THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Candice Pressinger, Director of Customer Data Security, Elavon EuropeThe past few years has seen businesses and consumers alike embrace new technologies and new habits that have changed how they work, communicate, shop and pay. This digital transformation has seen the cybersecurity landscape change too as new threats and malicious actors adapt to take advantage of this online world.
Cyber crime is a lucrative trade and ransomware attacks, the weapon of choice for hackers, are increasing. The ability to exfiltrate and hold hostage data in exchange for cryptocurrency payment is becoming all too common. It’s why in the next decade, cyberattacks will continue to be one of the greatest risks businesses face.
At the heart of what we do at Elavon are our merchant customers, and as more of them take payments online, protecting their data and their customers’ data from cyber threats is critical. But in a data-driven world, protecting them should not come at the cost of customer experience. Finding that sweet spot between a low-friction customer journey while keeping payments safe is the endgame.
A growing trend to meet this need is the use of artificial intelligence (AI). While used successfully to improve efficiencies, reduce costs, and increase product innovation, in payments it’s being used as a tool to determine whether transactions being made by customers are legitimate or not. Over time, AI is getting smarter, learning from patterns and behaviors and the fraud it detects. Implementing it into everyday payments activities can reduce fraud, while also leading to a smoother buying experience, in turn leading to lower cart abandonment and higher revenues for merchants.
Conversely, AI is being used to develop intelligent malware and attacks designed to circumvent the most recent data security protocols. Going forward, AI-powered threat detection systems that can predict new attacks and alert administrators to data breaches will be required.
Endpoint Detection and Response (EDR), credential security, and network security controls are critical to the success of emerging technologies and the prevention of cyberattacks. Businesses must be cautious about security as they integrate cutting-edge technologies,in case the increase in their attack surface leaves them vulnerable.
Despite the education around cybersecurity and the threat of cybercrime, human error remains one of the primary causes of the data breach. One mistake by an employee, one malicious link clicked in an email or one password hacked can bring down an entire organisation. Raising awareness and providing training are mission critical in order to protect data in every way possible.
“Raising awareness and providing training are mission critical in order to protect data in every way possible”
These simple steps can help businesses better protect their data:
- Support Strong Customer Authentication (SCA) to protect online transactions.
- Regularly update your systems and software. You or your IT team must be aware of new patches and software updates to ensure vulnerabilities of previous versions don’t cost you. Use strong anti-virus software and anti-spyware.
- Train your people. When it comes to cybersecurity, people are usually the weakest link. To avoid human error mistakes everyone in your organization should have cyber security tips set as the default in their minds. Strong passwords, for example, should be required on both personal and corporate devices. Regular phishing exercises are also useful. Ensure there is adequate spending and attention given to security awareness training for employees.
- Multi-factor authentication (MFA), also known as two-factor authentication (2FA), should be enabled all of the time.
- Test your systems. Regardless of the size of your company, it is critical to test your response team's readiness in the event of an attack. If an attack occurs, you and your IT team must have established protocols for responding in real time.
- Regular penetration testing. If you do not have an in-house cyber security professional, you could hire a skilled freelancer to look for vulnerabilities in your system on a regular basis. Continuous penetration testing allows you to use a hacker's mindset to predict how and where they might try to gain access to your network.
- Back up your data frequently. Even if you are following the best cyber security practices and doing everything possible to stay safe, it is important to understand that some cunning hacker may still manage to breach your systems. Remain prudent, and make a habit of regularly backing up all of your data to the cloud or hard drives.
Without a doubt, technology is a double-edged sword. While its advancements have made consumer payment options and journeys easier, depth in defence security measures are your best approach to protect valuable da