Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    PCI Security Lacks Teeth

    By
    Evan Schuman
    -
    March 1, 2007
    Share
    Facebook
    Twitter
    Linkedin

      Earlier this week, MasterCard officially (well, sort of officially) confirmed that retail chain TJX was not in compliance with Payment Card Industry rules at the time of the $16 billion retailers infamous January disclosure of a massive data breach.

      The significance of this news is not the fact that TJX was not complying with the rules themselves. As former federal prosecutor Mark Rasch said: “Its hardly surprising that they werent PCI-compliant. Thats from the Department of Obviousness.”

      Nor is it newsworthy that MasterCard opted to confirm the chains PCI-less state, although it is interesting. It might be a hint of the level of anger that many in the industry feel about the way TJX has been handling its crisis, coupled with a generous dose of CYA. In any other situation, its truly hard to envision the normally media-shy MasterCard going out of its way to publicly confirm that a retailer was not compliant. Officially, it merely confirmed that TJXs U.S. credit card transaction processor (technically: acquirer)—Fifth Third Processing Solutions—had reported to MasterCard that TJX wasnt PCI compliant.

      No, the true newsworthy aspect of this news is how it illustrates the irrelevance of PCI today, when it comes to retail security. To say that PCI has achieved a toothless reputation today is being generous. Its akin to those home page declarations that a site has been certified as safe. It only provides comfort to those who dont think about it very much. PCI has become a Santa Claus entity: It only works for those who really want to believe and who are willing to conveniently ignore any facts that disprove it.

      PCI certainly doesnt have to be toothless. It has provisions for serious financial penalties and for even banning a merchant from accepting credit or debit cards. But for it to be taken seriously, the credit card industry and retail industry must undergo a radical attitude conversion. Are MasterCards comments the first indication of someone trying? A tentative, toe-in-the-water, half-hearted try perhaps, but a try nonetheless.

      The industry must not only use those fines and penalties, but it must do so publicly—very publicly. Were talking about a news conference every time a fine is issued, and fines need to be issued every week. The announcements must be explicit and specific, detailing for the world what the retailer did—or failed to do—and why. For some retailers, the humiliation and embarrassment associated with such a disclosure might be worse than the penalties and thats a good thing.

      /zimages/5/28571.gifClick here to read more about how confusion over PCI guidelines is aggravating retailers.

      Retailers need a cost-benefit analysis that makes it worthwhile to heavily invest in security. They must constantly see what happens to companies that fail to comply and its critical that they must fear those consequences. Today, few retailers have that fear. Is the threat of rescinding a retailers ability to accept credit and debit cards a true deterrent if no retailer believes it will ever happen?

      The next step is taking a much more strict position with PCI-compliance audits. The fact that the auditors in questions are paid by—and are given instructions by—the retailers being audited is the most textbook conflict-of-interest Ive seen in quite some time. Why not have the auditors working for the credit card companies or the banks? Why not give the auditors the ability to explore any and all systems, as opposed to just the ones the retailer wants examined? The rules were written assuming that retailers would want to know what was really going on. But what if some key managers with that retailer were deliberately retaining forbidden data, perhaps for a CRM (customer relationship management) project? Is that Auditor Fox guarding the Retail Chickens?

      When the retail and banking industries want to take security seriously, they already have the tools to do so. Until then, please forgive us if were yawning at a multiyear-in-the-making data breach (which wasnt discovered for years). Its hard to get worked up about a retailer not taking seriously something that the banking and credit companies dont care about, either.

      Retail Center Editor Evan Schuman has tracked high-tech issues since 1987, has been opinionated long before that and doesnt plan to stop any time soon. He can be reached at Evan_Schuman@ziffdavis.com.

      To read earlier retail technology opinion columns from Evan Schuman, please click here.

      /zimages/5/28571.gifCheck out eWEEK.coms for the latest news, views and analysis on technologys impact on retail.

      Evan Schuman
      Evan Schuman is the editor of CIOInsight.com's Retail industry center. He has covered retail technology issues since 1988 for Ziff-Davis, CMP Media, IDG, Penton, Lebhar-Friedman, VNU, BusinessWeek, Business 2.0 and United Press International, among others. He can be reached by e-mail at Evan.Schuman@ziffdavisenterprise.com.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×