Beyond PCI compliance

As data protection demands evolve, so must managed service providers

In the wake of some much-publicised data leaks, many countries are tightening their data protection rules. This trend often starts in the public sector and then spreads out to the wider business community.

However, there are few trans-national security rules in place and widely enforced. One of these is the Payment Card Industry Data Security Standard (PCI DSS), a common standard to stop security breaches and ultimately reduce credit card fraud.

The standard is audited through an independent assessor, and the credit card companies behind PCI have the power to enforce sanctions - including fines and the suspension of merchant privileges - for organisations that fail to meet the grade

PCI, at least within financial services, has forced organisations to step up their security game.

It does not exist in isolation though. Increasingly, major international companies that dominate in areas such as logistics, automotive, retail and manufacturing are beginning to follow suit with their own security requirements imposed on suppliers before they are granted access to shared IT resources. This is on top of pan-European security and privacy regulations such as General Data Protection Regulation (GDPR), which also forces tighter security requirements around data retention and sharing.

Companies that need to adhere to these standards must find a way for the different parts of their organisations to work together, although this can often pose a challenge. IT departments are the core of this initiative but there is often a requirement to bring in HR elements for policy and training, legal experts for statutory obligations and compatibility with jurisdictional matters, perhaps even facilities managers to ensure that security extends to physical access policies.

Moreover, with regulators gaining more power to name, shame and ultimately fine organisations that fail to create satisfactory levels of security controls, MSPs have an opportunity to become indispensable partners in the goal to become certified.

But, for MSPs to reach this position, they need three key attributes.

The first is an investment in skills - especially an understanding of the key industry and governmental regulatory requirements. With clients seeking expertise, it is vital that MSPs can become an independent expert that's able to offer advice based on a depth of knowledge and practical experience. There are a number of training courses that can help brush up these skills and MSPs would be wise to invest in these as an initial position.

Next come technology platforms that help streamline the process of assessing a client's current position in respect to regulatory compliance and wider security best practice. For example, SolarWinds' MSP Risk Intelligence suite can run automated vulnerability scans along with PCI and HIPAA compliance scans to create a benchmark.

The last MSP requirement is a professional services capability that's needed to start the engagements that work towards solving any issues discovered in a risk intelligence scan, along with an understanding of the regulatory requirements that must be met to achieve full compliance.

Although PCI is the most noteworthy, having the skills and processes in place to meet client requirements for this standard also helps develop a service portfolio that can be extended to other areas.

What's more, PCI and other standards continue to evolve, requiring organisations to adapt to new threats and business practices, and helping the MSP relationship to grow and become more of a trusted partner over time.

Ultimately, as organisations move beyond PCI, the benefit of better security processes will impact across the entire organisation. For progressive MSPs, thinking further down the line is great way to build a sustainable and profitable security practice.

This is an independent article written by Channel Pro, sponsored by SolarWinds MSP to celebrate thought leadership in IT. Learn more about SolarWinds' MSP Risk intelligence and enjoy a free 14 day trial by clicking here.

Would you like to turn data protection into a differentiatior for your business? Download this whitepaper here to find out more.

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Leading the data race

The trends driving the future of data science

Download now

How to create 1:1 customer experiences at scale

Meet the technology capable of delivering the personalisation your customers crave

Download now

How to achieve daily SAP releases

Accelerate the pace of SAP change to support your digital strategy

Download now

Recommended

ICO to relax GDPR enforcement during coronavirus economic downturn
General Data Protection Regulation (GDPR)

ICO to relax GDPR enforcement during coronavirus economic downturn

16 Apr 2020
The NHS teams up with Apple and Google on coronavirus tracking app
privacy

The NHS teams up with Apple and Google on coronavirus tracking app

14 Apr 2020
Health sites are 'unlawfully' sharing medical data with Facebook and Google
data protection

Health sites are 'unlawfully' sharing medical data with Facebook and Google

7 Apr 2020
Supreme Court rules Morrisons was not liable for 2014 data breach
data protection

Supreme Court rules Morrisons was not liable for 2014 data breach

1 Apr 2020

Most Popular

Google Pixel 4a review: A picture-perfect package
Google Android

Google Pixel 4a review: A picture-perfect package

18 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020