Risk
2/13/2013
03:23 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Low Merchant PCI Compliance Rates Blamed On Dated Technology

PCI vendor calls for acquirer/ISO PCI program technology updates to meet merchant needs

SALT LAKE CITY, Feb. 13, 2013 /PRNewswire/ -- SecurityMetrics, a leader in payment data security and compliance, today revealed many merchants may not be compliant with the Payment Card Industry (PCI) Data Security Standard (DSS) because they lack the required liability reducing technology provided by their merchant processor. According to the company's annual Payment Card Threat Report, two-thirds of merchants aren't compliant with the PCI DSS because they store unencrypted credit card data and lack sufficient technology to eliminate sensitive information.

In addition, SecurityMetrics has revealed a growing trend that over 80% of merchants prefer their business to be covered by a breach protection program that includes prevention technology and financial stability tools in the event of a breach. However, this type of breach protection may not be readily available through many merchant processors.

SecurityMetrics recommends PCI technology modernization as a solution to the compliance crisis. Recently developed technologies, including data discovery, threat monitoring, and threat prevention tools are important in successfully achieving PCI compliance. In addition, updated management and compliance tracking tools enable easier program reporting, communication, and management for acquirer and ISO PCI compliance administrators.

"Dated technology is incapable of assisting its owner to meet today's current payment security objectives," said SecurityMetrics CEO, Brad Caldwell. "If an acquirer or ISO is stuck in a program that doesn't implement cutting edge technology, it's imperative to remodel the program to include updated technologies that increase portfolio value and decrease risk."

To learn how to remodel your PCI program with updated liability reducing technology, visit www.securitymetrics.com/remodel, contact 801.995.6864, or email remodel@securitymetrics.com

About SecurityMetrics (www.securitymetrics.com) SecurityMetrics assists in protecting electronic commerce and payments leaders, global acquirers, and their retail customers from security breaches and data theft. The company is a leading provider and innovator in merchant data security and compliance, and as an Approved Scanning Vendor and Qualified Security Assessor, has helped over 1 million organizations manage PCI DSS compliance and/or secure their network infrastructure, data communication, and other information assets. Founded in October 2000, SecurityMetrics is a privately held company headquartered in Orem, Utah, USA.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0543
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-0544
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

CVE-2015-2721
Published: 2015-07-05
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attacke...

CVE-2015-2722
Published: 2015-07-05
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

CVE-2015-2724
Published: 2015-07-05
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report