Having issues accessing the video above? Watch the video here.
PCI and Data Security Lessons for Franchises
In this webinar, Robbi Watson, Director of Business Development for SecurityMetrics and Cody Connatser, Manager of Operations Services for MOOYAH, discuss MOOYAH's experience implementing a PCI Program for their franchisees. They cover:
- Common misconceptions franchises have about PCI
- How to protect the brand image of your franchise
- The keys to set up a successful PCI and data security program
This webinar was hosted on May 17th, 2017.
PCI and Data Security Lessons for Franchises Transcript
So this is Colin from Security Metrics. We're gonna go ahead and get started with the webinar. I'll kinda introduce you to the topic and our speakers, and we'll get get going and hopefully provide some valuable information to your franchises.
As we get started, if you can just chat in that the audio is working, that way we are confident that you guys can benefit from the webinar and that everything's up and running smoothly. So today's webinar is PCI and data security lessons for franchises.
And part of the webinar today will discuss how Moojan is protecting their franchise brand.
And so our per our presenters today are Robbie Watson, director of business development here at Security Metrics. And co presenting and part of this, and will also help out with the q and a session at the end, will be Cody Knatzer, manager of off services at Moo Yacht burgers, fries, and shakes.
And so a little bit about security metrics before we get started. We've been helping organizations since two thousand get PCI compliant, avoid security breaches, and recover from data theft.
And so we have a lot of experience over fifteen years in the data security and compliance world, and I think we'll have some valuable insights, especially in today's environment. I mean, nothing more timely than with some of these cyberattacks over the weekend with ransomware. You know, data security, I think, is on a lot of businesses' minds, and we definitely have some some tools and some solutions and some ideas on how franchises can protect their organizations.
And so just a few housekeeping items before I turn it over to Ravi.
The most common question we get is will we be sending out an audio recording in the slide deck of the webinar? So we will be sending out a recording of the webinar in the next few days. We'll just send that to the email address that you registered for the webinar. And so just watch your inbox over the next few days. We'll send you the slide deck and the recording. That way, you can rewatch anything, relisten, or share it with any colleagues that you think would also benefit from it.
At at the end of the webinar, we will do a live q and a session.
We'll just have you chat them in using your GoToWebinar control panel, and we'll address as many as we can at the end.
During our q and a sessions, we try to make them as general as possible so that they can benefit everyone. And so if you do chat any questions that are gonna be really specific to your franchise or your environment or network setup, things like that, we'll probably take those offline, but we will reach out to you on an individual basis after the webinar.
So with that said, go ahead and chat in any questions you have throughout, and I'll turn the time over to Robbie to get into the webinar.
Great. Thanks, Pauline.
So thanks for joining us today, everybody. Hopefully, you can take away some valuable information, from this webinar.
So we're gonna get right into it and start talking about PCI and data security.
So why do we have to do PCI and why do we need to actually keep our data secure?
One of the most obvious reasons are gonna be all the images on this slide.
So a lot of these organizations have been breached, some of these being franchises.
In the franchise space, you guys have it pretty unique because, mom and pop shop, just one business, they could be breached, but it really only affects their business.
However, if a franchise was breached, it not only affects that one specific franchise location, it's going to affect your entire brand.
So without giving any names, there have been plenty of breaches in the franchise space, And I'm sure it's not only hurt that one specific organization with the amount of fees and everything in between, but it also affects the entire brand.
So why PCI and data security? Well, reason for that is because it really is easy to be hacked. The there's so many different ways someone can steal your data.
One of the most common being malware being embedded into systems and stealing any stored card data that's already there. So in two thousand and sixteen alone, sixty seven percent of businesses stored unencrypted, payment card data.
So those are kind of the low hanging fruits. If a hacker is able to get in and if there's stored credit card data there, they already have all the information they need. So, from a data security standpoint, tokenization is is pretty key there to make sure that you have some sort of systems that have that in place.
So you can actually, if a hacker is still any data, they're just getting a token from, you know, the actual payment card data. Another tool we we have in particular is called Panscan. It looks for any unencrypted cardholder data.
In two thousand sixteen, there was over thirty six million records exposed, and the average merchant at the time of data compromise was actually not truly compliant with forty seven percent of the PCI DSS requirements.
So what that bullet point pretty much means is a lot of merchants slash franchises have figured out, I'm just gonna answer yes, yes, yes, yes to every single question on my self assessment questionnaire and not actually do the requirement. So, sure, that may help them void a noncompliance related fee from their acquiring bank.
