Commentary
Survey Says: PCI DSS Compliance Not Strategic
That's right. A survey conducted by the Ponemon Institute, and backed by security firm Imperva, says that the vast majority of firms don't view the Payment Card Industry Data Security Standard (PCI DSS) as a strategic initiative.That's right. A survey conducted by the Ponemon Institute, and backed by security firm Imperva, says that the vast majority of firms don't view the Payment Card Industry Data Security Standard (PCI DSS) as a strategic initiative.The question is why? Why don't companies that handle credit card information view security as a strategic priority? There are a couple reasons that come immediately to mind. First, it's hard work and requires persistence. Second, good security doesn't increase market share: consumers don't reward companies when nothing bad happens. Third, many companies simply don't believe the worst will happen to them. Or, even if they do, they figure they'll handle the cost of the breach and move on.
The survey (registration required) included more than 500 U.S.-based and multinational firms. And, with the average annual revenue of survey respondents at $5.6 billion, the survey was not filled with small businesses that one would expect to be strapped. Nevertheless, the survey found that 71% of respondents said that their company does not treat PCI DSS as a strategic initiative.
More Security Insights
White Papers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
The kicker: 79% of this very same group has experienced a data breach that involved the loss or theft of credit card information.
That data hints that incurring the cost of a breach is cheaper than protecting systems and data. So does the finding that 60% of respondents don't think they have sufficient resources to comply with PCI DSS or to reach a necessary level of cardholder security.
I found that last data point especially troubling. The digital infrastructure is a crucial part of modern supply and delivery chain. And it needs to be maintained to be both sustainable, and secure, or it will break down. This should have nothing to do with regulatory compliance - but it does. Move away from heavily regulated companies and the attitude toward security gets more complacent.
They're simply not investing in the technology or the people necessary to manage risk properly.
So what happens when security isn't treated as a "strategic initiative" by a broad swath of the business community? You get what we have today, and that's the near daily news reports of credit card, financial, and other personal data being breached.
The sad fact is that PCI DSS compliance should be considered a security baseline -- not the ultimate objective, which would be a secure infrastructure. It seems many companies, most in fact, aren't even willing to make the investment required to hit bare minimum.
Follow me on Twitter, @georgevhulme
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












