05.04.2016 Views

SECURITY

25IKiLB

25IKiLB

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

APRIL/MAY 2016<br />

THE<br />

<strong>SECURITY</strong><br />

ISSUE


INDEX<br />

ISSUE 90 | APRIL/MAY 2016 connect<br />

connect Executive Editor<br />

RSPA Education Manager<br />

AMurdock@GoRSPA.org<br />

RSPA 2016 SPONSORS<br />

PLATINUM LEVEL SPONSORS<br />

Our Table of Contents has been temporarily disrupted! For the Connections and Association Updates you<br />

Need, see the blue and red boxes below. Our regular TOC format returns in our next issue.<br />

When you see these icons...<br />

Conversation<br />

Starters<br />

Statistics<br />

Take special note! The Conversation Starters will help you<br />

have deeper conversations with your customers or your<br />

future partners. The Statistics can provide color to those<br />

conversations, all to help you close more deals!<br />

AMBER MURDOCK<br />

GABBY COOR<br />

connect INFO<br />

DEADLINES<br />

June/July/August - Summer edition<br />

Ads & Content: May 9<br />

PAID ADVERTISING INDEX<br />

APG (18)<br />

BlueStar (22)<br />

Business Solutions Magazine (10)<br />

Cayan (16)<br />

Datacap (32)<br />

Discover (23)<br />

EPSON (6)<br />

Harbortouch (35)<br />

Heartland (28)<br />

RSPA CONTACTS<br />

connect Layout/Production Manager<br />

RSPA Graphics Specialist<br />

GCoor@GoRSPA.org<br />

connect Staff Contributors (April/May):<br />

Kelly Funk<br />

Stephen Gift<br />

September/October<br />

RetailNOW® 2016 Recap<br />

Ads & Content: August 22<br />

MMF (12)<br />

Merchant Link (13)<br />

Moneris (9)<br />

NEC (25)<br />

Payment Logistics (27)<br />

ScanSource (20)<br />

Star Micronics (7)<br />

Synnex (30)<br />

Vantiv/Integrated Payments (15)<br />

Communications: 704.940.9729 | Publications@GoRSPA.org<br />

Education: 704.940.9729 | Education@GoRSPA.org<br />

Member Services: 704.940.9720 | Membership@GoRSPA.org<br />

connect Issue 90 April/May 2016 (USPS 70)<br />

POSTMASTER:<br />

Send address changes to RSPA:<br />

9920 Couloak Dr., Unit 120, Charlotte, NC 28216-2460<br />

Published six times a year by Retail Solutions Providers Association.<br />

P 800.782.2693 • F 704.357.3127 • E Publications@GoRSPA.org<br />

Visit www.GoRSPA.org for subscription information and/or<br />

advertising rates. Items or information you would like to see<br />

published in connect may be sent to the above email address.<br />

Materials may not be reproduced without permission.<br />

© Copyright 2016 by RSPA<br />

GOLD LEVEL SPONSORS<br />

SILVER LEVEL SPONSORS<br />

FOUNDING EDUCATION PARTNERS<br />

EDUCATION PARTNERS<br />

MEDIA PARTNERS<br />

*Premier Media Sponsor<br />

W2W COMMUNITY<br />

founding sponsor<br />

For a list of Canadian Community Sponsors, please see page 33.<br />

How do I become a sponsor? www.GoRSPA.org<br />

CONNECTIONS<br />

04<br />

President's Note<br />

05<br />

RSPA News &<br />

Education Calendar<br />

SPECIAL <strong>SECURITY</strong> SECTIONS<br />

TECHNOLOGY<br />

& KNOWLEDGE<br />

TAKEOVER<br />

SECTION 1: <strong>SECURITY</strong><br />

PREPPING FOR YOUR<br />

BUSINESS...7<br />

RSPA HELPS MEMBERS WITH <strong>SECURITY</strong> RESOURCES<br />

BY: AMBER MURDOCK...8<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST -<br />

DUSTIN NIGLIO, PAYMENT LOGISTICS:...11<br />

SECTION 2: PROTECTING<br />

THE GOODS...13<br />

DIGITAL JOURNEY LEVERAGING NEW TECHNOLOGY IN<br />

LOSS PREVENTION<br />

BY: WILLIAM M. TITUS...14<br />

TAKE IT TO THE BANK<br />

BY: ANNE GRAY...18<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST -<br />

DAVID GUDJONSSON, HANDPOINT...21<br />

SECTION 3: SECURING<br />

THE PAYMENT...23<br />

PCI CHANGES DATE FOR MIGRATING FROM SSL AND<br />

EARLY TLS...24<br />

NEW POS <strong>SECURITY</strong> REQUIREMENTS AFFECT INDUSTRY<br />

PARTNERS<br />

BY: PAUL ST. GEORGE...26<br />

RSPA <strong>SECURITY</strong> RESOURCES/10 STEPS AFTER A DATA<br />

BREACH...29<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST - TODD<br />

BURGE, FOOD ONLINE ORDERING SYSTEMS, LLC...31<br />

ASSOCIATION<br />

32<br />

Special Contributors<br />

33<br />

Canadian Corner<br />

34<br />

In Memoriam<br />

John Lockington<br />

35<br />

Calendar of Events<br />

TABLE OF CONTENTS<br />

2 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 3


THE CONNECTIONS YOU NEED<br />

THE CONNECTIONS YOU NEED<br />

RSPA President's Note<br />

Spring is in the air—that means daffodils,<br />

warmer weather, and… security.<br />

Wait—security?<br />

Really, isn’t that a concern for all of us yearround?<br />

Yes—I would say it is, but given the<br />

higher level of interest and engagement in<br />

recent months—I’d venture to say security<br />

may be THE hottest topic in the industry this<br />

season.<br />

Recently, I spent several days at the NCC<br />

dealer meeting. PCI, EMV, and Liability were<br />

the focus of many of the conversations<br />

that took place there. In the midst of so<br />

much information (and, frankly, confusion),<br />

I was again reminded of the important role<br />

RSPA plays in helping our members. We<br />

are committed to continuing to be your goto<br />

resource. We are frequently updating<br />

our website, www.GoRSPA.org, with new<br />

content and news, as it becomes available to<br />

us. We are providing access to certifications<br />

and education to help you increase your<br />

knowledge (www.GoRSPA.org/Education).<br />

At RetailNOW®, in Dallas, July 31 - August<br />

3, we will be providing live sessions on a<br />

variety of topics, including security; oh yes,<br />

and Josh Klein, former hacker and current<br />

technologist will be our closing speaker,<br />

sharing his thoughts on concerns that are<br />

near and dear to us.<br />

Yes—security is the current hot topic, which<br />

will continue to be top of mind for most of us<br />

in the foreseeable future. Much like, I hope,<br />

RSPA is for you—there at the forefront, when<br />

it’s most important, but also a consistent<br />

partner you can count on year round.<br />

Happy Spring!<br />

Kelly T. Funk<br />

RSPA President & CEO<br />

Phone: 704.940.4274<br />

Email: KFunk@GoRSPA.org<br />

RSPA Scholarship Program—now accepting applications!<br />

deadline to apply: May 27, 2016<br />

Find out more at www.GoRSPA.org/Scholarship<br />

OUR MEMBERS HAVE<br />

NEWS TO SHARE.<br />

• iPayment, Inc. Announces<br />

Partnership with Harley Financial<br />

• Future POS Certifies to Vantiv<br />

Integrated Payments for EMV<br />

Solution<br />

• Heartland, Computop<br />

Collaborate to Offer Heartland<br />

Customers Secure International<br />

Payment Processing<br />

• Recognized Payment<br />

Integrations Expert Bill Pittman<br />

Joins Sterling Payment<br />

Technologies<br />

• Touch Dynamic Announces<br />

Arrival of New All-In-One Touch<br />

Terminal<br />

• TSYS and Handpoint to Offer<br />

Mobile EMV<br />

Find these stories and<br />

more industry news at<br />

www.GoRSPA.org or<br />

scan the QR code<br />

Want to publish news about your<br />

company? You must be an RSPA Member,<br />

and you may send your business<br />

announcements and press releases to<br />

Publications@GoRSPA.org.<br />

We want to hear from you.<br />

Email it:<br />

Publications@GoRSPA.org<br />

Tweet it:<br />

@InsideRSPA<br />

Post it on Facebook:<br />

www.facebook.com/InsideRSPA<br />

Upcoming RSPA Education<br />

Whether it’s live or online, RSPA has training options available for you and your<br />

team, and on your schedule. Check out what’s in store, so far, for 2016. The<br />

schedule is updated regularly, so please check our website: www.GoRSPA.org<br />

for the latest updates to our calendar!<br />

Wednesday, May 18th | 2PM:<br />

What's New and Upcoming in SMB Cash Management Solutions?<br />

Presented by Stephen Bergeron, APG Cash Drawer & Peter Wolf,<br />

Glory Global Solutions<br />

This webinar will showcase cash management solutions with tangible ROI<br />

and proven benefits, adding value to your customer relationships – while<br />

increasing your bottom line.<br />

Topics will include:<br />

• Increase hardware and services sales with cash management solutions,<br />

including smart cash drawers, electronic coin dispensers, cash counting<br />

solutions & cash recycling<br />

• Sell cash management solutions that protect from employee theft<br />

• Improve customer cash transaction times by 5-8 seconds<br />

• Increase cashier proficiency and reduce training time<br />

• Exponentially reduce shortages daily<br />

WEBINARS NOW ON DEMAND:<br />

⊲⊲<br />

The Nuts and Bolts of PCI QIR Certification: For RSPA Members<br />

Instructor: Ashley Naggy, RSPA’s Certification Program Leader<br />

⊲⊲<br />

The State of U.S. EMV Adoption: Perspectives from the RSPA's EMV<br />

Committee | Presented by: RSPA's EMV Committee<br />

To Access, visit www.GoRSPA.org and<br />

click on the 'Knowledge' tab.<br />

Want to subscribe to<br />

Connect magazine?<br />

Contact Publications@GoRSPA.org<br />

To take advantage<br />

of all RSPA member<br />

benefits, join!<br />

Contact Membership@GoRSPA.org or<br />

visit www.GoRSPA.org/Join<br />

4 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 5


SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

Security Prepping for<br />

Your Business<br />

Positively Outstanding Solutions<br />

Being a security subject matter expert is important<br />

for every VAR. Whether it’s physical security,<br />

network security, payment card security, or<br />

providing merchant customers with the protection<br />

they need to retain their profits, security is now<br />

a VAR’s priority. And, if it’s to provide both a safe<br />

cyber and physical environment for a merchant’s<br />

customers, who, in today’s world, will make buying<br />

choices based on how secure their data might<br />

be… retail technology professionals have the<br />

opportunity to be the solution provider that helps<br />

merchants attract and retain their customers.<br />

As a member of the RSPA, VARs have a number<br />

of resources available to help in building their<br />

security business. RSPA’s legal benefit provides<br />

members with free consultations with RSPA<br />

Attorney Robert C. Goldberg, as well as a number<br />

of form templates that will help members in all<br />

aspects of security protection, ranging from<br />

background checks to EMV liability waivers.<br />

RSPA’s Professional Development program<br />

provides exclusive member discounts to industryrecognized<br />

certification programs, significantly,<br />

the PCI Council’s Qualified Integrator and Reseller<br />

(QIR) certification.<br />

# of retail breaches<br />

in 2014<br />

Source: Verizon DBIR, 2015<br />

were POS intrusions<br />

were payment<br />

card skimmers<br />

Source: Verizon DBIR, 2015<br />

According to Verizon’s 2015 Data Breach Investigations<br />

Report (DBIR), the majority of retail breaches were<br />

caused by POS intrusions. Yes, this means that POS<br />

systems are a vulnerable point in the cybersecurity<br />

chain. And, it means that protecting the POS and<br />

reducing vulnerabilities provides a prime opportunity<br />

for RSPA VAR members to provide additional value to<br />

their merchant customers.<br />

TM-T88V<br />

TM-H6000IV<br />

TM-U220 OmniLink<br />

®<br />

i<br />

TM-m30 TM-m10<br />

Mobilink P80 Plus<br />

NEW MOBILE POS<br />

For over 30 years, Epson has been a leader in the POS industry. Our POS printers are at the heart of thriving retail<br />

and hospitality businesses around the world. With the broadest product line available, Epson has set the standard<br />

with solutions that deliver unmatched reliability, speed and fl exibility. And we’re continuing to lead the way forward<br />

with our innovative, new tablet POS solutions, all designed with one goal in mind: your success. To see our latest<br />

solutions, visit epson.com/pos<br />

EPSON is a registered trademark and EPSON Exceed Your Vision is a registered logomark of Seiko Epson Corporation.<br />

Mobilink is a trademark and OmniLink is a registered trademark of Epson America, Inc. Copyright 2015 Epson America, Inc.<br />

6 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 7


SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

RSPA Helps Members with Security Resources<br />

By: Amber Murdock<br />

RSPA works diligently to ensure members are adequately prepared for security concerns. Our website is the best<br />

source for up-to-date information on security. One particular members-only resource is the “Join” section of our<br />

website at www.GoRSPA.org/Join. According to many of our members, one of the premier benefits of membership is<br />

the legal benefit. In the Join section, you can find a path to all of the legal templates available to members. Templates<br />

include several documents you can use to bolster strategic security planning for you, and your customers.<br />

RSPA's Background Authorization Form<br />

“One of the QIR Company Administrative<br />

Requirements include logistics of doing business, like<br />

background checks. Background checks are required<br />

for QIR certified company employees.”<br />

ARE YOU U.S. EMV<br />

READY? WE ARE.<br />

Ashley Naggy, RSPA Certification Lead<br />

EMV Compliance Waiver<br />

“Waivers are not absolute protection from customer claims, but they<br />

are an excellent defense. A waiver establishes that the current<br />

industry requirements were communicated, however the customer<br />

declined the upgrade or installation. The waiver also emphasizes<br />

to the customer the importance of the requirement and prior<br />

to signing the customer may reconsider the initial decision. If a<br />

customer refuses to sign, note that on the form, sign, and date it.”<br />

Bob Goldberg, RSPA Attorney<br />

Partner with Moneris, the EMV leader<br />

U.S. EMV Developer Ready Specs for quick and easy integration<br />

A layered approach to data security including EMV,<br />

end-to-end encryption and tokenization<br />

More experience in EMV implementation than any<br />

other payment processor in North America<br />

RSPA's Data Breach Action Plan<br />

“The need for a data breach action plan for RSPA members grew<br />

out of necessity. We knew of resellers trying to help a breached<br />

merchant once the breach had already occurred. A plan helps<br />

the reseller be prepared, plus, it provides an additional talking<br />

point in a sales or service conversation.”<br />

Kelly Funk, RSPA President & CEO<br />

number of security breaches that occurred in American<br />

Restaurants, hotels, grocery, stores, gas stations, and other<br />

brick-and-mortar outlets<br />

Source: Verizon DBIR, 2015<br />

Let us help you become EMV ready today!<br />

Contact our strategic partner team at<br />

866-423-8475 or partnerships@moneris.com<br />

Visit monerisusa.com/EMV for details on EMV<br />

8 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 9


SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

SECTION 1: <strong>SECURITY</strong> PREPPING FOR YOUR BUSINESS<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST<br />

