Lax attitude to PCI, security costing businesses: Investigator
- 21 April, 2011 08:41
- Comments
Merchants who view security and payment card industry (PCI) compliance as an extra cost will be rueing the decision when hackers hoping to swipe credit card data strike, believes one industry specialist. PCI data security standards were created by Visa, MasterCard and other major credit card brands, and is administered by the PCI Security Standards Council.
All companies that accept payment cards are required to implement the 12 high-level security controls prescribed by the standard in order to help mitigate credit card fraud. Larger companies face significantly tougher compliance requirements than smaller firms.
Klein&Co director, Nick Klein, who works with Vectra on PCI breaches told Computerworld Australia that Vectra had investigated 15 PCI breaches in 2011 alone. Last year, 35 breaches were reportedfrom customers in Australia and New Zealand.
The hackers, all based overseas and compromising server boxes in one country to use as a channel attack, were quick to find weak spots in websites and extract data, such as credit card information.
Klein said he was surprised that more companies did not test their own Web defences first.
"We talk to merchants and they give us various reasons, but the attackers who break into your site should not have been the first person who ever tested your security," he said.
Klein also warned that attackers were changing tactics from point of sale (POS) manipulation to focus solely on e-commerce, as it was relatively easy to commit an attack and yield card details.
He advised that companies could improve PCI compliance by not holding card data on site.
"If companies don't store data on their systems and use third-party processing, that hugely reduces your risk," Klein said.
"Fundamentally, if you don't have a list of data to steal, than how much of a target are you?"
Simple security measures such as keeping operating systems updated with security patches was "critical", and doing the same for all applications systems was key.
"You don't need a big complicated, expensive infrastructure to be well secured," Klein said.
"In an environment where easy targets are being compromised, there are a lot of things you can do which are cheap or even free that would make you far less of a target than others out there."
Klein added that the organisation's research turned up different results to overseas reports from companies such as Verizon.
"The feedback we get [from customers] about those reports is that those ones tend to aggregate what is happening overseas," he said.
"In fact, a lot of the data is based towards the US market. We know from our experience that what is happening in Australia is slightly different."
Klein is scheduled to present at the upcoming security conference AusCERT in May.
IDG Communications is an official media partner for AusCERT 2011.
Got a security tip-off? Contact Hamish Barwick at hamish_barwick at idg.com.au
Follow Hamish Barwick on Twitter: @HamishBarwick
Follow Computerworld Australia on Twitter: @ComputerworldAU
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Businesses are ready for a new approach to IT - Simplify deployment and reduce complexity using systems integrated with expertise
- The Top 5 Server Monitoring Battles—and How You Can Win Them
- Six tips for choosing a unified threat management (UTM) solution
- Security Threat Report 2012
- Lost USB keys have 66% chance of malware
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
HP Managed Print Services solutioning methodology
Many organisations launch initiatives to increase the efficiency of their imaging and printing environment—only to quickly find that maintaining those improvements is the real challenge. Sustainable, long-term efficiency gains require that imaging and printing be approached as part of your organisation’s overall IT strategy. Read more. -
Seven Tips for Securing Mobile Workers
Seven Tips for Securing Mobile Workers is intended to offer practical guidance on dealing with one of the fastest growing threats to the security of sensitive and confidential information. -
Workshifting: a global market research report
New business requirements are transforming the demands placed on IT. To operate effectively in today’s fast-paced global environment, organisations need to be able to get work done anywhere, anytime, by any type of worker to achieve the best results. This is the context for the rise of workshifting—the practice of moving work to the most optimal location, time and resources. As one of the most comprehensive reports ever conducted into the role of desktop virtualisation in enabling workplace flexibility and mobility, it reflects the growing consensus of those using technology to improve the performance of their organisation.
-
Combinatorial Optimization and Theorical Computer Science
-
Big C++ WileyPlus Standalone Registration Card
-
Wiley Pathways
-
OS 2 2.1 Installation Configuration & Use
-
Mac OS X Power Tools Second Edition
-
Teach Yourself Microsoft Word 2000
-
Ingn Digital Classroom
-
Linux All-In-One Desk Reference for Dummies®, 3rd Edition
-
Symbian OS Internals - Real-time Kernel Programming








Comments
Post new comment