SHOW / EPISODE

PCI DSS 4.0: Who Really Owns Payment Security Risk?

Episode 3
52m | Jul 23, 2026

When a payment page breach happens, who is actually accountable: the merchant, the processor, the PSP, or the vendor whose script got compromised? This episode brings together security leaders from across the payment chain to answer that question.


What's covered:

Where PCI DSS 4.0 succeeds and where it leaves gaps in payment security accountability.

How requirements 6.4.3 and 11.6.1 apply to real third-party script monitoring.

Why client-side vulnerabilities create cardholder data exposure that server-side controls miss.

How global retail, e-commerce, and payment processing teams are dividing payment security responsibility in practice.

What compliance teams should do differently once checking the PCI box is not enough.


Speakers: Una Dillon, Regional Director Europe, PCI Security Standards Council; Deepak Kumar, CISO, APEXX Global; Pete Chenery, Global Head of Cyber Security, Naked Wines; Mark Barry, Senior Security Operations Manager, Domino's Pizza; Leor Eliashiv, UK Regional Manager, Reflectiz.


Key terms: PCI DSS 4.0, payment security, client-side security, cardholder data protection, third-party risk, Magecart, checkout page security.


Explore Reflectiz's payment security resources and PCI compliance guides at reflectiz.com/demo. A good next step if you're mapping out where your own payment risk ownership breaks down.

Paused
Audio Player Image
Reflections: Web Security Podcast
Loading...