Over the last four years, people in the payments, security, retail, restaurant and other industry have spoken about the "massive opportunity" associated with trying to get Level 4 merchants to be PCI compliant and secure, in a "beyond just card data" sense. But lately, I've come to the conclusion that this may not be possible. Or, if possible, the effort is beyond what those who seek to secure these firms are willing to invest in this clearly uphill battle.
As GuestView PCI Columnist David Taylor points out, data security is mostly about FUD. The more you scare people about unknown risks (of breaches, fraud, data loss), the more they tend to spend to guard against these risks. But given the high level of fear that already exists in the SME environment about going out of business, even the loudest and most well justified pitches don't even make the radar screen.Read more...