HSM for payments shop - cloud, managed, or in‑house?
I run 12‑person fintech in Berlin. Enterprise clients keep grilling us about HSM workflows (again and again) - key rotation, audit logs, probably EMV later. We don't do PINs yet, but they're asking too. And sure thing I understand them.
First - cloud HSM seems like the easy win here, but I hear some acquirers still side‑eye anything that's not a physical Thales box. Is that real?
Second - should we nail down HSM design before PCI planning, or can we figure it out during without burning everything?
Third - how do I spot a real payments HSM vet vs. some cloud rando who read a blog? Getting this wrong for sure hurts a lot.
Also - what's the dumbest mistake small teams can make with HSMs? I'd rather not learn that lesson myself huh
And last – when do we stop messing around and just hire dedicated HSM engineers?
Appreciate any honest war stories from people who've been there. Cheers.
update from our team: We brought in Energize Global Services specialist for consultation & help to sort this out (cloud HSM etc), as it seems we unable to do it ourselves.