Gartner: No need to drop Heartland over PCI delistings
- 25 March, 2009 08:21
- Comments
A Gartner Inc. analyst is urging companies that do business with Heartland Payment Systems Inc. and RBS WorldPay Inc. not to switch to other payment processors just because of Visa Inc.'s decision this month to remove Heartland and RBS WorldPay from its list of service providers that are compliant with the PCI data security rules.
Visa dropped the two payment processors from its PCI-compliant list on March 12, in the wake of their recent disclosures that they had been hit by data breaches last year. The credit card company said it would "consider" putting Heartland and RBS WorldPay back on the list, but only after they are recertified by third-party assessors.
The action by Visa had raised some questions about whether merchants and other organizations could continue using the two payment processors without being penalized for noncompliance themselves. Visa requires all entities that accept credit and debit cards issued under its name to work only with service providers that comply with the PCI rules, which are formally known as the Payment Card Industry Data Security Standard (PCI DSS).
But in a research bulletin issued yesterday (download PDF), Gartner analyst Avivah Litan said that customers can continue to utilize Heartland and RBS WorldPay without facing any fines from Visa.
Both payment processors are likely to soon be recertified as PCI-compliant, Litan said in the bulletin. In the interim, their customers have nothing to fear despite the recent delisting, she added, citing a statement that Visa issued to Gartner last week.
The statement clarifies "much of the confusion" that resulted from the delisting, according to Litan, who went on to say that the move was meant to serve as an indication of Visa's willingness to get tough with companies that fail to adequately protect cardholder data. At the same time, "Visa clearly did not want to risk putting the processors out of business, partly because of the potentially enormous disruption to their hundreds of thousands of merchant customers," Litan wrote.
A Heartland spokesman said that "several merchants" had expressed uncertainty over the consequences of Visa's delisting last week. "But Visa has been very good in recent days about clearing up this confusion," the spokesman said via e-mail. He also welcomed Litan's bulletin as being very helpful, "because a third party now reinforces what we believe - that we will return to the PCI DSS compliant list very soon."
A spokesman for RBS WorldPay said that company had no comments to make about the reaction of customers to the delisting move.
RBS WorldPay, an Atlanta-based division of The Royal Bank of Scotland Group PLC, disclosed in December that the personal data of about 1.5 million holders of prepaid payroll and gift cards had been compromised during a system intrusion (download PDF). It said last week that it hopes to be recertified as PCI-compliant by the end of next month.
Princeton, N.J.-based Heartland reported its breach in January, sparking widespread security concerns in the payment card industry and prompting at least eight banks and credit unions to file lawsuits against the company.
Heartland, which processes more than 100 million transactions per month, has yet to say how many card numbers were compromised in the intrusion there. It said last week that its goal is to be recertified by "no later than May."
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Study: Data breaches continue to get more costly for businesses
- Q&A: Head of PCI council sees security standard as solid, despite breaches
- (download PDF)
- Post-breach criticism of PCI security standard misplaced, Visa exec says
- (download PDF)
- Heartland data breach could be bigger than TJX's
- Heartland data breach sparks security concerns in payment industry
- Banks, credit unions begin to sue Heartland over data breach
-
The 30 best Safari extensions -- so far
-
Apple and Google disagree over licensing of essential patents
-
Monash Uni reduces IT teams after consolidation project
-
FTC warns makers of background checking apps
-
QLD govt demands answers after pay glitch
-
Cost Effective Security and Compliance with Oracle Database 11g Release 2
Information ranging from trade secrets to privacy related information has become the target of sophisticated attacks from both sides of the firewall. Protecting data now requires a strategy that enables both preventive and detective controls. Read on. -
8 reasons why Citrix NetScaler beats the competition
Application delivery controllers (ADC) are one of the most critical elements of cloud infrastructures and enterprise data centre architectures. ADCs strongly impact performance, scale and security of the entire application environment, so it is extremely important for IT leaders to choose the right one. -
Solid State Storage 101 - An introduction to Solid State Storage
Solid state data storage is gaining significant acceptance today. Storage based on Ram Access Memory (RAM) and Flash chips instead of mechanical hard disk drives is earning much greater attention by meeting the market requirements for reliability, performance, and cost more effectively than ever before. Read on.
-
Photoshop Cs3 for Nature Photographers
-
We Blog
-
Information Architecture with XML - a Management Strategy
-
Java, XML, and Jaxp (with Website)
-
PCs Just the Steps for Dummies
-
Iphone for Dummies, Special Edition
-
Digital Photos, Movies, & Music Gigabook for Dummies
-
Ubuntu Linux Toolbox
-
Crystal Reports 2008 for Dummies











Comments
Post new comment