This is page 2 of:
TJX Settlement: Is This Really The Message We Want Sent?
To be fair, TJX had other court costs and security upgrades to deal with, but given that it won both class-action lawsuits and that the reserves were so large, it’s clear that this invoice won’t exactly bring them down to their POS knees.
At a glance, the settlement appears to impose quite a few security rules on TJX, which seems worthwhile. That’s true until you look closely at the rules and realize, “Wait a second. Aren’t virtually all of those rules already mandated by PCI? And hasn’t TJX—as a level one merchant—already agreed to abide by those rules? Indeed, aren’t these ‘punitive’ new rules the exact same requirements that tons of large retailers—who, by the way, have not been breached to the tune of 100 million payment cards—also have to live by? Isn’t this akin to punishing drunk drivers who kill groups of children by saying that they must now pay federal, state and municipal taxes and also abide by posted speed limits?”
The few instances where the settlement tiptoed beyond PCI mandates, it didn’t seem to tiptoe very far. PCI guidelines do not mandate network segmentation, but it does recommend it, for example. The settlement has TJX having agreed to segment its network.
PCI guidelines do not currently take a firm position on so-called end-to-end encryption (by defining it as “from PIN pad to acquiring bank,” it’s more like middle-to-near-the-end encryption) but then again, neither does the settlement. It merely requires TJX to ” to encourage the development of new technologies” such as end-to-end encryption. Let’s call this the Attaboy mandate.
This would have more teeth in it were TJX not already making such reports back, courtesy of PCI. The difference, though, is the state reports are going to public organizations, rather than private industry players. Fear not, though, as TJX’s lawyers made sure that wouldn’t be problematic.
How? By insisting that the settlement include this line, which was somehow missing from the various state news releases that went out proclaiming the deal: the states agree that they “shall treat such documents as exempt from disclosure under the relevant public records laws.”
One might conclude from all of this that it would be wise to avoid getting into Poker games with TJX executives. But it’s not necessarily that they’d be such superb poker players. It truly helps to be able to use your own deck of cards and to be able to choose the dealer.