89% of UK companies are not certified as PCI compliant.
 
Tue, 9th March 2010
 
 

89% of UK companies are not certified as PCI compliant.

89% of UK companies are not certified as PCI compliant.

New independent market research by industry analyst, Redshift Research, on behalf of Tripwire, has found that as the September 2010 PCI DSS deadline looms, 89% of companies are not currently audited and certified as compliant.

The survey, which samples the views of 100 retail, financial services and hospitality businesses, also found that 35% of respondents still do not fully understand PCI compliance requirements, and nearly a third of respondents do not know if they will be compliant by the September 2010 deadline.

Significantly, at a time when IT budgets are under close scrutiny because of the difficult economic conditions, the survey found that 77% of respondents have not had problems securing funding and resources to ensure PCI DSS requirements are met, suggesting that the importance of PCI compliance is now widely understood at board-level within businesses. Indeed, 64% agree that PCI improves the overall security of cardholder information; 50% say that PCI compliance will improve attention to information and security, and help protect data privacy; and 44% say that PCI compliance will help enhance brand reputation by giving consumers greater confidence.

However, despite the majority of respondents saying they were confident about achieving PCI compliance, the research survey found that 32% are currently responding to weaknesses that were identified in their PCI DSS pre-audit; 27% of companies will put off becoming PCI compliant for as long as possible; 14% have completed a PCI DSS pre-audit but not undertaken any further action; and 14% are not compliant and are not in the process of becoming so. In addition, 39% of respondents believe that credit card security should be the problem of the credit card companies.

Another key finding was that only 26% of respondents have a dedicated PCI DSS Project Manager. Indeed, 78% say that PCI compliance falls within the remit of IT Security within their organisation which adds to an already busy workload for IT security professionals.   

The research study also highlights that smaller businesses are lagging behind larger organisations in terms of PCI readiness. 56% of Level 4 merchants and 36% of Level 3 merchants do not fully understand PCI requirements; in contrast, only 14% of Level 2 merchants do not fully understand the requirements, whilst all Level 1 merchants said that they fully understand the requirements. When asked whether they were confident about meeting the September 2010 deadline, 21% of Level 3 merchants said they would not be compliant in time, and a further 25% of Level 3 merchants did not know if they would be compliant in time; 7% of Level 4 merchants said they would not be compliant, and a further 31% said they did not know if they would be compliant. Only 11% of Level 2 merchants were unsure about achieving compliance, whilst all Level 1 merchants were confident about meeting the deadline.    

Comparing the results by industry sector, 57% of retailers admitted that they still do not fully understand PCI requirements, compared to 27% of finance companies and 27% of leisure companies. 20% of finance companies said they would not be compliant by the September 2010 deadline, and a further 20% of finance respondents did not know if they would meet the deadline. Furthermore, 25% of retailers did not know if they would be compliant, whilst only 9% of leisure companies were unsure about hitting the deadline.  

Commenting on the research results, Rob Warmack, Senior Director of International Marketing for Tripwire says, "As the evolution towards a cashless society continues to gain pace, every organisation from insurance companies to financial services, hospitality to retail is becoming reliant upon credit and debit cards. The research demonstrates that there is now a growing awareness of the importance of PCI DSS standards, however with only a small minority of companies currently certified as compliant many organisations are facing an uphill battle to meet the September 2010 deadline. In particular, Level 3 and 4 merchants lag Level 1 and 2 merchants in terms of PCI readiness, suggesting that many smaller businesses have to date perceived PCI standards to be the preserve of larger organisations." 

Guy Washer, Managing Director of Redshift Research, adds, "The results suggest that many companies could actually be taking a 'blind faith' approach to PCI compliance. Despite the fact that most companies remain confident of meeting the PCI deadline, only a small minority are currently audited and certified as compliant, and there is still confusion over PCI standards. There is also a huge divergence between large and small companies in terms of PCI readiness. Furthermore, whilst the importance of continuous compliance now seems to be hitting home, organisations are still not necessarily putting in place the processes or tools required to achieve that objective."

Warmack continues, "As many larger merchants who have gone first through the PCI compliance process have already realised, 'one-off' PCI DSS certification is not enough.  Simple system changes after an audit not only jeopardise PCI compliance but also create potentially significant security vulnerabilities. We are seeing clear evidence in the marketplace that companies face an ongoing struggle to collate volumes of change and event information across those systems charged with protecting cardholder data and then still maintain compliance between audits. Without automation through continuous monitoring and reporting, the process is both resource intensive and potentially valueless: why spend months achieving PCI DSS compliance only to slip out of compliance due to a system change within weeks?"