However, it doesn't truthfully protect their business, and we're in the business of protecting other people's businesses, not just doing checkbox compliance and giving them a little stamp of approval.
So that's one thing a lot of merchants kind of fail to grasp is truthfully meeting the PCI requirements.
Another reason for PCI data security is because it's very expensive if you're to be breached and compromised. I'm not gonna go over each and every one of these bullet points, but it starts with, I mean, as little as a noncompliance related fee from the merchant bank and processor.
And it's so interesting to hear from so many franchisers that their franchisees don't even know that they're paying a noncompliance related fee.
They may be doing an outside PCI program, but then that program doesn't really relay the info to the acquiring bank.
And that franchisee may still be receiving a noncompliance fee.
Aside from noncompliance fees, there's car brand compliance fees, forensic fees, fraud fees, fees from the car brands, lawsuits, everything in between.
So having, some sort of company that may offer some sort of warranty or service coverage, to help combat any sort of these fees and potentially provide some sort of reimbursement could be a a key solution for any sort of programs if you decided to select.
So what is PCI DSS? So it's the PCI data security standards.
And all businesses that store, accept, maintain, transmit, process, credit, or debit payments, so retail hospitality, payment gateways, hosting providers, anyone that's processing and handling credit card data, they need to do their PCI DSS.
There's several different levels of merchants, which we won't really dive into too deep. But if you have a question on that, we can go over it further.
And with the PCI DSS, there's twelve main requirements.
So in order to be compliant in the most basic scenario for a level four merchant, you wanna identify your scope. So you should have a tool that will accurately scope one of your franchises.
So many times we hear of, franchisees get it set up incorrectly, so they understand maybe that self assessment questionnaire a is the easiest to complete. So they're kind of self assessing and minimizing their scope so they only have to answer eleven question questionnaire, which, awesome, that would be pretty easy, but, again, it doesn't really keep them secure. So one, identifying your scope and making sure the company is able to make that as seamless as possible but accurate as possible, completing a self assessment questionnaire, achieve a passing scan if that's applicable for their environment.
And not only that, it's beneficial to have a company that you're working with know how to help your franchisee segment their IP addresses so that they're not just scanning an entire range of IPs, that they're really only scanning and targeting those that are handling card data and segmenting those away that aren't actually handling card data. And lastly, report your compliance. So whether that's to a card brand, if you're an acquirer, or if you're a franchisor and you're acquiring a bank partners need to see that reporting and compliance, we provide that too.
So there are common misconceptions about PCI for franchises.
I'm only gonna go over five, and you may be able to help me add some additional misconceptions to this list.
So briefly gonna go over these.
First one, it's unfortunate if one franchisee gets breached, but it shouldn't have any major effects on the brand as a whole. So that's one common misconception is, you know, if if I get breached, it's not really gonna or if I'm a franchisor and if one of my locations is not secure, not doing their PCI DSS, or I don't even have a plan in place for them to do anything, You could just be walking a steady line and a a fine rope is thinking if one of your locations gets breached, it's only gonna affect them, and it doesn't really affect the entire brand. However, we've seen that to be untrue.
It does affect the entire brand.
And I don't need to worry if my franchisees are compliant. That's their job. So that's one misconception I hear quite often.
And it does kinda go hand in hand with the first misconception of it's not just one brand if they're breached, it's all brands. So as a franchisor, unless you're already an extremely well established name, probably, You're gonna probably have a hard time having, new prospects and people want to franchise with you guys if there's lots of reports of data breaches.
So it's very important to make sure that you have a seamless, simple, yet secure solution so that these guys can validate their compliance.
Another misconception, my equipment is marked as PCI compliant, so that's all I have to do to reach compliance status.
So although a terminal or gateway may be level one PCI compliant, that's a marketing standpoint that many use on their websites because they have to go through a a PADSS, from a QSA, a qualified security assessor, that doesn't actually make the merchant secure and compliant.
Now there is technology that can help reduce their risks, such as, like, a validated p two p e solution, so that it's encrypted at the point of swipe.
There are ways to reduce that risks, but it still is very important for them to actually validate and truthfully go over their compliance standards, not just have their equipment there and rely on that solely.
And then the next misconception is PCI compliance is a once a year thing. I don't need to worry about it the rest of the year. So this kinda gets franchisees and merchants into the mindset of, crap. I have PCI. It's coming up for renewal. I'll just go into my questionnaire and answer yes to everything, and I'm done. And I'll worry about it when I get that annoying email next year.
So I can, I can relate to some of these merchants and franchisees?
PCI can be difficult. It's a headache, and I understand that. But it is important to have a provider that can help hold your franchisee's hands through this process.
And I mean, think of it like a dentist visit. No one likes going to the dentist, but you probably should go if you wanna keep up on your your dental health.
With PCI, try to find a vendor that can make it as easy as possible.
And although it's more than once a year requirement, that vendor can have certain measures in place like a managed firewall with monitoring to actually help the franchisees, stay updated on security threats and actually update their firewalls, stay up to date on vulnerability scanning and send them reports or an outbound phone call to notify them of any risks.
So taking more of a proactive approach is going to help your franchisees focus more on growing their business and not so much on data security.
And selecting the correct vendor for that is going to put the time and resources on that vendor, not your franchisees.
And the next one, becoming PCI compliant is too confusing. I'm not going to worry about it. Data breach will happen to me anyway.
And, I mean, that could be true.
Not everyone is going to get breached. But if you're storing credit card data and you're not doing anything, it's going to be a lot easier for a hacker to get into your systems and and try to, manipulate your machines and steal that card data if you're not having any sort of security measures in place to prevent that from happening.
So I'm going to introduce you and turn the time over a little bit to Kony Kanaster.
He's over operation services at Mooja. We've loved working with Mooja. They're a great franchiser.
They came to us, not too familiar with PCI and actually had a bad experience with, another vendor years back. And I want Cody to chat in about, I guess, his experience with security metrics, their challenges, what they've learned from going through this process, and how being secure has has helped their business. So, Cody, I'm gonna turn the time over to you for the next few slides here.
Alright, Robbie. And Colin, first off, thank you guys for, allowing me to, be a part of this.
I I'm glad you kinda touched on all those different things as in that was our experience.
You know, we realized that, without PCI compliance the past couple years that, you know, we're kind of opening a door, like you said, to to credit card theft, you know, which can potentially cost, hundreds of thousands, if not millions of dollars when, you know, we we factor in those different kind of damages. And and and, obviously, the the bigger one, is is part of a franchise community. You know, some of these guys only own, one store, some multiunit. You know, when you factor in those, those those different aspects, you're looking at customer trust going down the drain, and, of course, that impacts our brand, reputation as a whole. And so the going over about a hundred stores now with MOOYA, Burgers, Fries and Shakes, you know, we we we knew it was time. We were already working at, one of these initiatives as far as Visa compliance.
We had worked with a a previous brand, excuse me, company that, really didn't understand how to streamline, this process, and better yet explain it to our franchisees. And and that comes to the challenges piece.
Number one being PSAC compliance seemed overwhelming.
Like you said, you know, to a franchisee and ops ops minor person, all we know is does it protect credit cards? What do I have to do? My my POS is PSAC compliant. You know, they the company said it was. Why am I not PCI compliant? What steps do I have to take?
We number two, we were unsure how to get franchisees PCI compliant. How do we streamline this? How do we explain it to them in a way that, it's easier for them while they can focus on, what's going on in the restaurant facing issues.
And number three, not PSAC compliant experts, you know, needing guidance.
I think this is a big one. You know, when we when we talk to different people in the industry or even in the fast casual space, I hate to say it, but unless we talk to a company like SecurityMetrics or another company that does this kind of thing on a day to day basis, it's kind of a different language.
Even even from a IT perspective, when we talk to our department or other departments at the industry, there isn't really a definitive explanation of how to come to a PCI compliance for each of our restaurants. Like, how do we come to that end of that road? What is the process?
And so as far as the solutions go, SecurityMetrics provided tools for PCI compliance. So when I say that they when we talked about I think, Robert, before you talked about, you know, as a franchisee, I have a POS that's, let's just say, PCI compliant. Well, that's just one of the pieces.
Security metrics said, look. You need a, b, and c. They allowed us to do, weekly webinars as we needed, monthly webinars as we needed to address all of our franchise community, which is a big deal because they allowed us to explain the process from our point of view and from their point of view of what the requirements were.
And and better yet, they did it not from a IT perspective from but from a ops perspective. Like, hey, guys.
You need a POS, but you need all these other pieces.
And they also provided, from the webinar, they provided a portal. And the portal was also a big deal because it allowed us at a corporate level to maintain, a streamline, timeline to make sure that all of our franchisees were trying to attain the PSAC compliance, come out with the SAQ, etcetera, etcetera.
And also from a franchisee perspective to go in, log in, and look to see where they're at to make sure that, yes, they're filling out the right FAQ.
Is it a FAQ a, b, or c?
Are they, going through and making sure they're passing their scans? And this is like like, Rob, we spoke to, this isn't this isn't just a one time thing like we thought. To To be honest, two years ago with the previous company, we thought it was a one time thing because that's what we were told. But from Security Metrics, we realized that this is an ongoing thing. And believe it or not, I think today, Robbie, you can speak to if you like, but we still have, stores that do fall out of the scans and that need to be, need to meet certain requirements to get back to a passing level.
And especially when you look at, all these different brands, it's not worth it for our brand to be where we're at and our franchisees to invest the money that they've invested, to slip up. And especially if you slip up one time, to be honest, you you've seen it. Most most one store, single unit stores, especially with the franchise community, they go out of business. And that's that's the that's the gist of it. I mean, I don't know anybody that can keep up with either half a million or anywhere close to a million dollars in in fees and fines, while maintaining a business. It's it's just almost impossible.
But on top of those tools that they were, that they provided for us was the corporate team, with security metrics, whether it be on our side, with me trying to project management, you know, project manage this this project for us.
Whatever area that we were in, whether it be my side of streamlining it, whether it be a franchisee signing up, whether whether it was from Genesis to implementation, they were there every single step. And and that was another big thing. You know? We didn't want them to say, here it is.
Sign up. This is sent. You're you're done. It was a step by step by step all the way until we were, implemented per store, and also, beyond that, like I spoke to as far as, you know, scans go.
And and they explained that compliance process to us, and the the knowledge and experience that they provided, was beyond what we've seen with with any other company. And it actually made us better as a corporate team, here at our at Mooya, at our corporate, at our corporate, staff and also, to our franchisees. It it became easier to explain it because it wasn't something, like you said, where it's a different language, pages and pages and pages of of compliance.
It was something to say, you know what? We're gonna start with a, we're gonna end with c, and we're gonna be we're gonna be there to support you, ongoing to make sure that you guys stay peace and compliant, especially today where we see breaches, if we wanna call it that, every single day. This is not something that, you know, our franchisees brought it up to where, oh, I don't need it. It's not gonna affect me. Okay? But on that on that onset, if it doesn't affect you, the one time that it does, you lose your entire business. And not only do you lose your lose your entire business, you lose we lose as as far as a franchisor, that brand reputation.
And we've seen what it does to, not only the fast casual community, but, but other communities as retail, and etcetera. And so the goal achieved that we, as far as our initiative with security metrics I mean, the majority of our brand today is PCI compliant.
We implemented, an effective PCI compliant brand. Obviously, again, we talk about a to c. We, we implemented that within our budget. That was another big thing.
They worked with us, day to day to day to make sure that cost effective to us and and most likely to our franchisees, not to break the bank to to make sure that we're a piece of PSAC upon across the board. And and lastly, we found a trusted partner for PSAC compliance, basically, not just for now. You know? Of course, everybody wants to get PSAC compliant now because they wanna, you know, to be honest, cover cover their butts, you know, for the company and for the franchisees.
But, also, as we're going over to two hundred stores or so, in the in the future, it's provided us to trust these guys, from a day to day to make sure that as a company, as a franchisee, as my small business, that, we are PCI compliant, for now, and the future.
K. Great. Thanks so much, Cody, for sharing that. So, yeah, we've definitely loved to work with Moo You and go through that experience with you guys and your franchisees.
You're definitely a fun brand to work with, and, we're happy to to definitely help you out. So I'm gonna go over some keys to program success.
So what how how are you going to achieve and get your franchisees to be on board with data security and compliance?
A lot of them we went over these misconceptions. They have that. Those are barriers and their challenges because you've you've all done with this. You've spoke with them.
Obviously, I'm sure you would love a hundred percent compliance and security in your franchise, community, but it doesn't always happen, and it's very difficult. So, hopefully, we can help you, break down those barriers a little bit. And the best way is through education. If at the end of the day we help franchisees do anything, is to at least, at the very minimum, make sure that their footprint is smaller by implementing some security best practices for their businesses, so that we can make sure that they're secure and, their customer's car data is secure.
So first one, goals and deadlines.
As a franchiser, set some goals at a franchise level for PCI and data security. I've seen things as drastic as you know what? If you don't have a firewall in place, we're shutting you off. You can't be our franchise anymore. So there legitimately, there are franchisors that are taking that approach, and it's a very strong one. But they're very, very focused on the security aspect of it and really understand what this is going to mean if one of their locations is breached.
Determine program requirements for franchises. So is it just a basic PCI compliance?
Does their technology go through Internet? Are they using POS software?
Should they have a managed firewall based on the technology they're using? Is that gonna be a requirement?
Additional tools. So do they have card discovery software to look for any unencrypted card data if the POS systems they have are tokenized?
Because I get it. Let's say you have some franchisees using a POS software that doesn't use tokenization right now. That's a pretty big project for you to reimplement a lot of different technologies into all these different stores to get them some new and updated, payment processing technology with tokenization.
So maybe something to bypass that is, card discovery software like Panscan to look and detect and remove any unencrypted card data and create defined deadlines. So don't just say to one franchisee one thing and then let another guy slide because remember, it's not just one person. I mean, if one person does get breached, it doesn't just affect that one person. It affects the entire brand.
So define deadlines, incentives, and penalties for the program participation.
So I like how Cody mentioned, the fact that we did webinars for them. So find a company that will work with you and do some educational webinar pieces, not to necessarily, sell your franchisees, but to explain the risks and step a through c of what they would truthfully need to do to be secure and compliant. And that way, it doesn't pressure them into doing PCI, but it it really kinda nudges them in the right direction to where we would start receiving phone calls or people reaching out to us because they were interested in better improving their security.
And and that's what what it's really all about is to try to make sure that their footprint's smaller and they're more secure.
So a clear communication plan. Create a defined outreach plan for your franchisee's goals.
So whether it's a webinar like Cody mentioned, can be backed with a partner that can do very targeted email communications to speak to your franchisees.
And you can clearly communicate that PCI and data security requirement to your franchisees.
Again, you can have that plan initially go as drastic as if you don't have a firewall in place, we're shutting you off. If you don't have a firewall in place, we are going to fine you.
If you do get a firewall in place, you get an advantage of having a data security reimbursement guarantee if you ever were breached and compromised up to a hundred thousand dollars.
There's many different ways and pushes you could do that, But really kinda getting it into your franchisee's head that this is something they do need to do, and it is something that is very important to not only their business but the rest of the organization.
Include touch points for multiple channels, whether that's email, phone, statements, newsletters. So if you have a franchise or newsletter and you wanna have a little PCI blurb on it each month or data security blurb, a great example would be for this upcoming month, one on the new WannaCry ransomware. Maybe having a partner that can help you provide content for your newsletters that you send out to help your franchisees be more secure.
So tools for franchisees, understand franchisees will need to be at different levels of compliance and security. And then you wanna find a partner that has all the tools necessary to meet your objectives.
So selecting a vendor that actually can meet all these requirements for your franchisee is going to be key.
Not just having one that's going to push your franchisees into several different directions, for different products like card discovery software, internal scanning, penetration testing.
Or let's say you have some level ones and twos in your franchise portfolio.
Maybe selecting a a provider that can also do their on-site PCI assessments as well.
So So finding one that has all the tools necessary is definitely gonna streamline your user experience for both the partner side and your franchisee side.
Continuation of that is having enough staff with that provider to be able to handle whether it's live chat, inbound phone calls, outbound phone calls.
And you can either have it in house or outsourced, whichever you prefer. In particular, with Security Metrics, we have all of our support and employees in house to provide handheld support, but that's not required, obviously.
Clearly defined responsibilities.
So vendor versus franchise headquarters. So you wanna make sure that you're on the same page with your, your, PCI data security vendor too so that they're not soliciting your franchisees trying to sell them many different products that may not apply to them. So really having a dedicated program manager staff to make sure that your goals are aligned with your vendor's goals.
And perhaps the biggest takeaway and tool for franchisees is going to be a program management tool.
Sorry. I was taking a sip of water. But it's funny to talk to a lot of different franchises who are working off of, spreadsheets and lack of data.
So they don't really understand what their franchisees are doing from a compliance perspective.
They'd really like to, but it's hard to track and hard to monitor and maintain.
So, I mean, I talked to recently a very, very large franchisor that has thousands of franchisees.
And they're having a difficult time to track and monitor the compliance status of their merchants, understand who has a firewall in place, which vendor they're even using, because a lot of franchisers have multiple channels which are providing PCI and data security, and they're kinda blind. So the executive team's blind, the business operations team, the IT team. A lot of people are blind to what's really going on and what people are doing.
So very key to have a program management tool, whether that's an external dashboard from a company that has nothing to do with PCI or a company that can provide that all in one as part of the PCI managed firewall solution for you. So transparency into the partner interactions with franchisees so you can see exactly what your franchisees are saying to that partner, what they're purchasing, the actual education pieces, their questions, which can help you from a marketing standpoint as well.
Here's just a glimpse of part of a Security Metrics, partner plus portal. This is not actually Mooja's dashboard.
But at a glance, you can quickly see how many of the franchisees are enrolled or engaged in the program, and that isn't just specific to security metrics.
If you have franchisees that are in love with another vendor and wanted to use another vendor for compliance, we can still track and manage and monitor the compliance status of another vendor's compliance directly in this portal and tool.
You can see their compliance status, which SEQ types they are, their net promoter score, so how in favor they are of the solution or not, all their upcoming renewals.
So just from an an executive level, you can quickly see where your portfolio is at with data security and compliance. And if you wanted to dive deeper than that, you can.
So you could definitely manage it through spreadsheets. It's very difficult, especially as your franchise business grows.
But having a program that includes a program management tool is going to be key as well.
So going over some takeaways, PCI and data security help protect your brand, not just the one individual business.
Set franchise goals for PCI and data security.
Find a partner that meets your franchise's needs, and clearly communicate with your franchisees your program expectations, and have a partner that can work with you on strategizing some known ways to help improve improve the user experience for your franchisees.
And a quote from one of our QSAs, the cultivation of a year round PCI compliance and security culture is imperative to avoid simple mistakes.
And that's entirely true. Your businesses, your franchisors or sorry, franchisee businesses don't really have the time and maybe resources to spend with PCI compliance.
So it's not just a year or once a year thing, but having a partner that can help them maintain and monitor that year round is going to be key to yours and their success.
So that is all I have for the webinar today, But I hope you took some, some value out of that and would love to hear some questions from you. I'll try to give you some of the best answers I possibly can for them. But Chad and Ian, if we aren't able to get to them all, you'll receive an individual response to your question afterwards as well.
So I'll turn the time over to you guys. Feel free to chat any questions in.
Okay. Thanks again to Robbie and Cody. I think there were a lot of great things covered and hopefully some some good nuggets for you to take to your franchise and, you know, hopefully help your brand get more secure.
We do have some good questions that I'm gonna dive into.
So, Ravi, someone asked, you know, the security metrics help determine the scope for each franchisee.
So will you kinda just speak to the scoping process and how we can help?
Yeah. So that's a great question.
One way we do it is, first off, with an initial conversation with the franchisor, we'll have a really, really good understanding of how the franchisee is set up, processing, and handling cardholder data so that we will really understand how everyone is going to be set up. I understand that all businesses are gonna be cookie cutter, but from our experience, a lot of them are set up pretty in similar fashions.
So, initially, we'll have that conversation, and we can determine an outcome for that based on how they're processing.
And as we are on the phone with the franchisee, we'll go over a reduced scoping amount of questions to see exactly how they're processing and handling credit card data.
With some predefined answers from the franchisor, beforehand, we're able to make this call a lot shorter for the franchisee so they're not having to answer a lot more technical questions that may be redundant to how they're set up. But we accurately scope them, and we do it quickly, seamlessly, whether it's over the phone or online.
Great. Thank you.
We also got one that I'm gonna try to summarize as much as I can that kind of discusses, you know, this person understands the that their brand could be definitely harmed if there's a breach at one location.
But what is the risk if breached? Who's impacted, you know, and by whom? Is it fees from the bank, the merchant service provider? Is it just the consumer dropping off in loyalty and asking for some real world examples? So, Ravi, if you can just speak to even one or two of the real world examples of the financial impact to a franchise.
Yeah. That'd be great. So I'm gonna take, I I don't wanna throw anyone under the bus for it. I mean, you can look up and see any franchise data breaches you wanted to, but, we do forensics. So we're a PFI and do a lot of forensic investigations, where if I'm a franchise and I get notified by the card brands or, crazy enough, even the CIA, I would need to contact someone to consult about a forensic investigation.
