Card security needs collaboration
By Nicole Kobie in Malta,
Who should take responsibility for credit card security - merchants or card issuers?
That question was under debate at the NetEvents conference in Malta, with panellists discussing the payment card industry's data security standards (PCI DSS), developed by the PCI Security Standards Council.
Credit card payments systems need to be more secure, the panellists agreed. Considering the TJX/TK Maxx security breach, Bob Walder, the chief scientist at NSS Labs, noted that not protecting customer details can be expensive to companies. Aside from money lost directly through a data breach, cards need to be reissued, customers informed and longer term costs of fixing breaches and repairing customer confidence and brand damage. "Customers have a long memory which can cost even more in the long run," he said.
"If you've been compromised, you've put your customers at risk," added Carlos Solari, the vice-president of security for Alcatel-Lucent. "It's the end of your business."
But who should be held responsible for keeping data secure: retailers or the credit card companies themselves?
Walder said merchants can't be expected to be security experts. He asked the panel to consider the mindset of Larry the pizza shop owner: "He's got to look encryption up in the dictionary."
Despite this, over half of companies are found to be not compliant on their first DSS assessment, he said. But self-assessments are open to abuse, so end users need to be forced to be compliant, said one panellist. "For a small merchant, it's an alien thing... the only way is to force them to on pain of taking their business away or their ability to accept cards," said Michael Bacon, the head of information security at Xchanging.
But Alex Raistrick, director of Northern Europe for ConSentry Networks, said: "It's not in the interest of card companies to take away the ability to use cards."
He added that it's not just small merchants facing trouble. "It's confusing for everybody," he said, saying a retailer with 9,000 stores and several thousand staff faces huge challenges to keep data secure.
Because of that, more pressure should be put on credit card companies and networks to keep data secure. One solution could be certification of security products. "In the end, it doesn't matter how prescriptive you get, products need to be certified," said Neal Hartsell, vice president of marketing at Tipping Point. That way, smaller vendors and larger firms alike will know which products are proven to meet PCI standards, he said.
Alcatel-Lucent's Solari suggested credit cards themselves should be made more secure. "The credit card itself continues to be a weak point," he said.
But Bacon noted you can't certify people. "People will break security every time," he said. No matter how good the technology, he added, "there's still somebody putting it together." He asked the audience to consider cars. No matter how much safety technology manufacturers put into their cars, people will always make them dangerous - there's nothing you can do about "the nut behind the wheel," he said.
advertisement
Latest Security Features
Lessons to learn from a year of data breaches
In the year since the HMRC data breach, many more have been made public – here’s a roundup of 11 lessons (we should have) learned.
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
- Chinese web control an Olympic challenge for tech firms
- SOS Bletchley Park
Latest Security Reviews
Fortinet FortiGate-3810A
Rating: ![]()
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
advertisement
Latest News Videos in Security
Video: Q&A with Richard Archdeacon, Symantec
IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?