SlideShare ist ein Scribd-Unternehmen logo
1 von 10
Online payments
June 2013
Alternative Models
Requires Online Merchant
Account
 Merchant gateway account
connected to bank online
merchant account
 Settlement typically 24 hours
 Examples:
 eWAY
 SecurePay
 TNSI (was Dialect)
 PayPal Pro
 Payment Express
 Various bank gateways
No Online Merchant Account
 Transactions settled to any
bank account
 Settlement period typically 2
days +
 Examples:
 PayPal (Standard & Express)
 Paymate
 POLi (Can be same day – but
generally 24 hours)
 Skrill (was Moneybookers)
 Google Checkout (USA)
 Braintree
Hosted vs Integrated
Hosted Payment Page
 PayPal style model
 Customer leaves the website
to pay
 Payment page hosted on
providers’ servers
 Payment page branding
 PCI Compliance
 Return to website for
confirmation of order
Integrated Payment Page
 eWAY style model (support
both)
 Payment page exists inside
merchants’ website
 Information not kept on
website
 Information transferred using
encrypted (HTTPS) URL, XML
or similar
 SSL encryption essential
 Stay on the website
Payment Gateway Flow
Website
Checkout
Transaction
sent to gateway
Credit Card
entered in
hosted page
Gateway
checks with
merchant
bank
Merchant bank
corresponds with
issuer bank
3D Secure
direct to
issuer bank
Some Payment Providers
Note: Not a complete list
Pro
Wallets Gateways Bank
Cross Section – Supported
Banks
Others
        
       
     

 
     
    
       
    
      
Sample Costs
Provider Setup
Fees
Annual
Fees
Volum
e
Rate
Trans
%
Fees Note
No Yes Yes No 0.15c – 0.50c / trans Merchant account fees
No No Yes Yes 2.4% - 1.1% + 30c / trans No bank fees
No Yes Yes No 0.22c – 0.45c / trans Merchant account fees
Yes No N/A No $55 / month Merchant account fees
Yes Yes Yes No 0.16c – 0.24c / trans paid annually
in advance based on package
Merchant account fees
Yes Yes Yes No 0.10c – 0.50c / trans based on
volume package paid monthly
Merchant account fees
Note: Publicly available information taken from vendors’ websites
 Install and maintain a firewall
 Do not use vendor-supplied defaults
 Protect stored cardholder data
 Encrypt transmission of cardholder data over open
networks
 Use and regularly update anti-virus software
 Develop and maintain secure systems &
applications
 Restrict access to cardholder data by business
need-to-know
 Assign a unique ID to each person with computer
access
 Restrict physical access to cardholder data
 Track and monitor all access to network resources
and cardholder data
 Regularly test security systems and processes
 Maintain a policy that addresses information
security
Build and Maintain a Secure Network
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
PCI DSS Principles and Requirements
Website Security and Trust
 Hackers: exist and difficult to stop
 Increase in available hacker scanning and protection
systems
 PCI certified scanners listed –
www.pcisecuritystandards.org
 SSL Certificates: essential for an online
store that accepts personal details or
payments
 Many suppliers – 128/256 bit encryption
 Make shopping both safer and more trusted
 Additional supplier Anti-fraud options
 eWAY – Beagle Alerts Anti-fraud integrated
 Retail Decisions (ReD)Technologies
Improving user experience
Your payment methods can be a marketing tool
 PayPal Express Checkout
 Customer and Shipping data provided by
PayPal
 Less information input by buyer online
 Offer multiple payment methods
 Consumer choice
 People without credit cards
 Integrated Anti-fraud detection
 Geographic, blacklists, IP checks, matching
etc
 Example – eWAY Beagle and Beagle Alerts
 PayPal – built-in anti-fraud

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (12)

Chameleon PCI Presentation
Chameleon PCI PresentationChameleon PCI Presentation
Chameleon PCI Presentation
 
CS-Cart Addon - Braintree payment gateway (Version 2.2)
CS-Cart Addon - Braintree payment gateway (Version 2.2)CS-Cart Addon - Braintree payment gateway (Version 2.2)
CS-Cart Addon - Braintree payment gateway (Version 2.2)
 
E commerce payment systems
E commerce payment systems E commerce payment systems
E commerce payment systems
 
Secure electronic transaction ppt
Secure electronic transaction pptSecure electronic transaction ppt
Secure electronic transaction ppt
 
Secure electronic transaction
Secure electronic transactionSecure electronic transaction
Secure electronic transaction
 
Loanet_AccountingSettlement
Loanet_AccountingSettlementLoanet_AccountingSettlement
Loanet_AccountingSettlement
 
CREDIT CARD FRAUD DETECTION
CREDIT CARD FRAUD DETECTION CREDIT CARD FRAUD DETECTION
CREDIT CARD FRAUD DETECTION
 
Dwi Ebanking
Dwi EbankingDwi Ebanking
Dwi Ebanking
 
incuto Vision2020 launch event
incuto Vision2020 launch eventincuto Vision2020 launch event
incuto Vision2020 launch event
 
Secure Electronic Transaction
Secure Electronic TransactionSecure Electronic Transaction
Secure Electronic Transaction
 
Maria sparagis
Maria sparagisMaria sparagis
Maria sparagis
 
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliancee-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
e-Know Your Transaction (e-KYT) Solution for Financial Crime Compliance
 

Ähnlich wie Accepting Online Credit Card Payments Review

Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
gealehegn
 
opening keynote on the state of eCommerce
opening keynote on the state of eCommerceopening keynote on the state of eCommerce
opening keynote on the state of eCommerce
webhostingguy
 
