Artist's Impression of Spurs new ground
Spurs' planned 58,000 seater stadium needs all the credit card transactions possible

Spurs aiming for the goal of PCI card security compliance

Tottenham Hotspur hopes to avoid penalties by meeting 1 October deadline

Written by Dave Bailey

Our banks are thumping the desk and saying it's do-or-die by 1 October

Philip Rose Head of IT, Tottenham Hotspur

Premier League football club Tottenham Hotspur has a critical short-term goal to achieve - other than trying to remain near the top of the table.

The club is racing against an October deadline to roll out compliance with the payment card industry's data security standard (PCI DSS).

Spurs processes 700,000 credit card transactions a year, and a planned new 58,000-seater stadium, up from 36,000 seats, is expected to increase the number of credit card transactions significantly.

Currently, many of its match ticket and merchandise payments are made by credit card, and Tottenham’s four-strong IT team found itself having to keep up with the demands of PCI DSS.

Mail order sales make up half the merchandising business, although the club's popularity with longstanding fans makes ticket sales less of a worry.

"The ticketing side is less of an issue because 22,000 out of 36,000 are season tickets, and that's a single sale," said Tottenham Hotspur’s IT and telecommunications manager, Philip Rose.

But it soon became apparent that delivering PCI DSS was about more than just credit card security.

"When PCI raised its ugly head, one of the gaps that our quality service assurance found was that we did not have any structure here for incident management, which is one of the planks of PCI compliance," he said.

Rose said that Spurs had been using Numara Track-It software for its helpdesk, but wanted the supplier to add hardware and software asset management to the package, as well as change and incident management. When Numara bought rival UniPress in 2006, that opened up an opportunity to upgrade to the firm's FootPrints application to assist in the compliance process.

"Numara gave us a very good deal, because we were trading up, and another important point was that it was IT Infrastructure Library (ITIL) compliant," said Rose.

The change of software required Spurs' IT department to migrate its data from one package to the other.

"It's now in place and we have the incident management up and running, with full alerting in place, and we also have a dedicated helpdesk type of email where users can log emails straight into the system," said Rose.

Spurs also uses Centennial Software for asset management.

Rose said that when Spurs' IT department became aware of the PCI initiative, he knew that there would have to be big changes in the IT infrastructure.

"We also have to take on board the security management that you see in banks and financial institutions," he said.

Spurs has recently completed its second annual penetration test, and time is tight to achieve PCI compliance.

"Our banks are thumping the desk and saying it's do-or-die by 1 October," said Rose.

One of the problems for Spurs was that its application providers "are a little bit behind the ball", according to Rose. Some of the club's ticketing and software suppliers have found PCI, "hard to swallow", he said.

"You're looking at very big legacy software designed in the US, which has a lot of code to be checked," said Rose.

"PCI for us is quite crucial. It's not so much that we could have a breach, it's more the brand damage that our board wants to steer clear of. You only have to look at those firms who have been breached. Small companies who have a breach are either going to get fined out of business or they won't be able to continue trading online, and if you're a mail order business that's the end of the road. "

Spurs has managed to change most of its network infrastructure, network monitoring and security, but still has work to do.

"We're not quite there yet, but we've assured the bank that everything we're responsible for will pretty much be in place for 1 October," said Rose.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Skipton Building Society branch officeCommunications

Skipton deploys log management kit to ease PCI compliance

Skipton Building Society deploys LogLogic appliances to achieve PCI compliance and improve system security 27 Jul 2009

 

IT products and services set for regulation by 2015

Gartner advises firms to prepare for the likely effect rules will have on their processess 10 Aug 2009

Bolton Wanderers achieves virtual success

A new virtualisation infrastructure and disaster-recovery systems means the football club's IT systems will be better able to withstand match-day pressure 28 Aug 2009

PCI Council gives helping hand to merchants

Prioritized Approach framework to help attain PCI DSS compliance 04 Mar 2009

PCI to assess the assessors

New assurance programme for certified assessors 17 Nov 2008

Football season ticket prices face tax hike

Business tax rise for football clubs could provide local authorities with another £9m a year 27 Oct 2009

Tax concerns over offshore-owned football clubs

Christian Aid has a dig at the financial opacity of football clubs 11 May 2010

Clubs under pressure as HMRC blows the whistle

FDs lose out in boardroom battles as football clubs forget the lessons from previous administrations 18 Feb 2010

related white papers

today's top stories

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Genuinely intuitive technology is years away

If the aim of technology is to simplify our lives, then it has failed 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Clouds reflected in office blockFeatures

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

Dale VileFeatures

Defining cloud computing

Making sense of what cloud means to your business involves evaluating the options and clarifying the benefits you expect from its implementation, writes Dale Vile 08 Sep 2010

Primary Navigation