Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

Pets ready-made stem cell therapy may come

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » What PCI DSS V4 really means – Lessons from A&F Compliance Journey
Identity

What PCI DSS V4 really means – Lessons from A&F Compliance Journey

userBy userMarch 7, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 7, 2025Hacker NewsPayment Security/Compliance

Access the On-Demand Webinar here

Avoid a $100,000 monthly compliance disaster

March 31, 2025: The clock is ticking. What happens when a script that is often overlooked is a non-compliance fine that costs $100,000 per month? PCI DSS V4 is coming and you need to prepare a company to process your payment card data.

Beyond the fines, non-compliance exposes businesses to web skimming, third-party script attacks, and new browser-based threats.

So, how do you prepare on time?

Reflectiz sat down with Abercrombie & Fitch (A&F) for an unbanned discussion about the toughest PCI DSS V4 challenges.

Kevin Heffernan, director of risk at A&F, shared actionable insights:

What worked (and saved $$$) didn’t want what they knew before (and costs and resources)

Check out the whole fut PCI DSS V4 webinar now

(Free on-demand access – Learn from A&F compliance experts)

What’s changing with PCI DSS v4.0.1?

PCI DSS V4 introduces stricter security standards, particularly for third-party scripting, browser security and continuous monitoring. Two of the biggest challenges for online merchants are requirements 6.4.3 and 11.6.1.

Requirement 6.4.3 – Payment Page Script Security

Most companies rely on third-party scripts for checkout, analysis, live chat and fraud detection. However, attackers exploit these scripts to inject malicious code into the payment page (MageCart-style attack).

New PCI DSS V4 Mandate:

Script Inventory – You must record and justify all scripts loaded into the user’s browser.

Integrity Management – Companies need to verify the integrity of all payment page scripts.

Approval – Only approved scripts must run on the checkout page.

How A&F worked on it:

A script audit was conducted to identify unwanted or dangerous third-party dependencies. I used Content Security Policy (CSP) to restrict third-party scripts. We used smart automated approvals to save time and money.

Requirement 11.6.1 – Changes and Tamper Detection

Even if today’s scripts are safe, attackers can inject malicious changes later.

New PCI DSS V4 Mandate:

Mechanism – The development of continuous changes and tamper detection mechanisms for changes to the scripts of payment pages.

Incorrect Changes – HTTP header monitoring detects incorrect changes.

Integrity – Weekly consistency checks (or more frequently based on risk levels and compromise metrics).

How A&F worked on it:

Continuous monitoring has been deployed to detect fraudulent changes. Security information and event management (SIEM) was used for centralized monitoring. I created automatic alerts and batch approvals for scripts, structures and header changes on the checkout page.

Try Reflectiz PCI Dashboard – 30 Day Free Trial

Recent Updates: Clarification of SAQ A Waiver

A recent explanation from the PCI Council states the following regarding SAQ A Marchants: [self-assessment questionnaire]:

Eligibility requirements: Merchants must ensure that they are not affected by script attacks that affect the e-commerce system. Compliance Options: Implement protection techniques (such as PCI DSS requirements 6.4.3 and 11.6.1) directly or through a third party, or get confirmations from a PCI DSS-compliant service provider. Exemption: Merchants who redirect customers to payment processors or outsource payment functions entirely are not subject to this requirement. Recommendations: Merchants should consult their service provider about secure implementations and verify with the acquirer that SAQ A is suitable for the environment.

Please note that even if you are eligible for SAQ A, you will still need to protect your entire website. Many businesses still need real-time monitoring and alerting, so a full compliance solution is relevant regardless.

Top 3 PCI DSS V4 Pitfalls (and how to avoid them)

With multiple payment pages to protect around the world, Abercrombie and Fitch’s compliance journey was complicated. Risk Director Kevin Heffernan suggests three major mistakes online merchants often make:

Miss #1: Relying only on CSP

Content Security Policy (CSP) helps to prevent script-based attacks, but does not cover dynamic changes to scripts and external resources. PCI DSS requires additional integrity verification.

Mistake #2: Ignore third party vendors

Most retailers rely on external payment gateways, chat widgets, and tracking scripts. If these vendors do not follow you, you are still responsible. Periodically audit third party integrations.

Mistake #3: Treat compliance as a one-time fix

PCI DSS V4 requires continuous monitoring. This means you can’t audit the script once and forget it. Continuous monitoring solutions are important to compliance.

Try the Reflectiz PCI Dashboard in a 30-day free trial.

Final takeout from A&F’s PCI compliance journey

Risk assessment first – before jumping to compliance changes that identify and map vulnerabilities, supply chain risks, and component misconceptions. Ensure payment page scripts – configure strict HTTP security headers such as CSP.Monitors – integrating third-party scripts and integrations before replenishing attackers before using continuous monitoring, SIEM, and tamper detection alerts – Compliance responsibility doesn’t stop at the firewall.

The deadline for March 31, 2025 is closer than you think

If you start too long, you create a security gap and are risky. The A&F experience shows why early preparation is important.

Avoid costly pci fines – Check out the PCI DSS V4 webinar. Learn how major global retailers have worked on compliance and what they can do today to avoid fines and security risks.

Try the Reflectiz PCI Dashboard in a 30-day free trial.

Did you find this article interesting? This article is a donation from one of our precious partners. Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNigerian Senators suspend female senators who have made sexual harassment claims | Gender Equity News
Next Article Trump’s first Crypto Summit is ready for participants to seek restrictions
user
  • Website

Related Posts

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

July 5, 2025

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

July 5, 2025

TwinH: A New Frontier in the Pursuit of Immortality?

July 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

Pets ready-made stem cell therapy may come

TwinH: A New Frontier in the Pursuit of Immortality?

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.