https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Vertical Markets


PCI Compliance

3 Takeways from Verizon’s 2017 Payment Security Report

  • Written by James Anderson
  • August 31, 2017
Businesses ignore payment security compliance measures at their own peril.

A new study from Verizon shows businesses suffering a heavy price for not being compliant with their payment security.

Verizon on Wednesday released its 2017 Payment Security Report, which analyzes how organizations protect the privacy of customer payment cards. We analyzed the report and came up with three main findings.

1. Businesses ignore payment security compliance measures at their own peril.

Verizon's Rodolphe Simonetti

Verizon’s Rodolphe Simonetti

Verizon says it has shown a “demonstrable” correlation between businesses that are up-to-date on the Payment Card Industry Data Security Standard (PCI DSS) and businesses that have successfully defended themselves against cyber threats.

“There is a clear link between PCI DSS compliance and an organization’s ability to defend itself against cyberattacks,” said Rodolphe Simonetti, Verizon’s global managing director for security consulting. “[While] it is good to see PCI compliance increasing, the fact remains that over 40 percent of the global organizations we assessed – large and small – are still not meeting PCI DSS compliance standards. Of those that pass validation, nearly half fall out of compliance within a year — and many much sooner.”

The key finding is that none of the payment card breaches examined involved a fully PCI DSS-compliant company. Verizon studied nearly 300 breaches that occurred from 2010 to 2016. Those breached payment systems scored lower on compliance in 10 out of 12 of the standard’s main requirements. Those requirements include a regularly maintained firewall, passwords that have been updated from the default, antivirus software, network monitoring and policies that restrict access to cardholder data.

2. Compliance is growing.

But Verizon reports an increase in PCI-compliant companies. The number of surveyed organized organizations “at interim validation” was 55 percent this year, an increase from 48 percent in 2015. Only 11 percent passed the compliance measures in 2012.

Which vertical had the highest compliance rate? Perhaps not surprisingly, it was IT services, at 61 percent. Financial services followed at 59 percent, and retail (50 percent) and hospitality (42 percent) trailed even more. The compliance issues vary based on the industry. For example, retail struggles with security testing, and financial services struggles with protecting data in transit.

3. Being “compliant” isn’t all that matters.

Despite the increase in compliant companies, Verizon notes a potentially harmful “control gap.” This means that the number of failed PCI compliance measures divided by the total number of PCI compliance measures has increased over last year.

“The report highlights the challenges organizations have to consistently maintain security controls on an ongoing basis, leaving their cardholder data environments vulnerable to attack,” said Troy Leach, chief technology officer for the PCI Security Standards Council. “This trend was a key driver for changes introduced in PCI Data Security Standard version 3.2., which focus on helping organizations confirm that critical data-security controls remain in place throughout the year, and that they are effectively tested as part of the ongoing security monitoring process.”

The PCI requirement that companies most frequently met (94 percent) was the restricting of user access rights to a “need-to-know” basis. The respondents also scored well (92 percent) in protecting against malicious software. The worst compliance requirement was the testing of security systems and processes; only 72 percent of companies have instituted processes like vulnerability scanning and penetration testing.

Verizon has been rather prolific in publishing lengthy studies that pertain to cybersecurity and data breaches. It rolled out a survey of more than 42,000 data exposure incidents earlier this year and published a fascinating list of data-breach anecdotes.

Peter Merkulov has several tips for channel partners as they help their clients manage the more and more complex compliance landscape.

Tags: Agents Regulation & Compliance Security Vertical Markets

Most Recent


  • Doubling down
    The Gately Report: Huntress to Double Down on MSP Partner Investment in 2023
    A massive health care industry data breach remained under wraps for nearly a year.
  • Making Waves
    8 Channel People Making Waves This Week at T-Mobile, Kaseya, Google Cloud, Atlassian, More
    How much did Ryan Reynolds actually come away with from the T-Mobile-Mint Mobile deal?
  • Money Growth
    10 Findings from Channel Futures' MSP Quarterly Survey: Profit Outlook Positive Despite Macro Challenges
    Cybersecurity grew significantly among MSPs, but AI adoption didn't grow as much as one expert expected.
  • Layoff written in metal
    Wipro Layoffs Hit 120 Workers in Florida Due to Lack of Work
    During the last two months 44,900 IT jobs have been lost.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • College classroom
    Community College Ransomware Attack Wreaks Havoc
  • Cloud Certification
    CompTIA Updates Cloud+ Certification, Drops New AI Guide for Businesses
  • cybersecurity lock
    Telos Partners Get New CyberProtect Partner Program
  • Cloud security
    VMware Debuts Cloud Web Security on SASE Platform

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

VMware Partner Connect Now in Full Swing Worldwide

March 20, 2023

The Gately Report: Huntress to Double Down on MSP Partner Investment in 2023

March 20, 2023

8 Channel People Making Waves This Week at T-Mobile, Kaseya, Google Cloud, Atlassian, More

March 17, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

.@VMware has finalized #PartnerConnect and plans to keep it as-is (minus simplification changes) for years to come.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Our latest #GatelyReport includes a Q&A with @HuntressLabs, massive ILS #databreach, new @SECGov cyber proposal,… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Channel people making waves include: @MikeSievert, @TheFredVoccola, @Ichhpurani, @mcannonbrookes, @scottfarkas… twitter.com/i/web/status/1…

March 17, 2023
ChannelFutures

📣 Join us on April 4th to learn about the latest trends in cloud deployment and how to leverage cloud choice to emp… twitter.com/i/web/status/1…

March 17, 2023
ChannelFutures

#CPExpo preview: @ITinnovators' Dave Seibert on increasing #SMB client sales. dlvr.it/Sl3Rdx https://t.co/TVrCWkZmdS

March 17, 2023
ChannelFutures

Who run the world? >> #WomeninTech. See who made the list of top women-owned managed service providers in the techn… twitter.com/i/web/status/1…

March 17, 2023
ChannelFutures

#MSPs shared numbers about their technology sales and their expected business growth. dlvr.it/Sl2nfL https://t.co/fapRQ4jqlZ

March 17, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X