Action Suits
Attorney: Discovery is "the Biggest Battlefield"
September 9, 2009 - Linda McGlasson, Managing Editor


Preliminary legal hearings have begun in the class action suit against Heartland Payment Systems, the U.S.-based payments processor that was breached in 2008 



More than 30 financial institutions from 22 states have joined the lawsuit against Heartland, which is the largest data breach on record, with a reported 130 million credit and debit cards stolen.



One of the lawyers representing the financial institutions, Richard Coffman of Beaumont, TX, describes the case management conference in late August as a "very good one" for the banks.



A preliminary case management hearing was held on August 24 in Houston's Southern District Court of Texas, before Judge Lee H. Rosenthal, who set the dates for future hearings in the case,



There are two class action suits -- one on the consumer side and the second on behalf of the financial institutions affected by the massive breach. Earlier in June, a Multidistrict Litigation (MDL) panel decided the suits would be held in Houston....



Continue Reading at Bank Info Security

Reblog this post [with Zemanta]

Top Malware Threats Over the Last 20 Years



PandaLabs has issued a ranking of the most insidious malware threats that have surfaced in the past 20 years.  Here is their list:



Friday 13 or Jerusalem


Created in Israel in 1988 and first reported in Jerusalem, this supposedly commemorated the 40th anniversary of Israel. Whenever the date was Friday 13, it would delete all programs run on an infected computer.



Barrotes

The first well-known Spanish virus appeared in 1993. Once on the computer, it would remain hidden until January 5, when it would activate displaying just a series of bars on the monitor.



Cascade or Falling Letters

Created in Germany in 1997, this virus would make the letters on the screen fall in a cascade whenever it infected a computer.



CIH or Chernobyl

This virus was produced in Taiwan in 1998, and took just one week to propagate and infect thousands of computers.



Melissa

First appeared on March 26, 1999 in the USA. This ultra-smart malicious code used social engineering to spread, with a message that read "Here is that document you asked for. . . don't show anyone else ;-)"



ILoveYou or Loveletter

So famous, it hardly needs introduction. This romantic virus emerged from the Philippines in 2000. With the subject 'ILoveYou' it infected millions of computers around the world and even hit organizations like the Pentagon.



Klez

Created in 2001 in Germany, it only infected computers on the 13th of odd months.



Nimda

The name is basically 'admin' spelled backwards, as it was able to create administrator privileges on infected computers. It originated in China on September 18, 2001.



SQLSlammer

This was another major headache for companies. It first appeared on January 25, 2003, and affected more than half a million servers in just a few days.



Blaster

This virus, created in the USA on August 11, 2003, contained a message in its code: "I just want to say love you, San!!" (We still don't know who 'San' is), and "Billy gates, why do you make this possible? Stop making money and fix your software".



Sobig

This German virus was famous in the summer of 2003. The F variant was the most damaging, it attacked on August 19 of the same year and generated more than 1 million copies of itself.



Bagle

This emerged on January 18, 2004, and has been one of the most prolific viruses with respect to the number of variants.



Netsky

This worm also came from Germany in 2004 and exploited vulnerabilities in Internet Explorer. Its creator was also responsible for the notorious Sasser virus.



Conficker

Last on the list and most recent, it appeared in November 2008. Oddly enough, if your keyboard is configured in Ukrainian, it won't affect you...





Reblog this post [with Zemanta]
Put your Phishing Saviness to the Test with the SonicWALL Phishing and Spam IQ Quiz.   I think we would all be more "savvy" if we stopped "typing" altogether.  The purpose of phishing is to obtain information.  The way phish pholk obtain that information is by tricking consumers into "typing" their information into a box on a cloned, counterfeit, etc. website.  If people didn't type...phish pholk couldn't swipe.  That simple. 



We need to get more pholks on board the Don't Type, Swipe Train. 



But, until then, 43% of even the smartest pholks get phooled by phishing attacks...



From SonicWalls Website:  
 
Chances are that in the past week you've received an e-mail in your inbox that pretends to be from your bank, e-commerce vendor, or other on-line site.



Hopefully you've realized that many times this e-mail is fake - a phishing or spam e-mail. The sender (phisher) of these fake e-mails wants you to click on the link in the e-mail and go to a phishing Web site - which will look just like the Web site of the company being phished. Once on the phishers Web site they hope to obtain your account, financial, credit and even identity information. Of course not every e-mail you receive is a phish. In fact you should expect your bank or e-commerce vendor to send you legitimate e-mail. But how can you tell the difference? Well that's what the Phishing IQ test is all about - give it a try.


