Verizon: PCI-Compliant Businesses See Fewer Data Breaches

執筆者
Brian Prince
Brian Prince
Published: Oct 4, 2010
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Compliance regulations may not be a perfect gauge for security, but a new report from Verizon Business underscores how important they can be.

In the “Verizon Payment Card Industry Compliance Report [PDF],” the company analyzes compliance with the Payment Card Industry Data Security Standard (PCI DSS), and how it relates to data breaches. According to the report, breached organizations are 50 percent less likely to be PCI-compliant than a “normal population of PCI clients.” Just 22 percent of organizations were PCI-compliant at the time of their initial examination.

“To ensure security, you need a layered approach,” said Jen Mack, director of Global PCI Consulting Services at Verizon. “There is not a single magic bullet solution or product that will solve PCI needs or prevent breaches, but a layered and continually enforced approach to security is the best way to prevent breaches.”

The report is based on findings from approximately 200 PCI DSS assessments conducted by Verizon, mostly in the United States during 2008 and 2009. By coupling PCI assessment data with the post-breach analysis, Verizon ranked the top attack methods used to compromise payment card data: malware and hacking (25 percent), SQL injections (24 percent), and exploitation of default or guessable credentials (21 percent).

Of the 12 PCI DSS requirements, three of them-protect stored data, track and monitor access to network resources and cardholder data, and regularly test security systems and processes-address areas most vulnerable to security breaches, according to Verizon’s 2010 Data Breach Investigations Report.

Still, PCI is a snapshot in time and therefore is not always a full view of an enterprise’s security posture. There have been cases in the past where companies fell victim to data breaches in between annual audits despite having been found compliant in the previous assessment.

“Companies suck in their gut for inspection and then exhale once it’s all over,” said Wade Baker, director of risk intelligence at Verizon Business. “While annual assessments may not be an exact indicator of security, assessments do provide a best-case measure of a company’s security, which is still useful. Furthermore, based on what I’ve seen, the yearly “sucking in of the gut” at least makes them think of things they otherwise would ignore. So, an annual-albeit temporary-tidying up is better than the constant erosion that would otherwise occur.”

Seventy-eight percent of organizations were not compliant initially, but on average organizations meet 81 percent of the procedures required by PCI, the report found. Some 75 percent of the organizations meet at least 70 percent of the testing requirements; only 11 percent met less than half at the time of their initial review.

Advertisement

“[Organizations should] find a way to incorporate PCI DSS requirements into your overall security initiatives and programs so that compliance becomes part of your daily business activities,” Mack said. “Also, if you don’t know where to start, you can use the Prioritized Approach released by the PCI Security Standards Council: It provides a risk-based approach on which requirements to tackle first. The overall goal is to reduce the most amount of risk up front to cardholder data.”

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。