Interview With Eyal Nevo – CEO at PCI Booking

In a recent SafetyDetectives interview, Eyal Nevo, CEO of PCI Booking, delves into the origins and evolution of the company. Born from a need to ensure PCI compliance for credit card details in the travel industry, PCI Booking emerged as a pioneering solution. Nevo explains the vital role PCI Booking plays in safeguarding payment processing and facilitating outsourced PCI compliance, particularly within the travel sector. He discusses the immense challenges businesses face in achieving and maintaining PCI compliance and how PCI Booking eases this burden. Additionally, Nevo offers expert advice on best practices for handling payment card data and staying ahead of emerging threats in the payment processing landscape. How did the idea of PCI Booking come about, and what has the journey been like? We had been…

Continue ReadingInterview With Eyal Nevo – CEO at PCI Booking

A Comprehensive Guide to Credit Card Vaulting

As the digital age continues to evolve, the importance of card security measures is becoming increasingly crucial. Credit card vaulting is one of the most important components of any PCI compliance service, providing a secure way to store customer payment data. In this blog, we will review the basics of these services and provide a comprehensive guide for understanding how they work, as well as how they can protect your customers’ sensitive information. Why Is Card Security More Important Than Ever? With the rise of online transactions, cyberthreats have become a top priority for businesses everywhere. Every day, millions of customers are exposed to potential data breaches and identity theft. According to a 2023 survey conducted by the Insurance Information Institute, 33% of Americans have…

Continue ReadingA Comprehensive Guide to Credit Card Vaulting

Data Breach Recovery and Prevention: What You Need to Know

Data breaches have become an unwelcome part of doing business in the digital age. They cost time and money for recovery and cause reputational damage due to lost customer trust. Fortunately, with the right prevention measures and an effective data breach recovery plan, your business can protect itself. In this blog post, we'll discuss what a data breach is, how you can identify one, the steps you need to take to recover, and how you can prevent future events. What Is a Data Breach? To put it simply, a data breach occurs when an unauthorized individual or group gains access to a company's sensitive data, such as financial records, customer information, or intellectual property. Cybercriminals typically use malicious software (malware) to gain access to the…

Continue ReadingData Breach Recovery and Prevention: What You Need to Know

3D Secure Merchant Information Required

As we gear up to release 3D Secure services to our clients, we need to discuss some “back office” information needed for 3DS authentication.3DS authentication is a merchant-initiated activity. Similar to charging a card, an organization needs to be registered with an acquirer as a “merchant” in order to perform these actions.This means that in order to perform 3D Secure authentication on cards processed through PCI Booking, PCI Booking will need to provide the 3DS provider the relevant merchant information for the entity performing the 3D Secure authentication.In order to help our clients and make the deployment more streamlined, PCI Booking will be registered as the default merchant for processing 3DS on cards tokenized in our system. However, we strongly recommend that you provide us…

Continue Reading3D Secure Merchant Information Required

Protecting phone payments as criminals switch focus to card-not-present.

With the adoption of telephony cloud solutions and the increasing use of call recordings for training purposes in many companies, there is a greater risk that credit card information, shared between the card owner and the merchant during the call, will get stored on insecure servers in the cloud. As a reaction to this development, the PCI SSC recently published new guidance on how merchants should accept payment information from customers over the telephone. The Protecting Telephone-Based Payment Card Data guide highlights both the risks involved, and the areas that require the attention of merchants if they are to adequately protect customers payment details. This raises the question for merchants: what is the most secure and easiest way to accept card details over the phone?…

Continue ReadingProtecting phone payments as criminals switch focus to card-not-present.