Instructions
To begin click the "Start the Test" button below. Each question will be displayed one at a time in a browser window and you decide if the e-mail is a "Phish" or "Legitimate." When you have completed the test you'll get a score along with a chance to see "why" a question was a phish or legitimate. Good Luck!




Helpful Hints:

  1. At the bottom of each "e-mail", on the status bar, there is the URL of the active link - the one being pointed to in the e-mail. You can decide if what is displayed is "real" or fake.

  2. For this test, assume that you are "John Doe" or "Jane Doe" - in other words that you received the e-mail in your inbox addressed to you.


Phishing Facts


$886 – The average dollar loss per Phishing Victim (Gartner, Dec 17, 2007)
$3.6 Billion – The total dollar loss of all phishing victims over a 1 year period (Gartner, Dec 17, 2007)
3.2 Million – The number of people who fell victims to phishing scams over that same 1 year period (Gartner, Dec 17, 2007)
8.5 Billion – The estimated number of phishing e-mails sent world-wide each month (SonicWALL, 2008)
32,414 – The number of phishing web sites that were operational in May 2008 (Anti-Phishing Working Group)
Phishing IQ Facts
1,012,000 - The number of people who have taken the Phishing IQ Test worldwide
7.4% - The percentage of test takers who get 100% - answering all 10 questions
86% - The percentage of phishing e-mails that are identifies as "phish" by the test takers
57% - The percentage of legitimate e-mails that are identified as "legitimate" by the test takers
Reblog this post [with Zemanta]

PAY.ON and Elavon Formulate Strategic Partnership

Munich, Germany and London, Sept. 9, 2009 -(PIN Payments News Blog)- PAY.ON AG, a leading supplier of online payment and risk management technologies, and Elavon, a wholly owned subsidiary of U.S. Bancorp (NYSE: USB) and a leading global card acquirer, announce a cooperation to market their global payment services.



In cooperating, the two companies not only maximise their services but also manifest their global coverage. As a leading online payment technology provider and processor of payment transactions, PAY.ON serves its clients throughout the world with more than 140 different payment systems and connects on average 3-4 connectors every 4-6 weeks thereby offering a magnitude of payment methods. Typical clients of PAY.ON are leading payment service providers, payment scheme suppliers, acquirers, remittance provider, and risk management providers. With Elavon, the Company has forged a global relationship offering services that support the strong technology of PAY.ON.



The clients of PAY.ON have access to Elavon’s robust and secure payment platform that supports multi-currency and cross-border payment solutions for a number of industry segments such as retail, international sales trade, airlines, tourism, hotels and catering services. Elavon offers traditional and alternative payment methods and supports card-not-present-solutions from Visa & MasterCard as well as international and domestic debit cards such as Maestro, ec-cash, Electron, and V-Pay.



PAY.ON serves PSPs throughout the world with more than 140 different payment systems and provides Elavon an opportunity to continue expanding its global reach. In addition, PAY.ON and Elavon are in the position to offer localised services adapted to the individual market’s requirements. Therefore, both companies are able to penetrate new geographical as well as industrial markets. PAY.ON has recently opened a new office in Hong Kong and is well connected throughout Asia.



Robert Kuzelj, CEO of PAY.ON comments: „PAY.ON enhances once more its global partner network. We are very pleased to add Elavon’s merchant processing services to our payment platform. Both companies will benefit from synergy effects. The leading technology of PAY.ON combined with the competitive services of Elavon enable both companies to maximise their market potential. This will allow PAY.ON to further support its clients in becoming more active cross-border.”



Susanne Jenz, Head of Indirect Sales of Elavon adds: „As a globally acting technology provider, PAY.ON is a perfect match for us. Elavon not only offers the PSPs of PAY.ON a solid range of services, but also individual models of cooperation. We are very pleased to offer our services to the PSPs of PAY.ON.“



About PAY.ON AG:



PAY.ON is an internationally leading supplier of global online payment and risk management technologies. Clients of PAY.ON are leading payment service providers, payment scheme suppliers and financial institutions. The Company, founded in 2004 is headquartered in Munich, and has subsidiaries in Hong Kong and Manila. The Company follows a course of steady growth and expansion. PAY.ON offers the core competencies of global outsourcing services and routing for monetary transactions, wallet solutions, risk management and monitoring services, as well as various technical back-end solutions. All products are white-label and fully PCI-certified.



