Verizon: Just 25% of global businesses comply fully with the Payment Card Industry Data Security Standard
- Reference: 1602006073
- News link: https://www.theregister.co.uk/2020/10/06/verizon_pci_dss_survey/
- Source link:
The company's 2020 Payment Security Report found that only 27 per cent of organisations worldwide were in line with the full ambit of the PCI DSS (Payment Card Industry Data Security Standard) for handling payment card data in online purchases.
"Unfortunately we see many businesses lacking the resources and commitment from senior business leaders to support long-term data security and compliance initiatives. This is unacceptable," said Sampath Sowmyanarayan, president, Global Enterprise, Verizon Business. "Payment security has to be seen as an ongoing business priority by all companies that handle any payment data, they have a fundamental responsibility to their customers, suppliers and consumers."
Compounding that, Verizon also said that PCI DSS compliance has fallen by 27 percentage points since 2016, with [1]2017's report seeing 55 per cent of orgs passing the "interim assessment" stage.
A UK-based small business owner offered to shed a little light on the report's main finding for The Register anonymously, lest he trigger the wrath of his payment provider. He said: "The questions are so convoluted and confusing, and you can only put 'Yes', 'No' or 'Not sure' answers... which doesn't always fit. I fecking hate having to do it... too much technical speak and legalese and I have no idea what the majority of it means despite doing my best to understand it all."
More worryingly, Verizon reckoned that just 70 per cent of financial institutions "maintain essential security perimeter controls".
US outfits were the least likely to comply with PCI DSS, with just 20 per cent of orgs examined by Verizon making the grade. APAC, meanwhile, saw compliance rates of 70 per cent with Europe sitting in the middle at around half of organisations complying with the standard.
Hospitality was the industry least likely to be compliant across the world, with a quarter of businesses in that sector meeting full compliance standards. Financial services led the way: 40 per cent of institutions in that sector met the rules in full.
Some things don't change. More than a decade ago, a survey carried out by the Ponemon Institute found that [2]companies were struggling even back in the 2000s with PCI DSS . The standard was first devised in 2005. ®
Get our [3]Tech Resources
[1] https://www.theregister.com/2017/08/31/pci_compliance_survey_verizon/
[2] https://www.theregister.com/2009/09/23/data_security_survey/
[3] https://whitepapers.theregister.com/
Re: I bet it's even less in reality...
The problem is that the questionnaire is set up to where you have to answer "yes" on everything to pass. A single "no" means that you fail.
I work in IT security. I hold several IT security certifications, and have over 25 years of experience in IT. I can honestly say that it is completely unrealistic to be able to answer "yes" to 100% of the questions on the PCI questionnaire.
You read the thing, and keep thinking to yourself, that this must have been written by a group of Academics that have never worked in an actual business and have met real human beings.
The only way to answer "yes" to 100% of the questionnaire would be to close the business and lock up all of the servers in a vault somewhere. This is where the "clicking yes to everything" (the AC above mentioned) comes from.
I do completely agree with the spirit of what PCI DSS is trying to do. And I agree that as much as 90% of what is being asked is essential to security. The problem is the 10% that is not going to happen in most operating businesses.
I will also point out that most of the major breaches of credit card information happened at companies that were PCI Level 1 compliant at the time of the breach. That one fact right there shows what a useless exercise PCI really is.
The same Verizon...
....that allowed 14million billing accounts to be lifted?
Re: The same Verizon...
Why yes, yes I believe it is the same Verizon. Remember folks - do as I say, not as I do.
Standards make us feel good, but accountability keeps us right.
The PCI industry has only itself to blame. The bureaucratic rules are vague enough to drive a truck through, and they accept worthless trash as a security scan to certify compliance.
Want to know how to pass a Trustwave scan? Suppress web server version strings. That's it. If you let it grab the version, it'll list EVERY vulnerability against that version of the software as if you're vulnerable, never-mind whether you're running a version that's patched the vulns, the vulnerable features are all disabled, and it's duly harded. But disable the version reporting, and you can have loads of unpatched vulnerabilities and rootkits everywhere. There is no ATTEMPT to check. That would cut into their profits, which then cuts into the kickbacks...
I bet it's even less in reality...
... I have clients who just run down the questionnaire portion of TrustWave's audit, ticking yes on everything. I bet the true compliance number is even less; I wouldn't be shocked if it were single digit. (And yes, I've told them to actually read it and do what's needed...)