Why PCI DSS compliance matters.

Why PCI DSS compliance matters.

We’ve launched Verizon’s 2019 Payment Security Report today – our annual look at PCI DSS compliance. PCI DSS (the payment card industry data security standard) is a bit of a mouthful, but an important topic for anyone who processes payment data. And I’m sorry to say that this year’s report shows a downward compliance trend - only 1 in 3 companies globally make the grade and just 1 in 5 in the Americas.

PCI DSS compliance is all about helping organizations protect their payment systems from data breaches and theft of cardholder data. If you’re not compliant, you are quite simply more likely to suffer a payment systems breach – and any breach of cardholder data has an obvious impact on a company’s brand.

Indeed, data from the Verizon Threat Research Advisory Center demonstrates that a compliance program without proper data protection controls has a more than 95 percent probability of not being sustainable, and is more likely to be a potential target of a cyber attack. Conversely, our data also shows that we have never investigated a payment card security data breach for a PCI DSS compliant organization. Compliance works!

The Verizon team has put together a new framework to help organizations navigate the world of compliance. There’s no one-size-fits-all script to achieve sustainable data protection, but too many organizations still try to adopt this approach. What we’re trying to do is make compliance simple.

If your organization processes payment card data, and you’re not compliant, you need to start this journey. You can read the PSR on our website, and also find out more about how we can help you with compliance, and indeed all of your security requirements. Compliance matters. Make it matter to you today. 

Horacio Ballinas

Director of Global Cloud Security @ KPMG | MBA

5 年

The report says 60% of surveyed organizations do not apply capability and maturity models to measure their PCI security program. In addition, there is a direct correlation between data breaches and incident preparedness and the maturity of these processes. From this point of view, the Verizon’s compliance framework is more than justified. Thank you for the data!

回复

要查看或添加评论,请登录

社区洞察

其他会员也浏览了