Skip to content
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
Book a demo
Contact Us
Book a DemoContact Us
  1. Resources
  2. Blogs

Simplifying Contact Center Payment Security

Jun 30, 2022
  • Copied!

PCI DSS v4.0 Implications on Payment Security Protocols in Contact Centers

Simplifying contact center payment security can help organizations achieve PCI compliance and improve both customer and agent experience in the era of PCI DSS v4.0. Released earlier this year, PCI DSS 4.0 significantly raises the bar for all organizations accepting credit card payments. The new revision continues with the six goals and 12 requirements related to payment card data protection. The result is a greater level of detail for each security control within the Standard. Contact centers will need to revise their compliance program to adapt to the new clarifications introduced in PCI DSS version 4.0.

Ten new controls directly related to all contact centers include:

  1. Prevent copy and relocation of Payment Account Numbers (PAN) when using remote access technologies
  2. Certificates used to safeguard PAN during transmission over open, public networks
  3. Mechanisms are in place to detect and protect personnel against phishing attacks
  4. Review all user accounts and related access privileges appropriately
  5. Maintain the new minimum level of complexity for passwords when used as an authentication factor
  6. Use multifactor authentication for all access to the CDE (Card Data Environment)
  7. Determine the frequency of periodic Point of Interaction (POI) device inspections
  8. Review and update the security awareness program at least once every 12 months
  9. Include awareness of threats in training that could impact the security of the CDE
  10. Include security awareness training to provide an understanding of the acceptable use of end user technologies

Simplifying PCI Compliance

Companies need a simplified approach to address so many challenges. The solution needs to expand with the business. It must also prevent data compromise and fraud, improve the CX and CSR/Agent experience, address the cyber and business risks, and consistently be compliant with the DSS.

How do organizations achieve PCI DSS compliance, prepare for growth, reduce risk, and improve the customer and agent experience with one tool?

Benefits of Simplifying PCI Compliance

When it comes to the payment process, there is a simple answer to this question – simplify PCI compliance by reducing the scope of PCI DSS. From a business standpoint, simpler processes allow contact center employees to provide consistent service to customers. Other benefits of reducing PCI DSS scope include:

  • Cost Savings – Descoping increases payment success and reduces average handling time (AHT)
  • Improved Security – Since descoping prevents sensitive data from ever entering your contact center, cybercriminals have nothing to steal.
  • Improved Agent Experience – With descoping, there’s no need for clean room environments or pause and resume solutions. Plus, the resulting simplified payment process means customer interactions are smoother and faster.
  • Improved Customer Experience – A descoped solution can also provide customers single agent resolution, in turn improving metrics such as AHT time and NPS (net promoter score)
  • Omnichannel Payments – Customers can pay on the channel they choose in the way they wish to seamlessly, providing a truly omnichannel experience.

The 3 Key Elements to Simplifying Contact center payment security

Reducing PCI DSS scope is one of the best ways to lighten the workload associated with the planning, design, implementation, operation, maintenance, evaluation, and improvement of PCI DSS compliance. It drastically reduces the risk of payment card data compromise and significantly reduces the cost of compliance assessment and reporting. This strategy consists of three key elements to simplifying compliance and addressing growing cybersecurity threats.

Stop Storing Credit Card Data

Avoid receiving and storing Primary Account Numbers (PANs) and other sensitive payment data with automated solutions. By removing sensitive payment card information, the CSR/agent can focus on the customer and eliminate the risk of mishandled payments and fraud. This approach supports work in the contact center, small hubs, and work-from-home arrangements. Ideally, the customer will make payments during the conversation with the CSR. It’s simple and effective and improves the experience for everyone.

Segment Your Work

All the systems and applications within a contact center are in-scope of  PCI DSS when processing credit and debit card payments. Limit the systems and environments within the scope by separating network environments that store, process or transmit payment card data from those that don’t. When contact center agents do not have access to CHD (cardholder data), the employees are not in scope for PCI DSS 4.0 requirements.

Outsource aspects of card processing and security

Outsourcing can remove some of the burdens of PCI DSS compliance from your organization and free up resources. Contact centers, log monitoring, access control management, and e-commerce systems are everyday environments that can be outsourced and descoped. Organizations that implement segmentation or outsource the storing, processing and transmitting of CHD (cardholder data) can reduce the size of the CDE (cardholder data environment). Reducing the size of the CDE reduces risk to the organization and the level of effort to maintain PCI DSS compliance.

Learn how PCI Pal’s cloud-based PCI compliance solutions can help your organization simplify contact center payment security today or view the full white paper here.

Book a demo

 

 

Like what you see? Share with a friend.

  • Copied!
Tags: Omnichannel Remote Working PCI DSS Contact Center Compliance

Lastest News, Blogs, Events and More

  • Security in the Contact Center: A Comparative Study of Consumers and Contact Center Professionals
    Collateral

    Security in the Contact Center: A Comparative Study of Consumers and Contact Center Professionals

    Learn More
  • PCI DSS Compliance Checklist
    Blogs

    PCI DSS Compliance Checklist

    Learn More
  • Cybernews Payments Interview with PCI Pal’s CISO
    News

    Cybernews Payments Interview with PCI Pal’s CISO

    Learn More
  • Keep Calm and Simplify
    Podcasts

    Keep Calm and Simplify

    Learn More

Discover the Power of PCI Pal. Trust When It Matters Most.

Book a Demo
  • X
  • LinkedIn
  • YouTube

Products

  • Platform
  • Key to Pay
  • Click to Pay
  • Speak to Pay
  • Customer Authentication
  • Fraud Management
  • Services and Support

Outcomes

  • Financial Services
  • Retail
  • Government
  • Utilities
  • Healthcare
  • Travel & Leisure
  • BPO / Outsourced
  • Logistics & Shipping
  • Not For Profit

Partner Ecosystem

  • Partner Directory
  • Partner Hub

Resources

  • Blogs
  • Collateral
  • Events
  • Media Library
  • News
  • Success Stories
  • PCI Pal Glossary

Company

  • About Us
  • Careers
  • Investors
  • Trust Center

© 2026. PCI Pal. All rights reserved. Company Registration Number: 3869545

  • Cookie Policy
  • Privacy Policy
  • Terms of Use
  • Modern Slavery Act
  • Carbon Reduction Plan
  • Recruitment Data Protection Notice