[stock-market-ticker symbols="FB;BABA;AMZN;AXP;AAPL;DBD;EEFT;GTO.AS;ING.PA;MA;MGI;NPSNY;NCR;PYPL;005930.KS;SQ;HO.PA;V;WDI.DE;WU;WP" width="100%" palette="financial-light"]

Verizon report: firms still struggling with Payment Card Industry security standard compliance

4 septembrie 2017

Nearly half of retailers, restaurants, hotels and other business that take card payments are still failing to maintain compliance from year to year.

Despite the wave of costly data breaches over the last few years, nearly half of global firms that accept plastic are still failing to meet Payment Cards Industry (PCI) security standards, according to a report from Verizon. While overall PCI compliance has increased amongst global businesses, just 55.4% of organisations assessed by Verizon passed their interim assessment in 2016, compared to 48.4% in 2015.

And of all payment card data breaches Verizon investigated, no organisation was fully compliant at the time of breach, and showed lower compliance with 10 out of the 12 PCI DSS key requirements.

Rodolphe Simonetti, global managing director, security consulting, Verizon, says: „There is a clear link between PCI DSS compliance and an organization’s ability to defend itself against cyberattacks.”

„Whilst it is good to see PCI compliance increasing, the fact remains that over 40% of the global organisations we assessed – large and small – are still not meeting PCI DSS compliance standards. Of those that pass validation, nearly half fall out of compliance within a year — and many much sooner.”

According to the report, IT services achieved the highest full compliance of all key industry groups studied. Globally, about 61% of firms in this sector achieved full compliance, compared to 59% of financial services organisations, 50% of retail firms and 43% of hospitality companies.

Verizon uses an FS industry firm as an example of how standards can be missed. The unnamed outfit sought exemption from the Wi-Fi requirements of PCI DSS but was surprised to learn that it did in fact have a wireless network operating in its building – causing it to fail.

„The IT admin had got tired of traipsing from the server room in the basement to the IT department on the third floor, and so had installed a router to access the servers from his desk,” says Verizon.

Troy Leach, CTO, PCI Security Standards Council, says: „The report highlights the challenges organisations have to consistently maintain security controls on an ongoing basis, leaving their cardholder data environments vulnerable to attack.

„This trend was a key driver for changes introduced in PCI Data Security Standard version 3.2., which focus on helping organizations confirm that critical data security controls remain in place throughout the year, and that they are effectively tested as part of the ongoing security monitoring process.”

About the 2017 Verizon Payment Security Report

The aim of the 2017 PSR is not to convince readers of the need for PCI compliance, but to track the measurable performance of PCI compliance. This year’s report includes the results from PCI assessments conducted by Verizon’s team of PCI Qualified Security Assessors for Fortune 500 and large multinational firms in more than 30 countries.

Similar to Verizon’s Data Breach Investigations Report series, the 2017 PSR is based on actual casework with a specific focus on financial services (47.5 percent); IT services (22.3 percent), hospitality (15.1 percent) and retail (14.4 percent). Geographies include the Americas (42.4 percent), Europe (28.1 percent) and the Asia-Pacific region (29.5 percent).

The 2017 Verizon Payment Security Report can be downloaded here.

Source: prnewswire.com

Adauga comentariu

Noutăți
Cifra/Declaratia zilei

Anders Olofsson – former Head of Payments Finastra

Banking 4.0 – „how was the experience for you”

So many people are coming here to Bucharest, people that I see and interact on linkedin and now I get the change to meet them in person. It was like being to the Football World Cup but this was the World Cup on linkedin in payments and open banking.”

Many more interesting quotes in the video below:

Sondaj

In 23 septembrie 2019, BNR a anuntat infiintarea unui Fintech Innovation Hub pentru a sustine inovatia in domeniul serviciilor financiare si de plata. In acest sens, care credeti ca ar trebui sa fie urmatorul pas al bancii centrale?