The Malta Independent 4 September 2026, Friday
View E-Paper

Maltese Company qualifies to assess credit card payments

Malta Independent Saturday, 22 March 2008, 00:00 Last update: about 14 years ago

Kyte Consultants Ltd is the first Maltese company to be validated as a Qualified Security Assessor Company (QSAC) by the Payment Card Industry (PCI) Security Standards Council in the US, the company said in a statement.

This means that payment gateways, processors and merchants no longer need to acquire the services of an overseas firm to be certified as being Payment Card Industry Data Security Standard (PCI DSS) compliant.

This will result in considerable savings on fees and expenses.

The PCI, which is comprised of representatives from the major card brands, such as Visa, MasterCard, American Express, Discovery and JCB, had developed specific standards for companies that process, store or transmit credit card data. The standard is called the Data Security Standard (DSS) and all companies who handle credit card data had to comply with this standard once the implementation of the standard became mandatory. It then became necessary for the PCI Security Standards Council to validate companies who are qualified to certify merchants and payment processors as being compliant to the standard.

The directors of Kyte had to undergo a lengthy and rigorous application process, overseas training, and satisfy very stringent and extensive insurance requirements before being validated. The latter requirement proved to be the biggest challenge of all, but it too was finally satisfied.

On 12 February, Kyte Consultants Ltd were added to the list of Qualified Security Assessors (https://www.pcisecuritystandards.org/pdfs/pci_qsa_list.pdf) and they are now able to provide their services throughout Europe, including Malta.

Alan Alden and Trevor Axiak, Directors of Kyte Consultants Ltd, said that in its short period of time as an IT audit and security-focused company this was definitely their hardest earned but proudest achievement. They are confident that the local companies will utilise their services as it will be more convenient and less costly for them than hiring an overseas firm with the same credentials as Kyte.

Mr Alden and Mr Axiak are both Certified Information Systems Auditors (CISA). Combined with their experience in the IT audit and security field and their other information security certifications, namely Certified Information Systems Security Professional (CISSP) and Systems Security Certified Practitioner (SSCP), this helped them achieve the qualification and experience requirements specified for QSAs. Last September, they also attended training in Prague. Annual training of QSAs is a requirement of the PCI Security Standards Council for them to maintain their validation.

  • don't miss