Business Solutions Magazine<br />

was humbled to win the Gold<br />

Award for Reseller Support<br />

Services for the sixth year in<br />

a row at RetailNOW.<br />

We’ve worked hard for the<br />

past 29 years to educate and<br />

support the retail IT channel,<br />

and it’s an honor for you to<br />

consider us a valued resource.<br />

Rest assured we’ll work even<br />

harder in the coming year to<br />

prove that we deserved the<br />

accolade you placed upon us.<br />

You are what makes the<br />

industry great. Together, we’ll<br />

make it even greater.<br />

Editor’s Note: As the POS industry continues to morph and the way<br />

services are delivered continue to evolve, we here at RSPA realize<br />

how crucial the VAR-ISV relationship has become in creating a<br />

thriving industry. In the spirit of the Security Issue, we wanted to<br />

provide RSPA members with some security talking points as they<br />

are entering into partnerships with developers. As data/payment<br />

card security looms as the industry’s biggest security issue of<br />

the past few years, we asked several RSPA members to provide<br />

VARs with insight on how to have constructive and informative<br />

conversations with their future developer partners.<br />

What are 3 questions you suggest that<br />

VARs ask a developer partner about<br />

data security/cyber security before they<br />

decide to partner with them?<br />

☐☐<br />

Is DSS?<br />

your POS application in-scope of PA-<br />

If the POS application is in-scope<br />

DN<br />

of PA-DSS, then the VAR must<br />

become QIR certified pursuant to the new<br />

rules being put in place by Visa. Being<br />

QIR certified is much more involved than<br />

simply passing a test. On the other hand,<br />

there are certain semi-integration payment<br />

technologies in the market today which<br />

utilize a payment terminal to process the<br />

transaction and completely remove the<br />

POS application from the scope of PA-DSS<br />

and PCI-DSS compliance. Implementing<br />

a semi-integrated payment terminal is<br />

very similar to implementing a standalone<br />

payment terminal and does not necessarily<br />

require the VAR to be QIR certified.<br />

☐☐Which SAQ (A, A-EP, B, B-IP, C, C-VT,<br />

P2PE-HW, D) will merchants utilizing your<br />

system be subject to if your system is the<br />

only one they utilize to process credit and<br />

debit card payments?<br />

Acquirers require merchants in their<br />

DN<br />

portfolio to validate compliance<br />

with the PCI DSS. As part of validating<br />

compliance, most small and medium<br />

sized merchants must complete a Self<br />

Assessment Questionnaire (SAQ) that was<br />

developed by the Payment Card Industry<br />

Security Standards Council. SAQ C and D<br />

are the most common SAQs for merchants<br />

using POS systems with integrated<br />

payments. These SAQs are also the most<br />

challenging and because of this, merchants<br />

often times end up misrepresenting the<br />

truth on the questionnaire in order to<br />

get a passing grade. On the other hand,<br />

merchants that are subject to SAQ B-IP or<br />

SAQ P2PE-HW have a much easier time<br />

completing the questionnaire in a forthright<br />

manner and receiving a passing grade.<br />

Selling a system that subjects the merchant<br />

to SAQ B-IP or P2PE-HW gives the VAR a<br />

competitive advantage in the marketplace.<br />

☐☐Are you EMV live today?<br />

DN<br />

insight provided by<br />

Dustin Niglio, CEO,<br />

Payment Logistics<br />

Many POS systems are “EMV Ready”<br />

but not yet live with EMV. Being EMV<br />

ready generally means the POS system has<br />

performed an integration with a solution<br />

which includes EMVCo certified level 1 and<br />

2 kernels, but has not obtained an end to<br />

end EMV certification with the card brands<br />

(often referred to as level 3 certification).<br />

On the other hand, systems that are live<br />

with EMV are actively able to support EMV<br />

transactions in a production environment.<br />

Deploying systems that are not yet EMV live<br />

can be problematic for the VAR and the end<br />

user since the end user has a higher chance<br />

of suffering EMV related chargebacks, is a<br />

greater target for data security thieves, and<br />

the VAR will have more work to do in the<br />

future to eventually convert the system from<br />

EMV ready to live.<br />

Payment Logistics is a<br />

PCI DSS level 1 validated<br />

merchant acquirer and<br />

payment integration<br />

solution provider.<br />

10 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 11


Enclose • Protect • Secure<br />

SECTION 2: PROTECTING THE GOODS<br />

PayVue Illuminated Cash Drawer<br />

Innovative Design for Cash Handling in<br />

Low-Light Environments<br />

“PayVue has made it easier to<br />

monitor cash operations. My staff<br />

likes it because it helps them see what<br />

they are taking in and giving back.<br />

This has resulted in fewer shortages,<br />

and ultimately higher profit. It’s good<br />

for us all.”<br />

Ken Hoffman, Owner, Howard Street Inn<br />

Protecting the Goods<br />

SECTION 2: PROTECTING THE GOODS<br />

Physical Security is an element of the POS structure that has been<br />

embedded from the very beginning. The invention of the cash<br />

register was predicated upon the fact that storekeepers needed<br />

a way to protect their profits from being pilfered. Back then,<br />

storekeepers were attempting to protect their sales earnings from<br />

employees. Now, even though more than 34% of the $44B in retail<br />

theft in 2014 was due to employee theft (2015 NRF Retail Study),<br />

there are so many other “trackable” factors that contribute to profit<br />

loss, including shoplifting (37% of profit loss in 2014), vendor fraud<br />

(6.8% of shrinkage), administrative errors (16.5% of shrinkage), etc.<br />

All of these causes of shrinkage can be aided by an informed and<br />

trusted advisor, like an RSPA VAR. In this section, we’ll hear about<br />

the strategic journey of a major retailer, and, in an effort to hearken<br />

back to the old days of the first cash registers, learn how to help<br />

merchants get more of their earnings into their bank accounts.<br />

Merchant Link<br />

Payment Gateway<br />

Hosted, Processor-Neutral<br />

Gateway<br />

TransactionVault®<br />

Tokenization<br />

TransactionShield®<br />

Point-to-Point Encryption<br />

TransactionLink<br />

EMV Solution<br />

E-commerce Solutions<br />

Photos courtesy of Howard Street Inn, Niles, Illinois<br />

Pictured left to right: Ken Hoffman, Owner, Rebecca Ebert, Manager,<br />

Sergio Torres, Owner & POS Reseller, TEEPOS, Chicago, IL<br />

Only<br />

of Staff Responses to a loss<br />

prevention alarm is “meaningful”<br />

e.g. checking the receipt or<br />

identifying the product that<br />

triggered the alarm.<br />

Acquire Program<br />

Source: Hayes and Blackwood Study<br />

PayVue Improves:<br />

• Transaction Accuracy and Speed<br />

• Customer Service<br />

• Loss Prevention Management<br />

• Low-Light Ambiance<br />

Ideal for<br />

restaurants,<br />

bars and<br />

nightclubs<br />

Supermarkets and grocers lose<br />

the highest percentage of sales<br />

to shrink, seeing an average of<br />

3.23% evaporate, or 2.5 times<br />

more than the industry average.<br />

Source: Fortune Magazine<br />

There are many causes of shrinkage, in all verticals. For<br />

many of RSPA member customers—SMB merchants—<br />

they can ill afford the losses that shrinkage causes. If<br />

you’re not selling security options outside of the POS, in<br />

what ways can you start that overall security conversation<br />

with your customer? Should you be thinking about video<br />

surveillance options? Are there new mobile applications<br />

that allow them to monitor on-the-go?<br />

Trying to keep up in the<br />

changing world of payments<br />

can feel like another full-time<br />

job – adding new payment<br />

types, protecting cardholder<br />

data, complying with evolving<br />

PCI and security standards, all<br />

while trying to keep your costs<br />

under control. At Merchant<br />

Link, our goal is to remove the<br />

risk and hassle of payments so<br />

you can focus on your business.<br />

Contact us today to learn more<br />

866.853.3845<br />

www.merchantlink.com<br />

An ISO 9001 Certified Company<br />

www.mmfpos.com | 800.769.1954<br />

For more information visit: www.mmfpos.com,<br />

www.howardstreetinn.com and www.teepos.com<br />

www.GoRSPA.org<br />

connect 13


SECTION 2: PROTECTING THE GOODS<br />

SECTION 2: PROTECTING THE GOODS<br />

Editor’s note: We often get requests from RSPA<br />

VAR members for more insight on what drives retail<br />

technology purchasing decisions from the end user<br />

angle. The inclusion of the following article is part of<br />

our response to that request. William Titus was the<br />

longtime vice-president of loss prevention at Sears<br />

Holdings Corporation. While his company is not the<br />

size that most of our members serve, the strategy he<br />

used to apply technology in his overall loss prevention<br />

strategy is one that can be replicated with a merchant<br />

of any size. This article has been republished, with<br />

permission from LP Magazine. The original article,<br />

and other loss prevention insights (from the end<br />

user’s perspective) can be found at the LP Magazine<br />

website: www.losspreventionmedia.com<br />

Digital Journey Leveraging New<br />

Technology in Loss Prevention<br />

By: William M. Titus<br />

Imagine walking into a location for a visit. As you<br />

sip your morning coffee, you pull up the store’s<br />

current performance from your iPad or tablet PC.<br />

At a glance you have all the vital statistics and<br />

performance trending information you need.<br />

As you enter the store, the tablet’s GPS identifies<br />

your location and sends you three alerts that require<br />

your immediate attention. During your visit you identify<br />

possible signs of theft, so you pull the IP-video CCTV<br />

feeds from your tablet and review the footage.<br />

A week later you complete a follow up visit from<br />

two states away via video-chat from your tablet.<br />

Do these ideas sound like some far-fetched dream of<br />

a future loss prevention organization? They are not.<br />

This is the present at Sears Holdings.<br />

While our customers are accessing Shop Your<br />

WaySM special member offers from their mobile<br />

devices, our Sears and Kmart loss prevention teams<br />

are using similar devices to dynamically access<br />

performance rankings, theft statistics, outlier reports,<br />

and a vast array of other data, reports, and charts that<br />

visually demonstrate the risks and relative “health” of a<br />

given store location, district, or region.<br />

As our economic and technological landscapes<br />

have changed, so has the loss prevention industry.<br />

More often, loss prevention and retail in general are<br />

being challenged to do more with less. How can<br />

we drive profit while mitigating risk and improving<br />

performance? Our strategy at Sears Holdings has<br />

always been to empower our teams with technology<br />

that helps them increase efficiency and make informed<br />

decisions.<br />

Right: The external<br />

dashboard allows<br />

the user easy<br />

access to review not<br />

only external-theft<br />

performance, but it<br />

also provides quick<br />

access to narratives<br />

and exceptions. The<br />

field teams can now<br />

quickly validate case<br />

procedures and<br />

ensure each report is<br />

written correctly.<br />

Technology Is a Journey<br />

We started on what we call our “digital journey”<br />

over five years ago with a series of incremental<br />

steps aimed at leveraging the emerging technology<br />

landscape. At the time we had no idea smart devices<br />

were the end game, but we knew that to stay<br />

competitive, we needed to be prepared for the future.<br />

Every time we’ve considered implementing<br />

new technology, our first step has always been to<br />

review our current processes and ask ourselves three<br />

questions:<br />

• Can we eliminate this process or task?<br />

• Can we centralize this?<br />

• Can we automate it?<br />

We call this process “task modernization.” From our<br />

first web-based applications to our current mobile<br />

solutions, our vision has always been to leverage<br />

systemic and technological advances that deliver the<br />

highest value to the enterprise. This digital journey is<br />

not about technology for technology’s sake; it’s about<br />

giving our professionals a competitive advantage in<br />

understanding their business and making informed<br />

decisions.<br />

Investing Strategically<br />

The demands of end users have continually<br />

exceeded network infrastructures, but as quickly as<br />

network providers can meet demands, consumers and<br />

developers create new ones. This cycle of evolution<br />

continues throughout the landscape—IP phones have<br />

replaced traditional landlines, smartphones have<br />

replaced cell phones, online video has replaced video<br />

rental stores, e-books have replaced book stores, and<br />

we all know what happened to the music industry.<br />

Consumers have even connected their homes<br />

to control everything from their alarms to their<br />

thermostats via smartphone. With so much change in<br />

technology, how can the loss prevention industry keep<br />

up?<br />

Our first priority has been to invest in data.<br />

From collecting data about theft to census data to<br />

enhance environmental risk models, our ability to make<br />

actionable decisions based on business results, trends<br />

and outlier activities consistently results in the greatest<br />

payback. Similarly, we constantly challenge ourselves<br />

to better manage our data and improve the delivery<br />

method to end users. The focus is to make our teams<br />

more agile and prepared with actionable information.<br />

We’ve always believed that knowledge is power, and<br />

our technological investment decisions reflect that<br />

philosophy.<br />

We began our journey years ago by transferring our<br />

data from a myriad of spreadsheets and disparate<br />

sources to a uniform data storage platform. This paved<br />

the way for the establishment of key metrics on our<br />

business and a means for developing goals and rating<br />

mechanisms for our locations.<br />

Our latest investment in a business intelligence<br />

platform has allowed us to standardize and optimize<br />

reporting on key areas of loss prevention, such as<br />

theft, shrink, labor utilization, and investigations, as well<br />

as non-LP-related areas, such as sales, financial, and<br />

pricing.<br />

We’ve taken advantage of the explosive growth in<br />

mobile computing by equipping our field personnel<br />

with iPads, giving them access to data via a quick swipe<br />

of a finger that might have required hours to compile in<br />

the past.<br />

It Pays to<br />

Partner with Us<br />

Be Proactive<br />

Payments security is too important to be ignored. We’re here to help simplify it for you and your customers<br />

with resources, technology, and tried and true strategies for guarding against security threats. From EMV,<br />

tokenization and encryption, to PCI assistance and breach protection, Vantiv Integrated Payments has a solution<br />

for every payment security need.<br />

Security is our priority.<br />

We offer incentives for partners who practice secure behaviors, and make it affordable for merchants to<br />

implement secure technologies for their business. Together we can help merchants avoid becoming a data<br />

