Picture of a credit card
New standards are designed to prevent credit card fraud

Payment security is lagging

Failure to comply with card data rules puts UK businesses at risk

Written by Lisa Kelly

Just one in 10 UK merchants are compliant with payment card data security rules, leaving them open to security breaches and criminal attacks.

Only 11 per cent of retailers, financial services institutions and other businesses accepting card payments conform to the Payment Card Industry Data Security (PCI DSS) rules, according to a survey by secure transaction specialist The Logic Group.

The guidelines were developed by the PCI Security Standards Council, a global forum established by credit card firms ­to help prevent security breaches such as fraud and hacking.

The penalties of non-compliance are starting to be felt, said MasterCard vice president Paul Baker.

“Non-compliant merchants are realising the impact through the account data compromises or hacks that are now being seen,” he said.

“The damage to the brand and to customer confidence can be extreme. Our aim is to move all merchants to a compliant status as quickly as possible.”

More than four out of five relevant businesses have assessed the impact of meeting the PCI DSS requirements, says the survey. But six per cent of respondents have neither started working towards compliance, nor intend to.

Insiders say the standard needs to be more widely publicised. “Awareness is growing, but I am amazed at how many people do not know about the standard,” said one hospitality industry source.

“And many people think their software is secure but do not realise compliance means much more.”

One explanation for the slow progress is that attention has been focused elsewhere, said Gartner research director Alistair Newton.

“There has been a lack of priority in the retail community ­ merchants in the UK have been busy implementing the highly-visible chip-and-PIN so the back-end storage issues have slipped,” he said.

In May TJX, the parent company of high-street chain TK Maxx, admitted nearly 46 million credit and debit card records had been stolen over an 18-month period from July 2005. The breach cost the company nearly $130m (£64m).

“What happened to TK Maxx should drive retailers to compliance because it shows the reputational damage of a breach,” said Newton.

reader comments

related articles

Pressure on retailers over data compliance

Many could struggle to meet new security standard, reports Dave Friedlos 03 May 2007

 

Firms slow to apply card standards

Study shows 40 per cent of firms have no plans to achieve PCI standard 07 Dec 2006

Retailers ignore security plan

Survey suggests new data security standard having little effect 22 Sep 2005

TK Maxx ruling prompts sales pitch

VARs urged to watch for retail sector security sales opportunities 14 Aug 2008

Meru locks out car park hackers

New system aims to stop wireless data seeping out of the office 28 Jul 2008

US cracks 'largest ever' ID theft ring

Gang allegedly stole millions of dollars using 40 million stolen credit and debit card numbers 06 Aug 2008

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation