Posted on August 10th, 2009 No comments
If Firms are PCI Compliant, Why are They Getting Breached?The recent data breach at Internet domain administrator and host Network Solutions compromised more than 573,000 credit and debit cardholders and begs the question: What more can be done to secure such systems? The incident also raises new questions about the Payment Card Industry Data Security Standard (PCI).
Network Solutions Breach Revives PCI Debate
Posted on May 4th, 2009 No comments
The back-and-forth compliance dance that is being forced upon Heartland Payment Systems took its latest journey through the PCI Looking Glass Friday (May 1), with Heartland declaring that it has now returned to Visa’s list of PCI DSS validated service providers (aka the list of providers that Visa heartily recommends today but will deny ever having heard if they’re breached tomorrow).The journey began when Heartland was certified PCI compliant April 2008. A few months later, Heartland was severely breached and Visa began its revisionist history dance. Given a public stance that no PCI-compliant merchant or processor had ever been breached, Visa determined that Heartland therefore could not have been truly compliant in April 2008