compromise statistic.<br />

Partner with Vantiv Integrated Payments for total peace-of-mind payments.<br />

Learn more at: info.mercurypay.com/security-pays<br />

14 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 15


SECTION 2: PROTECTING THE GOODS<br />

SECTION 2: PROTECTING THE GOODS<br />

We invested the better part of a year preparing<br />

our infrastructure for the new devices:<br />

• We updated our existing web applications to<br />

properly render on the new screens.<br />

• We built iOS applications to truly take advantage<br />

of all the capabilities of these devices, such as the<br />

accelerometer, GPS, and touch navigation.<br />

• We built mobile device management (MDM) profiles<br />

specific to our team’s needs to manage application<br />

deployment.<br />

• We invested in a team of professionals who created<br />

visually insightful charts and reports that allow<br />

field personnel to instantly view trends over time,<br />

performance to goal, and performance relative to<br />

peers.<br />

Our Journey Continues<br />

We are busy developing models to help us explain<br />

the past and predict the future. We’re able to<br />

implement those models through our business<br />

intelligence platform to create scoring algorithms,<br />

cluster algorithms, and regression-based metrics.<br />

This sets the stage for even greater peer-to-peer<br />

benchmarking, outlier analysis, and forecasting<br />

methodologies.<br />

Giving our field teams the ability to “analyze on the<br />

fly” has provided a real return on investment for our<br />

LP enterprise since deployment five months ago.<br />

Some key advantages we are realizing here at Sears<br />

Holdings include the following:<br />

• Store visits that used to take a full day are now<br />

completed in a few hours, often allowing managers<br />

to visit multiple stores in a day.<br />

• Everyone in the company has access to the<br />

same information, allowing for true transparency in<br />

reporting and alignment of goals.<br />

• Managers can consistently drive key behaviors<br />

by ensuring the most important aspects of<br />

performance, such as compliance, meeting notes,<br />

and case performance, are covered during every<br />

visit.<br />

• Access to store outliers and the ability to dive<br />

deeper into results allows our team to work almost<br />

exclusively from the iPads.<br />

• Access to our IP-video CCTV allow our teams<br />

to easily review video from their mobile devices<br />

without having to be in store.<br />

Redefining Talent<br />

To improve the science of data, we have<br />

added statisticians to our team. To enable agility and<br />

speed in our product creation, we now have dedicated<br />

developers inside our LP organization. To manage<br />

our infrastructure and integrate with IT, we have team<br />

members with backgrounds in data architecture,<br />

project management, and systems. To combat the<br />

modern day thief who wields a computer instead of<br />

a lined bag, we have an experienced online fraud<br />

team. Our investigators are skilled in SQL and other<br />

query tools.<br />

The traditional loss prevention roles within<br />

the corporation have changed. Making streamline<br />

simplified technology available to our field teams<br />

involves a complex team of players who spend their<br />

day analyzing consumer and criminal behaviors,<br />

both in-store and online. At the corporate level we’ve<br />

created new teams, such as:<br />

• LP Systems and Technology works as our liaison<br />

between LP and IT to ensure we are involved in<br />

system changes, infrastructure upgrade, and have a<br />

voice on new company initiatives, including mobile<br />

checkout, loyalty promotions, and so forth.<br />

• LP Business Intelligence works to design and<br />

develop new mobile and web applications and<br />

reports for our field and corporate users.<br />

• LP Analytics works on researching and<br />

developing new performance metrics and<br />

predictive models to gain insights from our data<br />

and performance. e-Commerce/Payment Systems<br />

teams are an integral part of investigations, scouring<br />

millions of online transactions annually.<br />

The same kinds of transformations are also true<br />

for our field teams. Traditional security roles are still<br />

vital, but we’ve also adjusted our core competencies<br />

to include a Digital Innovator section. This new section<br />

helps us identify competencies, such as forward<br />

thinking, early adopters, computer literacy, and<br />

systems knowledge.<br />

From our web applications to our mobile solutions, we<br />

have always held the belief that when the content<br />

experts—in our case, loss prevention—are responsible<br />

for application design, the end user always wins.<br />

We currently design and develop our own mobile<br />

apps, which have allowed us to reduce the time to<br />

deployment considerably. Additionally, having teams<br />

who work with loss prevention and safety data daily<br />

allows them to build up expertise and anticipate the<br />

needs of the end user.<br />

The Future<br />

What we have developed thus far should only<br />

be considered our beta version. We are continually<br />

reiterating and refining our existing dashboards and<br />

audits to be smarter. At this point we have provided<br />

our store teams with faster customized access to<br />

information.<br />

Our next challenge is to build enhanced<br />

automation, alerts, and scheduling into our various<br />

systems. Building on the concept of intelligent<br />

reporting, we will develop a calendar app to help our<br />

teams schedule the most important tasks and improve<br />

time management. We are building “smart audits” to<br />

manage which questions are asked in each store,<br />

based on each store’s specific opportunities. More<br />

importantly, we are integrating our various systems into<br />

a single core application to drive greater efficiency.<br />

Whether you’re accessing POS exceptions, financial<br />

reports, CCTV, or training programs, everything our<br />

teams do will be seamless and integrated. Whether<br />

the next device innovation takes the form of a wrist<br />

watch or some type of virtual heads-up display,<br />

it is certain technology will continue to evolve. Be<br />

prepared to say goodbye to your PC and your laptop.<br />

Eventually, tablets will go the way of the VCR, but you<br />

can be sure whatever replaces it will be connected and<br />

mobile.<br />

After all, it’s a journey, not a destination.<br />

©2015 LP Magazine<br />

16 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 17


SECTION 2: PROTECTING THE GOODS<br />

SECTION 2: PROTECTING THE GOODS<br />

Take it to the Bank<br />

By: Anne Gray<br />

How would your customers react if you “increased”<br />

their cash revenue by 25%?<br />

During college, my summers were spent working<br />

at a lakeside resort. One day the owner sent<br />

me, in her MG convertible, top down through<br />

the Paso Robles hills to make a bank deposit.<br />

I took the deposit bag she’d left on her desk and<br />

headed off. The deposit was significantly short.<br />

Someone had been in the zippered pouch before<br />

me, knowing it was not secure. If she’d had a tamperresistant/evident<br />

deposit bag she’d be richer today.<br />

As POS experts, our world revolves around a<br />

microcosm of payment software and terminals, printers<br />

and cash drawers. Everything that touches the pointof-sale.<br />

A lot to keep up with in an Internet of Things<br />

“IoT” world.<br />

With all the great opportunities IoT brings, it’s also<br />

brought security breaches, fraud and theft. All of which<br />

are eating into merchant profit. Bringing us incredibly<br />

delicate issues as well, like the debate between the<br />

F.B.I. and Apple® over iPhone® access and encryption.<br />

As a result, your ability to protect customers lost<br />

revenue becomes harder.<br />

Your focus may only be at the point-of-sale. Or<br />

perhaps you’re a Managed Service Provider (MSP).<br />

Either way you can help your customers take more of<br />

the money they’ve earned to their financial institution.<br />

This<br />

article<br />

focuses on<br />

reducing back cash<br />

room and bank or credit<br />

union deposit theft. Looking<br />

at your customer’s business from<br />

what happens after revenue leaves<br />

the point-of-sale. The “other part” of the<br />

revenue cycle, to reduce the roughly 25%<br />

being lost today.<br />

Merchants want sales and profit. The point-of-sale is the<br />

starting point. The finish line? The bank or credit union.<br />

Yet, according to the 2015 US Retail Fraud Survey,<br />

26% of theft comes from employees stealing cash. *<br />

Therefore, it seems merchants are only taking 75% of<br />

that revenue to a financial institution or have it available<br />

for operating funds.<br />

Some of the below solutions are available from your<br />

valued distribution partner. Others you might just want<br />

to recommend. They may not yield enough revenue<br />

for you to offer directly.<br />

Back Room/Cash Office<br />

Currency and Coin Counters: Save time creating start<br />

funds and closing, but also help insure an accurate<br />

count of what you really have available.<br />

Locking Till Covers: Useful for securely transferring<br />

funds from the point-of-sale to the cash room, but also<br />

for securing till contents while stored there.<br />

POS Safes: More popular in Europe, but also deployed<br />

in the US, these safes have tremendous advantages.<br />

They are relatively small and can be discreetly<br />

mounted under-counter. Saving valuable counter space<br />

as well as reducing theft.<br />

At the point-of-sale, high denomination notes are fed<br />

into tamper-resistant and evident pouches. They are<br />

taken directly to the cash room safe and finally to the<br />

bank or credit union. No intermediate count is needed.<br />

These safes are available with few bells and whistles<br />

or complete with options such as counterfeit detection,<br />

electronic audit trail and real-time data capture. From<br />

the safe’s pouch to the bank or credit union. Saving<br />

time while reducing theft. Sounds good to me!<br />

Cash Room Safes: Utilizing a commercial safe for cash<br />

storage, envelope drops and till sweeps is a simple<br />

and secure way to deter internal and external theft.<br />

Cash and Coin Recyclers: This technology has<br />

significant deployment in US financial institutions. It’s<br />

in the “Early Adopter” phase for retail markets due to<br />

relatively high cost and ROI hurdles, a large footprint,<br />

and limited understanding of the value they offer.<br />

Recyclers store cash and coin in a secure safe with<br />

limited access. They accept and dispense exact<br />

amounts required—hence the term “recycler”. Most<br />

with over 99% accuracy. Many are UL291 approved for<br />

24 hour Level 1 storage.<br />

The benefits are immense. Opportunities for theft, trips<br />

to the bank, related commercial fees and armored car<br />

or cash-in-transit “CIT” visits decline.<br />

Beyond theft, operating funds can be managed more<br />

efficiently. Also, depending upon the safe’s security<br />

rating, financial institutions may treat the cash recycler<br />

as a "second vault." Daily credit is given without the<br />

need for physical deposits. Considerable advantages,<br />

including preventing theft.<br />

Smart Safes: These safes have many of the same<br />

benefits that you get with a cash recycler. They are<br />

“smart” because, as mentioned above, they are often<br />

linked to a financial institution and if you use one, your<br />

CIT. Again, daily credit is given without a trip to the<br />

bank or credit union.<br />

payments, but also for immediate short-term storage<br />

of cash and coin, left behind customer credit cards and<br />

other valuables. With this option you can place them in<br />

the locked compartment temporarily until they can be<br />

transferred to a secure location.<br />

Look for inboxes or monitor stands with key-lock<br />

compartments. But remember, they are not a secure<br />

place for longer-term cash storage.<br />

Employee Zippered Pouches: Provide clear “purses”<br />

for cell phones, cash and other personal items. This will<br />

help avoid situations where purses or backpacks find<br />

their way anywhere cash and coin is used or stored.<br />

Finally, do not forget the importance of sound cash<br />

counting data validation which can catch mistakes and<br />

fraud. Whether using a more manual process or an<br />

automated one, an employee intent on stealing often<br />

finds loopholes that good data validation can uncover.<br />

Financial Institution Deposits<br />

Single Use Deposit Bags - Tamper-resistant and<br />

tamper-evident security features make attempts at,<br />

or actual theft recognizable. Many are simple. Others<br />

detect attempts to gain access through heat, cold,<br />

chemical, and seam tampering.<br />

Reusable Deposit Bags - Again with tamper-resistant<br />

and tamper-evident security features they come in<br />

various sizes with simple or complex combination or<br />

key lock systems.<br />

In closing, you can do a lot to help generate profitable<br />

growth for your customers by helping them keep that<br />

“25%”. Money that belongs to them and could be used<br />

for building improvements, advertising and promotions,<br />

or for improved EBIDTA. For hiring the best employees<br />

they can afford. Or for POS enhancements that you<br />

can offer.<br />

Roughly 95% of all US businesses experience<br />

employee theft. ** Whether you offer these theftreducing<br />

solutions directly or simply bring them to your<br />

customer’s attention, you come out a winner.<br />

What would your customers say if you could “increase”<br />

their bankable cash revenue by 25% though theft<br />

reduction?<br />

*US Retail Fraud Survey, 2015<br />

** http://www.allfoodbusiness.com<br />

Opportunities for internal and external theft are greatly<br />

reduced. However, as with recycling technology, the<br />

cost and ROI may be out of reach for many merchants.<br />

For many, it’s definitely worth exploring.<br />

Key Control: In addition to dual control cash<br />

drawer lock options, effective key control prevents<br />

unauthorized access to POS and other areas where<br />

money is stored. From complex two-tag systems to<br />

simple locked key portfolios, options exist for all needs.<br />

of retailers increased<br />

their loss prevention<br />

budget for 2015<br />

(Source: NRF Retail Study)<br />

Locking Organizers: Useful not only for personal<br />

items like cell phones, wallets, and outbound vendor<br />

18 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 19


SECTION 2: PROTECTING THE GOODS<br />

POWERED BY<br />

SCANSOURCE<br />

SECTION 2: PROTECTING THE GOODS<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST<br />

SECURE. SIMPLE. AFFORDABLE.<br />

Editor’s Note: As the Digital Journey Leveraging New Technology<br />

in Loss Prevention article recounted, the importance of having<br />

mobile capabilities and technological flexibility is paramount for<br />

loss prevention professionals, as well as retailers in general. When<br />

partnering with a developer, make sure you’re asking how secure<br />

their platform is so that when it is installed at a merchant site,<br />

security will never be compromised!<br />

insight provided by<br />

David Gudjonsson,<br />

CEO and Co-Founder of<br />

Handpoint<br />

MERCHANT CHALLENGES<br />

• Data breaches are forcing<br />

improved security processes<br />

• Increased liability around<br />

card data breaches<br />

• Difficulty knowing which<br />

solutions are most effective<br />

SCANSOURCE SOLUTIONS<br />

• Provide total POS offerings that<br />

include payment terminal hardware<br />

• Offer complete configuration<br />

and key injection services<br />

• Help navigate the complexity<br />

of payments offerings<br />

800.944.2432 X4219 | SCANSOURCEPOSBARCODE.COM/PAYMENTSOLUTIONS<br />

What are 3 questions you suggest that VARs ask a developer partner<br />

about data security/cyber security before they decide to partner with<br />

them?<br />

☐ DG ☐What kind of solution and provider are you using for EMV?<br />

☐☐Is your solution / provider using an encryption?<br />

☐☐<br />

How us (VAR) is deployment with access and to TMS key injection and remote handled? config Do tools?<br />

you provide<br />

What are some of the precautions you’ve taken to ensure that your<br />

platform is secure before the merchant even installs your product?<br />

Handpoint is built from the ground up to completely abstract payments<br />

DG<br />

from the point of sale and deliver a secure payments solution for<br />

merchants of all sizes. We built our proprietary payment application to<br />

meet all of the PCI-P2PE certification requirements, and we host it within<br />

the tamper proof environment of the card reader, providing multiple levels<br />

of encryption from the instant a card is tapped, dipped, or swiped. No<br />

sensitive information touches the merchant’s systems with our out-of-scope<br />

architecture, and our PCI-DSS platform provides a secure switch to a range<br />

of global processors. We also built a remote terminal management system<br />

to keep merchants secure over time—our terminals stay up-to-date with the<br />

latest security feature with zero merchant effort and lost devices can be<br />

deactivated remotely. Together, the Handpoint solution keeps customer data<br />

secure end-to-end and over time.<br />

Quick poll: P2PE or E2EE? Why?<br />

I N -S TO C K<br />

I N V ENTO RY<br />

TEC H N I C A L<br />

S U P P O RT<br />

WO R LD - C L A S S<br />

LO G I S TI C S<br />

DG<br />

Both. P2PE to the secure decryption point and full E2EE to the<br />

processor. P2PE simplifies the key management for the merchant side.<br />

With E2EE the merchant might need to handle encryption keys itself.<br />

For more information, visit www.handpoint.com<br />

20 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

Payment Solutions Suite Ad 316.indd 1<br />

3/9/16 9:08 AM<br />

connect 21


SECTION 3: SECURING THE PAYMENT<br />

SECTION 3: SECURING THE PAYMENT<br />

Security in the<br />

cloud<br />

Securing the Payment<br />

Without a doubt, the biggest acronyms this year in data/payment<br />

card security have been PCI, QIR, and EMV; EMV made the biggest<br />

splash in 2015, with the US EMV liability shift deadline of October<br />

1. But with slow adoption by merchants and consumers, along<br />

with certification delays, EMV was a timeworn subject by the end<br />

of Q1 2016. However, never a topic to lay dormant, payment card<br />

security’s hottest topic for RSPA VARs in Q1 came in the form<br />

of six letters: PCI QIR. With a new mandate by VISA for all level<br />

4 merchants—who want to accept VISA cards—requiring those<br />

merchants who use third parties for POS application and terminal<br />

installation and integration to engage only PCI QIR professionals<br />

looming, QIR quickly became both the topic of conversation and a<br />

top priority among RSPA members in 2016's first quarter. (See page<br />

26 for more details.)<br />

$75,000<br />

average cost to<br />

a restaurant for<br />

a data breach<br />

Source: Heartland Payment Systems<br />

of restaurants<br />

number of restaurants that<br />

will suffer a breach event<br />

within the next two years<br />

Source: Heartland Payment Systems<br />

Source: Heartland Payment Systems<br />

will go out<br />

of business<br />

within one<br />

year of a<br />

breach.<br />

These are restaurant<br />

stats, but the statistics on<br />

costs of data breaches for<br />

merchants are staggering.<br />

How can you leverage<br />

statistics such as these to<br />

help you close a deal with<br />

a merchant who’s in need<br />

of upgrading their data<br />

security protections?<br />

70<br />

MILLION.<br />

It’s more than<br />

a big number.<br />

It’s a big<br />

opportunity.<br />

Discover<br />

Network<br />

delivers over<br />

70 million<br />

loyal<br />

cardholders * to<br />

businesses in<br />

185 countries<br />

around the<br />

world.<br />

Welcome to<br />

buying power<br />

on a global<br />

scale.<br />

Welcome to<br />

Discover. ®<br />

DiscoverNetwork.com<br />

© 2015 DFS Services LLC<br />

*Nilson Report #1033, January 2014<br />

22 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 23


SECTION 3: SECURING THE PAYMENT<br />

SECTION 3: SECURING THE PAYMENT<br />

PCI Changes Date for Migrating from SSL and Early TLS<br />

By: PCI Security Standards Council<br />

As noted in our initial<br />

post in December<br />

2015, the Council<br />

officially extended<br />

the migration completion<br />

date to 30 June 2018 for<br />

transitioning from Secure<br />

Sockets Layer (SSL) and<br />

Transport Layer Security (TLS)<br />

TLS 1.0 to a secure version of<br />

TLS (currently v1.1 or higher).<br />

This supersedes the original<br />

dates issued in both PCI<br />

Data Security Standard v3.1<br />

(DSS 3.1) and in the Migrating<br />

from SSL and early TLS<br />

Information Supplement in<br />

April 2015. While the date<br />

has been changed to help<br />

resolve business relationship<br />

and customer issues, it is not an excuse to delay<br />

addressing vulnerabilities. To best protect your data<br />

and your customers, we encourage all organizations to<br />

migrate as soon as possible and remain vigilant.<br />

To help you better understand what this means for you,<br />

we’ve put together the below information including<br />

updated timelines, requirements and reasons for the<br />

adjustments. We encourage you to share this with your<br />

customers and business partners.<br />

How Big is the Risk?<br />

The vulnerabilities within SSL and early TLS are serious<br />

and left unaddressed put organizations at risk of being<br />

breached.<br />

Q: Why change the original date for SSL included in<br />

PCI DSS v3.1?<br />

A: For more than 20 years Secure Sockets Layer (SSL)<br />

has been one of the most widely-used encryption<br />

protocols. It remains in widespread use today despite<br />

existence of a number of security vulnerabilities and<br />

being deprecated by NIST in 2014.<br />

According to NIST, there are no fixes or patches that<br />

can adequately repair SSL or early TLS. Therefore, it<br />

is critically important that organizations upgrade to a<br />

secure alternative as soon as possible, and disable any<br />

fallback to both SSL and early TLS.<br />

In April 2015, after extensive marketplace feedback,<br />

PCI SSC removed SSL as an example of strong<br />

cryptography from the PCI Data Security Standard<br />

(PCI DSS) version 3.1, stating that it can no longer be<br />

used as a security control after 30 June 2016. During<br />

the implementation period of PCI DSS 3.1, PCI SSC<br />

continued to seek feedback from the market, and has<br />

now revised and updated sunset dates.<br />

The new date of June 2018 offers additional time to<br />

migrate to more secure protocols, but waiting is not<br />

recommended. The existence of the POODLE and<br />

Heartbleed exploits, among others, prove that anyone<br />

using SSL and early TLS risks being breached.<br />

Q: What is the PCI Standards Security Council doing<br />

next?<br />

A: PCI DSS v3.1 will be updated in 2016. Information<br />

supplements and additional guidance will also be<br />

updated at this time.<br />

Understanding the Risk<br />

Q: What is SSL/TLS?<br />

A: Transport Layer Security (TLS) is a cryptographic<br />

protocol used to establish a secure communications<br />

channel between two systems. It is used to<br />

authenticate one or both systems, and protect the<br />

confidentiality and integrity of information that passes<br />

between systems.<br />

Q: What are the SSL/TLS Vulnerabilities?<br />

A: Because of its widespread use online, SSL and<br />

TLS have been targets by security researchers and<br />

attackers. Many vulnerabilities in SSL and TLS have<br />

been uncovered over the past 20 years.<br />

Q: What are the different classes of vulnerabilities?<br />

A: Protocol Vulnerabilities: There are many!<br />

Cryptographic vulnerabilities in either the SSL/<br />

TLS protocol itself, or in how it uses cryptographic<br />

algorithms. e.g., POODLE, BEAST, CRIME.<br />

Implementation Vulnerabilities: Vulnerabilities in<br />

TLS software. E.g., Heartbleed’s Buffer over-read<br />

vulnerability in OpenSSL.<br />

Configuration Vulnerabilities: e.g., weak cipher suites<br />

or key sizes. Logjam attacks using export-grade<br />

cryptography.<br />

Q: What are the impacts of vulnerabilities?<br />

A: Loss of confidentiality or integrity: Many of the<br />

attacks, particularly protocol vulnerabilities, allow for<br />

Man-in-the-Middle attacks allowing an attacker to<br />

decrypt sensitive information.<br />

Loss of cryptographic keys: In some of the most serious<br />

cases, vulnerabilities could allow an attack to steal<br />

long-lived cryptographic keys.<br />

Q: Who is most susceptible to SSL vulnerabilities?<br />

A: Online and e-commerce environments using SSL<br />

(and early versions of TLS) are most susceptible<br />

to the SSL exploits and attacks and should be<br />

upgraded immediately. With that being said, the PCI<br />

DSS migration date of 30 June 2018 applies to all<br />

environments (except for Point of Interaction (POI)<br />

environments as stated above).<br />

Q: What you can and should do now?<br />

A: Migrate to a minimum of TLS 1.1, preferably TLS 1.2.<br />

