MDR Services

Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...

Incident Response

Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...

Gartner Recognised

Integrity360 has been recognised as a Gartner Representative Vendor.

Download our CyberFire MDR ebook

Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.

The hidden human costs of a cyber attack

Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories. 

The reality of ransomware in 2025: What you need to know

In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.

Your guide to 2026: Trends and Predictions

Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.

Cybersecurity testing services

Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.

What is PCI? Your most common questions answered

If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.

Weekly Threat roundups

Stay informed with the latest cybersecurity news with our weekly threat roundups.

The A-Z Glossary of cybersecurity terms

Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.

Read our latest blog

For many small and mid-sized businesses, cybersecurity can feel overwhelming.

Integrity360 completes SOC 2 certification to strengthen global cyber defence ecosystem

SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries. 

Integrity360 acquires Identity specialist CyberIAM

Integrity360 has acquired leading Identity specialist CyberIAM, a well-established and highly respected cybersecurity Identity services company operating from the UK and South Africa. 

Security First 2026

See the full list of our conferences across the UK, Europe, Africa & the Caribbean
Integrity360 Emergency Incident Response button Under Attack?

Your payment provider is secure. Is your payment page?

Wednesday, 23rd September at 11:00 BST | 12:00 CET / SAST

Web header-Reflectiz-PCI-ENG-23092026

 

 

Speakers

  • Martin Petrov, CTO - PCI, Integrity360



  • Leor Eliashiv, UK&I Country Manager, Reflectiz

 

Outsourcing payment processing can reduce PCI scope, but it does not outsource the security of the customer's checkout journey. A payment provider can remain secure while attackers compromise the web environment around it—using malicious scripts, tag managers and even trusted services to steal payment data inside the customer's browser.


Join Leor Eliashiv from Reflectiz and Martin Petrov from Integrity360 for a thought-leadership session examining how the modern web-skimming attack surface has evolved beyond the payment provider itself. Using recent Magecart campaigns that abused trusted infrastructure including Stripe APIs and Google Tag Manager, the session will show how attackers can impersonate legitimate payment experiences, execute malicious code in the browser and move stolen data through services that security teams already trust. Recent research illustrates precisely why this distinction matters: the payment provider itself does not need to be compromised for customers' payment data to be put at risk.

 

Attendees will walk through the anatomy of a modern checkout attack—from initial compromise and malicious script execution to card-data capture and exfiltration—and explore why server-side controls, traditional scanning, allowlists and other conventional defenses may have limited visibility into what is actually executing in the consumer's browser. PCI SSC has identified this browser-side attack surface as a significant payment-security concern and introduced specific PCI DSS v4.0.1 controls to address payment-page script integrity and tamper detection.

 

The discussion will conclude with the practical implications for merchants using hosted payments, embedded payment forms and other third-party payment integrations: where responsibility still sits, what PCI DSS expects, and how organizations can gain meaningful visibility across the checkout experience without assuming that a trusted payment provider eliminates the wider risk. PCI SSC's current SAQ A guidance reinforces this distinction for merchants using embedded payment forms, requiring them to address susceptibility to script-based attacks even where account-data functions are outsourced.

“I cannot commend your team’s work enough, and this opinion is shared throughout the senior management team. It is a testament to your thoroughness and expertise”
Head of Information Security Operations, Technology/SaaS