Risk
2/13/2013
03:23 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Low Merchant PCI Compliance Rates Blamed On Dated Technology

PCI vendor calls for acquirer/ISO PCI program technology updates to meet merchant needs

SALT LAKE CITY, Feb. 13, 2013 /PRNewswire/ -- SecurityMetrics, a leader in payment data security and compliance, today revealed many merchants may not be compliant with the Payment Card Industry (PCI) Data Security Standard (DSS) because they lack the required liability reducing technology provided by their merchant processor. According to the company's annual Payment Card Threat Report, two-thirds of merchants aren't compliant with the PCI DSS because they store unencrypted credit card data and lack sufficient technology to eliminate sensitive information.

In addition, SecurityMetrics has revealed a growing trend that over 80% of merchants prefer their business to be covered by a breach protection program that includes prevention technology and financial stability tools in the event of a breach. However, this type of breach protection may not be readily available through many merchant processors.

SecurityMetrics recommends PCI technology modernization as a solution to the compliance crisis. Recently developed technologies, including data discovery, threat monitoring, and threat prevention tools are important in successfully achieving PCI compliance. In addition, updated management and compliance tracking tools enable easier program reporting, communication, and management for acquirer and ISO PCI compliance administrators.

"Dated technology is incapable of assisting its owner to meet today's current payment security objectives," said SecurityMetrics CEO, Brad Caldwell. "If an acquirer or ISO is stuck in a program that doesn't implement cutting edge technology, it's imperative to remodel the program to include updated technologies that increase portfolio value and decrease risk."

To learn how to remodel your PCI program with updated liability reducing technology, visit www.securitymetrics.com/remodel, contact 801.995.6864, or email remodel@securitymetrics.com

About SecurityMetrics (www.securitymetrics.com) SecurityMetrics assists in protecting electronic commerce and payments leaders, global acquirers, and their retail customers from security breaches and data theft. The company is a leading provider and innovator in merchant data security and compliance, and as an Approved Scanning Vendor and Qualified Security Assessor, has helped over 1 million organizations manage PCI DSS compliance and/or secure their network infrastructure, data communication, and other information assets. Founded in October 2000, SecurityMetrics is a privately held company headquartered in Orem, Utah, USA.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7441
Published: 2015-05-29
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

CVE-2014-9727
Published: 2015-05-29
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

CVE-2015-0200
Published: 2015-05-29
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

CVE-2015-0751
Published: 2015-05-29
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

CVE-2015-0752
Published: 2015-05-29
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?