While it is possible to implement countermeasures<br />

against some attacks on TLS, migrating to a later<br />

version of TLS—notably TLS 1.1 and TLS 1.2—is the only<br />

reliable method to protect yourself from the current<br />

protocol vulnerabilities.<br />

Patch TLS software against implementation<br />

vulnerabilities. Implementation vulnerabilities, such<br />

as Heartbleed in OpenSSL, can pose serious risks.<br />

Keep your TLS software up-to-date to ensure you<br />

are patched against these vulnerabilities, and have<br />

countermeasures for other attacks.<br />

Configure TLS securely. In addition to providing<br />

support for later versions of TLS, ensure your TLS<br />

implementation is configured securely. Ensure you’re<br />

supporting secure TLS cipher suites and key sizes,<br />

and disable support for other cipher suites that are not<br />

necessary for interoperability. For example, disable<br />

support for weak “Export-Grade” cryptography, which<br />

was the source of the recent Logjam vulnerability.<br />

Q: If my payment terminals (POIs) use SSL or TLS 1.0 for encryption, do I<br />

need to replace my payment terminals?<br />

A: Not necessarily. POIs are currently not as susceptible to the same<br />

known vulnerabilities as browser-based systems. Therefore, after 30 June<br />

2018, POI devices (and the termination points to which they connect) that<br />

can be verified as not being susceptible to any of the known exploits for<br />

SSL and early versions of TLS may continue to use SSL / early TLS<br />

If SSL/early TLS is used, the POIs and their termination points must have<br />

up-to-date patches, and ensure only the necessary extensions are enabled.<br />

Additionally, use of weak cipher suites or unapproved algorithms—e.g.,<br />

RC4, MD5, and others—is NOT allowed.<br />

Q: Who can verify my POIs meet the above characteristics?<br />

A: Entities may contact the terminal vendors directly for evidence<br />

or attestation that payment devices are not susceptible to known<br />

vulnerabilities. Entities may also consult with knowledgeable security<br />

professionals to obtain verification. The verification will need to occur any<br />

time a new SSL/TLS vulnerability is discovered, and organizations will<br />

need to remain up-to-date with vulnerability trends to determine whether<br />

or not they are susceptible to any known exploits. New threats and risks<br />

must continue to be managed in accordance with applicable PCI DSS<br />

Requirements, such as 6.1, 6.2, and 11.2.<br />

Q: Do all POIs use SSL for encryption?<br />

A: No. Newer payment devices should already be using secure protocols<br />

such as TLS version 1.2. Check with the terminal manufacturer or terminal<br />

documentation to understand what level of encryption your particular POI<br />

uses. If a device does not need to support SSL/early TLS, disable both use<br />

of and fallback to these versions.<br />

Q: My ASV scan is flagging the presence of SSL and my scan is failing.<br />

What should I do?<br />

A: Prior to 30 June 2018: Entities that have not completed their migration<br />

should provide the ASV with documented confirmation that they have<br />

implemented a Risk Mitigation and Migration Plan and are working to<br />

complete their migration by the required date. Receipt of this confirmation<br />

should be documented by the ASV as an exception under “Exceptions,<br />

False Positives, or Compensating Controls” in the ASV Scan Report<br />

Executive Summary.<br />

After 30 June 2018: Entities that have not completely migrated away<br />

from SSL/early TLS will need to follow process outlined in the ASV<br />

Program Guide section entitled “Managing False Positives and Other<br />

Disputes” to confirm the affected system is not susceptible to the<br />

particular vulnerabilities. For example, where SSL/early TLS is present but<br />

is not being used as a security control (e.g. is not being used to protect<br />

confidentiality of the communication).<br />

To read the entire article, scan the QR code or<br />

visit www.GoRSPA.org/Newsroom.<br />

Re-printed with permission from the PCI Security Standards Council ©2016<br />

18 months after the Heartbleed vulnerability was<br />

announced, it was reported there were still<br />

200,000+<br />

VULNERABLE DEVICES<br />

on the internet.<br />

Do you have<br />

the right partner<br />

to help your<br />

business grow?<br />

The Stanchion suite<br />

of retail IT bears all<br />

of NEC's highest<br />

standards to help<br />

your commerce<br />

succeed tomorrow,<br />

the next day and<br />

years to come.<br />

Hardware. Software. People.<br />

contact us at: retaildirection@necam.com<br />

© 2015 NEC Corporation of America. All rights reserved. NEC and<br />

NEC logo are trademarks or registered trademarks of NEC Corporation<br />

that may be registered in Japan and other jurisdictions.<br />

24 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 25


SECTION 3: SECURING THE PAYMENT<br />

SECTION 3: SECURING THE PAYMENT<br />

New POS Security Requirements Affect Industry Partners<br />

By: Paul St. George<br />

ONE SIMPLE PAYMENT INTEGRATION WITH<br />

Retail businesses are<br />

constantly under attack<br />

by cybercriminals trying<br />

to steal payment card<br />

data—and in some cases,<br />

retailers are making it easier<br />

for hackers to succeed. In fact,<br />

credit card company Visa has<br />

found that improperly installed<br />

POS applications and merchant<br />

payment devices create the<br />

conditions hackers like to exploit<br />

to steal information.<br />

That’s why the financial services<br />

giant is pushing merchants,<br />

payment application developers,<br />

POS system integrators and<br />

resellers to comply with security<br />

requirements designed to combat<br />

the threat of hacker attacks. Visa<br />

has set a deadline of March 31 for<br />

small merchants to meet a set of<br />

requirements that restricts who<br />

they can buy POS technology<br />

from.<br />

As of March 31, all new Level<br />

4 merchants (owner-operated<br />

retail locations of franchise or<br />

corporate organizations) must<br />

use only Payment Card Industry<br />

(PCI)-certified QIR resellers and<br />

integrators for the installation and<br />

integration of POS applications<br />

and terminal installations. Also,<br />

as of Jan. 31, 2017, all Level 4<br />

merchants must validate full PCI<br />

DSS compliance annually.<br />

Requirement Revisions<br />

As the March deadline looms,<br />

it’s important to know that the<br />

Payment Card Industry Security<br />

Standards Council (PCI SSC)<br />

has eased QIR requirements.<br />

Changes to the requirements,<br />

which had caused some concern<br />

among solution providers, include<br />

condensing the QIR agreement<br />

(from 12 pages to less than<br />

three) and requiring only one<br />

employee per company—or a<br />

sole proprietor—to qualify for QIR.<br />

The previous requirement called<br />

for two qualified employees.<br />

This easing of requirements<br />

should remove some of the<br />

obstacles for POS solution<br />

providers to earn their QIR<br />

certifications. While the mandate<br />

may feel like a burden, integrators<br />

and resellers should look at it this<br />

way: Visa is effectively forcing<br />

merchants to work with the best<br />

qualified providers to ensure<br />

retail operations have properly<br />

designed and installed systems<br />

with the security they need to<br />

protect themselves and their<br />

customers.<br />

For you, our partners, QIR<br />

certification brings some real<br />

benefits. Qualified providers<br />

stand to expand their businesses<br />

with existing customers, win new<br />

customers and boost revenue. So<br />

if you don’t have QIR certification<br />

yet, it’s time to start the process.<br />

Learn more about the process<br />

by visiting the PCI site, or by<br />

contacting RSPA for more<br />

information.<br />

3/15/16 UPDATE:<br />

(NEW) Effective 31 March 2016,<br />

acquirers must communicate<br />

to all Level 4 merchants that<br />

beginning 31 January 2017, they<br />

must use only Payment Card<br />

Industry (PCI)-certified Qualified<br />

Integrators and Reseller (QIR)<br />

professionals for point-of-sale<br />

(POS) application and terminal<br />

installation and integration.<br />

Effective 31 January 2017,<br />

acquirers must ensure that<br />

Level 4 merchants using third<br />

parties for POS application<br />

and terminal installation and<br />

integration engage only PCI QIR<br />

professionals.<br />

Effective 31 January 2017,<br />

acquirers must ensure Level 4<br />

merchants annually validate PCI<br />

DSS compliance or participate<br />

in the Technology Innovation<br />

Program (TIP).<br />

EMV LEVEL 3 CERTIFIED<br />

LOGISTICS<br />

When you integrate your POS application with Paygistix, you gain a partner who handles the<br />

configuration, testing, deployment, end user setup and ongoing support associated with adding a<br />

payment device to your system - freeing you up to focus on what you do best.<br />

