|
IS YOUR RESTAURANT VULNERABLE TO A
POS SYSTEM ATTACK?
AN IMPORTANT SECURITY MESSAGE FROM MICROS' CHIEF INFORMATION SECURITY OFFICER, JAMES WALSH
There are powerful new malware programs attacking merchants in all industries, including the hospitality arena. The latest type of malware does not steal cardholder data from the POS application, but rather, from the operating system's volatile memory, which the POS application doesn't control.
Therefore, it doesn't matter which POS product or version is in use, as the data is not being taken from the POS application.
It is much more important to protect your payment processing network in order to prevent the attackers from gaining access and deploying malware tools like Dexter, the one that has been covered in recent news.
There have been numerous warnings about this type of attack over the last 3+ years by the PCI-SSC and Card Brands. Their recommended mitigation strategy is to prevent the attackers from gaining access to your network by complying with the PCI-DSS. MICROS has also issued warnings about this type of attack. You will still find these posted on our information security site, by clicking here.
Another very effective mitigation strategy is Point-To-Point-Encryption, (P2PE). As the cardholder data is strong-encrypted at the point of card "swipe", attackers using memory parsing malware would obtain only strong-encrypted data which is obviously harder for hackers to use easily. MICROS offers P2PE with a product called "Transaction Shield", when installed in conjunction with the latest software version of MICROS RES 3700 POS (v5.0) and Magnetic Stripe Readers having P2PE capability.
Our strong recommendation would be to comply with the most current PCI-DSS standards, and consider implementing P2PE.
Please make sure you have a strong security plan in place for 2013 and have a safe and successful year!
|