Maintaining PCI compliance is a big challenge for most companies

Many tend to treat compliance as a lone annual event, leaving them vulnerable, Verizon says

A majority of companies that achieve annual compliance with the Payment Card Industry Data Security Standard (PCI DSS) fail to then maintain that status. As a result, they often remain exposed to potential data breach risks and other security threats, Verizon said in a report this week.

Verizon's report is based on the results of annual PCI compliance assessments the company performed at more than 500 large organizations between 2011 and 2013. The results are based on actual compliance data gathered from companies in the retail, financial services, travel and hospitality sectors and other vertical markets.

The analysis showed that barely 11.1% of enterprises maintained their compliance status between each assessment.

More than 82% were compliant with only about eight in 10 PCI DSS requirements at the time of their annual assessments and needed an additional three months or so to close the gaps, said Rodolphe Simonetti, managing director, PCI practice for Verizon Enterprise Solutions.

The problem has to do with a tendency by many companies to treat PCI compliance as an annual end goal rather than treating it as part of a continuous risk management effort.

"Too many companies still look at PCI as pure compliance and don't use it to mitigate risk," Simonetti said. "Often, compliance is managed as a project -- particularly as the build phase of a project." Once compliance is achieved, many companies simply stop paying attention, he said.

"It is really a failure to use compliance standards and tools and a day to day basis," Simonetti said.

The areas where many companies appear to have particular problems involve PCI requirements on protecting data at rest, security testing and monitoring security controls and detecting and responding to compromises, he said. More than half of the companies assessed failed compliance requirements for protecting data at risk in their initial annual compliance assessments.

The recent data breach at Target that exposed data on more than 40 million debit and credit cards has focused considerable attention on PCI standards and compliance issues in general.

Target, like many others before it, has noted that it was breached despite achieving compliance with all PCI requirements. The implication is that the standard does little to protect companies against new and sophisticated threats.

But the reality is that "most breaches are not a failure of the technology or standards but rather a failure to implement the standards," according to Simonetti.

A lack of resources and manpower continue to be major roadblocks to ongoing PCI compliance at many companies, which often reassign staff to other projects once they have passed their annual security audit.

Under PCI rules, large companies such as Target are required to conduct quarterly vulnerability scans to check for threats to payment card data. But companies then fail to take the requirement in the spirit it was intended and fail their quarterly scans, Simonetti said.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed. His e-mail address is

See more by Jaikumar Vijayan on

Read more about malware and vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.

Join the CSO newsletter!

Error: Please check your email address.

Tags Cybercrime and HackingsecurityVerizon Enterprise SolutionsMalware and Vulnerabilities

More about TopicVerizonVerizon

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Jaikumar Vijayan

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts