Axcess Payment Services, a regulated payments business based in Leeds, has partnered with GuardWare to enhance their data security and ensure compliance with the highest tier of the payment card industry’s data security standard.
In a white paper authored by Axcess Payments Group CEO Nick Fox, the company’s strategic shift towards persistent, data-centric protection is documented. This move is aimed at addressing the gap in their data security architecture, specifically at the point where sensitive data leaves controlled environments.
Axcess Payment Services currently operates as a PCI DSS Level 1 compliant organization and has invested in various security platforms, including CrowdStrike Enterprise, Microsoft Defender, Microsoft 365, and AWS-native controls. However, a recent internal review revealed a critical limitation shared by all of these platforms – the lack of persistent file-level protection once data leaves controlled environments.
As a remote-first organization, where data frequently crosses device, network, and organizational boundaries, this limitation poses a significant risk. Encrypted files become readable as soon as they are opened, even by unauthorized parties who may have obtained them through exfiltration, insider action, or supply chain compromise.
In the white paper, Fox states, “We adopted the assumption that data compromise is possible, and that controls must ensure any exfiltrated data remains unusable to an attacker.”
After a thorough market evaluation, Axcess Payment Services chose GuardWare for its ability to extend protection to the data itself, rather than just the perimeter containing it. The platform’s three core modules, Insight, Discover, and Protect, introduce a data-centric security layer that operates independently of network boundaries and persists across all data states, including during active use.
Protect applies hybrid AES-256 and RSA-2048 encryption at the file level, with unique per-file keys, automated rotation, and decentralised key management to eliminate single-point compromise. Additionally, encryption is maintained not just at rest and in transit, but also while files are actively being used, addressing the window of exposure that conventional controls often leave open.
Discover performs deep content inspection across endpoints, Microsoft 365, and SharePoint environments, including data embedded within images, a vector that conventional data loss prevention tools frequently miss. Insight provides real-time visibility into data movement, anomalous access patterns, and potential exfiltration activity across online, offline, and air-gapped environments.
The white paper outlines a detailed mapping of GuardWare capabilities to ten specific PCI DSS Level 1 requirements, including stored cardholder data protection, cryptographic key management, least-privilege access enforcement, forensic audit trail generation, and incident response.
The deployment aligns with a threat environment that is becoming increasingly difficult for perimeter-based defenses to address. According to the white paper, AI-driven phishing and social engineering, deepfake impersonation targeting financial workflows, ransomware-as-a-service operations, and advanced persistent threats are among the primary vectors that now bypass traditional network controls, targeting users and data rather than infrastructure.
Supply chain and third-party access risk are also identified as major concerns, with GuardWare’s file-level governance extending access controls to external participants, regardless of device or network.
According to Ian McKinley, CEO of GuardWare, “Nick’s comments reflect what we’re seeing across the payments sector – the assumption that a breach is a question of when, not if, and the need to protect the data itself rather than just the environment around it.” He adds, “Our platform keeps encryption and governance attached to the file itself, whether it’s sitting in storage, moving through a supply chain, or open on a remote device, ensuring the data remains worthless to anyone who shouldn’t have it. Working with a PCI DSS Level 1 provider like Axcess shows how data-centric security can work alongside existing tools to close that gap. We believe this model will become necessary for the wider payments industry, as attackers continue to shift their focus from networks to the data itself. However, preparing for the inevitability of a data security breach is not unique to the payments industry; it is incumbent on all industries, regardless of their sector or operation.”
Axcess Payment Services reports that the deployment of GuardWare has strengthened their evidence of PCI DSS Level 1 compliance, reduced exposure to insider and supply chain risks, improved forensic visibility and audit readiness, and maintained productivity across remote and offline workflows, without causing any operational disruption to existing Microsoft, AWS, and CrowdStrike environments.
The partnership between Axcess Payment Services and GuardWare is a significant step towards data-centric security and demonstrates the importance of protecting data at all times, regardless of location, device, or network state.