Comments on: The costs and benefits of PCI-DSS http://tomorrowstransactions.com/2013/02/the-costs-and-benefits-of-pci-dss/ Thought leadership from Consult Hyperion Tue, 09 Sep 2014 00:19:19 +0000 hourly 1 http://wordpress.org/?v=4.0 By: PCI Guru http://tomorrowstransactions.com/2013/02/the-costs-and-benefits-of-pci-dss/#comment-207 Tue, 26 Feb 2013 12:23:48 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/02/the-costs-and-benefits-of-pci-dss/#comment-207 PCI compliance is only expensive if you either; (a) have done nothing in the past to secure your cardholder data, or (b) are just plain stupid in how you approach it.

Most of the merchants I encounter fall into the (a) category in that they have POS systems from the late 1990s (remember Y2K?) and have not updated their infrastructure since they went to an IP network around the same time. Merchants live on thin margins and upgrading hardware and software every three to five years is just not affordable, even for the largest merchants. These merchants have no choice but to spend a lot of money to get PCI compliant.

However, I do encounter the occasional merchants that are in the (b) category. Typically they are in this situation because their IT personnel tried to find a “silver bullet” solution and bought every PCI compliance “widget” they could find in a vain attempt to get an easy way out. Had they put together a plan, it might have cost them a fraction of what they spent and still do not have a solution. They will continue to spend money like a drunken sailor until someone finally stops it and gets a plan put in place.

]]>
By: PCI Cynic http://tomorrowstransactions.com/2013/02/the-costs-and-benefits-of-pci-dss/#comment-206 Wed, 20 Feb 2013 09:32:25 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/02/the-costs-and-benefits-of-pci-dss/#comment-206 One of the things that make PCI expensive to implement is that at the end of the day you have to be able to decrypt data to send it to the acquirer/card schemes in the clear, so you have to have a means of doing this and controls around how it is done (which is not cheap). If the risk equation above really made sense card acquirers/ schemes would not accept data in the clear as the risk/libability using the Maths above would be astronomic. They do – they have not and do not intend to modify the way they receive clearing files and probably site compensating controls – the big PCI get out of jail free card. Spending money on security will always improve security, but I wholehartedly agree that the bang per buck on PCI is woeful – which is obvious from the huge costs that have been incured and the lack of impact to overall card fraud figures. Chip and PIN had and impact .The PCI benefits are theoretical and have not been measured objectively.

]]>