Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    PCI DSS Compliance Does Not Mean Companies Are Secure From Breaches

    Written by

    Todd R. Weiss
    Published January 13, 2015
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      NEW YORK—An upcoming Verizon report on mobile and retail security and Payment Card Industry Data Security Standard (PCI DSS) compliance shows that many companies fall out of compliance once they finish their projects, leaving security holes that then lead to future data breaches and data loss that could have been prevented.

      “Most customers still see compliance as a project for two or three months,” said Rodolphe Simonetti, the director of compliance and governance professional services for Verizon. “Where customers failed is in maintaining compliance” once the projects are completed because they don’t continue to work on the systems.

      Simonetti made his comments on Jan. 12 at a Verizon press event here during the National Retail Federation conference, where he spoke during a panel discussion on PCI compliance at the Ink48 hotel in Manhattan.

      Simonetti was summarizing data from an upcoming annual Verizon PCI Report, which shows that companies are still struggling with properly implementing and maintaining PCI DSS compliance inside their corporate systems, he said.

      The report, due out at the end of February, looked at more than 5,000 company security assessments in some 30 countries around the world over the last five years, focusing on mostly Fortune 500 companies. The results of the analysis were striking, he said, including the finding that not a single company that suffered a security breach in 2014 was in compliance with existing PCI DSS at the time of the breach.

      “Most companies are really and definitely failing to maintain compliance,” said Simonetti. “It was astonishing.”

      The data in the report showed that less than a third of the companies remained in compliance with PCI DSS after six months, he said. “That’s a very, very low number. Becoming compliant is tough, but staying compliant is a bigger challenge.”

      Interestingly, the areas in which companies failed to maintain PCI DSS compliance over time were the areas in which Simonetti said he would have expected them not to fail in the first place, such as maintaining firewalls, patching systems, and regularly scheduled security and vulnerability testing.

      “I would think this is Security 101,” he said. “But, still, a lot of companies are failing to maintain this very basic security.”

      The problem often is that some companies look at PCI compliance as a yearly project, rather than as an ongoing process to support security, he said. “You will never be able to be 100 percent secure,” he said. “What is important, then, is to be resilient, to make sure that the impact of the breach is not that bad. Some do a lot to make sure it doesn’t happen, but they fail to react quickly if it does.”

      Greg Buzek, principal analyst of retail and hospitality analyst firm, IHL Group, said that for most companies, the answer to the problem of PCI DSS compliance is that credit card security must entail a multi-pronged approach today that also includes data encryption and tokenization.

      “Honestly, PCI [DSS] is the Y2K that never ends,” said Buzek. Companies often today have compliance letters from security companies that were produced just before they were battered by data thieves, he said. “They had letters saying they were compliant. That’s the challenge when it only protects the card” and not the data. “That’s why it is better to have encryption and tokens because then the cards are worthless” if they are stolen.

      Todd R. Weiss
      Todd R. Weiss
      Todd R. Weiss is a seasoned technology journalist with over 15 years of experience covering enterprise IT. Since 2014, he has been a senior writer at eWEEK.com, specializing in mobile technology, smartphones, tablets, laptops, cloud computing, and enterprise software. Previously, he was a staff writer for Computerworld.com from 2000 to 2008, reporting on a wide range of IT topics. Throughout his career, Weiss has written extensively about innovations in mobile tech, cloud platforms, security, and enterprise software, providing insightful analysis to help IT professionals and businesses navigate the evolving technology landscape. His work has appeared in numerous leading publications, offering expert commentary and in-depth analysis on emerging trends and best practices in IT.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×