So our experience as a PFI and being in the forensic space, we've really seen a lot of a lot of breaches and a lot of ways how to prevent them. So I I know from a personal standpoint that not I guess nothing happened to me. But from our standpoint, a forensic investigation costs a lot of money, and that could be between twenty and thirty thousand dollars right there just for the forensic investigation to determine how that franchisee was breached.
Great. Yeah. So no shortage of unfortunate fines and fees that could come along with the data breach. So and we obviously be happy to dive into some more detail offline regarding that question.
And we got another really good question that I think will apply to many of the attendees.
This specific one is regards in regard to implementing similar principles in even the HIPAA compliance space. I'm sure there are many franchisees on this that either have to work on not just PCI, but potentially HIPAA or other compliance mandates or even just data security in general. So do you have any additional tips or recommendations on how these principles can be implemented for any compliance or security program?
Yeah. That's a great question too. So to touch on that, I mentioned it earlier in the webinar, but to have your organization set a plan in place and be focused on data security and compliance.
Not just thinking our franchisees, they need to worry about that and they need to do that and not really having a plan to help them get there. Because if they're not there's not really any plan or not really any pressure to do it. They're probably not going to do it. But instead of putting a hammer down on them, maybe doing some more educational pieces to guide them in that direction so that they will voluntarily do their PCI data security.
And it's actually pretty pretty crazy to think how many franchisees have utilized security metrics based off just educational material alone and have taken that step to actually better secure their business. Let's say that they're not ready to do a penetration test right now, but they wanted to take that first step and actually have a firewall in place that we'd monitor for them. It's just taking those initial steps. And I think with HIPAA compliance, it's not just a one and done compliance. It's proactively working to be better secure and validate your your actual security. Not really worry about compliance questionnaire, but meeting all those requirements on that questionnaire and being secure.
Great. We're getting a lot of really good questions. Some of them a little more specific to maybe your needs, and we'll definitely reach out on individual basis or would be happy to schedule a call to maybe dive into your specific franchise needs. But to try to make a few of these a little more general, how would you you know, what would be your recommendation and maybe even if if Cody wants to chime in on this one of how they've handled it. But if they're if a franchise is using solutions where they can use remote access or they're doing things that are kind of outside of the franchise's control, the franchise headquarter, and they're doing things on their own or implementing different solutions, You know, what would you recommend as far as standardizing or, you know, monitoring these kind of solutions?
Yeah.
And that really kinda goes back to your plan. And not everyone's going to be cookie cutter, but having someone that can help them with because as basic as a a network segmentation check so that if your franchisee does have a range of IPs to segment anything related to payments away from guest Wi Fi, away from security cameras, in a way from if remote if someone can remote access into the business, they're not getting into the network that can, handle cardholder data.
And that can potentially be a little bit more difficult if they only have one IP for their entire business.
But having someone that can explain the risk to them of the way that they're doing things from a educational standpoint, not just trying to sell them an additional product by saying, hey. You need to get this because of this. But really kind of, like I said before, is kinda guiding them to want to do that.
But, yeah, tools like vulnerability assessment scanning to define and find any sort of, open ports, the managed firewall that would be monitored, and weak card discovery software if they were to be breached to actually, find and remove any unencrypted pans that might be on that system. But I would say probably the best thing to do would be to to utilize something that can segment the network away. So if someone does remote access in, they're not accessing any, PANS.
Awesome. And and I'll just add because we've had so many good questions come in that are specific to your needs, that whether you use security metrics as a vendor, whether you implement a program on your own, or whether you find another third party that you feel fits your culture and environment, The beauty of it is if you find the right partner, you can customize things to what you're looking for. So kind of what Robbie was saying there, if your franchise is set up in a very standardized way, then maybe you wanna implement it differently or maybe you're gonna let each franchise kind of do their own thing, whatever fits their needs best. So I would just say because of so many of the questions kind of leading to this that if you put together a solid plan, then you can really tailor it to your franchise's needs and your franchisee's needs, which will make it that much more successful and get them more on board with the program.
So it looks like that's that's all the questions we have that we will address here on the webinar. Like I said, we'll reach out to others on an individual basis and and see if we can help further.
We appreciate everyone's participation. Thanks again to Robbie and Cody for it for the webinar.
Just a reminder, we will send out a recording and the slide deck in the next few days. So just watch your inbox for that, and feel free to reply with any questions you might have.