BENEFITS<br />

Add immediate support for EMV & NFC<br />

Remove POS application from scope of PA-DSS & PCI DSS<br />

Connect to multiple major processing networks<br />

Maximize ROI with competitive revenue sharing options<br />

The QIR (Qualified Integrators and<br />

Resellers) designation is issued<br />

to solution providers that have<br />

received training and qualification<br />

on the secure installation of<br />

Payment Application Data<br />

Security Standard (PA-DSS)-<br />

validated payment in compliance<br />

with the PCI Data Security<br />

Standard.<br />

Visa’s new requirement affects<br />

merchants and their POS<br />

suppliers alike. If, as a reseller<br />

or integrator, you have yet to<br />

earn QIR certification, you’ll be<br />

excluded from a lot of business<br />

opportunities going forward.<br />

More than 1/3 of consumers reported<br />

they ignored data breach notification<br />

letters, taking no action to protect<br />

themselves from fraud.<br />

Source: 2014 Ponemon Institute Study<br />

FEATURES<br />

• Traditional Tip Adjust on EMV sales<br />

• PIN Bypass<br />

• Online Signature Capture<br />

• Pay at the Table<br />

• Tokenization<br />

DEVICES<br />

• ISV / VAR End User Billing<br />

• P2P Encryption<br />

• Recurring Billing<br />

• Customer Interaction Platform<br />

• Real-time Transaction Management<br />

888.472.9564 | paymentlogistics.com<br />

26 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 27


SECTION 3: SECURING THE PAYMENT<br />

SECTION 3: SECURING THE PAYMENT<br />

Security Resources<br />

Available 24/7 for RSPA Members<br />

Start with our website<br />

RSPA is committed to helping you gain the knowledge<br />

you need to be successful in your business, especially<br />

when it comes to the security solution area of your<br />

business. There are several resources available to you<br />

with regard to payment card security.<br />

A data breach can be a merchant’s<br />

worst nightmare, especially those<br />

SMB merchants. Solution providers<br />

can often be the voice of calm during<br />

the storm.<br />

Do you know how to advise your customers<br />

if a breach occurs? This infographic from<br />

RSPA member Netsurion gives you 10 steps<br />

you can follow to advise and help your<br />

merchant if a breach happens:<br />

Click on our “Knowledge” banner, and you’ll find RSPA’s EMV Central.<br />

Consider this one of your business’ key resources on EMV. One of its<br />

most important features is the RSPA’s EMV Integrated Solutions Grid.<br />

Want to know which Integrated and Semi Integrated EMV solutions are<br />

available? Make the grid your first stop. Looking for training resources<br />

for your team or your end users? EMV Central has videos, webinars,<br />

whitepapers, articles, handouts, and more to help you stay informed and<br />

educated about the ongoing EMV rollout.<br />

In the “Join” section, you’ll be able to access those legal document<br />

templates mentioned on page 8. Remember, you’ll need your Member<br />

username and password to access.<br />

Contact RSPA Education at Education@GoRSPA.org<br />

The RSPA Education team is constantly working to collect new and useful<br />

information for RSPA members. If you’re interested in getting PCI QIR<br />

certified at a significant discount for RSPA members (available only until<br />

the end of April), please email us at Education@GoRSPA.org.<br />

We’ve also recently held a webinar, hosted by RSPA’s Certification Lead,<br />

Ashley Naggy. The Nuts and Bolts of PCI QIR Certification featured tips<br />

for success on examination prep from two newly QIR certified RSPA VAR<br />

members. Check out a recording of this webinar in our Education 24/7<br />

library: www.GoRSPA.org/Education.<br />

Check out the RSPA Webinar series, including our on-demand<br />

webinars<br />

Speaking of our webinars, we have featured security topics of all types in<br />

our bi-monthly webinar series. You can always find the schedule/register<br />

for our webinars on our website. We also archive all webinar broadcast<br />

recordings on our www.GoRSPA.org/Education site.<br />

Take RSPA’s PCIwise Course<br />

Are you looking for a rigorous course that will prepare your team with<br />

a crash course on PCI Compliance? Look no further than RSPA’s own<br />

PCIwise course! 7 courses (all approximately 1 hour each) are available<br />

FREE to all RSPA members, and accessible 24/7. Upon completion of the<br />

course, a certificate of completion is issued. Contact RSPA Education to<br />

get access to this course: Education@GoRSPA.org.<br />

44<br />

people<br />

completed<br />

7hours<br />

of coursework<br />

in 2016...<br />

and scored<br />

over 90% on<br />

136<br />

test questions<br />

28 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 29


SECTION 3: SECURING THE PAYMENT<br />

See Past The Storefront...<br />

SECTION 3: SECURING THE PAYMENT<br />

DEVELOPER PARTNER <strong>SECURITY</strong> CHECKLIST<br />

SYNNEX STORESolv can help you grow your education, IT, or network business<br />

by offering complete POS/AIDC solutions.<br />

And we don’t stop there:<br />

• Eliminate POS complexity for retail customers<br />

• Help retailers react quickly to sales trends<br />

• Become the MSP your retail customers need<br />

• Offer complete POS solutions<br />

PHYSICAL<br />

<strong>SECURITY</strong><br />

POS<br />

mmf article<br />

PROAV<br />

SYNNEX<br />

TECHNOLOGY<br />

SOLUTIONS<br />

DIGITAL<br />

SIGNAGE<br />

SERVERS,<br />

STORAGE & POWER<br />

SYSTEMS &<br />

SOFTWARE<br />

WIRELESS,<br />

NETWORKING & UNIFIED<br />

COMMUNICATIONS<br />

Editor’s Note: All of the Developer Partner Security Checklists<br />

featured in this issue have provided insight from various software<br />

developers on data security as it relates to software. As data and<br />

cyber security become a top priority for merchants, PCI and EMV<br />

should hold equal priority for VARs. While the customer only wants<br />

to see the positive outcome (translation: no breaches occur), it<br />

becomes imperative for the VAR to ask detailed questions to<br />

ensure all aspects of systems are secure.<br />

What are 3 questions you suggest that VARs ask a developer partner<br />

about data security/cyber security before they decide to partner with<br />

them?<br />

TB<br />

☐☐<br />

☐☐<br />

☐☐<br />

Hosting Environment—Ask about the hosting environment.<br />

Who manages it? Where? Ask about redundancy and<br />

backup.<br />

Customer<br />

share information Data—What with information third parties? do Who you and store? Why?<br />

Do you<br />

PCI<br />

Security Compliance—How protocols?<br />

do you protect the data you store?<br />

What are some of the precautions you’ve taken to ensure that your<br />

platform is secure before the merchant even installs your product?<br />

We do regular PCI compliance scanning to ensure our dedicated<br />

TB<br />

private servers remain up to par and secure. Many providers use<br />

things like Amazon Web Services where they will not tell you where<br />

your data is stored. In that type of environment your data could be<br />

anywhere or even everywhere across multiple data centers. You<br />

do not want your company in the news regarding a drive that went<br />

missing from some data center causing a PCI breach. There are<br />

benefits to Amazon in terms of scaling faster and savings on pay-foruse<br />

type arrangements; however, not knowing where our data was<br />

going to be stored was too risky for our palette. In our environment<br />

we use dedicated private servers in fully managed data centers.<br />

insight provided by:<br />

Todd Burge, Chief<br />

Executive Officer, Food<br />

Online Ordering Systems<br />

11 WAREHOUSES • GSA SCHEDULE • GRANT SPECIALIST • STATE CONTRACTS • SITE CONTRACTS • CLOUD SERVICES • TECHNICAL SUPPORT<br />

Simplified POS • Data • Retail Management<br />

CONTACT SYNNEX TODAY:<br />

STORESolv@synnex.com | 800.456.4822<br />

For more information,<br />

visit www.foodonlineorderingsystems.com<br />

Copyright 2016 SYNNEX Corporation. All rights reserved. SYNNEX, the SYNNEX Logo and all other SYNNEX company, product and services names and slogans are trademarks or<br />

registered trademarks of SYNNEX Corporation. SYNNEX and the SYNNEX Logo Reg. U.S. Pat. & Tm. Off. Other names and marks are the property of their respective owners.<br />

30 APRIL/MAY www.GoRSPA.org<br />

www.GoRSPA.org<br />

connect 31


CONNECT CONTRIBUTORS<br />

THE ASSOCIATION YOU NEED<br />

About Anne Gray<br />

Anne Gray is a Senior Product Manager with MMF POS where she works with cross-functional teams<br />

to ensure profitable growth from existing and new products. Previously, she was a Product Manager<br />

with De La Rue (now Glory Global Systems) where she was responsible for North American banking<br />

and retail cash-handling equipment, including cash recyclers, cash dispensers, currency counters<br />

and coin counters. Anne’s current interests include POS trends in Nightclubs, Bars and Restaurants,<br />

and the relationship between IoT—the Internet of Things—and POS Physical Security.<br />

About Paul St. George<br />

Paul St. George is the Director of Product Management for Mobile and Interface Solutions at APG<br />

Cash Drawer. In this role, Paul focuses on cash drawer solutions that meet the needs of retailers<br />

deploying mobile and thin-client hardware platforms. He manages a team dedicated to development<br />

of new products and software solutions designed to meet these emerging trends.<br />

About William M. Titus<br />

William M. Titus is a former vice president of loss prevention for Sears Holdings Corporation. Prior<br />

to his appointment to VP of LP at Sears, Roebuck and Co. in April 2003, Titus was senior VP of LP<br />

and risk management at OfficeMax. He also held LP and operations management positions with<br />