Source: Company press release.
Reblog this post [with Zemanta]

sQuid eMoney Launches Prepay Contactless Smart Card with Pizza Hut



DUNDEE, Scotland–(PIN Payments News Blog)– sQuid eMoney today announces a new Pizza Hut branded pre-pay contactless smartcard for customers at stores in Dundee.



The eMoney smartcard uses contactless payment, the latest innovation in retailing. It combines ‘pay as you go’ to make life easier for customers with a loyalty email voucher scheme giving customers rewards to redeem in-store.



With three stores in Dundee and Dunfermline now accepting sQuid eMoney payments, this is an extension to sQuid’s launch across the City of Dundee, where they already work with Dundee City Council, the National Entitlement Card (NEC), the University of Abertay and local Dundee retailers.



sQuidcard provides contactless eMoney services in retail and campus networks. With an ability to provide an available-to-all prepaid card and to deliver multi-purse technology, sQuid is much more flexible than bank cards or other loyalty schemes. It has been specifically designed to replace cash transactions in fast retail environments, and is compatible with transport smartcard applications including ITSO.



Andrew Pollard, the franchisee owner of the three Dundee stores says: “I am pleased to be supporting the local community here in Dundee while being among the first to use this innovative and new payment scheme for our customers. sQuid means that we can make our customers life easier at the point of purchase, while rewarding loyal customers with some great deals at the same time as.”



All sQuid eMoney cards are accepted at the participating Pizza Hut Delivery stores and they are also launching with a limited edition branded card, which can also be used across Dundee. Customers can register their cards online and then view their transactions, top-up their card and receive special money-off vouchers by email.



sQuid is a new kind of cash: smart cash. It can be used to pay for those everyday items, such as your morning coffee, a mid morning snack, your lunchtime sandwich or evening pizza treat. It saves time, is more convenient than cash, and helps you keep an eye on where your money is going. sQuid is an independent eMoney network, you can’t get into debt and you don’t even need a bank account to use it, making it ideal for everyone.



“It’s great to be working with Pizza Hut in Dundee, following on from some other successful trials we have undertaken with similar high profile, high street brand,” says Adam Smith, Managing Director of sQuidcard. “We are extending the use of sQuid across the wider Dundee community and the way that people pay for everyday items; we’re making life so much easier. By incorporating easy payment on a branded card for Pizza Hut and emailing personal voucher rewards to registered card holders, customers will be able to enjoy hassle-free payments whilst benefiting from some great deals.”



About sQuidcard Limited



sQuid eMoney is the alternative to the debit and credit card networks for sub £10 contactless transactions – a market forecast to grow rapidly, replacing some of the £200bn cash transactions made each year in the UK.



Deploying its own technologies, with proven contactless payments between card and reader, sQuid delivers a significantly faster transaction than chip & pin.



sQuid has a multi-purse capability and is compatible with ITSO (transit) schemes. sQuid operates enhanced security between the card, the terminal and the payments engine, and allows additional functions to be delivered to the card holder and the retailer. This enables a sQuidcard to be used not only for low value purchases but also as a pre-pay transit card.



sQuid eMoney is available in Bolton, Greater Manchester where it complements the Council’s Bolton Smart smartcard programme. This includes a transport smartcard service which is being developed with the sQuid and Greater Manchester Passenger Transport Executive. sQuid is also available in Dundee in partnership with the Scottish National Entitlement Card.



sQuidcard is a subsidiary of Nucleus Limited, a leading brand, internet and venturing business.



www.squidcard.com/pizzahut



About Pizza Hut Delivery



In 1958, Frank and Dan Carney had an idea for a great local pizza restaurant in Wichita Kansas. The small 25 seat restaurant only had room for 9 letters on the sign… the building looked like a hut… so ‘Pizza Hut’ was born!



Fifteen years later, we opened the first UK restaurant and since then we’ve become the biggest Pizza Company on the planet!



For more information about Pizza Hut Delivery please visit www.pizzahut.co.uk/delivery

Press Release Contacts

Armadillo Consulting Group Lloyd Mullenger, +44 (0)203 195 6727 lloyd@armadillocg.com

Press Release Tags

Tags: , , , , , , , , , , , , , , , , , , ,









Reblog this post [with Zemanta]

Google Offering Micropayments for Newspapers?

Extra Extra...Read All About It...



