Survey: Most organizations accepting credit cards don't maintain PCI security standards
In the wake of several recent security breaches at major department stores, a new study by telecom giant Verizon shows the need for organizations to comply with Payment Card Industry security standards is more important than ever as payment card data becomes more valuable.
February 12, 2014 at 04:07 AM
5 minute read
The original version of this story was published on Law.com
In the wake of several recent security breaches at major department stores, a new study by telecom giant Verizon shows the need for organizations to comply with Payment Card Industry (PCI) security standards is more important than ever as payment card data becomes more valuable.
What are PCI security standards? They are international standards created and maintained by the PCI Security Standards Council (SSC), which represents major global card brands, to verify that merchants and service providers are appropriately protecting cardholder data. While PCI security standards are not enforced by the law, except in just a handful of states, businesses often comply through the terms of the business contract with the merchant.
The “Verizon 2014 PCI Compliance Report” affirms that payment card transactions remain a prime target for attackers, and the rate at which data breaches are occurring appears to be increasing. It is estimated by The Nilson Report that global credit cards fraud exceeded $11 billion in 2012 alone.
“We continue to see many organizations viewing PCI compliance as a single annual event, unaware that compliance needs to have a 365 day-a-year focus,” said Rodolphe Simonetti, managing director, PCI practice, Verizon Enterprise Solutions.
The Verizon report though, finds one bright spot in the report: Organizations' initial compliance with the PCI standards has shown some improvement. In 2013, more than 82 percent of organizations were compliant with at least 80 percent of the PCI standards at the time of their annual baseline assessment, compared with just 32 percent in 2012. Region-to-region, Asia-Pacific organizations are the most compliant (75 percent) versus American (56.2 percent) and European organizations (31.3 percent).
Head of PCI-DSS APAC Sebastian Mazas said this result is “very impressive and a very good surprise.”
However, Mazas also said there is still room for improvement, pointing out three key areas in which businesses are struggling to manage compliance: Security testing, security monitoring and the capability to respond to a compromise, and the protection of stored data. He noted that these areas are where attacks are more likely to occur going forward.
Related News:
In the wake of several recent security breaches at major department stores, a new study by telecom giant Verizon shows the need for organizations to comply with Payment Card Industry (PCI) security standards is more important than ever as payment card data becomes more valuable.
What are PCI security standards? They are international standards created and maintained by the PCI Security Standards Council (SSC), which represents major global card brands, to verify that merchants and service providers are appropriately protecting cardholder data. While PCI security standards are not enforced by the law, except in just a handful of states, businesses often comply through the terms of the business contract with the merchant.
The “Verizon 2014 PCI Compliance Report” affirms that payment card transactions remain a prime target for attackers, and the rate at which data breaches are occurring appears to be increasing. It is estimated by The Nilson Report that global credit cards fraud exceeded $11 billion in 2012 alone.
“We continue to see many organizations viewing PCI compliance as a single annual event, unaware that compliance needs to have a 365 day-a-year focus,” said Rodolphe Simonetti, managing director, PCI practice, Verizon Enterprise Solutions.
The Verizon report though, finds one bright spot in the report: Organizations' initial compliance with the PCI standards has shown some improvement. In 2013, more than 82 percent of organizations were compliant with at least 80 percent of the PCI standards at the time of their annual baseline assessment, compared with just 32 percent in 2012. Region-to-region, Asia-Pacific organizations are the most compliant (75 percent) versus American (56.2 percent) and European organizations (31.3 percent).
Head of PCI-DSS APAC Sebastian Mazas said this result is “very impressive and a very good surprise.”
However, Mazas also said there is still room for improvement, pointing out three key areas in which businesses are struggling to manage compliance: Security testing, security monitoring and the capability to respond to a compromise, and the protection of stored data. He noted that these areas are where attacks are more likely to occur going forward.
Related News:
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllBest Practices for Adopting and Adapting to AI: Mitigating Risk in Light of Increasing Regulatory and Shareholder Scrutiny
7 minute readCrypto Groups Sue IRS Over Decentralized Finance Reporting Rule
SEC Penalizes Wells Fargo, LPL Financial $900,000 Each for Inaccurate Trading Data
US Reviewer of Foreign Transactions Sees More Political, Policy Influence, Say Observers
Trending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250