Security in Focus: Practical Ways to Strengthen Your Payment Defences

September 30, 2026

Security in Focus: Practical Ways to Strengthen Your Payment Defences

October is Cyber Security Awareness Month, an annual opportunity for businesses to review how they protect their systems, data and customers from evolving online threats.

For businesses taking payments, that conversation is particularly important.

Fraudsters continually change the way they operate, and the latest UK figures show that both cyber attacks and payment fraud remain significant challenges.

The UK Government’s Cyber Security Breaches Survey 2025/26 found that 43% of businesses had identified a cyber security breach or attack during the previous 12 months. Phishing remained by far the most common type, experienced by 38% of businesses.

Meanwhile, UK Finance’s latest Annual Fraud Report found that criminals stole £1.28 billion through payment fraud during 2025. Remote purchase fraud – where stolen card details are used to make purchases online, over the phone or by mail order – accounted for £423.5 million of losses, with cases increasing by 13% to 3.2 million.

For Merchants, it reinforces an important point: payment security isn’t something to configure once and forget about.

Security works best in layers

There is no single setting or fraud prevention tool that can identify every suspicious transaction.

Different controls protect against different risks, which is why a layered approach is so important.

For Cardstream Merchants, there are a number of tools available within the Gateway that can form part of that approach. Two worth reviewing this Cyber Security Awareness Month are Velocity Checks and IP whitelisting/locking.

What are Velocity Checks?

Not every fraudulent transaction looks obviously fraudulent in isolation.

Sometimes, it is the pattern around the transaction that provides the warning sign.

A sudden burst of transactions from the same card, repeated payment attempts over a short period or unusual transaction values can all warrant closer attention.

Cardstream’s Velocity Checking system allows Merchants to create rules which monitor transactions against configurable thresholds.

For example, a rule might look at the number of matching transactions received during a particular period, the combined value of those transactions or whether an individual transaction exceeds a defined value.

Rules can also group transactions using properties including:

  • Card number
  • Customer IP address
  • Customer email
  • Merchant
  • Currency
  • Transaction purpose or outcome
  • Merchant customer reference

If the threshold is exceeded, the rule can generate an email notification and, where configured, decline the transaction.

This means Merchants have the flexibility to set controls that reflect the way their own business normally processes payments rather than relying on a single generic threshold.

Getting the balance right

Velocity Checks are most useful when the rules reflect genuine transaction behaviour.

Set thresholds too high and potentially suspicious patterns may not be detected. Set them unnecessarily low and legitimate customer activity could be interrupted.

That makes regular review important.

Consider whether your transaction volumes have changed, whether you have introduced new products or services, expanded into different markets or seen changes in normal customer behaviour.

It is also worth reviewing how frequently rules are triggered. A rule that never triggers may need revisiting, while one that triggers constantly may no longer reflect normal trading patterns.

The Cardstream Merchant Management System provides an overview of configured VC Rules, including their thresholds, time windows, grouping, state and the number of times each rule has been triggered.

Restricting Direct Integration with IP whitelisting

Another simple but useful layer of protection is controlling where Direct Integration requests can originate.

Cardstream allows Merchants using Direct Integration to configure authorised IP addresses within the MMS.

Requests received from non-authorised IP addresses are not accepted. Different permission levels can also be applied, with standard authorised IPs able to perform Sales and Preauthorisations and advanced authorised IPs supporting additional operations including Refunds, Captures and Cancels.

In practice, this helps ensure that sensitive payment operations are only being requested by systems you expect and trust.

If your infrastructure changes – perhaps because you migrate hosting provider, introduce a new server or make changes to your integration – remember to review your authorised IP configuration at the same time.

Don’t rely on one control

Velocity Checks and IP restrictions are only parts of a wider payment security strategy.

Depending on your integration and requirements, other measures available through the Cardstream Gateway include EMV 3-D Secure, request signing using a Signature Key, controls around card types and issuing countries, and third-party fraud prevention services.

The important thing is that these controls work together.

A strong security approach isn’t necessarily about adding as many checks as possible. It is about understanding your normal payment behaviour, choosing controls that address the risks relevant to your business and reviewing them regularly.

Review your Cardstream security settings

If you haven’t reviewed your payment security configuration recently, October is a good time to start.

Cardstream’s Knowledge Base includes guidance on creating and managing Velocity Check rules, alongside information on the risk functionality available through the Gateway.

And if you are unsure whether your existing configuration is right for your business, speak to the Cardstream Support team.

Review your settings today and make payment security part of your everyday business routine.