Google moves toward micropayments for newspapers





According to the Nieman Journalism Lab,  Google want to build a payment platform that is geared toward newspapers that want to charge for digital content.
Here's the letter that details Google's plan and was sent  to the Newspaper Association for America.



"While currently in the early planning stages, micropayments will be a payment vehicle available to both Google and non-Google properties within the next year," the letter, as published by the Nieman Lab, explained. "The idea is to allow viable payments of a penny to several dollars by aggregating purchases across merchants and over time. Google will mitigate the risk of non-payment by assigning credit limits based on past purchasing behavior and having credit card instruments on file for those with higher credit limits and using our proprietary risk engines to track abuse or fraud. Merchant integration will be extremely simple."






Reblog this post [with Zemanta]

Hawkins Strategic Releases Retail 3.0 Paper on Marketing Communications



Hawkins Strategic was the creator of SmartShop, the very innovative and very promising "personalized marketing" platform employed by biometric payments firm Pay By Touch. The results were outstanding, click picture on right for brief overview or read about Supervalu's adoption of SmartShop here.



Hawkins Strategic issued a press release announcing their new whitepaper:



Los Angeles, CA: (PIN Payments News Blog | Thursday, September 10, 2009 ) Hawkins Strategic today announced the release of a new position paper on Marketing Communications, the latest installment in its Retail 3.0 series. The paper describes how product-driven and customer-focused strategies must interact in the Retail 3.0 ecosystem, and provides a framework within which marketers can decide what communication channels are appropriate for any given task.



Marketing Communications makes clear the importance of tying marketing spend to a Shopper Inventory, providing management a way to truly begin objectively measuring marketing effectiveness. The paper includes an example of a Shopper Inventory statement drawn from Gary Hawkins’s book Customer Intelligence, where the idea was first raised. This analysis makes it possible to measure total marketing cost per realized shopper. This metric is revolutionary. It is also a reality for 3.0 Retailers—today.





“CEOs should demand regular measurement of their company’s total marketing cost per realized shopper, a powerful new metric available to companies in the Retail 3.0 ecosystem,” says Gary Hawkins. “The growing divide in the retail industry between those retailers who possess shopper-identified transaction data and those who do not, will become a chasm when applied to the area of marketing communications.”



The Retail 3.0 position paper series has received extensive coverage in industry media. The first paper in the series, Shopper Data, demonstrated why retailers without means to consistently identify shoppers and link them with their transactions will become increasingly disadvantaged, regularly underperforming compared to their peers and being penalized in the financial markets.



To download Marketing Communications and learn more, please click here.



To learn more about Retail 3.0, please click here.




About Hawkins Strategic: Hawkins Strategic is leading the genesis of Retail 3.0, a new industry ecosystem driven by relevant marketing to the individual shopper, supported by realtime marketing and supply chain synergies, and built on the foundation of shopper-identified transaction data. From launching one of the first loyalty programs in the U.S., to advising some of the world’s largest and most progressive retailers and manufacturers; from founding the world’s first truly personalized retail communication platform, to partnering with world-class enabling technologies; Hawkins Strategic is ideally and uniquely positioned to move the industry to this next level through thought leadership, strategic guidance, value creation, and its Center for Advanced Retail Technology.



For more information please contact Berkeley Hawkins at berkeley.hawkins@hawkinsstrategic.com.







Reblog this post [with Zemanta]

Analyst Upgrades MasterCard



NEW YORK (AP) -- A Citi Investment Research analyst upgraded MasterCard Inc. Wednesday, writing in a note to investors that a negative adjustment in consumer spending is largely over.



Analyst Donald Fandetti lifted his rating for the credit card and global payments processor to "Hold" from "Sell" and lifted his price target to $209 from $172. While consumer spending remains weak and there is a trend towards less consumption, Fandetti said he has a positive outlook for the sector.



"We are upgrading ... as signs of stabilization in U.S. and global economies simply make us less bearish," Fandetti said.



Tougher new card regulation and constrained credit will likely contribute to soft volumes, Fandetti said. Still, fourth-quarter results should be an improvement from a year ago and would get a boost from any weakness in the U.S. dollar.



Fandetti also upgraded Capital One Financial Corp. Wednesday, citing an expected improvement in credit losses.



Shares of MasterCard rose $2.28, or 1.1 percent, to $209.73 in late trading. The stock has traded between $113.05 and $239 over the past year.

