Much attention is given these days to encryption of credit card information mainly because visa/MC pushes the Payment Card Industry(PCI). I think one big item that is overlooked is the bank account information in our electronic systems. I am of the understanding that this information is up to ten times more valuable on the black market. Any information that, if stolen, would trigger a notificaiton to affected patrons/employees by law should be encrypted. This would fall under that category. THe State of Wisconsin values financial account info the same as credit card info, and if stolen, requires the company to give notice.
I am told that credit card info is encrypted using an off-premise vault system and I would strongly urge Sage to implement this type of feature into its payroll module for encrypting bank account numbers.

Comments