Recently I was talking the manager of the company that cleans our office building about facility security to insure that they were following all appropriate security procedures in our space. During that discussion, he told me a story about one of their employees that had a very bad day. The cleaning company has a company-wide policy against propping open doors (even for just a minute). This policy exists to protect their clients as well as their employees. One of their employees didn't follow that policy one night. He had a bunch of boxes to carry out to the dumpster and wanted to do it as quickly as possible. With all of the best intentions, he propped open the door figuring that it would only be for a few minutes. Unfortunately for him, some "bad guys" saw him do that. While he was inside getting a load of boxes, they came in, beat him badly enough to subdue him, and then stole a bunch of computers from the office he was cleaning. Fortunately he fully recovered physically. Unfortunately, his company had to fire him that same day for violating security policies and causing the cleaning company’s client to be victimized because of that violation. Double ouch.
So what does that have to do with Parking, Parking System Software, and Parking Access and Revenue Control? It is all about balancing security with convenience and expediency. Lots of parking facilities accept credit cards. If you take credit cards, you’re subject to PCI compliance rules. Much like the unfortunate employee in the cleaning crew, if you take shortcuts that compromise security, your parking facility could face some rather severe consequences. A parking lot can't be beat up or fired, but your bank could take away your ability to accept credit cards, you could be subject to fines and even huge civil penalties resulting from a credit-card related security breach. When an important or valued customer asks you to "just keep their credit card on file" or emails you their credit card information, it is tempting (and often good customer service) to just do what they ask. Unfortunately, like our ill-fated cleaner, doing that can get you in a lot of trouble.
The key is finding a way to balance good service and following good security practices. Unfortunately, security and convenience are inversely related. It is a heck of a lot more convenient to leave your home unlocked rather than fumble with keys when you come home in the dark with your arms full of groceries, kids, or both, but most of us don’t do that. We lock our homes (and often arm alarm systems) because we want and need to take reasonable precautions to keep our homes safe.
T2 Systems has recently completed our PCI-DSS Assessment to become a Service Provider. As a result of that project, we have been listed on the Visa Global List of PCI DSS Validated Service Providers (
http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf). This is a long, complicated, expensive process, but it was well worth it for us and for our customers. By T2 being a PCI-DSS Service Provider, our Advanced Parking Solutions customers have a lot less PCI-related work ahead of them by using the integrated Parking Payment Systems within our products. Our customers still can’t keep credit card numbers on post-it notes, but they have a whole lot less computer system work to do. Regardless of whether or not you are a T2 Systems customer, diligence with credit cards is critical. Credit card breaches typically don’t result in physical beatings, but if you have to deal with a breach, you may almost envy the guy that was
only beat up and fired.