Wednesday, September 9, 2009

67% of French Organizations Hit by One or More Data Breaches



Press Release: 67% of French Organizations Hit by One or More Data Breach Incidents within Last Twelve Months





Research from Ponemon Institute Reveals that only 9 Percent of Respondents have an Overall Encryption Plan or Strategy Applied Consistently across the Enterprise


Paris and Menlo Park, CA/9 September 2009 – (PIN Payments Blog)  PGP Corporation, a global leader in enterprise data protection, has announced the results of its inaugural annual study by The Ponemon Institute, identifying the steps French organizations are taking in order to safeguard their confidential data. The 2009 Annual Study: France Enterprise Encryption Trends study, which polled 414 IT security professionals at enterprises and public sector organisations, found that 67 percent of French organizations have been hit by at least one data breach incident within the last year, with 18 percent having been hit by more than five incidents.



A massive 92 percent of the data breaches were never disclosed as there was no legal or regulatory requirement to do so.



Despite the large number of data breach incidents, 71 percent responded that data protection was a ‘very important’ or ‘important’ part of their risk management strategy, with protecting sensitive or confidential information in motion (transfer) or at rest (storage) their top priority.



“It is very encouraging to see that 71 percent of respondents view data protection as a critical part of their overall risk management plan” said Dr Larry Ponemon, Chairman and founder of The Ponemon Institute. “However, the low percentage of French organisations having an overall encryption strategy in place or using a platform approach to encryption suggests that there are still considerable improvements to be made. The focus for 2010 needs to be on applying a strategic approach to data security across the enterprise.”



The following provides an overview of the key findings of the 2009 France Encryption Trends report:

  • Only 9 percent of organizations have an overall encryption plan or strategy that is applied consistently across the entire enterprise. Forty-five percent have no encryption plan or strategy whatsoever while the remaining 46 percent adjust their encryption plan to fit different applications and data types, or use encryption for certain types of sensitive/confidential information such as social security numbers or credit card accounts.

  • Encryption is primarily used to comply with privacy or data security regulations (65 percent) or to limit the brand and reputation damage linked to data breaches (43 percent). With regard to the regulations and regulatory bodies most influential in organisations’ decision to implement encryption, the French Data Protection Commission and French National Privacy Law come out on top with 66 percent and 62 percent respectively. International regulations such as Sarbanes Oxley have a very minor impact (4 percent).

  • Eleven percent of organizations use a platform approach to managing encryption solutions across the enterprise. Eight-two percent of these organisations believe the encryption platform increases the effectiveness and efficiency of their IT security programme. Reduced operational costs, consistent policy enforcement across applications and integration with third-party encryption applications were specifically listed as the primary benefits.

  • Fifty-six percent of respondents use encryption technology at some level and the remaining 44 percent are in the process of introducing it. Encryption is most widely used to protect data on databases, VPNs and file servers. Mainframe and USB flash drive encryption are the least deployed applications.

  • Seventy-one percent of organisations have a fully executed or just launched implementation of data archive and e-discovery systems programme. The figure is just slightly lower for the implementation of network-based data leak detection and prevention technologies (70 percent). More than half of respondents (58 percent) have just launched or fully executed an endpoint device control technology.

  • Sixty-seven percent of respondents revealed that they had been hit by at least one data breach in the past 12 months. Of the companies that experienced 2 to 5 or more than 5 data breach incidents, none of them had implemented a company-wide strategy governing the use of data encryption technologies.

  • A majority of respondents (58 percent) believe the ability to install a management infrastructure once, and then add additional encryption applications as needed is ‘very important’ or ‘important’. Other important features include the automation of key encryption management activities (55 percent) and enforcement of encryption policy across all applications.

  • Encryption solutions are seen as a security priority for 39 percent of respondents. 29 percent also indicate that key management for encryption solutions is earmarked amongst the security initiatives in the current budget and accounts for just over 21 percent of overall spending on encryption.

  • Forty-five percent of respondents consider loss or theft of confidential or sensitive data one of the major security threats of the next 12 to 24 months. Despite this, 68 percent do not encrypt sensitive or confidential information on mobile data-bearing devices such as PDAs and smartphones, only 4 percent use encryption on USB flash keys and 47 percent are ‘unsure’ or ‘not confident’ about their ability to protect confidential or sensitive information in motion.

“The Ponemon data demonstrates that compliance and fear of reputational or brand damage are driving French organizations to prioritize data protection,” commented Phillip Dunkelberger, president and CEO of PGP Corporation. “Encryption solutions, when coherently and consistently applied across the enterprise to confidential and sensitive information, can protect data at rest, in motion and in use.”





