Close Menu
    • Digital Transformation
    • Open Banking
    • Funding
    • Remittance
    • Regtech
    • Hong Kong Fintech Report
    • HK Fintech Startup Listing
    • China
    • Taiwan
    • Submit Press Release
    Facebook LinkedIn X (Twitter) YouTube RSS
    • About
      • About Fintech News Network
      • Contact Us
      • Work With Us
    • FNN Media Kit
    • Fintech Newsletter
    • Submit Press Release
    • Submit
      • Submit Press Release
      • Submit Startup
      • Webinar Inquiry APAC
    • HK Fintech Startup Directory
    Fintech Hong Kong
    part of Fintech News Network

    Fintech News Network

    LinkedIn Facebook X (Twitter) Instagram YouTube TikTok RSS
    Free Newsletter
    • Payments
    • Blockchain
    • Wealthtech
    • Virtual Banking
    • InsurTech
    • Lending
    • Report
    • Fintech Events
    Fintech Hong Kong

    Fintech News Network

    Home»Mobile Payment»Verizon 2017 Payment Security Report: Payment Card Security Standard Compliance And The Ability To Defend Against Cyberattacks
    Mobile Payment

    Verizon 2017 Payment Security Report: Payment Card Security Standard Compliance And The Ability To Defend Against Cyberattacks

    Fintech News Hong KongFintech News Hong KongSeptember 22, 20175 Mins Read
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Share
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Free Newsletter

    Get the hottest Fintech Hong Kong News once a month in your Inbox

    With cybercrime on the increase, payment card security is increasingly a focus for companies and consumers alike.

    The Payment Card Industry Data Security Standard (PCI DSS) is there to help businesses that take card payments protect their payment systems from breaches and theft of cardholder data. The findings from the Verizon 2017 Payment Security Report (2017 PSR) demonstrate a link between organizations being compliant with the standard, and their ability to defend themselves against cyberattacks.

    Of all payment card data breaches Verizon investigated, no organization was fully compliant at the time of breach, and showed lower compliance with 10 out of the 12 PCI DSS key requirements.

    Overall PCI compliance has increased amongst global businesses, with 55.4 percent of organizations Verizon assessed passing their interim assessment in 2016. This is an increase from 2015, when only 48.4 percent of organizations achieved full compliance during their interim validation.This means that nearly half of retailers, restaurants, hotels and other business that take card payments are still failing to maintain compliance from year to year.

    Rodolphe Simonetti

    “There is a clear link between PCI DSS compliance and an organization’s ability to defend itself against cyberattacks,”

    comments Rodolphe Simonetti, global managing director for security consulting, Verizon.

    “Whilst it is good to see PCI compliance increasing, the fact remains that over 40 percent of the global organizations we assessed – large and small – are still not meeting PCI DSS compliance standards. Of those that pass validation, nearly half fall out of compliance within a year — and many much sooner.”

    Key insight and real-life examples into business sector compliance

    According to the report IT services industry achieved the highest full compliance of all key industry groups studied. Globally, about three fifths (61.3 percent) of IT services organizations achieved full compliance during interim validation in 2016, followed by 59.1 percent of financial services organizations (which includes insurance companies), retail (50 percent) and hospitality (42.9 percent).

    The 2017 PSR also flags the compliance challenges faced by specific business sectors including:

    • Retail: security testing, encrypted data transmissions and authentication.
    • Hospitality and travel: security hardening, protecting data in transit and physical security.
    • Financial Services: security procedures, secure configurations, protecting data in transit, vulnerability management and overall risk management.

    Real-life examples highlight situations where compliance controls are not followed. For example – a financial services organization seeking exemption from the Wi-Fi requirements of PCI DSS was surprised to learn that it did in fact have a wireless network operating in its building – this lack of knowledge causing it to fail. The IT admin had got tired of traipsing from the server room in the basement to the IT department on the third floor, and so had installed a router to access the servers from his desk.

    Mind the ‘control gap’ – key to compliance sustainability

    When looking at the PCI controls that companies would be expected to have in place (such as security testing, penetration tests etc), the report found an increased ‘control gap,’ meaning that many of these basics were absent. In 2015, companies failing their interim assessment had an average of 12.4 percent of controls absent; this has increased to 13 percent in 2016.

    Simonetti continues,

    “It is no longer the question of ‘if’ data must be protected, but ‘how’ to achieve sustainable data protection. Many organizations still look at PCI DSS controls in isolation and don’t appreciate that they are inter-related – the concept of control lifecycle management is far too often absent. This is often the result of a shortage of skilled in-house professionals – however, in our experience, internal proficiency can be dramatically improved with lifecycle guidance from external experts.”

    The 2017 PSR offers five key guidelines to assist with control lifecycle management:

    1. Consolidate for ease of management – Adding more security controls is not always the answer – the PCI DSS Standard already contains numerous interlinked data protection standards and regulations. Organizations should be able to use this to consolidate controls, making them easier to manage overall.
    2. Invest in developing expertise – Organizations should invest in their people to develop and maintain their knowledge of how to enhance, monitor and measure the effectiveness of controls in place.
    3. Apply a balanced approach – Companies need to maintain an internal control environment that is both robust and resilient if they want to avoid controls falling out of compliance.
    4. Automate everything possible – Applying data protection workflow and automation can be a huge asset in control management – but all automation also needs to be frequently audited.
    5. Design, operate, and manage the internal control environment – The performance of each control is inter-linked. If there is a problem at the top, this will impact the performance of the controls at the bottom. It is essential to understand this in order to achieve and maintain an effective and sustainable data protection program.

