Tuesday, January 22, 2013

Teaching Merchants the PCI Compliance Process: Successful or Not?


Over the last couple of years, many in the credit card processing industry have discussed our attempts to teach merchants the fundamentals of the PCI compliance process, including PCI requirements. These conversations often revolve around one question: are we succeeding?
This emphasis on PCI requirements may seem new, but PCI has been around for more than a decade. Visa's 2001 Cardholder Information Security Program (CISP) was the first major push for PCI, and in 2004 that program grew into the Payment Card Industry (PCI) Data Security Standard (DSS).
A recent National Retail Federation study examined merchants' knowledge of PCI, and its results are mixed as to whether we're doing a good job educating merchants.
  • Merchant's familiarity with PCI. 66% of small merchants were aware of the PCI DSS, which is a finding that seems encouraging. But that also means our education efforts over the last decade have failed to reach the other 34%, which doesn't sound so good after all.

  • How many have been tested? Almost 75% of merchants who are familiar with PCI have participated in a PCI compliance test, showing that many merchants consider PCI a serious issue. Yet the study also found that less than 50% of all merchants have taken a PCI compliance test.

  • A false sense of security. 94% of merchants care about the security of their customers' card information. But many have a false sense of security; 64% don't believe that their business could ever be breached by criminals or hackers.

  • Are they aware of all the consequences? Half of all merchants know that a breach could put them at risk for a lawsuit and also cause them to lose their ability to accept Visa or MasterCard. But, as you may know, a security breach can have many more consequences, including being fined by MasterCard and Visa, being liable for the use of stolen cards as well as having to pay card cancellation fees. The study found that 60% of merchants weren't familiar with these other consequences.
The study shows that our education efforts have been somewhat successful, but why are compliance and awareness not even better?
One reason is new businesses. 700,000 new businesses are born each year, and most of them are small. The owners have a lot to handle, and PCI gets forgotten in the scramble.
Another reason is the aforementioned false sense of security. Many merchants don't pay attention to PCI because they think that a security breach just won't happen to them.
Fees are also a deterrent to compliance, as some processors are using PCI to make significant revenue. It's unfortunate that fees sometime take precedent over protecting customers.
What do you think of the study's findings? Have our education efforts been successful, or just moderately successful?
Jeff Zimmerman, Vice President of Marketing and Product Management at Clearent, has 15 years of marketing and product management experience. Clearent is serious about the PCI compliance process, offering a free program to guide merchants through PCI requirements so that they can best protect their customers.


Article Source: http://EzineArticles.com/7428917

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.


breast enlargement breast enlargement exercise

عدد الزيارات