Merchants who store unencrypted payment card data directly violate Payment Card Industry Data Security Standard (PCI DSS) requirements and may be subject to fines and other penalties after a compromise. The discovery of unprotected cardholder data may indicate a number of factors, including an improperly designed or configured payment application, a non-PCI compliant payment application or improper card handling by employees.
"There's so much going on in the security industry that it's sometimes difficult to target the most important things," said SecurityMetrics CEO Brad Caldwell. "We think these findings are a game changer for the security industry, and will help focus priorities on the bigger problem plaguing merchants today. After all, criminals can't steal card data merchants don't have."
In it's entirety, the study found over 370 million unencrypted cards on various-sized business and home networks, with the largest amount of payment cards discovered in a single network scan at over 96 million. The study concluded card discovery and deletion is not a one-time event, but must be a part of regular business operation to impact security.
"Today's business landscape is littered with merchants that don't know exactly what's on their system," said SecurityMetrics Director of Forensic Investigations, David Ellis. "In the majority of cases we've investigated, the merchant was unaware their system was storing unencrypted payment card data. Merchants must take responsibility for their customers' card data, which in turn will benefit worldwide commerce in general."
Core to the study was PANscan, a card discovery tool that searches for unencrypted track 1, track 2 and Primary Account Number (PAN) data on merchant networks. If you would like to view the report, or download PANscan to determine if your business is storing data, visit https://www.securitymetrics.com/sm/public/panscan/resources.
About SecurityMetrics
SecurityMetrics assists in protecting electronic commerce and payments leaders, global acquirers, and their retail customers from security breaches and data theft. The company is a leading provider and innovator in merchant data security and compliance, and as an Approved Scanning Vendor and Qualified Security Assessor, has helped over 1 million organizations manage PCI DSS compliance and/or secure their network infrastructure, data communication, and other information assets. Founded in October 2000, SecurityMetrics is a privately held company headquartered in Orem, Utah. For more information, visit www.securitymetrics.com.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
What's Next for Certificate Technology
A recent rash of certificate authority breaches has left a bad taste in many people's mouths. There is no one reason for the breaches. The compromises were the result of a breakdown in people, processes and technology, but not necessarily the certificates themselves. We take a look at what?s wrong with certificate technology, what can be done to fix it, and what's down the road for certificates and CAs.
Will Smartcards Live Up to Their Name?
Recent compromises of smartcard data have exacerbated concerns about the technology?s privacy, security and standards (or lack thereof). Yet the promise of smartcards is too compelling to ignore. New technologies and applications prompt us to take a fresh look.
Get The Best Of Biometrics
As data volume and sensitivity grow, companies cannot rely on password- and token-based authentication. Biometrics can be used to provide strong access control, but you must weigh added complexity and costs against assurance that users are who they say they are.
Other reports from the Authentication Tech Center:
MORE NEWSFEED >>>