First Data Fiserv Logo

.


Customer: First Data, now Fiserv

Region: Worldwide

Challenge: PCI P2PE Validation

Solution: First Data TransArmor P2PE Solution

fiserv.com

“The quality of Sysnet’s work, and the professionalism displayed by their team was truly impressive. If Sysnet is capable of handling complex technology integrations with a company like ours, and accomplish our goals in record time, I am sure they could deliver similar success to others. We’re incredibly impressed with the work to date so have already selected Sysnet for multiple future projects.


Marco Mabante, Director, Global Merchant Solutions at Fiserv.

Taking the heavy lifting out of compliance.

Fiserv, Inc. aspires to move money and information in a way that moves the world. As a global leader in payments and financial technology, the company helps clients achieve best-in-class results through a commitment to innovation and excellence in areas including account processing and digital banking solutions; card issuer processing and network services; payments; e-commerce; merchant acquiring and processing; and the Clover® cloud-based point-of-sale solution.

Through a transformational acquisition of First Data, which closed on July 29, 2019, Fiserv acquired a global leader in commerce-enabling technology, serving approximately six million business locations and in more than 100 countries around the world. An industry leader in secure merchant technology, First Data’s goal was always to deliver solutions that ease the burden of compliance for its customers – and did so by engineering features like Point-to-Point Encryption (P2PE) and other solutions that reduce the scope of Payment Application Data Security Standard (PA-DSS) for integrators. Alongside this, they aimed to deliver the evidence that a merchant requires for its Qualified Security Assessor and auditor status.

This is why First Data, now Fiserv, built TransArmor P2PE, a new Payment Card Industry (PCI) P2PE solution that would make the company the first processor to offer enterprise clients a single, multi-layered solution with both point-to-point and end-to-end encryption. With TransArmor P2PE, clients were delivered a P2PE solution that did not require a gateway and also made it simple for integrators to leverage legacy certifications and integrations.

Partnering with global leaders in compliance.

Sysnet is a global cyber security company, providing assessment and consulting services across more than 60 countries. Sysnet has built a reputation for helping clients achieve compliance in a cost-effective manner, adopting a uniquely pragmatic and business focused approach. Information security services offered by Sysnet, include PCI DSS, P2PE, PSD2, PA DSS, GDPR, ISO27001 and many other internationally defined standards. The company proudly boasts a wide client base that includes global commercial organizations, acquirers, ISOs, international banks and payment service providers.

Sysnet undertook TransArmor’s P2PE validation process with a collaborative approach, building a strong partnership with First Data, now Fiserv, to understand the requirements of the project and set out a delivery timeline that met the project goals. It was a consultative process, with Sysnet offering constructive guidance throughout the process rather than simply playing the role of the final auditor.

As a result, the complimentary partnership can provide integrators, and ultimately their customers, the assurance that all systems and processes meet the highest standards of data protection for payment processing ecosystems. Comprehensive validation of cryptographic framework and processes was undertaken, in addition to validation and testing of all cryptographic devices and supporting infrastructure. This ensures that customers benefit from an industry leading offering that allows customers to benefit from enhanced security posture and an overall reduction in ongoing compliance costs.

The team at First Data, now Fiserv played a major part in the success of the validation engagement. While, Sysnet’s highly skilled and experienced Cyber Risk Specialists were able, embedded and available throughout the process.

Achieving compliance at lightning speeds.

Working with Sysnet helped First Data, now Fiserv, submit paperwork to PCI in near record time. The process started from scratch on April 2018 and submission of P-AOV to PCI began in November 2018. The first listing on the PCI SSC website occurred in January, 2019, with a successful P2PE decryption environment component listing shortly after in May 2019. Two more full solution listings followed shortly afterwards. The speed with which this project was initiated and delivered was of enormous benefit to clients, as a swifter time to market allows First Data, now Fiserv to actively offer listed solutions to its customer base and allow their compliance journey to be significantly impacted and costs reduced.

Marco Mabante, Director, Global Merchant Solutions at Fiserv, said:

The quality of Sysnet’s work, and the professionalism displayed by their team was truly impressive. If Sysnet is capable of handling complex technology integrations with a company like ours, and accomplish our goals in record time, I am sure they could deliver similar success to others. We’re incredibly impressed with the work to date so have already selected Sysnet for multiple future projects.”

About Sysnet Cyber Risk.

Sysnet is a global cyber security company, currently providing assessment and consulting services across more than 60 countries. Established in 1989, we have built a reputation for helping clients achieve compliance in a cost effective manner, adopting a uniquely pragmatic and business focused approach.

Sysnet offers a range of information security services including PCI DSS, PSD2, GDPR, ISO27002, HIPAA, Sarbanes Oxley, POPIA, FedRAMP, SWIFT and other internationally defined standards. Proudly boasting a wide client base that includes global commercial organisations, acquirers, ISOs, international banks and payment service providers, Sysnet is Headquartered in Dublin, Ireland.

Connect with Sysnet on LinkedIn, follow us on Twitter. Subscribe to our Blog.

To learn more about our

Audit & Assessment Services

REQUEST A CALLBACK