FrontRow

Cybersecurity

Your payment provider is secure. Is your payment page?

Presented by Integrity360

Handing card payments to Stripe or another provider cuts your PCI scope, but it doesn't protect the checkout page around it. Integrity360 and Reflectiz show how web skimming works now, and what PCI DSS v4.0.1 expects you to do about it.

About this webinar

What this webinar covers

A lot of businesses assume that once payments are hosted by a provider, card security is someone else's problem. Martin Petrov (CTO – PCI, Integrity360) and Leor Eliashiv (UK&I Country Manager, Reflectiz) explain why that isn't true. They use recent Magecart campaigns that abused trusted services like Stripe's APIs and Google Tag Manager to skim card details in the customer's browser, all without the payment provider being breached. The session walks through a checkout attack from start to finish and explains why server-side controls and traditional scanning often miss what's running in the browser.

It finishes with where responsibility sits for hosted and embedded payment forms, and what the newer PCI DSS script-integrity requirements and SAQ A guidance ask of merchants. Reflectiz sells browser-side monitoring, so expect their platform to come up.

Categorisation

Relevant roles

  • IT & Technology
  • Leadership & Management
  • Cybersecurity & Information Security
  • Risk, Compliance & Governance
  • Operations
  • Procurement & Vendor Management

Event details are provided for information purposes. Registration takes place directly with the event organiser. Something wrong with this listing?

Related webinars