T.J. Maxx and Montgomery Ward. Titus was also a chair of the Loss Prevention Research Council<br />

and past chairman of the National Retail Federation loss prevention advisory committee. He holds a<br />

management and accounting degree from the University of Southern California.<br />

NOMINATIONS FOR RSPA BOARD<br />

OF DIRECTORS ARE NOW OPEN!<br />

The August election will feature 2 open reseller<br />

seats and 2 open vendor seats on the RSPA’s<br />

Board of Directors.<br />

To nominate yourself, or another RSPA member,<br />

please contact a current RSPA Board Member<br />

(www.GoRSPA.org/Board-of-Directors)<br />

or Kelly Funk at KFunk@GoRSPA.org.<br />

Canadian Corner<br />

There’s still time to register!<br />

The RSPA Canadian Community will host its first 2016 event on Thursday,<br />

April 14th from 6-9pm at Le Place D'Armes Hotel & Suites in Montreal,<br />

Québec. The event is open to RSPA members and non-members who are<br />

interested in connecting with individuals in the POS ecosystem as well as<br />

learning more about the Association.<br />

Check out the photos below to see what you can expect!<br />

Le Place D'Armes Hotel & Suites<br />

For those who cannot make the journey to Montreal, save the date for<br />

our next Canadian Community event to take place at RetailNOW® 2016 in<br />

Grapevine, TX on Monday, August 1st.<br />

Canadian Community Sponsors<br />

After three successful<br />

years of hosting<br />

Canadian networking<br />

events, the Community<br />

is new to Montreal. Participation<br />

in events held in Toronto and<br />

Vancouver has been healthy,<br />

and the Community—including<br />

Co-Chairs Jacques LaPierre<br />

(BlueStar Canada), Maureen<br />

Chomica (Epson Canada) and<br />

Paul Leduc (Globe POS)—is<br />

hopeful that the 4th annual<br />

gathering on Canadian soil<br />

will be just as productive for<br />

attendees. Held in conjunction<br />

with the 2016 SIAL Canada<br />

event, the RSPA Canada<br />

gathering has great potential<br />

to draw additional attendees<br />

from Canada’s largest agrifood<br />

industry event, which attracts<br />

more than 850 national and<br />

international exhibitors from 50<br />

countries, and hosts over 15,000<br />

buyers from Canada, the U.S.,<br />

and 60 other countries.<br />

Attendees for this year’s event<br />

can expect an event primarily<br />

focused on networking with a<br />

short program on the value of<br />

RSPA membership as well as<br />

food and beverages. For more<br />

event details and to register for<br />

this event, you can visit<br />

www.GoRSPA.org/Canada.<br />

The success and growth of<br />

this community would not be<br />

possible without the help of<br />

the RSPA Canadian Committee<br />

and Community Sponsors. For<br />

questions or to find out how to<br />

get involved with the Canadian<br />

Community, contact<br />

Membership@GoRSPA.org.<br />

32 APRIL/MAY www.GoRSPA.org www.GoRSPA.org<br />

connect 33


THE ASSOCIATION YOU NEED<br />

THE ASSOCIATION YOU NEED<br />

Remembering John Lockington<br />

RSPA Hall of Famer and Former Executive<br />

Director of the DTSDA/SDA leaves lasting legacy<br />

of dedication, humor<br />

By: Amber Murdock<br />

On February 9, 2016, the POS technology<br />

industry lost one of its giants. John<br />

Lockington, a 2011 RSPA Hall of Fame<br />

inductee, and the only executive director<br />

of the Data Terminal Systems Dealers Association<br />

(DTSDA) and Systems Dealers Association (SDA),<br />

passed away in Naperville, Illinois, after a short illness.<br />

Remembered fondly as a tireless and devoted leader<br />

in the point of sale industry, John Lockington was<br />

considered a “man of great integrity,” declares Wayne<br />

Williams (Co-Founder, Macro Integration Services),<br />

who, while serving as president of the SDA, began<br />

working with Lockington in the early 1980’s. Lockington<br />

was the driving force behind the SDA’s annual dealer<br />

meeting, called Advantage. The event was a “must<br />

attend,” according to Bob Bauer, (President, BMC)<br />

who first met Lockington in the summer of 1982. “The<br />

education seminars and the tradeshow were all key to<br />

the success of many SDA dealers,” Bauer adds. The<br />

education sessions were segmented, so that a dealer<br />

could develop team members from every department:<br />

“There were sessions for sales people, led by sales<br />

people and trainers in our business; [sessions for]<br />

service people, which were led by the service leaders<br />

in our business and leaders in the industry,” Bauer<br />

recalls. Additionally, Business Owners and General<br />

Managers were able to spend time reviewing best<br />

practices and learning about future industry trends.<br />

The Advantage event usually spanned three days, and<br />

SDA members spent more than 15 hours each day in<br />

education sessions, on the show floor, and networking.<br />

All that valuable information was highly sought after—<br />

so much so that “John stood guard at the door, to<br />

assure that only registered attendees participated,”<br />

recalls Bob Goldberg, RSPA Attorney and longtime<br />

friend of Lockington.<br />

In addition to the trailblazing Advantage event,<br />

Lockington was an integral part of the merging of<br />

the SDA and the ICRDA (Independent Cash Register<br />

Dealers Association). In the spirit of what Goldberg,<br />

Bauer and Williams consider Lockington’s devotion to<br />

the health of the industry, Lockington could see that<br />

the unity of two organizations with such similar goals<br />

and interests made sense for industry growth. “John<br />

was a proponent [of the merger],” Goldberg shares.<br />

“He recognized the advantages even though it would<br />

lessen his role.”<br />

It’s that selflessness that was a hallmark trait of<br />

Lockington’s. “John would (and did) do his best to<br />

help anyone if they were sincere, including many onsite<br />

visits,” says Bauer. “He did not complain about<br />

the low pay, short staff, and long hours, he just got<br />

the job done.” Lockington and his wife, Joan, often<br />

had to postpone payroll for their own staff in order to<br />

accommodate the needs of the association and the<br />

industry. Goldberg, who hired Lockington for the SDA<br />

position, also finds Lockington’s humility and generosity<br />

From L-R: Bob Goldberg with John Lockington and wife, Joan.<br />

to be quite memorable. Whether it was his commitment<br />

to the ongoing education of dealers, or in small ways,<br />

like interviewing for the SDA Executive Director position<br />

while sitting on a bed in a Texas Holiday Inn hotel room,<br />

Goldberg says that Lockington “dedicated himself to<br />

the point of sale industry.” So much so, that he made it<br />

a family affair: “Joan was brought on as his assistant at<br />

the SDA after a few years,” says Williams.<br />

While he spent so much of his time and energy giving<br />

to the industry, Lockington is also remembered for his<br />

kindness, loyalty, as well as his lively sense of humor.<br />

Williams says that Lockington’s Chicago roots appeared<br />

often: “He adopted an Al Capone or Dick Tracy<br />

persona at times,” laughs Williams, while remembering<br />

his friend’s light-hearted nature. “But it was all in jest.”<br />

Goldberg remembers affectionately the trip back to<br />

Illinois from the Texas SDA interview: Lockington’s<br />

cleverness even cheered up a harried flight attendant.<br />

“John told her he could make her laugh and she just<br />

frowned,” he recalls. “John then cut out chicken feet<br />

from paper and placed them down the aisle. The flight<br />

attendant laughed long and loudly. I appreciated the<br />

free drinks.”<br />

Without a doubt, the groundwork Lockington laid with<br />

the SDA Advantage conference created the foundation<br />

of today’s RetailNOW®. His unswerving pursuit of<br />

success for the industry through his direction of the<br />

SDA as well as his mentorship of up-and-coming<br />

professionals (like Bauer) echo in today’s RSPA, with<br />

many of his mentees carrying the torch he lit many<br />

years ago, in the days where a staff of two worked to<br />

provide resources for a growing and evolving industry.<br />

John Lockington, Navy veteran, POS industry<br />

champion, committed association executive, RSPA Hall<br />

of Famer, and loving family man leaves behind his wife<br />

and soul mate, Joan. She notes that her husband was<br />

“strong to the end, even though the pain was severe.”<br />

His perseverance and strength, until the end, is<br />

certainly a loss for the POS industry in general, but for<br />

those who knew him well and had experienced working<br />

with him, the loss is devastating. “It is impossible to<br />

calculate John’s contributions to the channel and our<br />

industry,” says Bauer. “Goodbye, my mentor and friend.<br />

We’ll miss you.”<br />

APRIL 2016<br />

CALENDAR OF EVENTS<br />

10-13<br />

14<br />

19-21<br />

Synnex Varnex<br />

Conference<br />

Dallas, TX<br />

RSPA's Canadian<br />

Community Event*<br />

Montreal, QC<br />

TRANSACT16*<br />

Las Vegas, NV<br />

MAY 2016<br />

CALENDAR OF EVENTS<br />

16-18<br />

16-18<br />

Shoptalk*<br />

Las Vegas, NV<br />

Toshiba Connect<br />

Las Vegas, NV<br />

JULY 2016<br />

CALENDAR OF EVENTS<br />

31<br />

RSPA's<br />

RetailNOW® 2016*<br />

Grapevine, TX<br />

(through August 3)<br />

* indicates RSPA presence at event.<br />

Have an event you’d like other RSPA members to<br />

know about?<br />

Submit to us (at least 6 weeks in advance) at<br />

Publications@GoRSPA.org.<br />

34 APRIL/MAY www.GoRSPA.org www.GoRSPA.org<br />

connect 35


R<br />

CONNECT MAGAZINE<br />

2016<br />

July 31 - August 3<br />

Gaylord Texan Resort & Convention Center<br />

Grapevine, TX<br />

RetailNOW 2016<br />

Event Sponsors<br />

33+<br />

Education<br />

Sessions<br />

2000+<br />

Attendees<br />

170+<br />

Exhibitors<br />

A very special thanks to all our<br />

Package sponsors, visit them at<br />

www.GoRSPA.org/Our-Sponsors<br />

Registration Opens May 2016<br />

Learn More | www.GoRSPA.org/RetailNOW<br />

connecting the Point of Sale technology ecosystem<br />

36 APRIL/MAY www.GoRSPA.org

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!