All the latest UK technology news, reviews and analysis

PCI compliance still lagging

by Phil Muncaster

23 Sep 2009

Comment: 1

  • Tweet this

New research shows data security is still not high enough on the list of priorities for many firms, with PCI compliance also being ignored.

The research, from app security firm Imperva, may seem a little of the "they would say that" variety, but nevertheless illuminates the attitudes of many multinational firms when it comes to protecting sensitive customer data.

It found that 71 per cent of firms still don't treat data security as a top strategic initiative, while 55 per cent said they only secure credit card information and not other sensitive information such as Social Security numbers, driver's license numbers, and bank account details .

Unsurprisingly, the report said companies taking a strategic approach to PCI compliance have fewer data breaches.

More interestingly, nearly two thirds of the firms surveyed said they don't have the resources to comply with PCI. Given that many of these are multinationals, that figure seems alarmingly high, and if true, would seem to indicate security teams need to work harder to communicate to the business the importance of compliance with the standard.

"Security departments are using PCI compliance as leverage to gain more budget, but these resources are not always translating into greater security for sensitive customer data," said Larry Ponemon, chairman and founder, Ponemon Institute.

"The results of our study indicate that while some companies have figured out how to convert PCI standards into an overall security mandate--many more have not."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Technical support Specialist (2/3rd Line) CCNA/MCITP

Technical support Specialist (2/3 rd Line) CCNA...

Senior .NET Engineer

Aufgabe: - Das Design, die Implementation und Durchführung...

Supporter

Aufgaben: - Provide basic IT support for the end users...

Network Engineer - Wireless - Manchster - CCNP - Contract

VPN - WAN - LAN - ASA - FSWM - Cisco - Routers - Swicthes...

To send to more than one email address, simply separate each address with a comma.