
NEWS & INSIGHTS
The latest industry insights & news from CCSI, Specialists in Establishing Contact Centers in Mexico for Debt Collection, Customer Service, Sales, BPO and more.

NEWS & INSIGHTS
The latest industry insights & news from CCSI, Specialists in Establishing Contact Centers in Mexico for Debt Collection, Customer Service, Sales, BPO and more.
Contact centers that store, process, transmit, or otherwise handle payment card information must take information security seriously. The Payment Card Industry Data Security Standard (PCI DSS) provides a framework designed to protect payment account data and reduce the risk of security incidents involving cardholder information.
If your contact center handles payment card information, you may already be familiar with the Payment Card Industry Data Security Standard (PCI DSS), a global security standard developed to help organizations protect payment account data.
The original version of this article was published in 2017. Since then, PCI DSS has evolved substantially. The current PCI Security Standards Council documentation should always be consulted when determining which requirements apply to a specific organization or cardholder data environment.
Organizations working toward PCI DSS compliance — as well as those that have already validated compliance — should remember that information security is not a one-time project. Security controls, employee awareness, systems, access privileges, service providers, and testing procedures all require ongoing attention.
For organizations evaluating a nearshore operation that may handle sensitive customer or payment information, CCSI's cybersecurity certifications and compliance standards provide additional information about the security frameworks supporting CCSI operations.
The following seven recommendations were included in the original article. They remain useful security principles, but the explanations have been updated to better reflect modern PCI DSS terminology and information security practices.

Each individual should have a unique account so that access and activity can be associated with a specific person. Shared accounts make accountability and security monitoring more difficult.
Authentication credentials should be protected and should not be shared between employees. PCI DSS also includes requirements for strong authentication and multi-factor authentication in applicable environments.
Individual identification helps organizations maintain accountability, investigate suspicious activity, and determine which users accessed particular systems or information.
Access to cardholder data and security-sensitive systems should be limited according to business need and job responsibility.
Not every employee requires access to the same applications, databases, files, or administrative functions. Applying least-privilege principles reduces unnecessary exposure and limits the potential impact of compromised credentials or inappropriate access.
This principle is especially important in contact center environments where large teams may interact with customer information through multiple applications and communication channels.
The original article recommended properly configuring firewalls. That remains relevant, but modern PCI DSS terminology more broadly addresses network security controls.
Organizations should establish and maintain appropriate controls between trusted and untrusted networks and carefully manage traffic entering or leaving environments that contain or can affect payment account data.
Security devices and configurations should also be reviewed and maintained rather than treated as a one-time installation.
Strong network controls are one part of the broader security infrastructure required to support enterprise IT and contact center operations.
The original recommendation was to use antivirus software on every computer. Today's security environment requires a broader approach to protection against malicious software.
Anti-malware technologies should be implemented where appropriate, kept current, monitored, and supported by additional security controls designed to detect and prevent malicious activity.
Organizations should also maintain security updates, manage vulnerabilities, and continuously review their systems as threats and attack techniques evolve.
Information security is strongest when multiple layers of protection work together rather than relying on a single security product.
Technology alone cannot protect sensitive information. Employees remain an important part of an organization's security program.
Security awareness training should help employees understand how their actions can affect payment information, customer data, systems, and the organization itself.
Training can address topics such as credential security, phishing, social engineering, appropriate system use, suspicious activity, data handling, incident reporting, and applicable company security policies.
Security awareness should not end after employee onboarding. Regular training and reinforcement can help keep security responsibilities visible as threats, systems, and business processes change.
Information security is a continuous process. Systems, applications, vulnerabilities, attack techniques, and business processes change over time.
Organizations should regularly test security controls and procedures to identify weaknesses before they become security incidents.
Depending on the organization's PCI DSS scope and validation requirements, this may include vulnerability scanning, penetration testing, monitoring, security-control testing, and other assessment activities.
Testing should also evaluate operational procedures. A security policy provides limited protection if employees and systems do not consistently follow it.
Related Reading: Cybersecurity & IT Compliance for Contact Centers
Third-party service providers can affect an organization's PCI DSS responsibilities, particularly when they store, process, transmit payment account data or can affect the security of the cardholder data environment.
Organizations should perform appropriate due diligence, clearly define security responsibilities, maintain applicable agreements, identify which PCI DSS requirements are being managed by each party, and monitor the compliance status of relevant third-party service providers.
Simply outsourcing a function does not automatically outsource responsibility for protecting payment information.
This is particularly relevant when selecting a contact center or BPO partner that will interact with payment systems, financial information, customer records, or other sensitive data.
One of the most important principles from the original article remains unchanged: PCI DSS compliance and information security require continuous attention.
Access privileges change. Employees join or leave organizations. New applications are introduced. Vendors change. Vulnerabilities are discovered. Security threats evolve.
Organizations should therefore continue reviewing their security controls, employee access, training, systems, third-party relationships, and assessment requirements throughout the year rather than focusing on security only when an audit or validation deadline approaches.
The official PCI Security Standards Council Document Library should be consulted for the current PCI DSS standard, guidance, validation documents, and supporting resources.
Payment security is also part of a much broader cybersecurity environment. Modern contact centers may handle personally identifiable information, healthcare information, financial data, customer account information, authentication credentials, and other sensitive records depending on the client program.
A mature security program therefore combines access management, employee awareness, network security, endpoint protection, vulnerability management, monitoring, incident response, risk management, and appropriate compliance frameworks.
CCSI's current security framework includes PCI DSS alongside SOC 2, HIPAA, and ISO 27001 standards and certifications supporting operations for clients in regulated industries.
For organizations processing customer payments, CCSI also offers an Integrated Payment Solution designed to support secure payment processing across multiple customer channels.
Call Center Services International (CCSI) helps U.S. companies establish and manage secure, high-performance bilingual nearshore contact centers in Mexico.
CCSI operates under recognized cybersecurity and compliance frameworks designed to support organizations handling sensitive customer and business information. Current CCSI security certifications and standards include SOC 2, PCI DSS, ISO 27001, and HIPAA compliance.
In addition to information security controls, CCSI provides professional facilities, bilingual and bicultural personnel, technology infrastructure, administrative support, quality assurance, and operational resources to help clients establish scalable nearshore operations.
Explore CCSI's Cybersecurity & Compliance Standards
Historical note: This article and infographic were originally published in 2017. The original seven security recommendations have been preserved, while terminology and guidance have been updated to reflect the current PCI DSS security framework. Organizations should consult the current PCI Security Standards Council documentation and their applicable compliance authority when determining specific PCI DSS requirements.
Originally published: May 1, 2017
Last reviewed and updated: July 25, 2026