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
Miminten
 
Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...
Danail Yotov
 

Ähnlich wie Accepting Online Credit Card Payments Review (20)

Payment Gateway
Payment GatewayPayment Gateway
Payment Gateway
 
E commerce overview
E commerce overviewE commerce overview
E commerce overview
 
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
 
Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
 
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce MerchantECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
 
eCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain MediaeCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain Media
 
Payment Gateway
Payment GatewayPayment Gateway
Payment Gateway
 
How can E-commerce businesses leverage payment gateway.pdf
How can E-commerce businesses leverage payment gateway.pdfHow can E-commerce businesses leverage payment gateway.pdf
How can E-commerce businesses leverage payment gateway.pdf
 
Payment processing
Payment processingPayment processing
Payment processing
 
opening keynote on the state of eCommerce
opening keynote on the state of eCommerceopening keynote on the state of eCommerce
opening keynote on the state of eCommerce
 
Understanding Credit Card Processing.pptx
Understanding Credit Card Processing.pptxUnderstanding Credit Card Processing.pptx
Understanding Credit Card Processing.pptx
 
PCI Compliance - Delving Deeper In The Standard
PCI Compliance -  Delving Deeper In The StandardPCI Compliance -  Delving Deeper In The Standard
PCI Compliance - Delving Deeper In The Standard
 
PCI Compliance for Community Colleges @One CISOA 2011
PCI Compliance for Community Colleges @One CISOA 2011PCI Compliance for Community Colleges @One CISOA 2011
PCI Compliance for Community Colleges @One CISOA 2011
 
Safex pay wl-pg-presentation
Safex pay wl-pg-presentationSafex pay wl-pg-presentation
Safex pay wl-pg-presentation
 
E Payment
E PaymentE Payment
E Payment
 
home.ubalt.edu
home.ubalt.eduhome.ubalt.edu
home.ubalt.edu
 
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
 
Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...
 
Maze & Associates PCI Compliance Tracker for Local Governments
Maze & Associates PCI Compliance Tracker for Local GovernmentsMaze & Associates PCI Compliance Tracker for Local Governments
Maze & Associates PCI Compliance Tracker for Local Governments
 
Online Payment Solutions UK
Online Payment Solutions UKOnline Payment Solutions UK
Online Payment Solutions UK
 

Kürzlich hochgeladen

Kürzlich hochgeladen (20)

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

Accepting Online Credit Card Payments Review

  • 2. Alternative Models Requires Online Merchant Account  Merchant gateway account connected to bank online merchant account  Settlement typically 24 hours  Examples:  eWAY  SecurePay  TNSI (was Dialect)  PayPal Pro  Payment Express  Various bank gateways No Online Merchant Account  Transactions settled to any bank account  Settlement period typically 2 days +  Examples:  PayPal (Standard & Express)  Paymate  POLi (Can be same day – but generally 24 hours)  Skrill (was Moneybookers)  Google Checkout (USA)  Braintree
  • 3. Hosted vs Integrated Hosted Payment Page  PayPal style model  Customer leaves the website to pay  Payment page hosted on providers’ servers  Payment page branding  PCI Compliance  Return to website for confirmation of order Integrated Payment Page  eWAY style model (support both)  Payment page exists inside merchants’ website  Information not kept on website  Information transferred using encrypted (HTTPS) URL, XML or similar  SSL encryption essential  Stay on the website
  • 4. Payment Gateway Flow Website Checkout Transaction sent to gateway Credit Card entered in hosted page Gateway checks with merchant bank Merchant bank corresponds with issuer bank 3D Secure direct to issuer bank
  • 5. Some Payment Providers Note: Not a complete list Pro Wallets Gateways Bank
  • 6. Cross Section – Supported Banks Others                                                         
  • 7. Sample Costs Provider Setup Fees Annual Fees Volum e Rate Trans % Fees Note No Yes Yes No 0.15c – 0.50c / trans Merchant account fees No No Yes Yes 2.4% - 1.1% + 30c / trans No bank fees No Yes Yes No 0.22c – 0.45c / trans Merchant account fees Yes No N/A No $55 / month Merchant account fees Yes Yes Yes No 0.16c – 0.24c / trans paid annually in advance based on package Merchant account fees Yes Yes Yes No 0.10c – 0.50c / trans based on volume package paid monthly Merchant account fees Note: Publicly available information taken from vendors’ websites
  • 8.  Install and maintain a firewall  Do not use vendor-supplied defaults  Protect stored cardholder data  Encrypt transmission of cardholder data over open networks  Use and regularly update anti-virus software  Develop and maintain secure systems & applications  Restrict access to cardholder data by business need-to-know  Assign a unique ID to each person with computer access  Restrict physical access to cardholder data  Track and monitor all access to network resources and cardholder data  Regularly test security systems and processes  Maintain a policy that addresses information security Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy PCI DSS Principles and Requirements
  • 9. Website Security and Trust  Hackers: exist and difficult to stop  Increase in available hacker scanning and protection systems  PCI certified scanners listed – www.pcisecuritystandards.org  SSL Certificates: essential for an online store that accepts personal details or payments  Many suppliers – 128/256 bit encryption  Make shopping both safer and more trusted  Additional supplier Anti-fraud options  eWAY – Beagle Alerts Anti-fraud integrated  Retail Decisions (ReD)Technologies
  • 10. Improving user experience Your payment methods can be a marketing tool  PayPal Express Checkout  Customer and Shipping data provided by PayPal  Less information input by buyer online  Offer multiple payment methods  Consumer choice  People without credit cards  Integrated Anti-fraud detection  Geographic, blacklists, IP checks, matching etc  Example – eWAY Beagle and Beagle Alerts  PayPal – built-in anti-fraud