Welcome Guest. | Log In | Register | Membership Benefits

Research: Small Merchants Don't Believe PCI Compliance Will Protect Them

Study finds a continued lack of knowledge on PCI DSS

Nov 11, 2011 | 05:48 PM | 


The prominence of large and small data breaches in number and resulting media coverage has served to further polarize how small- to mid-sized merchants approach data security and PCI compliance – from little worry to security priority. This conclusion is just one of the major findings from a survey of nearly 620 Level 4 merchants conducted by ControlScan (www.controlscan.com) and Merchant Warehouse' (www.merchantwarehouse.com).

According to the survey, A “Perfect Storm” of Complacency: The Third Annual Industry Survey of Level 4 Merchant PCI Compliance Trends, merchants with 10 or fewer employees – known as micro-merchants – are stubbornly persistent in their belief that PCI compliance will not protect their business. Even more, the study finds a continued lack of knowledge on the Payment Card Industry Data Security Standard (PCI DSS). Of those micro-merchants surveyed, 48 percent reported they were either “unsure” of or “not at all familiar” with the Payment Card Industry Data Security Standard.

In contrast, 77 percent of large Level 4 merchants, which are defined as those that employ 51 or more employees, confirmed they are “very” or “somewhat” familiar with the PCI DSS, with 79 percent considering data security a high priority and 82 percent considering PCI compliance mandatory. Awareness of PCI compliance is also high among e-commerce merchants at 64 percent.

“The results of this year’s survey, compared to years’ past, show us that education and structured PCI compliance programs are helping large Level 4 and e-commerce merchants make strides in PCI compliance,” said Henry Helgeson, co-CEO of Merchant Warehouse. “Unfortunately, the results also show us that micro-merchants are either unaware of the PCI DSS or actively choose not to embrace data security or the PCI DSS, because they don’t understand the risks. Merchants’ lack of awareness makes them more vulnerable to hacker attacks on cardholder data and could lead to catastrophic financial losses.”

Belief among Level 4 merchants that PCI compliance should be mandatory increased to 60 percent over the last year – a 10 percent gain. E-commerce (68 percent), companies with 51 or more employees (82 percent) and transaction volumes of $251,000 - $1M (69 percent) rated it even higher.

“We are encouraged by both the adoption and serious thought large Level 4 and e-commerce merchants are putting into their security posture and compliance, which we find directly related to the education and resources they receive on PCI compliance,” said Joan Herbig, CEO of ControlScan. “There is still a tremendous opportunity, however, for ISOs and acquirers to share that same education with micro-merchants in order to guide them through PCI compliance by setting stronger repercussions for non-compliance and establishing data security as an ongoing process.”

For the first time, the survey asked if small- to mid-sized merchants were more concerned with “outsider” or “insider” data security attacks. Of micro-merchants, 85 percent saw outsiders as the biggest threat, while the percentage went down for larger Level 4 merchants to 69 percent.

The precise impact of emerging technologies, such as point-to-point encryption and tokenization, on a merchant’s PCI compliance efforts is still unfolding. Yet, ISOs and acquirers are encouraged to stay apprised of developments in this space.

“These technologies hold great promise for reducing the merchant’s efforts to comply with the PCI DSS, while increasing their security posture,” continued Herbig. “The PCI Council has also recently provided guidance in these areas and will be providing more information in the coming months, which should help increase clarity and adoption.”

To access a copy of the detailed study findings, please click on the following link:

https://www.controlscan.com/whitepapers/merchant_study_2011.php. NOTE: link will be live Thurs., Nov. 3.

ControlScan and Merchant Warehouse are also hosting a joint Webinar to be held on November 10, 2011 at 2 – 3 p.m. ET to present the study’s findings. To register, please click on the following link: https://www2.gotomeeting.com/register/714284818.

About the Survey

The survey was completed in August 2011 by 621 Level 4 merchants who represent a mix of e-commerce, retail stores and mail order/telephone order businesses.

About the PCI Compliance Provider, ControlScan:

Headquartered in Atlanta, Georgia, ControlScan is the leading provider of Payment Card Industry (PCI) Compliance and Security services designed to meet the unique needs of small to mid-sized merchants and the acquirers that serve them. The company’s flexible solutions, easy-to-use online tools and personalized support significantly simplify PCI and security for its clients. In addition, as an Approved Scanning Vendor and a Qualified Security Assessor, ControlScan is positioned to help merchants meet compliance requirements and maintain secure business environments for their customers. For more information about ControlScan and its cloud-based solutions, visit www.controlscan.com or call 1-800-825-3301.

About Merchant Warehouse:

Merchant Warehouse is an award winning provider of secure payment processing solutions and merchant account services to merchants and point-of-sale developers nationwide. As an industry leader, Merchant Warehouse is committed to ensuring its merchants, agents and partners are offered the most forward thinking payment solutions, delivering PCI compliant solutions that minimize the complexities of compliance for merchants. Headquartered in Boston, MA, since 1998, Merchant Warehouse continues to provide account services to hundreds of thousands of merchants and serves hundreds of agents and partners. For more information, please visit merchantwarehouse.com or follow us on Twitter at http://twitter.com/MWarehouse. Visit our blogs at http://blog.merchantwaresolutions.com/ and http://blog.merchantwarehouse.com.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Compliance Reports

report How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.

report Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.

report FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.

Other reports from the Compliance Tech Center:

Related Content

Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.

SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.

Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.

Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.

Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.




Featured Webcasts
Featured Whitepapers
Featured Reports