Intelligent Fin.tech Issue 35 | Page 18

T A L K I N G P O I N T

T A L K I N G P O I N T

PAYMENT SECURITY STARTS WITH DESIGN, NOT THE AUDIT

Johannes Briel, Group IS Manager / PCI DSS QSA at Galix
Johannes Briel, Group IS Manager / PCI DSS QSA at Galix, discusses the importance of building PCI DSS processes into day-to-day operations to reduce fraud risk.
hile many businesses still view the Payment Card
W
Industry Data Security
Standard( PCI DSS) primarily as a compliance obligation, the reality is that payment security has a direct impact on operational stability, customer trust and commercial resilience. The way payment architectures are designed ultimately determines risk exposure, and without clear scoping and strong controls, vulnerabilities can quickly emerge. With the guidance of a qualified PCI DSS expert, organisations can clearly define their cardholder data environment, reduce unnecessary complexity and embed controls that support both security and performance. When approached correctly, PCI DSS becomes a practical framework for continuously managing risk, controls and monitoring across payment environments rather than a periodic audit exercise.
The way payment environments are designed determines where risk sits across each channel, and different payment channels expose businesses to different types of risk depending on how cardholder data is captured and controlled. In-store environments, for example, are typically exposed to physical risks such as device tampering, substitution and weaknesses in network segmentation across distributed locations. Online payment systems, by contrast, are more exposed to automated attacks.
Mobile applications introduce additional risks through insecure APIs, weak certificate validation and the potential for reverse engineering. Across all channels, risk is determined by how payment flows are designed and where cardholder data is stored, processed and transmitted. When organisations directly handle card data, the responsibility to secure it increases, making proper scoping, segmentation and access control critical.
A common challenge is that many organisations still approach PCI DSS as a once-a-year audit focused on documentation and evidence collection. This often creates unnecessary pressure and encourages reactive remediation rather than proactive control management.
Embedding PCI DSS processes and controls into day-to-day operations changes this dynamic. When organisations treat compliance as an ongoing framework, they replace periodic firefighting with structured governance and ongoing control management.
Across payment environments, several weaknesses consistently appear. Poor network segmentation, excessive user privileges, unpatched systems and weak payment page integrity controls remain common entry points for attackers. Flat networks, where proper segmentation methodology is overlooked to isolate critical systems that process cardholder data from corporate systems, increase the likelihood of lateral movement, while stolen or reused credentials continue to be a primary attack vector where authentication controls are insufficient.
PCI DSS provides a structured approach to addressing these risks through strong segmentation, multi-factor authentication, least-privilege access and effective logging and monitoring. Secure software development practices and regular testing further reduce exposure, particularly where organisations build or manage payment applications. Continuous vulnerability management ensures that, as new threats emerge, controls evolve alongside them, maintaining security posture and keeping the environment secure and stable.
Failing to maintain compliance can lead to more than just financial penalties. It can damage your reputation and, in some cases, result in losing the ability to process card payments. Organisations that build PCI DSS into their day-to-day operations not only reduce fraud risk and make it easier to do business with customers and payment providers, but they are also seen as trusted partners. �
18 www. intelligentfin. tech