Website Security

Xero Website security is something that even the biggest and best companies struggle to get right at times (in the last 18 months Adidas, Macy’s, Delta, Under Armour and Forever 21 have all experienced a data breach). However, it is really important that you get it right – a recent KPMG survey revealed that 19% of customers would completely stop using a retailer if they found out they’d had a breach. Some of the key things to consider are:

  • Payment Card Industry Data Security Standards (PCI DSS compliant) – your software and hosting will need to meet these standards if you want to take Mastercard, American Express, Visa or Discover credit cards. You only need this if customer credit card data actually flow through site – as opposed to being submitted directly to a third party payment system such as Paypal. Using a third party company reduces the security risk around card payments, but it doesn’t exclude a business from PCI DSS compliance. Your payment provider should provide you with information that clearly states what their own responsibilities are in order for you to assess your compliance, which you do by completing a Self Assessment Questionnaire
  • Transport layer security (TLS) – an encryption protocol used to secure communications over the internet (TIP: If a web address doesn’t start with https:// it doesn’t use TLS!). TLS is required for PCI compliance, but it doesn’t in itself make you PCI DSS compliant.
  • ISO 27001/27002/27018 – these are internationally recognised frameworks for website security. Whilst they aren’t mandatory, it’s a good idea to look out for providers which have them as they do provide you with additional comfort over the security your provider has in place.

There is a tendency for small merchants to rely heavily on their third party providers for security and it is a subject that is very technical and often daunting. The PCI Security Standards Council provides a PCI Data Security Essential Evaluation Tool for Small Merchants and we very much recommend that e-commerce businesses use this.

Website building solutions

If you’re using a 3rd party e-store solution that includes hosting, then server security will be provided by that provider. Here’s a summary of how some of the key players in the e-commerce market will help to keep your site safe:

Provider Wix Shopify EKM Magento
PCI compliance Yes Yes Yes Yes
Transport layer security Yes Yes Yes Yes (if configured)
ISO 27001 compliant Yes No Yes Yes

However, where hosting is not provided and your site is kept on your own or another server, you cannot rely on your e-commerce platform provider and will need to consider the security of your own server separately.

If you would like to find out more about any of the above-mentioned retailers, please take a look here for more details on the wider/pros and cons. Alternatively, if you’d like to speak to one of our e-commerce accounting experts at Elver Consultancy, please call us on 01942 725419.

Internet security is something that is constantly evolving. Whilst we do our best to keep our site fully up to date, please do get in touch with us rather than placing any reliance on the accuracy of the information on this page.

Help and Guidance

Specialist E-Commerce Accountants for Online Retailers

Elver E-Commerce Accountants Accounting and Business Advisory Services for E-Commerce Businesses Book an Appointment Specialist Accounting Services for E-Commerce Businesses Elver E-Commerce Accountants empower and enable the growth of ecommerce…

Website Security

Website security is something that even the biggest and best companies struggle to get right at times (in the last 18 months Adidas, Macy’s, Delta, Under Armour and Forever 21…

Card Fraud

You cannot ignore the possibility that your online store will be subject to card fraud. A fraudulent transaction, where the transaction is not authorised by the cardholder, can result in…

E-Commerce – Getting Started

You will find lots of websites offering advice on starting up your own e-commerce business and how easy it is. And it is…….create a company using an e-commece platform like…

Wait! Before You Go…

Don’t miss out on your FREE consultation with one of our experienced directors.

Benefit from personalised advice and tailored solutions for your e-commerce business. Our directors are here to help you navigate the complexities of e-commerce accounting and VAT/GST compliance, alongside Virtual Finance Director (VFD) services to provide comprehensive financial guidance tailored to your e-commerce business.