Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Banks Say Share of Credit Card Security Costs Is Unfair

The PCI standards were created by five credit card companies &#8212 Visa International, MasterCard International, American Express, Discover Financial Services and JCB &#8212 to protect credit card data before, during and after transactions

A panel of financial services and retail executives this month disagreed on which side bears the brunt of the burden to ensure compliance with the Payment Card Industry (PCI) Data Security Standard.

Executives from US-based JPMorgan Chase & Co and First Horizon National told an audience at Symantec's Vision user conference in Las Vegas that high-profile data breaches at retailers like TJX Companies are not originating from their side of the fence — yet they must spend significant sums to make sure such incidents don't happen.

All the enforcement scheduled has been on the processing and retailer side, so it has been unfair, frankly
Avivah Litan - Gartner

The TJX incident "was not a JPMorgan [data breach]; it wasn't at First Horizon or Citigroup. It was at a merchant. And yet all the plans to remediate that have been with the banks," said Christopher Leach, senior vice president and chief information security officer at US-based First Horizon.

US-based TJX disclosed early this year that more than 45 million credit and debit card numbers were stolen from two of its IT systems over an 18-month period.

An AT&T executive, on the other hand, contended that banks have so far done little to share in the burden of ensuring credit and debit card security compared with businesses that accept such payments.

The PCI standards were created by five credit card companies — Visa International, MasterCard International, American Express, Discover Financial Services and JCB — to protect credit card data before, during and after transactions.

First Horizon, which operates in 43 states and claims $US5 billion in annual revenue, is currently going through a costly new round of PCI certification efforts — or, as Leach put it, "trying to build that airplane as we build the runway".

"We've discovered that PCI keeps changing," Leach said. "We went down the path to be certified at one point and did a great deal of due diligence only to find out some of the requirements would change. One Visa analyst would say one thing, and another Visa analyst would say something very contradictory."

Brian Glowacki, vice president and lead architect for global storage technology at JPMorgan in the US, agreed that banks are bearing an unfair security burden compared with merchants.

Vanessa Pegueros, US director of compliance services at AT&T, contended that banks are "thumbing their noses at the PCI regulation, so we are paying the price."

"We were doing a good job — maybe not as fast as some would like, but we were on a plan and trying to meet the [PCI] requirements," Pegueros said. "But [Visa is] trying to take a hard-line approach, and we're caught in the middle. Now we have to adjust our plans."

Gartner analyst Avivah Litan agreed that banks are not yet taking adequate measures to comply with the PCI standards.

"There has not been a lot of enforcement at the bank level," she said. "All the enforcement scheduled has been on the processing and retailer side, so it has been unfair, frankly."

Litan said retailers are upset because they believe that they are being held to a higher standard than banks in securing their systems.

Bob Russo, general manager of the PCI Security Standards Council in the US, said that both sides should work together to ensure that the cards are secure.

"This should not be a blame game," he said. "The bottom line is everyone who touches consumer payment card data has a responsibility to secure it."

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: American Express, AT&T, AT&T, Billion, CitiGroup, Gartner, Mastercard, Symantec, Visa, Visa International

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Oracle SOA Suite – Oracle BPEL Process Manager
    Changing markets, increasing competitive pressures and evolving customer needs are placing greater pressure on IT to deliver greater flexibility and speed. In response to these challenges, leading companies are adopting Service-Oriented Architecture (SOA) as a means of delivering on these requirements by overcoming the complexity of their application and IT environments. Read on.
    Learn more »
  • Magic Quadrant for Managed Print Services, Worldwide
    Gartner's managed print services (MPS) Magic Quadrant is a useful starting point for identifying and evaluating MPS providers. It is intended for Gartner's client base of mainly midsize and large organisations, many of which operate throughout two or more regions, and some of which are truly global. Although not all MPS projects are multiregional or global at the outset, customers often choose to scale up one region at a time. In this way, they can manage their office printing in a unified manner globally. Read more.
    Learn more »
  • Data Center Physical Infrastructure: Optimising Business Value
    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in data center physical infrastructure (DCPI). No longer are simply availability and upfront cost sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a changing global marketplace.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments