Well then, the method I described earlier would work for you; Exposure is limited to clients actually giving their passwords and/or using the credit cards _while the system is compromised_ ; It mitigates the risk that you keep hearing about in breaches, of _all_ accounts being exposed.
And just remember, that by storing those numbers locally, you're also taking potential liability for things that go wrong. To assess how much that is in cash, call a few insurance companies and ask them to give you a quote. Assume they have 25% markup on the real cost; That's how much you are "paying", although you are not doing it out-of-pocket (Though, in a catastrophic event, you _will_ be paying a lot)
Comments
Well then, the method I described earlier would work for you; Exposure is limited to clients actually giving their passwords and/or using the credit cards _while the system is compromised_ ; It mitigates the risk that you keep hearing about in breaches, of _all_ accounts being exposed.
And just remember, that by storing those numbers locally, you're also taking potential liability for things that go wrong. To assess how much that is in cash, call a few insurance companies and ask them to give you a quote. Assume they have 25% markup on the real cost; That's how much you are "paying", although you are not doing it out-of-pocket (Though, in a catastrophic event, you _will_ be paying a lot)