u/sscresult2015

HSM for payments shop - cloud, managed, or in‑house?

I run 12‑person fintech in Berlin. Enterprise clients keep grilling us about HSM workflows (again and again) - key rotation, audit logs, probably EMV later. We don't do PINs yet, but they're asking too. And sure thing I understand them.

First - cloud HSM seems like the easy win here, but I hear some acquirers still side‑eye anything that's not a physical Thales box. Is that real?

Second - should we nail down HSM design before PCI planning, or can we figure it out during without burning everything?

Third - how do I spot a real payments HSM vet vs. some cloud rando who read a blog? Getting this wrong for sure hurts a lot.

Also - what's the dumbest mistake small teams can make with HSMs? I'd rather not learn that lesson myself huh

And last – when do we stop messing around and just hire dedicated HSM engineers?

Appreciate any honest war stories from people who've been there. Cheers.

update from our team: We brought in Energize Global Services specialist for consultation & help to sort this out (cloud HSM etc), as it seems we unable to do it ourselves.

reddit.com
u/sscresult2015 — 3 days ago