ITBriefcase Exclusive Interview: Securing Cloud Based Contact Centers with Dennis Empey, Echopass Corporation

Sep 11, 2013 | Cloud, Data, Fresh Ink, Security

In the following interview, Dennis Empey, chief information security officer at Echopass Corporation, discusses the serious risks to cloud-based contact centers – and what you should be doing today to protect your customers.

  • Q. What’s driving the need for cloud service providers to take such a heightened approach to security?

A. As cloud adoption expands, maintaining adequate security protection for applications managed from the cloud has become increasingly important. Dramatic market acceptance and growth rates of cloud-based applications and services are quickly colliding with an explosion in security intrusions and violations, requiring intensive and ongoing corporate vigilance to meet enhanced security standards.

Echopass Corporation believes that the threat of personal information theft will expand enormously in the future, and continued hacking and infrastructure intrusion will require significant additional allocation of resources to protect corporate assets, customer confidentiality and privacy. The well-publicized security breach incidents at T.J. Maxx and American Honda resulted in multiple millions of dollars of liability and court cases related to these intense, focused and well-organized attacks that have had significant repercussions for companies – and their customers that were on the receiving end of these malicious acts.

Source: Gartner Forecast Overview: Public Cloud Services, Worldwide, 2011-2016, 4Q update, February 8, 2013

  • Q. So where does PCI fit into these risks?

A. PCI DSS is a comprehensive set of international security requirements for protecting personal cardholder data. PCI DSS was developed by Visa and the founding payment brands of the PCI Security Standards Council (Visa, MasterCard, American Express, Discover, and JCB International) to help facilitate broad adoption of consistent data security measures on a global basis.

Customer facing contact center solutions are quickly moving to the cloud, putting additional pressure on the “front lines” for Payment Card Industry Data Security Standard (PCI DSS) compliance. That includes processes for requesting, entering and storing of personal and confidential customer information such as social security numbers, credit card numbers and CCV (card code verification) by today’s geographically dispersed contact center agents.

  • Q. How serious is the threat, specifically for contact center providers?

A. Credit card data theft has exploded, increasing 50 percent between 2005 and 2010, according to the latest figures from the U.S. Department of Justice. Millions of credit card numbers are for sale for as little as $10, according to Monica Hamilton, marketing director at McAfee. (Source: USA Today April 14, 2013).  And the number of malicious computer programs written to steal confidential information has grown from about one million in 2007 to an estimated 130 million today, according to Hamilton. Key elements to protect against personal information theft include awareness, security of personal devices, and the reliance on businesses to protect the use of customer’s personal information by implementing stringent security practices and conforming to strict PCI DSS requirements.

  • Q. Doesn’t anyone processing or storing credit card information need to be PCI compliant?

A. In the past, and despite the growth of cyber-crime, cloud service provider companies had the option to support PCI DSS processes and confidentiality through “Self-Attestation” and a Self-Attestation Questionnaire (SAQ) to comply with the Level 2 standards required by the PCI Standards Security Council.  While conformance to Level 2 “Self-Attestation” is important, today’s business and customer care environment demands a much more stringent approach. As PCI Compliance below Level 1 certification is performed on the honor system, it becomes even more critical that companies maintain their vigilance and due diligence.

Regardless of the number of transactions involved, it is essential to provide greater scrutiny and maximum compliance with PCI DSS standards to prevent ever-increasing attack efforts and the huge financial liabilities for the companies under attack.

  • Q. Is that what motivated Echopass to go the full extent of Level I certification?

A. Exactly. At Echopass, we process millions of calls a month for some of the largest companies in the Fortune 500. These large organizations often require consumers to provide confidential credit card information as part of their interactions. We believe that the need to operate at the absolute highest levels of conformance to ensure both client and customer security is critical regardless of transaction volumes.

In February 2013, and in response to the current growth of cloud services, a new update to PCI DSS Version 2.0 was released by the special Cloud Special Interest Group of the PCI Standards Security Council. Although not required for every contact center, implementing and adhering to the most current set of PCI DSS security measures are critical and essential steps for any cloud provider seeking to demonstrate conformance and compliance with the latest accepted PCI standards.

The need for utmost attention and discipline around PCI DSS compliance is paramount to protect consumers and the companies that they do business with. This requires PCI Level 1 certification, complete with a rigorous audit by a QSA and ongoing periodic review of all policies and procedures to ensure continued Level 1 compliance and protection of customer data and privacy.

  • Q. Looking forward, what message would you send to other cloud providers who are evaluating – or maybe not even considering – the available methods to protect their customers’ data?

A. As a cloud service provider, we strongly believe the dramatic cloud-based contact center adoption signals the need for more discipline, tools and adherence to full Level 1 PCI compliance and certification to confront the growing security threats. If they haven’t already, companies also should initiate full-time security alertness and mentoring by positions such as the recently created Chief Information Security Officer that is quickly gaining importance.

Cyber-attacks will continue to escalate over time. It is incumbent upon responsible organizations to seek suppliers and environments that conform to the highest levels of security. Managing to the highest standards of security provisioning, inspection, and diligence is an on-going requirement that dictates continued observance if organizations are to properly protect their clients, and most importantly, their client’s customers.

Dennis Empey

Chief Information Security Officer and Senior Vice President, Service Delivery

Dennis Empey is responsible for all security within the Echopass environment and for the Echopass service delivery platform, and is the senior product strategist, setting direction for all Echopass platforms, products and services. His 20 years of product management and marketing experience includes tenure as vice president and general manager for Argogroup and key management roles with Lucent Technologies’ Service Provider Messaging division including responsibility for all international markets.

Earlier in his career, Dennis also was responsible for advanced network services products as a senior marketing and product manager at MFS Intelenet, and managed enterprise ACD products and services at Nortel.

He holds a B.S. in management from Golden Gate University.

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more