PCI Security: 2007 Was the Worst Year

  • Post author:
  • Post category:PCI

The Payment Card Industry Data Security Standard was supposed to fix credit card security. After 2007, I think it is fair to say it has not.

TJX lost 45 million card numbers while arguably meeting PCI requirements. Hannaford Brothers was PCI compliant at the time of their breach. Multiple other retailers suffered breaches despite having passed their PCI audits.

The compliance trap

Here is the fundamental problem with PCI: organizations treat it as a security program instead of what it actually is – a minimum baseline. Meeting PCI requirements means you have done the bare minimum that the card brands require. It does not mean you are secure. It means you have checked the boxes.

I talk to CISOs who tell me we are PCI compliant as if that sentence should end the security conversation. It should start it. Compliance is where security begins, not where it ends.

The audit problem

PCI audits are a point-in-time assessment. You prepare for the audit, you pass the audit, and then everything gradually drifts back to its natural state. By the time the next audit comes around, you prepare again. This cycle creates an illusion of continuous security while actually delivering periodic compliance theater.

What would actually help

Continuous monitoring instead of annual audits. Real penetration testing instead of vulnerability scans. Security awareness training that goes beyond a PowerPoint. And leadership that understands the difference between being compliant and being secure.

But that costs money, so we will keep doing it the current way until the breach costs exceed the compliance costs. Basic economics.