Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    Retailers Not Exactly Where Visa Wants Them to Be

    Written by

    Evan Schuman
    Published July 31, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      When Visa on July 30 released its latest PCI compliance statistics, it showed small but steady progress, with slight increases in most areas. But it also showed that there is still a small handful of major retailers who are still retaining prohibited credit card information.

      Visa stressed in its statement that the vast majority (96 percent) of Level 1 and Level 2 merchants—a category including virtually all of the nations largest retailers—have written to Visa that “they are not storing sensitive account data” including credit card security codes and PINs.

      But given that Visa has said that there are 1,057 retailers in that group (327 Level 1 U.S. retailers and 730 Level 2 retailers), that four percent suggests that about 42 major retail chains arent even claiming that theyve stopped retaining that data. Visa estimates that the 96 percent relates roughly equally to both groups, suggesting about 13 retailers in the Level 1 group (with the very largest retailers) and about 29 in the Level 2 group.

      /zimages/1/28571.gifClick here to read more about PCI confusion aggravating retailers.

      Gartner security analyst Avivah Litan expressed particular concern about the Level 1 retailers who are still retaining the prohibited data. “Even if its just 13, thats way too many,” Litan said, adding that if 13 are saying that they still retain the prohibited data, the actual number of retailers who are doing so is likely much higher.

      Of all of the PCI security areas (including encryption, wireless detection methods, not retaining old transaction data, etc.), Litan argues that Visa considers retention of prohibited data to be the most serious. “That’s the data the banks really care about,” Litan said. “If the crook steals the data from the [magnetic] stripe, they can make a perfect card.”

      Litan said that when she met with Visa officials in October 2006, they reported that only three retailers were then saying they were still storing the data, which is less than one third the number apparently reporting that today.

      “We know that merchants that store full magnetic-stripe data expose themselves to risk exponentially,” said Michael E. Smith, senior vice president of Enterprise Risk and Compliance at Visa USA, in the Visa statement. “By removing prohibited data from their payment systems, large and small businesses alike are denying hackers the data they covet for use in counterfeiting payment cards and are thus making their businesses and the payments system more secure.”

      Why are some major retailers still holding onto this information, which likely is of little to no marketing or analytical value to them? “In the merchants defense, its very costly to change their systems,” Litan said. “For a Level 1 retailer with 500—and sometimes 10,000—store locations, its not that simple to change POS systems.”

      Eduardo Perez, vice president, payment systems risk, Visa USA, agreed that cost can be a key factor. “It can require notable resources to change or upgrade payment applications,” Perez said. “It can pose some notable challenges.”

      But he saw the usage of some non-compliant payment applications as a much bigger culprit, which is why Visa has distributed names of those ISVs to key retailers. Visa has refused to identify those ISVs because they fear that doing so might help cyber thieves zero in on those customers.

      “Its the payment application that is causing the merchant to store track data,” Perez said.

      Theres also the distinct possibility the numbers might be far worse. The Visa statement suggested that the percents referenced came from retailer declarations to Visa, as opposed to audit results. If thats the case, the question isnt actually getting at whether the retailer stores the prohibited as much as whether the person filling out the form believes the data is being retained.

      The complicated enterprise networks today allows many copies of these numbers to be scattered in various departments: store operations, marketing, IT, accounting, etc. This raises the question of whether copies of the prohibited data arent floating around somewhere, well beyond the knowledge of the IT manager filling out the form.

      “How do they know they’re not? If you were to ask me, Are your doors locked?, Id say Of course they are. That is, until I find one that isnt,” said Mark Rasch, a legal security consultant with FTI Consulting and the former head of the U.S. Justice Departments high-tech crimes unit. “This is the equivalent of going out to the top 100 companies and asking, Are you violating any securities laws?”

      Visa also released on Monday the latest compliance numbers for its Payment Card Industry Data Security Standard (PCI DSS), which showed slow but steady improvements in all areas. These results are based on audited results.

      Level 1 includes any merchant processing more than 6 million Visa transactions per year, regardless of volume or acceptance channel. Level 2 includes any merchant that processes 1 million to 6 million Visa transactions per year, regardless of acceptance channel. Level 3 are retailers that process 20,000 to 1 million Visa e-commerce transactions per year and Level 4 includes any merchant processing fewer than 20,000 Visa e-commerce transactions per year as well as all other merchants processing as many as 1 million Visa transactions per year.

      The figures for July showed that 40 percent of Level 1 retailers were compliant, thats up from the 35 percent compliance rate for that group that Visa reported in May 2007. In May 2006, the compliance rate for that group was 18 percent.

      The new July 2007 figures for Level 1 retailers showed that an additional 50 percent have pledged to repair security holes, a process known as filing a ROC (Report On Compliance).

      Back in May, Visa reported that 51 percent had been involved in the ROC stage, a slight one percent increase that is more than made up for by the increase in actually compliant Level 1 retailers. That July figure leaves 10 percent that are neither compliant nor pledging to be compliant, a sharp drop from the 14 percent Visa reported in May.

      With the somewhat smaller Level 2 retailers, the July figures showed a 33 percent compliance rate—up from 26 percent in May—and the smaller Level 3 retailers showed 52 percent compliance, just slightly up from the 51 percent that Visa reported for that group in May.

      Visa didnt release any figures for its Level 4 retailers, but Visas Perez said, “We know that compliance is low.” Visa is expecting to have more specific numbers for that group soon.

      Level 4 may represent the smallest retailers in the country, but it has strength in numbers, representing more than 6 million retailers, Perez said. Although those retailers represent only about a third of all of the Visa transactions, they account for some 80 percent of all data breaches. Still, despite all of those data breaches, fewer than five percent of all compromised cards came from Level 4 merchants, Perez said.

      In Europe, some PCI advocates are actually stepping back from their own deadlines, fearful of not being able to bring in sufficient retailer support.

      Rasch saw the increase in PCI compliance for Levels 1, 2 and 3 as a hopeful sign that “the standards are getting more mature and companies are getting more sensitive to it. The question is whether this will translate to an actual dip in retail fraud.”

      Gartners Litan pointed out that Visa is the only credit card player that releases any security compliance figures. “You cant get anything out of Amex, Discover or MasterCard,” she said.

      Visas Perez used the numbers to make a pitch for contactless payment cards, which rotate CVV numbers as part of their security protocol. “With contactless, the CVV number on the next transaction would be different,” he said. “Contactless is one way to render the data useless.”

      Retail Center Editor Evan Schuman can be reached at [email protected].

      /zimages/1/28571.gifCheck out eWEEK.coms for the latest news, views and analysis on technologys impact on retail.

      Evan Schuman
      Evan Schuman
      Evan Schuman is the editor of CIOInsight.com's Retail industry center. He has covered retail technology issues since 1988 for Ziff-Davis, CMP Media, IDG, Penton, Lebhar-Friedman, VNU, BusinessWeek, Business 2.0 and United Press International, among others.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.