advertisement
advertisement

This is page 2 of:

PCI Education More Neglected Than We Thought

January 26th, 2011

The good news is that training has the biggest financial payoff for achieving and maintaining compliance. Training is cheap. It is a few hours once or twice a year. It is having users sign a piece of paper acknowledging their responsibility each year. I firmly believe people want to do the right thing, either because they are moral beings or because they want to keep their jobs. Either way, the idea is to tell users what they can and cannot do with cardholder data—and then enforce the rules.<pPCI v2.0 requires a comprehensive effort to determine a merchant's PCI scope. This requirement, coupled with the spread of personal technology, means educating users should be a high priority for IT managers.

The NRF/First Data survey of small to midsize retailers leads me to a related conclusion about the criticality of education for security and PCI compliance. In that survey, the overwhelming majority of businesses (86 percent) said they care about protecting their customers’ card data and they feel payment card security is important to their business. That certainly is great news, but what followed had me scratching my head.<pOf those businesses that store PAN data, only 68 percent reported taking any steps at all to protect that data. That sounds a bit like me saying I recognize traffic accidents are dangerous, so I'll use my seatbelt about two-thirds of the time. Or telling the IRS I know I should pay my taxes, but how about I just pay two-thirds of them.

That nearly a third of small and midsize retailers are retaining cardholder data without protecting it should be very frightening news for security professionals and, unfortunately, very good news for the bad guys.

Once again, I believe education can be a big part of the solution. It’s good that smaller retailers have heard of PCI (66 percent of survey respondents), but we have to do better. For example, about the same percentage (64 percent) made the incredible statement that their business is not vulnerable to payment card data theft. I don’t know what newspaper these merchants are reading or where they get their news, but it seems like a lot of small retailers are not making a connection between storing cardholder data and their risk of a very expensive data compromise.

As an industry we have done a good job of raising awareness of PCI DSS, but we now need to move to convincing the majority of small retailers that they are at risk. I want to commend the NRF and First Data for this survey. It paints a very interesting and complex picture, and I’m only looking at a small part of it. The challenge now will be what the industry can do to get the rest of the PCI message to vulnerable small and midsize retailers.

An alternative to education might be technology. Actually, it might be two technologies. For retailers who feel they need to retain cardholder data, tokenization can be an attractive solution. They can track what they need to track, but by using meaningless tokens instead of PANs. For the rest of those retailers, a point-to-point encryption approach that encrypts cards when they are swiped might be a good way to reduce PCI scope and risk.

Right now, we are all waiting for additional guidance on these promising technologies from the PCI Council. But the potential for reducing retailer risk is enormous.

What do you think? I’d like to hear your thoughts. Either leave a comment or E-mail me at wconway@403labs.com.


advertisement

One Comment | Read PCI Education More Neglected Than We Thought

  1. david marsh Says:

    Walt, I had an interesting conversation on this last week with a mutual contact in the QSR business. He had an interesting perspective – maybe it is not so much a case of the smaller merchants being unaware, maybe it is a case of not wanting to admit it. Maybe it is human nature to not want to admit that you know it is a problem, but since you really perceive it as an expensive hassle, you are less likely to admit that on a survey.
    I am not going to pretend to be a psychiatrist, but I do know that many merchants will continue to resist anything that they perceive as an unnecessary cost to their business. Until there is a bigger pain to them in the form of penalties paid for non-compliance, some will simply pretend that the risk of breach does not exist…

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.