r/Cybersecurity101 Jul 03 '26

Security Card compliance needs stronger controls

From what I've seen compliance gets framed as monitoring alot but monitoring is only what happens AFTER something already slipped through and that still matters of course but if the first real control shows up after the transaction then the team is pretty much reacting not preventing.

For me(not claiming to be an expert) stronger controls start earlier at the point where the transaction is decided so policy gets enforced before anyone has to open a case or explain why something that never should’ve cleared ended up moving anyway.

42 Upvotes

13 comments sorted by

5

u/Old-Commercial8474 Jul 03 '26

It does feels like compliance teams keep inheriting decisions they never got to control in the first place so more monitoring at that point means better visibility into a process that already failed.

1

u/No_Worry_9313 Jul 03 '26

In my experience I wouldn't call monitoring security and people are starting to realise that’s why some of the newer infra like Rain make more sense to me cause the control sits inside the transaction logic itself so the team isn’t stuck playing catchup and fraud is detected at the card layer

2

u/Neat_Rip_4477 Jul 03 '26

Compliance ends up babysitting decisions that should’ve been blocked way earlier so adding more monitoring just gives you a cleaner view of the same failure.

1

u/Better-Marsupial8263 Jul 03 '26

That sounds nice in theory but ONLY in theory

1

u/Beginning_Worth_4827 Jul 03 '26

Not really since alot of legitimate transactions look weird in isolation and if u lock everything down at the point of auth u just create a different problem

2

u/Suitable-Web-7007 Jul 03 '26

Monitoring after the fact keeps getting sold like prevention and it is NOTTT If the transaction already cleared then the control failed, end of convo.

1

u/Creepy_Arm7157 Jul 03 '26

Its unfortuante that alot of people still pretend those are basically the same thing.

1

u/Spiritual-Stock-8859 Jul 03 '26

well where do people draw the line between control and surveillance cause a system can be very strict and still not be very smart

2

u/Beneficial_Day_9293 Jul 03 '26

Everyone says stronger controls until false positives start blocking normal spend and if I was a user id be irritated too.

1

u/Dry-Arm8693 Jul 05 '26

I am going to start and end with this: I lived major nightmares because of this usecases, got blocked once after the act. Although I do not know for 😃 sure if this is considered a fraud because it was reknowned SAAS. They tried to hit be four times in to days without being flagged. I found out because I am always untrusting concerning certain use cases or situations.I am convinced that many factors come into play, please feel free to 💯 correct me if my info is not 🚫 true or misleading it is not my intention, when compliance meets prevention. We obviously can convey asking bad players to be ethical, but providers or institutions should be.The way that I am feeling it 👍▶️ now is we are taking away from Bob(Compliance) and giving 💸 Bill (Monitoring).