Improvements made to Property Management System

We would like to let you know regarding some improvements that have been made to the Property Management System. Until now, the process of managing properties (actions such as sending or resending activation emails and reopening closed properties) required logging into the PCI Booking user's portal and manually completing these actions. We recognize this is time consuming and, in order to improve this process, we have developed and released the following functionality updates: Closed properties may now be re-opened via the API.Activation emails may now be re-sent via the API. We welcome your feedback on these changes and, as always, will keep you updated regarding any further new developments - including ones also related to management of properties through the API that we are currently working on.…

Continue ReadingImprovements made to Property Management System

Introducing option to remove token duplicates

We are pleased to inform you of updates we have introduced to our PCI Shield product. Effective now, customers have the option of preventing storing the same card details multiple times, thus creating multiple tokens for, effectively, the same data. If enabled, PCI Booking will identify cards that have been previously tokenized and assign them with their original token. Currently, PCI Booking creates a new token each time a card is processed, regardless of whether it has already stored in the system. By using the card lookup feature, you can save money on both the tokenization request and storage fees, in addition to reducing the headache of managing multiple tokens that are the same card. Preventing duplicates in this manner is optional, and you have…

Continue ReadingIntroducing option to remove token duplicates

Customers advised to test environment prior to TLS 1.0 discontinuance

Due to security vulnerabilities, and following the PCI Council’s requirement to cease support of older security protocols, PCI Booking will discontinue support of both TLS 1.0 (an older security protocol use on SSL secure web pages) and older versions of SSL onJune 1, 2018. Prior to this date, we strongly recommend that customers test their environment within our pilot environment, where support for TLS 1.0 has been already disabled.  This will allow you to send requests to the pilot environment and confirm there will be no issues in your production system once support for TLS 1.0 is removed on June 1st. A description of the behavior change in the system, once support of TLS 1.0 has been removed, and our full recommendations on how to prepare and…

Continue ReadingCustomers advised to test environment prior to TLS 1.0 discontinuance

Improving Load Balancing in Gateway

As part of our efforts to constantly improve the PCI Booking offer, we have been busy developing a range of improvements for the Gateway feature that both strengthen performance and reduce the required level of customer interaction with the Gateway. The main change is, instead of providing direct IP addresses of the server(s) hosting the customer’s Gateway endpoints, we will now provide one CNAME record to be set by the customer into their DNS records. Setting up the Gateway in this configuration will support and allow the following: 1. The customer will only need to set one DNS record per endpoint to direct the endpoint URL to the CNAME URL. 2. The CNAME URL will direct traffic to a load balancer and high availability system within PCI…

Continue ReadingImproving Load Balancing in Gateway

PCI Booking launch solution for PCI compliant telephone bookings: Card Over The Phone

To enable merchants to remain fully PCI DSS compliant while accepting payment details from customers over telephone calls, PCI Booking has launched its latest feature: Card Over The Phone. Card Over The Phone allows merchants to accept payment card data via telephone by providing the customer with a card capture page through a shared link delivered via SMS or email and completed in order to confirm the booking being requested. This eliminates the current requirement, and the PCI compliance issues that arise from such, of payment details being verbally communicated with employees. Compliance issues, many of which that are unique to telephone payment, include employee screening procedures, the recording and storage of customer calls, plus the protection of details taken from both recorded and non-recorded…

Continue ReadingPCI Booking launch solution for PCI compliant telephone bookings: Card Over The Phone

Card Over The Phone

Successfully remaining PCI compliant requires attention across all methods of accepting payment card data, including telephone. To facilitate telephone bookings, PCI Booking has developed Card Over The Phone. Card Over The Phone enables merchants to remain fully PCI DSS compliant while accepting payment details from customers over telephone calls. This is achieved by removing the requirement for customers to verbally communicate their card details. Instead, a card capture page is accessed through a shared link delivered via SMS or email, which is then completed by the customer themselves. Implementation of Card Over The Phone, in place of the current system of verbal communication, allows merchants to remain PCI compliant without worrying about the PCI compliance issues - some of which that are unique to telephone payment.…

Continue ReadingCard Over The Phone

PCI Booking introduces new feature: Universal Tokenization

As part of PCI Booking’s efforts to improve user experience, we are delighted to announce Universal Tokenization, a solution designed to aid customers working with multiple third party partners (such as Booking.com, Expedia and many others). Universal Tokenization eliminates the previous need for customers to manually develop a separate integration for each partner, a timely and complicated task. Customers using this solution are now required configure only one integration. All third-party requests will be directed through PCI Booking, where such requests are automatically translated into the required format of the selected partner. Learn more about Universal Tokenization on our dedicated product page. Also, see our technical documentation for more information and to retrieve a complete list of all supported third-parties.

Continue ReadingPCI Booking introduces new feature: Universal Tokenization