Fidelity and Sterling banks are the only two money deposit banks in the country that have completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 3.1, the latest security measure aimed at waging off hackers from their system, Nigeria CommunicationsWeek can report.
First Bank, Standard Chartered and Wema bank are at various stages in the completion of the certification for the framework for ensuring that critical information assets are protected from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.
The major global payment brands require that every entity including financial institutions as well as merchants and service providers stores, processes, or transmits payment card data, in every channel including catalogue and online retailers as well as brick-and-mortar businesses -- must be in compliance with the PCI Data Security Standard.
Oluseyi Akindeinde, chief technical officer, Digital Encode, a company that assist banks and other organisations to achieve PCI DSS, said though there is no deadline by CBN to banks on this version, but it is mandatory for banks to upgrade to this version as a security measure to protect their customers against external fraud.
He added that, PCI DSS Version 3.1 is just an update to the already existing PCI DSS version 3.0.
“It was brought about by the ever evolving and changing sphere of information security. It has updated a few of the objectives and added new controls in line with the current landscape of payment systems threats and risks. There are quite a number of advantages. One now is that it makes application security testing a very key component of the overall process. Other key advantages include systems component inventory, third party and vendor relationships, advanced persistent threats and malware as well as physical access and point of sale security,” he stated.
Nodding in agreement, Ahmed Adesanya, IT Security and Connectivity consultant, said that version 3.1 compliance extends to merchants, payment application providers, communications service providers as well as cloud service providers.
He said that the new version has 12 requirements and over 200 control processes.
“Banks need to show a report of compliance, covering all the processes of security control that applied to them. If any bank doesn’t meet up with this version 3 compliance, payment card brands such as Visa and MasterCard will sanction such bank,” he noted.
He added that such sanctions include fine of $450 per card bridge recorded by the bank that did not comply to this version 3.
He pointed out that the tedious process of compliance to PCI DSS has led to some banks to outsource some of the process to cloud services providers that have met the requirement.
Concerns as Banks March Slowly to PCIDSS Version 3.1 Certification

Fidelity and Sterling banks are the only two money deposit banks in the country that have completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 3.1, the…
Comms Week
Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

NAICOM Dismisses Allegations of $100Bn Fraud in Recapitalisation Exercise

Yellow Card Financial Gets SEC’s ARIP Recognition

NPF-NCCC @ CIBN Conference, Urges Banks to Set up eFraud Response Teams

Dangote Refinery IPO Opens Banks, Fintechs, Apps for Share Purchase

CBN Warns Banks, Says A Bank’s Cyber Weakness Could Trigger System-Wide Crisis