 
 
category Retail  |  source The Retail Bulletin
 
   
 
 
 
 
Fri, 10th September 2010
Laura Ashley first half profits surge
Furniture and fashion retailer Laura Ashley experienced a surge in pretax profits excluding exceptionals from £100,000 to £5.7m in the 26 weeks to July 31.

more >
 
Fri, 10th September 2010
Childrenswear sales drive 5.6% sales uplift at John Lewis
Department store John Lewis sales rose 5.6% to £57m last week as Back to School drove a record week for childrenswear.

more >
 
Fri, 10th September 2010
Tesco Launches First Ever Shopping App for iPhone
Tesco has announced that it is launching its first ever shopping app for iPhone. The Tesco grocery app joins the family of hugely successful Tesco apps, including Clubcard and the Winefinder, which together have now reached over one million downloads.

more >
 
Fri, 10th September 2010
Christmas preparations start now
E-Village draws up 'The Twelve Rules of Christmas Email Marketing.

more >
 
Fri, 10th September 2010
Faster payments frontrunner to replace cheques.
July 2010 marks the first anniversary of Direct Corporate Access (DCA) to the Faster Payments Service (FPS).

more >
 
Fri, 10th September 2010
Strong profits predicted for Next
Broker UBS retained its buy stance on Next ahead of interim results expected next week.

more >
 
Fri, 10th September 2010
Comet begins fightback with softer rebranding
Electricals retailer Comet has unveiled a wide-ranging rebranding encompassing a new logo, strapline and in-store approach designed to put clear blue water between itself and rivals Dixons Retail and Best Buy.

more >
 
Fri, 10th September 2010
Potential buyers sit tight as Blockbuster awaits its fate
Uncertainty dogs up-for-sale DVD firms Christmas prospects as US parent mulls bankruptcy

more >
 
Fri, 10th September 2010
GameStop prepares UK online assault with transactional launch
The worlds biggest games retailer GameStop is preparing to launch an online assault on the UK market in time for Christmas.

more >
 
Fri, 10th September 2010
GameStop prepares UK online assault with transactional launch
The worlds biggest games retailer GameStop is preparing to launch a an online assault on the UK market in time for Christmas.

more >
 
Fri, 10th September 2010
Intersport teams up with The Hut to boost website visitor numbers
Intersport has joined forces with ecommerce specialist The Hut to build a bigger online presence.

more >
 
Fri, 10th September 2010
Conran Shop pushes social media with new site
Upmarket furniture retailer The Conran Shop has relaunched its website to include social media functions as it aims to grow its online sales five-fold by 2015.

more >
 
Fri, 10th September 2010
New Firebox MD plans to expand etailers offer
The new managing director of quirky gifts etailer Firebox Paul Zimmerman has said he will seek to expand the etailers offer into new categories and launch a social media site as he took the helm this week.

more >
 
Fri, 10th September 2010
H&M casts its net
H&M online went live to subscribers this week with its launch, which is set to go live to all H&M customers next week.

more >
 
Fri, 10th September 2010
Biba is back
House of Fraser has relaunched iconic British brand Biba.

more >
 
Fri, 10th September 2010
Dune outlines strategy to hit sales of £200m
Footwear retailer the Dune Group has outlined its strategy to reach sales of £200m in the next three years after operating profits rocketed 630% to £7.3m in the year to January 30.

more >
 
Fri, 10th September 2010
New look for John Lewis womensear
John Lewis has reopened the womenswear floor of its Oxford Street store following a £10m investment.

more >
 
Fri, 10th September 2010
Browns to open basics concept store in Mayfair
Iconic independent department store Browns is opening a new concept store called Shop 24.

more >
 
Fri, 10th September 2010
Vertical fashion show stops Oxford Street traffic
Londons Oxford Street came to a standstill on Monday when a pop-up vertical fashion show took over the area.

more >
 
Fri, 10th September 2010
Thorntons moves to sweeten its own-store offer
Chocolatier Thorntons is to localise in-store ranges as part of its efforts to re-energise the performance of company-owned shops.

more >