.
/v3-uk/news/1972705/heartland-usd60m-settlement-visa-issuers
09 Jan 2010, Phil Muncaster , V3
Heartland Payment Systems, the fifth largest payments processor in the US, has agreed to pay issuers of Visa-branded credit and debit cards up to $60m (£37m) in compensation for losses incurred after the huge data breach in 2008.
The company revealed in January last year that hackers had infiltrated its computer systems and planted malware on its servers designed to steal card data. In the region of 100 million cards are thought to have been compromised.
Heartland chairman Bob Carr said that he was pleased to have reached a "fair settlement agreement" regarding the losses issuers may have suffered as a result of the intrusion.
"At Heartland, we are committed to helping issuers, as well as all stakeholders in the payment ecosystem, to mitigate future risk," he added.
"We have assumed a leadership position in the development of enhanced data security and fostering the sharing of information."
Ellen Richey, chief enterprise risk officer at Visa, urged issuers to participate in the settlement programme while emphasising Visa's security credentials.
"Helping financial institutions mitigate costs after a data security breach has been a long-standing component of Visa's security strategy, along with promoting new security technologies, preventing fraud and leading efforts to secure sensitive data across the entire payment system," she said.
The Visa payout comes just a month after Heartland announced a similar settlement with American Express of $3.6m (£2.2m), and yet again highlights the financial penalties that can result when IT systems are compromised.
Do you agree?
Most Companies Enjoy "Security" as a Matter of Luck
Anyone else here reading ?I.T. WARS?? I had to read parts of this book as part of my employee orientation at a new job. The book talks about a whole new culture as being necessary ? an eCulture ? for a true understanding of security, being that most identity/data breaches are due to simple human errors. It has great chapters on security, as well as risk, content management, project management, acceptable use, policies, and so on. Just Google ?IT WARS? ? check out a couple links down and read the interview with the author David Scott. (Full title is ?I.T. WARS: Managing the Business-Technology Weave in the New Millennium?).
Posted by Janice Gaines, 09 Jan 2010