Here is a link to the white paper we have just completed analyzing the effect of the new law in Connecticut on businesses and organizations doing business here:
http://marchalpert.googlepages.com/WhitePaperoct07.pdf
In a nutshell, the law states that if your organization or company is the source of a breach of personal data of any customer, you can be held financial liable to correct the banking loss of that person and his/her banks. Connecticut is the second state in the nation to enact such a law.
Please pass this to anyone who can benefit from it. They need to know the ways to remedy their exposure. Let us know if you have any questions.
Monday, October 29, 2007
Tuesday, October 16, 2007
A sense of place

It's amazing how you come across new concepts, and this is one concept that I have always thought about, but never heard articulated: "a sense of place."
While at a lecture by a local historian/author, she mentioned that she shared a "sense of place" with the town she wrote of. These new ideas are useful inspirations for postings for my blog, so here goes another one:
I share the "sense of place" in electronic payments with a lot of people and institutions, some honorable, some not, often many have not fully explained something to a client. Thus, the overall need for this blog: education.
I sense the "bad guys" ruin it for the "good guys." But not only in my industry.
It happened to a potential client whose business type, while legal and honorable, was rejected by my processor and many others I referred them to as well, suffering guilt by association with the less-than-honorable competitors who make certain miraculous health claims.
What their competitors don't tell you is the number of people who buy and then return the items as useless. That makes credit card processors nervous, so the entire industry was placed on the "unacceptable merchant list."
Not that these guys are unacceptable as merchants, in fact they have a great concept and can truly help a lot of people-it's just the place they share with others is murky. They know they have these challenges, as do I in the industry I am in.
That's another reason to have this blog: to provide a level of service and explanation the other guys aren't, even though they can live with their consciences.
I welcome your comments on this topic. Help share my sense of space with your notes and opinions.
Labels:
a sense of space,
clarification,
credit cards,
salespeople
Sunday, October 14, 2007
Blog Action Day-Environmental Theme

Tomorrow, October 15th, is Blog Action Day, where blogs can comment on the environmental aspects of what they do.
Simply put, don't mail payments to people or have them mail payments to you! Save the gas, paper, and reduce carbon emissions associated with business as usual for the past 100 years:
- don't create or mail paper invoices-email them with a link on the email to your website to accept online payment
- don't create paper checks: pay electronically by creating an ACH (e-check) and crediting the payee-saves postage, time, effort, gas and waste
- don't make your clients or customers expect that they have to mail you a check-accept payments electronically via e-check or credit card-and you can do that over the phone, e-fax (saves paper over regular fax), by email, or online
- ask your bank and credit card processor to convert you to electronic statements-you get them faster and without wasting the paper for an envelope or a stamp
That's only 4 ways. There are so many more which we can explore creatively and effectively. Ask us. Challenge us. We will find a way to make payments more environmentally-friendly.
Labels:
Blog Action Day,
environment,
green,
save paper
Tuesday, October 9, 2007
Response to our posting yesterday on the change of the law in Connecticut
Here's a response we just received to our posting on the new law in Connecticut (see posting dated 08Oct07):
That's EXACTLY the type of response that makes us feel this blog is worthwhile-helping one client at a time...
Please tell others about this law. It affects all of us in one way or another and other states are adding the law to their books.
If anyone has a question about best practices, please contact us for a no-obligation phone consultation.
Hi Marc,
thanks for the update on the new bill. I printed it off and will review to make sure we are covered. I believe we are doing most of the suggestions already. Your blog is great.
SC
thanks for the update on the new bill. I printed it off and will review to make sure we are covered. I believe we are doing most of the suggestions already. Your blog is great.
SC
That's EXACTLY the type of response that makes us feel this blog is worthwhile-helping one client at a time...
Please tell others about this law. It affects all of us in one way or another and other states are adding the law to their books.
If anyone has a question about best practices, please contact us for a no-obligation phone consultation.
Monday, October 8, 2007
The law in Connecticut has changed
Public service announcement to my Connecticut clients:
Connecticut Substitute Bill 1089 was enacted as of 01Oct07. It places the onus on each merchant, organization, or company to:
By adopting the credit card payment industry's PCI DSS compliance(Payment Card Industry Data Security Standard), you can make strides towards protecting yourself from this liability:
1. Install and maintain a firewall configuration on any computer to protect cardholder data-these are easy to get and free.
2. Do not use vendor-supplied defaults for system passwords and other security passwords-change them and make them as difficult as possible to guess or steal.
3. Protect stored cardholder data: lock up any receipts or paperwork that contains full credit card numbers and names, addresses, etc. When no longer needed, shred it!
4. Encrypt transmission of cardholder data across open, public networks-do not email this data under any circumstances.
5. Use and regularly update anti-virus software-this is obvious.
6. Develop and maintain secure systems and applications-document the security methods and stick to them.
7.Restrict access to cardholder data by business need-to-know: do not trust employees, in-house volunteers or temp workers with access to this information!
8.Assign a unique ID to each person with computer access-each employee should get an ID and password so you can track the access to this data if you had to.
9.Restrict physical access to cardholder data-lock it up or shred it
10.Track and monitor all access to network resources and cardholder data-again, be careful and question anything that looks suspicious. If you had a breach of security, the sooner you act on it, the better!
11.Regularly test security systems and processes-this helps protect you. Set a schedule to do this NOW so you do not forget.
12.Maintain a policy that addresses information security-write it down, have your employees read and agree to it.
While these steps will not completely protect you (nothing will), heightened awareness of the need to maintain security of personal financial data and documenting the precautions you have taken will avert the serious financial penalties you might otherwise face.
If you have any questions, please let us know.
Connecticut Substitute Bill 1089 was enacted as of 01Oct07. It places the onus on each merchant, organization, or company to:
- disclose any breach of personal financial data originating from your location to the authorities without unreasonable delay
- that party shall be liable to a bank whose customers’ personal financial data was compromised, for any costs, to protect their financial interests, including :
–Cancelling credit or debit cards or accounts,
–Closing any account or blocking any transactions,
–Opening or reopening any accounts,
–Refunding any account,
–Any assistance to customers.
(highlighting added for emphasis)
HOW DO YOU KEEP THIS FROM HAPPENING TO YOU?By adopting the credit card payment industry's PCI DSS compliance(Payment Card Industry Data Security Standard), you can make strides towards protecting yourself from this liability:
1. Install and maintain a firewall configuration on any computer to protect cardholder data-these are easy to get and free.
2. Do not use vendor-supplied defaults for system passwords and other security passwords-change them and make them as difficult as possible to guess or steal.
3. Protect stored cardholder data: lock up any receipts or paperwork that contains full credit card numbers and names, addresses, etc. When no longer needed, shred it!
4. Encrypt transmission of cardholder data across open, public networks-do not email this data under any circumstances.
5. Use and regularly update anti-virus software-this is obvious.
6. Develop and maintain secure systems and applications-document the security methods and stick to them.
7.Restrict access to cardholder data by business need-to-know: do not trust employees, in-house volunteers or temp workers with access to this information!
8.Assign a unique ID to each person with computer access-each employee should get an ID and password so you can track the access to this data if you had to.
9.Restrict physical access to cardholder data-lock it up or shred it
10.Track and monitor all access to network resources and cardholder data-again, be careful and question anything that looks suspicious. If you had a breach of security, the sooner you act on it, the better!
11.Regularly test security systems and processes-this helps protect you. Set a schedule to do this NOW so you do not forget.
12.Maintain a policy that addresses information security-write it down, have your employees read and agree to it.
While these steps will not completely protect you (nothing will), heightened awareness of the need to maintain security of personal financial data and documenting the precautions you have taken will avert the serious financial penalties you might otherwise face.
If you have any questions, please let us know.
Monday, October 1, 2007
Time flies...

It's October 1st.
At dinner on Saturday night a friend was lamenting the end of the 3rd quarter and meeting his sales quota. I had lost track of time-I forgot it was the end of the 3rd quarter.
Then I remembered: In August during a summer evening in New York City, we were amazed the convenience stores had started to show their Halloween displays. That candy will certainly be stale at the end of October!
In October we start seeing Christmas and Hanukkah displays.
Soon it will be Thanksgiving.
What does that tell you? The year end is fast approaching.
If cash flow has been a primary focus for this year and you haven't gotten around to improving it, start now. No time like the present.
Ask us how.
Thursday, September 27, 2007
National Customer Service Week
The Congress, by Senate Joint Resolution 166, has designated the week of first week of October, as "National Customer Service Week."
I disagree-I think every day of every week should be customer service-oriented.
A client just emailed me with a problem. Knowing the right people to help, I referred him to the vendor (since this was an ID and password issue, it was not something I am allowed to fix, but I knew who could help).
In minutes, the problem was fixed and I received this email from my client:
Marc,
Thanks for the fast return. I was not expecting it so fast. It is all set and up. SUPER!
Thanks again
Paul
Customer service-It's just what we do. Every day.
I disagree-I think every day of every week should be customer service-oriented.
A client just emailed me with a problem. Knowing the right people to help, I referred him to the vendor (since this was an ID and password issue, it was not something I am allowed to fix, but I knew who could help).
In minutes, the problem was fixed and I received this email from my client:
Marc,
Thanks for the fast return. I was not expecting it so fast. It is all set and up. SUPER!
Thanks again
Paul
Customer service-It's just what we do. Every day.
Subscribe to:
Posts (Atom)