Beyond PCI compliance

As data protection demands evolve, so must managed service providers

In the wake of some much-publicised data leaks, many countries are tightening their data protection rules. This trend often starts in the public sector and then spreads out to the wider business community.

However, there are few trans-national security rules in place and widely enforced. One of these is the Payment Card Industry Data Security Standard (PCI DSS), a common standard to stop security breaches and ultimately reduce credit card fraud.

Advertisement - Article continues below

The standard is audited through an independent assessor, and the credit card companies behind PCI have the power to enforce sanctions - including fines and the suspension of merchant privileges - for organisations that fail to meet the grade

PCI, at least within financial services, has forced organisations to step up their security game.

It does not exist in isolation though. Increasingly, major international companies that dominate in areas such as logistics, automotive, retail and manufacturing are beginning to follow suit with their own security requirements imposed on suppliers before they are granted access to shared IT resources. This is on top of pan-European security and privacy regulations such as General Data Protection Regulation (GDPR), which also forces tighter security requirements around data retention and sharing.

Companies that need to adhere to these standards must find a way for the different parts of their organisations to work together, although this can often pose a challenge. IT departments are the core of this initiative but there is often a requirement to bring in HR elements for policy and training, legal experts for statutory obligations and compatibility with jurisdictional matters, perhaps even facilities managers to ensure that security extends to physical access policies.

Advertisement - Article continues below
Advertisement - Article continues below

Moreover, with regulators gaining more power to name, shame and ultimately fine organisations that fail to create satisfactory levels of security controls, MSPs have an opportunity to become indispensable partners in the goal to become certified.

But, for MSPs to reach this position, they need three key attributes.

The first is an investment in skills - especially an understanding of the key industry and governmental regulatory requirements. With clients seeking expertise, it is vital that MSPs can become an independent expert that's able to offer advice based on a depth of knowledge and practical experience. There are a number of training courses that can help brush up these skills and MSPs would be wise to invest in these as an initial position.

Next come technology platforms that help streamline the process of assessing a client's current position in respect to regulatory compliance and wider security best practice. For example, SolarWinds' MSP Risk Intelligence suite can run automated vulnerability scans along with PCI and HIPAA compliance scans to create a benchmark.

Advertisement - Article continues below

The last MSP requirement is a professional services capability that's needed to start the engagements that work towards solving any issues discovered in a risk intelligence scan, along with an understanding of the regulatory requirements that must be met to achieve full compliance.

Although PCI is the most noteworthy, having the skills and processes in place to meet client requirements for this standard also helps develop a service portfolio that can be extended to other areas.

What's more, PCI and other standards continue to evolve, requiring organisations to adapt to new threats and business practices, and helping the MSP relationship to grow and become more of a trusted partner over time.

Ultimately, as organisations move beyond PCI, the benefit of better security processes will impact across the entire organisation. For progressive MSPs, thinking further down the line is great way to build a sustainable and profitable security practice.

This is an independent article written by Channel Pro, sponsored by SolarWinds MSP to celebrate thought leadership in IT. Learn more about SolarWinds' MSP Risk intelligence and enjoy a free 14 day trial by clicking here.

Would you like to turn data protection into a differentiatior for your business? Download this whitepaper here to find out more.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now


data protection

Supreme Court rules Morrisons was not liable for 2014 data breach

1 Apr 2020

UK government may trace COVID-19 patients using mobile phone data

20 Mar 2020
General Data Protection Regulation (GDPR)

Irish data regulator racks up GDPR cases against Big Tech

24 Feb 2020
data management

EU-US data transfer tools used by Facebook ruled legal

19 Dec 2019

Most Popular

application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020
flexible working

Why we’re lucky COVID-19 has come now

3 Apr 2020