Visa, Discover and others are taking a tougher stance on noncompliance as data breaches continue to tarnish the retail industry
Major credit card companies have made it mandatory for merchants and payment processors to comply with stringent network security rules that went into effect in mid-2005. But getting buy-in from the millions of companies that handle credit card information remains elusive.
American Express, Visa International, MasterCard Worldwide and Discover Financial Services are among the backers of the rules known as the Payment Card Industry Data Security Standard (PCI DSS).
“All the merchants are required to comply with the PCI data-security standards or face fines,” says Rob Tourt, vice president of network services at Discover. Yet adoption of PCI DSS is not widespread, Tourt admits, though he wouldn’t disclose exact figures.
To improve compliance, Discover is getting more aggressive and working individually with certain merchants to make sure they get through the 12-point security plan, which covers firewalls, vulnerability assessment and encryption, among other requirements.
Discover isn’t alone in striving to turn PCI DSS into more than a paper tiger. Visa, which works more directly with acquiring banks than with merchants, also is trying to shore up low merchant adoption numbers.
Visa’s new approach calls for levying punitive fines on banks that fail to get their merchant customers to comply with the PCI standard — while promising multimillion-dollar incentive packages for banks that prod their largest customers into complying.
The broader goal is to stem the hemorrhage of sensitive customer card data lost in recent security incidents, including the data breach acknowledged earlier this month by TJX Companies, which operates retail chains including T.J. Maxx and Marshalls.
The $16 billion Framingham, Mass., retailer won’t divulge whether it complies with PCI DSS, despite the fact that Gary Crittenden, the executive vice president and CFO at American Express, sits on the TJX board.
American Express is one of the five payment-card companies that last September founded the PCI Security Standards Council, which issues the PCI security standard. The other four founding members are: Discover, JCB, MasterCard and Visa.
PCI DSS too tough?
The latest version of the standard, PCI DSS v. 1.1, includes about 200 detailed network and physical security requirements the council’s founders say they want to see become the norm for protecting payment-card information.
“We want to work together to drive things forward,” says Seana Pitt, chair of the PCI Security Standards Council and a vice president at American Express. “This is the first time the five competing brands have come together.”
The standard also includes provisions for “compensating controls” that let organizations propose alternative solutions if they can’t reasonably meet a particular requirement, such as using encryption to render cardholder data unreadable.
“For older retailers with mainframe systems from the ’70s, this may be difficult to do,” Pitt says. “If you have a business or technical challenge, the compensating control is a way to demonstrate how to secure that data through alternative methods.”
In spite of such allowances, PCI DSS adoption lags among merchants that tend ignore the requirements until they face punishment for noncompliance, some industry sources say.
Visa, which wouldn’t disclose how many of the 24 million Visa card-accepting merchants worldwide are compliant, says it is focused on working with acquiring banks to get Level 1 and Level 2 merchants — which account for nearly two-thirds of Visa’s U.S. transaction volume — on board.
Current PCI compliance among the 230 Level 1 merchants, which process more than 6 million card transactions per year, is 36%, Visa says. Among Level 2 merchants, which process between 1 million and 6 million card transactions, compliance is 15%.
As part of its carrot-and-stick approach, Visa is investing $20 million in an incentive fund payable to the financial institutions of the largest U.S. merchants that have already or will validate PCI compliance by the end of August. Conversely, banks risk fines between $5,000 and $25,000 per month for failing to get Level 1 merchants on track by August and Level 2 merchants on track by year-end.
Other fines also could apply, such as $10,000 per month, per merchant, for storing prohibited types of card information. Visa says it levied $4.6 million in fines last year, up from $3.5 million the year before.
A priority for some
Some businesses that process card payments say they take the PCI DSS mandate very seriously.
Boddie-Noell Enterprises, which operates 385 restaurants and stores, is focused on attaining PCI DSS compliance as a Level 1 merchant. The challenge is that Level 1 certification requires some changes in its data center. “This really impacts how you design your network,” says Adam Ipock, senior director of information systems at the Rocky Mountain, N.C.-based company.
For example, to satisfy one part of PCI certification, Boddie-Noell determined it would need to add VPN equipment, and probably more staff, to link point-of-sale (POS) devices in its restaurants and stores, says Bob Larimer, the company’s director of network computing.
Instead of tackling the issue in-house, Boddie-Noell is turning to an outsourcing partner. Contingent Network Services of Cincinnati is providing the VPN and firewall support to cover PCI requirements to encrypt card data traveling from POS terminals over the wide area.
Putting encryption technologies in place also has been a priority for Communications Data Services (CDS), a division at Hearst that carries out data processing on behalf of magazine publishers.
“We are covered under the PCI requirements for about 20 million credit cards,” says Paul McCarthy, a CDS vice president. “All the credit card information in our files is encrypted.”
CDS also uses Palisade Systems’ data-leak prevention gear to monitor outbound and inbound communications with business partners to make sure card data is sent securely.
An inbound transmission “could come from some marketing company unaware of the rules, so we quarantine it to find out exactly where it came from,” McCarthy says. “Each week we might find an Excel spreadsheet with 150 credit-card numbers exposed.”
Security-assessment firms accredited by the PCI Security Standards Council to assist in compliance say the standard is tough but necessary.
“It goes very deep into the way a company organizes its security,” says Abe Kleinfeld, president and CEO of scanning vendor nCircle. He admits the standard can be burdensome, but says a zero-tolerance approach is necessary “because we’ve got to try and prevent these data breaches, which are happening at about one per week.”
The frequency of news about data breaches could soon put the card-processing business community in the hot seat with Congress. The new chairman of the House Financial Services Committee, Barney Frank (D-Mass.), voiced dismay earlier this month over the TJX breach, and his aides suggested he might consider legislation aimed at payment-card protection.
Pitt says the PCI Security Standards Council, while advocating adoption of PCI DSS, isn’t ready to push for it become federal law. “We see this remaining a robust standard,” Pitt says.




