North American Bancard
United Bank Card
NACHA
BAI
Kioskcom
Wausau
February 9, 2010


News
Current Issue
Subscribe
Advertise
Archive
About Us
Contact Us
Calendar
Buyers Guide
Web Transaction
Performance Indexes
NEW! Data on outage hours

MSI
Don’t Hire a QSA by Seeking the Lowest Bid, Warns Heartland’s Carr

(September 13, 2009) Among lessons learned by Heartland Payment Systems Inc. after the massive data breach at the merchant acquirer last year: Don’t necessarily hire the qualified security assessor (QSA) offering the lowest bid, says Robert O. Carr, chairman and CEO.

Processors and merchants need to hire QSAs in the same way they hire financial auditors, Carr said during a webinar on Thursday sponsored by Debix.

“We get bids but auditors pretty much will say ‘if we find something we feel has to be investigated further, we’re going to charge you more,’” he said. “Most of us agree to that. That’s the way it needs to be done in the QSA world.”

Prior to the breach, Heartland had been audited six times by qualified assessors as being compliant with the Payment Card Industry data security standard, or PCI, the major card networks’ common set of rules. “Our QSA reports were not worth very much—they didn’t really tell us much at all of value,” Carr said. “That doesn’t mean QSAs are bad people but it means that the system is not working very well."

Heartland used the bidding process when it hired the QSA that performed the audits before the data breach was revealed. “We went through the process with the QSA and they would ask us the questions and we would answer them to the best of our ability,” Carr said. “And we would get a report that everything is fine.”

But Carr noted that it’s unlikely that a QSA offering the lowest bid or to do “a full assessment for $15,000” will be able to do a thorough audit. “You don’t want somebody saying, ‘okay, I put in my hours’ and walking out the door,” he says. “That’s what happened not just to Heartland but that’s the way it’s being done today for many of the audits.”

An industry study found that there were 650 data breaches in 2008, including Heartland, “so obviously others were being breached at the same time,” Carr says.

Following the breach, Heartland hired a new QSA to audit its system. “We said find anything you can,” Carr said. “We don’t want a bid from you, we’ll pay you time and materials, and we want you to find everything possible and give us any weakness information that you can.”

During the webinar, Carr also outlined the steps Heartland took to ensure data security after discovering a so-called SQL injection into its system at the end of 2007. The injection—a series of instructions to access computer databases—often are used by hackers to install malicious software that seeks out, stores and transmits payment card numbers outside of a system.

The SQL injection occurred in a merchant-facing payroll page, not directly into the payment system, Carr said. “We found this SQL injection quickly and we cleaned it up, we thought,” he says. “Unfortunately, we learned 13 months later that the bad guys had gotten in through this SQL injection and we had not found it.”

Over a period of months, the SQL injection worked its way undetected into the payments network despite numerous security checks, including penetration testing of the corporate environment by a QSA in early 2008. “Nothing was found,” Carr said.

The malware eventually was uncovered in January by a forensic company hired by Heartland, he says.

Carr was scheduled to testify Monday morning at a U.S. Senate Homeland Security Committee hearing about protecting against cyber-attacks.







As Competition Heats up, USA Technologies Settles With Dissidents
USA Technologies Inc. and a dissident shareholder group buried the hatchet last week, but their...

Debit Growth Is Still the Story As Visa And MasterCard File Results
The bank card networks have weighed in with their latest earnings reports, and operating...

Encryption, PIN Security, EMV Top Busy Agenda for PCI Council in 2010
A busy year is on tap for the PCI Security Standards Council, with revisions due not only for the...

Same-Store Card Sales Continue to Plunge for Small Businesses
Same-store sales on credit and debit cards continue to drop for small businesses, indicating that...

Hackers Target Hotels for Card Data As Malware Gets More Insidious
A growing emphasis by computer hackers on stealing payment card data from hotels and resorts and...

Fiserv Sees An Opportunity in Filters for the ACH’s New IAT Code
As financial institutions find themselves processing more and more international transactions...

VeriFone Goes Outside Usual Channels to Sell Its New iPhone Product
VeriFone Holdings Inc.’s PAYware Mobile mobile-payments initiative includes not just the...

M&A Optimism Rises Even As NAB Stays Mum About Possible Sale
One of the nation’s biggest independent sales organizations may be putting itself up for sale,...


Copyright 2010 by Boland Hill Media LLC. All the text, graphics, audio, design, software, and other works are
the copyrighted works of Boland Hill Media LLC. All rights reserved. Any redistribution or reproduction of any
materials herein is strictly prohibited.
Privacy policy