Axcess Payment Services strengthens payment data security with GuardWare deployment

Nick Fox, CEO of Axcess Payments Group

Axcess Payment Services has deployed GuardWare’s persistent file-level encryption platform to strengthen the protection of payment and business-critical data in an increasingly remote and interconnected operating environment.

The deployment forms part of Axcess Payment Services’ wider security strategy to address one of the most challenging areas in modern payments security: protecting sensitive data once it leaves traditional security boundaries.

White paper

The project is documented in a newly published white paper by Axcess Payments Group CEO Nick Fox, offering practical insights for payment organisations seeking to strengthen PCI DSS compliance, mitigate supply chain risk and protect sensitive data beyond traditional security boundaries.

While organisations continue to invest heavily in endpoint protection, cloud security and network controls, Axcess identified a key security challenge common across many businesses. Data may be encrypted while stored or transmitted but often becomes accessible once opened, creating potential exposure if files are intercepted, shared inappropriately, or obtained through cyberattack, insider activity or third-party compromise.

As a provider operating under PCI DSS Level 1 compliance, Axcess Payment Services undertook a review of its security architecture to evaluate how payment-related and business-sensitive information could be protected throughout its lifecycle, regardless of where that data resides.

“Payment security has evolved significantly over the last decade, but many security models still focus primarily on protecting the environment rather than protecting the data itself,” said Nick Fox, CEO of Axcess Payments Group.

Protected and unusable

“As payment providers, we must assume that attempted compromises will occur. The important question is what happens if data is accessed or exfiltrated. Our objective was to ensure that any information leaving a controlled environment remains protected and unusable to unauthorised parties.”

Following a market evaluation, Axcess selected GuardWare to add a persistent, data-centric security layer to its existing technology stack, which includes CrowdStrike Enterprise, Microsoft Defender, Microsoft 365 and AWS-native security controls.

GuardWare’s platform combines deep data discovery, monitoring and file-level protection technologies designed to maintain security controls around data regardless of location, device or network. The deployment enables Axcess to apply encryption and governance controls directly to files, helping to reduce risks associated with remote working, third-party access and supply-chain relationships.

The implementation supports a range of PCI DSS security objectives, including the protection of stored account data, cryptographic key management, auditability and access control enforcement.

Supply-chain breaches

For organisations operating in the payments industry, these capabilities are becoming increasingly important as cybercriminals continue to target users and data rather than network infrastructure. AI-driven phishing attacks, business email compromise, ransomware operations and supply-chain breaches are placing growing pressure on payment organisations to demonstrate stronger governance and protection over sensitive information.

“Nick’s comments reflect exactly what we’re seeing across the payments sector: the assumption that a breach is a question of when, not if, and there is a need to protect the data itself rather than just the environment around it,” said Ian McKinley, CEO of GuardWare.

“Payment files carry some of the most sensitive information any organisation handles, and once they leave a controlled network, traditional perimeter tools simply can’t follow them. Our platform keeps encryption and governance attached to the file itself, whether it’s sitting in storage, moving through a supply chain, or open on a remote device, so the data stays worthless to anyone who shouldn’t have it. Working with a PCI DSS Level 1 provider like Axcess shows how data-centric security can sit alongside existing tools like CrowdStrike and Microsoft Defender to close that gap. It’s a model we believe the wider payments industry will need to adopt as attackers keep shifting their focus from networks to the data itself.  However, preparing for the inevitability of a data security breach is not unique to the payments industry, it is incumbent on all industries, whatever their sector or operation,” he added.

Data-centric security

Axcess believes data-centric security approaches will play an increasingly important role in helping payment organisations strengthen security resilience while supporting evolving compliance requirements.

“The payments sector has always been a prime target for cybercriminals because of the value of the data it holds,” added Nick.

“Protecting payment information requires more than perimeter defences. Security controls must travel with the data itself. Our deployment of GuardWare reflects our commitment to continually enhancing the security of our environment and ensuring the highest standards of protection for both our business and our merchant partners.”

Axcess reports that the deployment has enhanced its ability to protect sensitive data, strengthen audit readiness, support PCI DSS compliance activities and improve visibility into potential data security risks, while integrating seamlessly within its existing Microsoft, AWS and CrowdStrike environments.

Picture shows Nick Fox, CEO of Axcess Payments Group.