Where Does Cardholder Data Actually Hide? Lessons From the Front Line of PCI Scoping
GuardWare
0:00 / 0:00
Where Does Cardholder Data Actually Hide? Lessons From the Front Line of PCI Scoping
9 просмотров · 7 дней назад
GuardWare
4 подписчика
9 просмотров · 7 дней назад
Every note of physical cash gets counted, locked, reconciled and audited, yet cardholder data, which is really just another way to access that same money, ends up scattered across emails, archives, spreadsheets, file shares and forgotten workstations. In this webinar, GuardWare CEO and cofounder Rizwan Mahmood sits down with Kashif Hassan, Director of Cyber Security and IT at Risk Associates, one of the leading PCI QSA firms across South Asia and the Middle East, to unpack why manual, sample based PCI scoping keeps missing cardholder data hiding in plain sight, and what to do about it.
Kashif shares real war stories from the field, including a card holder data export buried in a routine marketing campaign, a mystery laptop quietly collecting card data every evening for months, and a single reporting server that pulled an entire bank into PCI scope. Rizwan then runs a live demonstration of GuardWare DISCOVER PCI, showing how automated, agentless scanning finds cardholder data across SharePoint, email and endpoints (including inside scanned images) and streamlines remediation. The conversation also covers what PCI DSS 4.0.1's new requirement 12.5.2 means for scoping evidence, what happens when a Payment Forensic Investigator gets involved after a breach, and how QSAs are approaching AI generated audit evidence.
Chapters:
0:00 Welcome and housekeeping
0:49 Rizwan opens: where does cardholder data actually hide
3:22 Kashif introduces Risk Associates
8:06 What is PCI scoping, really
9:11 What scoping actually involves in practice
10:43 The unstructured data problem
16:15 Marketing team data dumps with card numbers
17:46 What happens when you fail to find it all
22:17 QSA liability and validating the scope
22:45 War story: the isolated computer with daily email attachments
27:13 Poll: live demo transition
28:12 About GuardWare
30:18 Live demonstration of GuardWare DISCOVER PCI
38:50 Why Risk Associates selected GuardWare
43:11 PCI DSS 4.0: requirement 12.5.2 and what changed
45:20 Poll: how confident are you in your scoping
47:52 What happens when a Payment Forensic Investigator gets involved
49:49 Poll results: 60% not confident in their scoping
50:29 Q&A: is GuardWare PROTECT quantum resistant
51:12 Q&A: can AI generated logs be accepted as audit evidence
54:09 War story: the reporting server that put an entire bank in scope
54:40 Free DISCOVER PCI assessment offer
56:48 Closing remarks
Learn more about GuardWare: www.guardware.com.au
#PCIDSS #DataSecurity #GuardWare #CyberSecurity #PCIScoping #DataDiscovery