HomeBusinessPayment Card Industry Data Security Standard (PCI DSS): Companies' compliance...

Payment Card Industry Data Security Standard (PCI DSS): Company compliance has dropped by 28% since 2016

Verizon said its compliance with the Payment Card Industry Data Security Standard (PCI DSS) has declined for the third consecutive year, with organizations failing to meet their long-term plans. PCI DSS is a set of rules and regulations created in 2006 by a coalition of Visa , Mastercard, American Express, Discover and JCB to manage security standards and improve security throughout the transaction process in an effort to reduce credit card fraud .

The tech giant compiled the Verizon Business 2020 Payment Security Report based on data collected by its own and other companies' PCI DSS qualified security assessors (QSAs).

Payment Card Industry Data Security Standard-compliance

Additionally, Verizon revealed that on average only 27.9% of organizations worldwide are fully compliant with the Payment Card Industry Data Security Standard, a 28% decrease since 2016.

The report also highlighted that only 52% of organizations assessed successfully test systems and procedures, as well as unattended system access, while about two-thirds effectively monitor access to business-critical systems. In addition, only 71% of financial institutions maintain basic security perimeter controls, Verizon added.

Payment Card Industry Data Security Standard

The Payment Card Industry Data Security Standard is designed to provide a carrot-and-stick approachto improving data security for merchants that process card payments. On the one hand, it offers a best practice framework to help businesses mitigate the risk breach , but if they fail to comply and are subsequently breached, large fines could be imposed.

For example, 86% of data breaches in 2019 were financially motivated, while in the commerce industry, 99% of security incidents were related to the acquisition of payment data by attackers, according to Verizon's latest report on data breach investigations.

Verizon President Sampath Sowmyanarayan argued that many companies still lack the resources and commitment to drive long-term compliance strategies.

Payment Card Industry Data Security Standard

Additionally, the COVID-19 has shifted consumers away from traditional cash, towards contactless payment methods with credit cards and mobile devices. This has created more electronic payment data, with consumers trusting businesses to protect their information. Payment security should always be a priority for companies handling any payment data, as they have a responsibility to their customers, suppliers and consumers.

The report also outlined specific challenges that small and medium-sized businesses face in executing what is commonly perceived as a burdensome and costly PCI DSS compliance process.

Maxine Holt, senior research director at Omdia, said the report’s findings should serve as a wake-up call for businesses. She added that aligning security strategy with organizational strategy is essential for organizations to maintain compliance, in this case with PCI DSS 3.2.1, to provide the appropriate levels of payment security. Finally, Holt pointed out that long-term data security and compliance combine the responsibilities of a number of roles, including the chief information security officer, chief risk officer, and chief compliance officer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS