Перейти к содержимому

Where Does Cardholder Data Actually Hide? Lessons From the Front Line of PCI Scoping

GuardWare

0:00 / 0:00

Where Does Cardholder Data Actually Hide? Lessons From the Front Line of PCI Scoping

9 просмотров · 7 дней назад
GuardWare
4 подписчика
9 просмотров · 7 дней назад
Every note of physical cash gets counted, locked, reconciled and audited, yet cardholder data, which is really just another way to access that same money, ends up scattered across emails, archives, spreadsheets, file shares and forgotten workstations. In this webinar, GuardWare CEO and cofounder Rizwan Mahmood sits down with Kashif Hassan, Director of Cyber Security and IT at Risk Associates, one of the leading PCI QSA firms across South Asia and the Middle East, to unpack why manual, sample based PCI scoping keeps missing cardholder data hiding in plain sight, and what to do about it. Kashif shares real war stories from the field, including a card holder data export buried in a routine marketing campaign, a mystery laptop quietly collecting card data every evening for months, and a single reporting server that pulled an entire bank into PCI scope. Rizwan then runs a live demonstration of GuardWare DISCOVER PCI, showing how automated, agentless scanning finds cardholder data across SharePoint, email and endpoints (including inside scanned images) and streamlines remediation. The conversation also covers what PCI DSS 4.0.1's new requirement 12.5.2 means for scoping evidence, what happens when a Payment Forensic Investigator gets involved after a breach, and how QSAs are approaching AI generated audit evidence. Chapters: 0:00 Welcome and housekeeping 0:49 Rizwan opens: where does cardholder data actually hide 3:22 Kashif introduces Risk Associates 8:06 What is PCI scoping, really 9:11 What scoping actually involves in practice 10:43 The unstructured data problem 16:15 Marketing team data dumps with card numbers 17:46 What happens when you fail to find it all 22:17 QSA liability and validating the scope 22:45 War story: the isolated computer with daily email attachments 27:13 Poll: live demo transition 28:12 About GuardWare 30:18 Live demonstration of GuardWare DISCOVER PCI 38:50 Why Risk Associates selected GuardWare 43:11 PCI DSS 4.0: requirement 12.5.2 and what changed 45:20 Poll: how confident are you in your scoping 47:52 What happens when a Payment Forensic Investigator gets involved 49:49 Poll results: 60% not confident in their scoping 50:29 Q&A: is GuardWare PROTECT quantum resistant 51:12 Q&A: can AI generated logs be accepted as audit evidence 54:09 War story: the reporting server that put an entire bank in scope 54:40 Free DISCOVER PCI assessment offer 56:48 Closing remarks Learn more about GuardWare: www.guardware.com.au #PCIDSS #DataSecurity #GuardWare #CyberSecurity #PCIScoping #DataDiscovery