For more information or to receive a complete copy of this study, visit: www.encryptionreports.com


About The Ponemon Institute


The Ponemon Institute is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors and verifies the privacy and data protection practices of organisations in a variety of industries.



About PGP Corporation


PGP Corporation is a global leader in email and data encryption software for enterprise data protection. Based on a unified key management and policy infrastructure, the PGP® Encryption Platform offers the broadest set of integrated applications for enterprise data security. PGP® platform-enabled applications allow organisations to meet current needs and expand as security requirements evolve for email, laptops, desktops, instant messaging, smartphones, network storage, file transfers, automated processes, and backups.



PGP® solutions are used by more than 100,000 enterprises, businesses, and governments worldwide, including 95 percent of the Fortune 100, 75 percent of the Fortune Global 100, 87 percent of the German DAX Index, and 51 percent of the UK FTSE 100 Index. As a result, PGP Corporation has earned a global reputation for innovative, standards-based, and trusted solutions. PGP solutions help protect confidential information, secure customer data, achieve regulatory and audit compliance, and safeguard companies’ brands and reputations. Contact PGP Corporation at www.pgp.com



Media & Analyst Contacts for PGP Corporation:


Carol Pender/Alexandra Radius

Johnson King

+33 (0)1 53 16 11 11

carolp@johnsonking.fr

alexandrar@johnsonking.fr



North America

Tom Rice

Merritt Group

+1 703 856 2218

rice@merrittgrp.com



United Kingdom

Jacqui Depares / Richard Scarlett

Johnson King

+44 (0) 20 7401 7968

pgpteam@johnsonking.co.uk



Germany

Ingrid Daschner

Johnson King

+49 (0) 89 8940 8511

ingridd@johnsonking.de





Reblog this post [with Zemanta]

The ROI of Small Business Mobile: New Report from Aite Group















A New Report From Aite Group
The ROI of Small-Business Mobile




Small-business mobile banking promises to be an important revenue driver, with one-third of U.S. small businesses willing to pay for the service.  Editor's Note:  73% are NOT willing to pay for a mobile banking service according to the graphic depiction below:



Boston, MA, September 9, 2009 –  (PIN Payments Blog) A new report from Aite Group, LLC analyzes the types of mobile banking transactions small businesses are most willing to adopt, and how that willingness varies by business size. Based primarily on the results of a July 2009 survey of 283 U.S. small businesses (defined as any business generating less than US$10 million in annual revenues), the report also points out challenges, such as misperceptions about mobile security, that banks will have to overcome to ensure a successful deployment. Finally, the report examines small-business willingness to pay for mobile banking/transaction service, expected adoption rates and estimated deployment costs and potential revenues for banks seeking to calculate return on investment (ROI).
Many institutions have deployed mobile banking services as a must-have to "keep up with the Joneses." As a consequence, retail mobile banking services have become commoditized, compressing vendor revenue opportunities.



Mobile small-business banking may reverse this trend, allowing banks to re-invest in the mobile channel and open up tightly controlled budgets. To date, banks' failure to offer mobile banking services to small-business customers has not only resulted in lost potential revenues, but also missed opportunities to deepen relationships and achieve greater cross-selling success with this important customer segment. More than one-third of U.S. small businesses would be willing to consider using mobile banking if it were offered by their primary institution, and 27% would even be willing to pay for the service.

"Most banks recognize the additional convenience they can offer to customers by proffering mobile banking capabilities," says Christine Barry, research director with Aite Group and co-author of this report. "Despite this, many U.S. banks have been slow to roll out mobile offerings, especially to small-business customers."


Nick Holland
, senior analyst with Aite Group and co-author of this report, adds, "Small businesses are looking for a host of extra functionalities above and beyond the requirements of vanilla mobile banking, such as wire approvals and positive pay. Banks will be looking to monetize small-business mobile banking, and an offering that does not justify end-users paying for the service is unlikely to receive implementation."


This 24-page Impact Note contains 15 figures. Clients of Aite Group's Wholesale Banking service can download the report by clicking on the icon to the right.


Related Aite Group Research:


To purchase this report or

for additional information,

please contact:

Aite Group Sales

Tel: +1.617.338.6050

sales@aitegroup.com
Reblog this post [with Zemanta]

Disqus for ePayment News