paysquare presentatie - safe online shopping

10
Safe online shopping Richard van Oeffel SafeShops Café, January 26th 2017 1

Upload: safeshopsbe

Post on 13-Feb-2017

20 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: PaySquare presentatie - Safe online shopping

Safe online shopping

Richard van OeffelSafeShops Café, January 26th 2017

1

Page 2: PaySquare presentatie - Safe online shopping

• Online shopping: access, technology, payments

• Risks with online shopping: Availability, Confidentiality & Integrity

• Measures and common practices to mitigate risks

SafeShops

Agenda

2

Page 3: PaySquare presentatie - Safe online shopping

3

Bandwith at home (up to 10 Gbit)Devices (desktop, laptops, tablet and smartphones)Skills (95% shopped, 50% shopping)

Online shopping - Access

Page 4: PaySquare presentatie - Safe online shopping

4

Omni-channel retailing (when, where and how)Big Data and Personalisation (track)In-store experiences (BLE)Pop-up and street-trading (mobilePOS)Marketing technologies (NFC, QR codes, BLE, Geo-location)Mobile wallets (history, loyalty)Beyond retail (Restaurants, cafes, cinemas)Social media (facebook, twitter, youtube)

Online shopping - Technology

Page 5: PaySquare presentatie - Safe online shopping

5

Credit cardDebit cardMobile (debit/credit card)PaypalBitCoinMr. CashiDeal QROthers: direct debit (iDeal)

Online Shopping – Payment methods

Page 6: PaySquare presentatie - Safe online shopping

6

Distributed Denial of Service (DDoS)RansomwareWebsite defacingCrossite scripting

Risks – Availability & Integrity

Risks – Availability & Integrity - Mitigation

Monitoring, processes in place (understanding)Incident response planningDevelopment: OWASPSystem: SSL/TLS

Page 7: PaySquare presentatie - Safe online shopping

7

Personal Identifiable Information (PII)Payment Card Industry (PCI)

Risk – Confidentiality & payments

Page 8: PaySquare presentatie - Safe online shopping

8

Refunds -> reduce chargeback ratio3D secure -> reduce use of fraudulent transactionsSSL/TLS & profile -> loyalty and one click orderingConfirmation emails: No embedded links, no request for info

Risk – Confidentiality & payments - Mitigation

Page 9: PaySquare presentatie - Safe online shopping

9

Decent website with latest technology (desktop/laptop/tablet/mobile, personalization)Decent products and information (retour sending, refunds, reviews!)Decent development (OWASP rules)Decent hosting (PCI, ISO 27001)Testing (scanning) monitoring (what’s going on/tracking)Decent procedures and processes Decent communication to customers: Customers first!

Risk mitigation – General

Page 10: PaySquare presentatie - Safe online shopping

paysquare.eu