Security as a Checklist? Think Again.

July 14, 2011 • Published Categories Archive, PCI 101Tags , , , , , ,

The concept of summarizing Payment Card Industry (PCI) requirements into a simple checklist is a welcome one, especially for merchants without a dedicated security team and budget. These are usually merchants with less than one million in annual transactions and who only recently have been … Read more

The Real Cost of Data Breach

April 16, 2009 • Published Categories ArchiveTags , , , , , , , ,

(It’s more than you think—and you’re more at risk than you know.) Confusion. Denial. Plain old wishful thinking. That’s what we hear when we talk to people about the real cost of data breach. Whether you’re an ISO, an acquirer, or a merchant, maybe you’ve … Read more

Is PCI Compliance a Law? Should it be?

February 27, 2009 • Published Categories ArchiveTags , , , , , ,

Is PCI compliance a law? The short answer is no. The long answer is that while it is not currently a federal law, there are state laws that are already in effect (and some that may go into effect) to force components of the PCI … Read more

Security vs. PCI Compliance

January 30, 2009 • Published Categories ArchiveTags , , , , , , , , ,

Reading accounts of highly publicized data breaches over the last few months occurring in companies that are seemingly PCI compliant, begs the question, “does PCI compliance equal security?” The answer is, “it depends.” Unfortunately no business is ever completely secure, but companies can mitigate their … Read more

What Constitutes a Payment Application?

November 25, 2008 • Published Categories ArchiveTags , , , , , ,

Companies frequently ask us about what constitutes a payment application as it relates to PCI Compliance. The term payment application has a very broad meaning in PCI. So hopefully the content of this brief article will help clarify the subject and better define the term. … Read more

Five Common Myths Debunked

September 30, 2008 • Published Categories ArchiveTags , , , , , , ,

There is a vast need for better information about PCI compliance in the marketplace. It is a relatively new standard and there is a lack of good information available. In this article I will outline a few of the most commonly held myths that we … Read more