Security Measures for Banks and Non-Banks
摘要
When offering payment services, payment service providers (PSPs) are exposed to various security risks, such as payment fraud and cyberattacks. These risks are an increasing concern for PSPs for a number of reasons. First, the ever-increasing technological complexity of new electronic payment (Payment) products, such as the open banking products that were launched under PSD2 (i.e., products/services that qualify as account information services and payment initiation services within the meaning of PSD2), continue to create new and unanticipated security risks for PSPs. Second, payment service users nowadays demand near real-time processing of Payments, which significantly reduces the time frame for PSPs to adequately address any security concerns related to these transactions. For the establishment of an internal market for Payments it is essential to have a legislative framework that requires PSPs to adequately address these security risks. This chapter sets out the European framework covering security risk exposures for PSPs and the measures that PSPs must implement to minimise these risks to the extent possible. An important measure that is discussed in this chapter involves the obligation for PSPs to apply strong customer authentication.