
Axcess Payment Services strengthens payment data security with GuardWare deployment

Sydney, Australia, 23 July 2026
Axcess Payment Services, the PCI DSS Level 1 compliant technology division of UK-based Axcess Payments Group, has deployed GuardWare’s persistent file-level encryption platform to strengthen the protection of payment and business-critical data in an increasingly remote and interconnected operating environment.
The deployment forms part of Axcess Payment Services’ wider security strategy to address one of the most challenging areas in modern payments security: protecting sensitive data once it leaves traditional security boundaries.
The project is documented in a newly published white paper by Axcess Payments Group CEO Nick Fox, offering practical insights for payment organisations seeking to strengthen PCI DSS compliance, mitigate supply chain risk and protect sensitive data beyond traditional security boundaries.
While organisations continue to invest heavily in endpoint protection, cloud security and network controls, Axcess identified a key security challenge common across many businesses. Data may be encrypted while stored or transmitted but often becomes accessible once opened, creating potential exposure if files are intercepted, shared inappropriately, or obtained through cyberattack, insider activity or third-party compromise.
As a provider operating under PCI DSS Level 1 compliance, Axcess Payment Services undertook a review of its security architecture to evaluate how payment-related and business-sensitive information could be protected throughout its lifecycle, regardless of where that data resides.
“Payment security has evolved significantly over the last decade, but many security models still focus primarily on protecting the environment rather than protecting the data itself,” said Nick Fox, CEO of Axcess Payments Group.
“As payment providers, we must assume that attempted compromises will occur. The important question is what happens if data is accessed or exfiltrated. Our objective was to ensure that any information leaving a controlled environment remains protected and
unusable to unauthorised parties.”
Following a market evaluation, Axcess selected GuardWare to add a persistent, data-centric security layer to its existing technology stack, which includes CrowdStrike Enterprise, Microsoft Defender, Microsoft 365 and AWS-native security controls.
GuardWare’s platform combines deep data discovery, monitoring and file-level protection technologies designed to maintain security controls around data regardless of location, device or network. The deployment enables Axcess to apply encryption and governance controls directly to files, helping to reduce risks associated with remote working, third-party access and supply-chain relationships.
The implementation supports a range of PCI DSS security objectives, including the protection of stored account data, cryptographic key management, auditability and access control enforcement. For organisations operating in the payments industry, these capabilities are becoming increasingly important as cybercriminals continue to target users and data rather than network infrastructure. AI-driven phishing attacks, business email compromise, ransomware operations and supply-chain breaches are placing growing pressure on payment organisations to demonstrate stronger governance and protection over sensitive information.
“Nick’s comments reflect exactly what we’re seeing across the payments sector: the assumption that a breach is a question of when, not if, and there is a need to protect the data itself rather than just the environment around it,” said Ian McKinley, CEO of GuardWare
Axcess believes data-centric security approaches will play an increasingly important role in helping payment organisations strengthen security resilience while supporting evolving compliance requirements.
“The payments sector has always been a prime target for cybercriminals because of the value of the data it holds,” added Fox.
“Protecting payment information requires more than perimeter defences. Security controls must travel with the data itself. Our deployment of GuardWare reflects our
commitment to continually enhancing the security of our environment and ensuring the highest standards of protection for both our business and our merchant partners.”
Axcess reports that the deployment has enhanced its ability to protect sensitive data, strengthen audit readiness, support PCI DSS compliance activities and improve visibility into potential data security risks, while integrating seamlessly within its existing Microsoft, AWS and CrowdStrike environments.
About Axcess Payment Services
Founded in 2007, Axcess Payment Services is the technology division of Axcess Payments Group, delivering secure payment gateway and payment technology solutions to businesses across the UK and Europe. Operating under PCI DSS Level 1 compliance, the company provides secure, scalable payment infrastructure designed to support merchants in an increasingly digital economy.
About Axcess Payments Group
Axcess Payments Group delivers payment solutions across acquiring, gateway technology and payment consultancy services. The Group comprises Axcess Payments Group, Axcess Merchant Services, Axcess Merchant Services Europe and Axcess Payment Services, serving merchants across multiple sectors with secure and
innovative payment technologies.
About GuardWare
GuardWare provides persistent, data-centric security through its INSIGHT, DISCOVER, and PROTECT platform. The solution delivers file-level encryption, granular governance, and forensic auditability across the full data lifecycle, supporting compliance with PCI
DSS, and operating across on-premises, cloud, remote, and air-gapped environments.
GuardWare is complementary to formal PCI DSS audits and does not constitute a substitute for them. A full PCI DSS control mapping is available in the published white paper.