    Troy Leach, chief technology officer for the PCI Security Standards Council comments:

    Troy Leach

    “The report highlights the challenges organizations have to consistently maintain security controls on an ongoing basis, leaving their cardholder data environments vulnerable to attack. This trend was a key driver for changes introduced in PCI Data Security Standard version 3.2., which focus on helping organizations confirm that critical data security controls remain in place throughout the year, and that they are effectively tested as part of the ongoing security monitoring process.”

     

    Featured image via pixabay

    Payment Card Industry Data Security Standard (PCI DSS) Verizon
    Share. LinkedIn Facebook Twitter Telegram Copy Link Email

    Author

    Avatar photo
    Fintech News Hong Kong
    • Website
    • Facebook
    • X (Twitter)

    Related Posts

    Citi Launches eVouchers in Hong Kong as Digital Spending Rises

    June 16, 2026

    Turn Any iPhone Into a Payment Checkout Device With Adyen

    March 25, 2026

    Alipay Tap! Hits 100M Users, Driving Payment and AI Breakthroughs

    April 24, 2025

    Ant Group and Mastercard Launch International Consumer Friendly Zones in Shanghai

    June 3, 2024

    Ant Group Advances Global Expansion with Alipay+

    May 7, 2024

    Alipay+ Integrates 14 Global E-Wallets for Seamless Payments in Hong Kong

    April 29, 2024

    How PayMe by HSBC is Shaping Digital Payment Usage in Hong Kong

    April 11, 2024

    China’s Ant Group Increases Transaction Limits for Overseas Travelers

    March 11, 2024
    Payments Sponsored

    Why Multi-Currency Cards Need More Than Card Issuing

    7 August 2026
    Fintech Hong Kong Newsletter
    Subscribe to the most important Fintech Hong Kong News
    Follow Us
    • LinkedIn
    • Facebook
    • X / Twitter
    • Instagram
    • YouTube
    • TikTok
    Blockchain/Bitcoin Security Sponsored

    Thales Maps Out a Complete Institutional Digital Asset Security Framework

    Izzat Najmi AbdullahAugust 24, 2026
    Featured Fintech Reports

    LexisNexis Solutions

    Featured Fintech Programme

    Global FastTrack

    Featured Fintech Event

    Hong Kong FinTech Week and StartmeupHK

    Featured Webinar Replay

    Featured Fintech Videos

    TNG Digital

    Hong Kong Fintech Report

    Hong Kong Fintech Report 2025

    Australia Fintech Map

    Australia Fintech Map

    Philippines Fintech Report

    Malaysia Fintech Report

    MY Fintech Report 2025

    Singapore Fintech Report

    SG Fintech Map 2025

    Indonesia Fintech Report

    Indonesia Fintech Report 2025

    UAE Fintech Report

    UAE Fintech Map 2024

    Whitepapers & E-Books
    State of Digital Trust: AI Governance Benchmark
    State of Digital Trust: AI Governance Benchmark
    Sumsub
    Upcoming Fintech Events
    2026 Green Fintech Symposium
    September 11, 2026
    Hong Kong
    -
    Central
    Taiwan Innotech Expo 2026
    September 17, 2026
    -
    September 19, 2026
    Taiwan
    -
    Taipei
    Fin.Tech Marketing Community Hong Kong Conference 2026
    September 22, 2026
    Hong Kong
    APAC fin.tech Marketing Conference 2026
    September 22, 2026
    Hong Kong
    -
    Central
    HKIB Annual Banking Conference 2026
    September 25, 2026
    Hong Kong
    -
    Wanchai
    Promote Event View More
    FINTECH RESOURCES

    Navigations
    • About Fintech News Network
    • Contact Us
    • Media Kit
    • Work With Us
    • Fintech Hong Kong Newsletter
    • Submit a Fintech Hong Kong Press Release
    • Fintech Events Hong Kong & China
    • Fintech HK Startup Report
    • Submit Your HK Fintech Startup
    • Privacy Policy / Disclaimer
    Other Fintech News Network Publications
    Fintech News Hong Kong
    Fintech News Singapore
    Fintech News Malaysia
    Fintech News Philippines
    Fintech News Network Indonesia
    Fintech News Network Australia
    Fintech News Switzerland
    Fintech News Baltic
    Fintech News Nordics
    Fintech News America
    Fintech News Middle East
    Fintech News Africa
    Get Informed

    Subscribe to Updates

    Subscribe to the most important Fintech Hong Kong News

    LinkedIn Facebook X (Twitter) YouTube RSS
    • About Fintech News Network
    • Contact Us
    • Media Kit
    • Work With Us
    • Fintech Hong Kong Newsletter
    • Submit a Fintech Hong Kong Press Release
    • Fintech Events Hong Kong & China
    • Fintech HK Startup Report
    • Submit Your HK Fintech Startup
    • Privacy Policy / Disclaimer
    © 2015 - 2026 Copyright Finanzpro GmbH. All Rights reserved.

    Type above and press Enter to search. Press Esc to cancel.