89% of UK companies are not certified as PCI compliant.
 
Tue, 9th March 2010
 
 

89% of UK companies are not certified as PCI compliant.

89% of UK companies are not certified as PCI compliant.

New independent market research by industry analyst, Redshift Research, on behalf of Tripwire, has found that as the September 2010 PCI DSS deadline looms, 89% of companies are not currently audited and certified as compliant.

The survey, which samples the views of 100 retail, financial services and hospitality businesses, also found that 35% of respondents still do not fully understand PCI compliance requirements, and nearly a third of respondents do not know if they will be compliant by the September 2010 deadline.

Significantly, at a time when IT budgets are under close scrutiny because of the difficult economic conditions, the survey found that 77% of respondents have not had problems securing funding and resources to ensure PCI DSS requirements are met, suggesting that the importance of PCI compliance is now widely understood at board-level within businesses. Indeed, 64% agree that PCI improves the overall security of cardholder information; 50% say that PCI compliance will improve attention to information and security, and help protect data privacy; and 44% say that PCI compliance will help enhance brand reputation by giving consumers greater confidence.

However, despite the majority of respondents saying they were confident about achieving PCI compliance, the research survey found that 32% are currently responding to weaknesses that were identified in their PCI DSS pre-audit; 27% of companies will put off becoming PCI compliant for as long as possible; 14% have completed a PCI DSS pre-audit but not undertaken any further action; and 14% are not compliant and are not in the process of becoming so. In addition, 39% of respondents believe that credit card security should be the problem of the credit card companies.

Another key finding was that only 26% of respondents have a dedicated PCI DSS Project Manager. Indeed, 78% say that PCI compliance falls within the remit of IT Security within their organisation which adds to an already busy workload for IT security professionals.   

The research study also highlights that smaller businesses are lagging behind larger organisations in terms of PCI readiness. 56% of Level 4 merchants and 36% of Level 3 merchants do not fully understand PCI requirements; in contrast, only 14% of Level 2 merchants do not fully understand the requirements, whilst all Level 1 merchants said that they fully understand the requirements. When asked whether they were confident about meeting the September 2010 deadline, 21% of Level 3 merchants said they would not be compliant in time, and a further 25% of Level 3 merchants did not know if they would be compliant in time; 7% of Level 4 merchants said they would not be compliant, and a further 31% said they did not know if they would be compliant. Only 11% of Level 2 merchants were unsure about achieving compliance, whilst all Level 1 merchants were confident about meeting the deadline.    

Comparing the results by industry sector, 57% of retailers admitted that they still do not fully understand PCI requirements, compared to 27% of finance companies and 27% of leisure companies. 20% of finance companies said they would not be compliant by the September 2010 deadline, and a further 20% of finance respondents did not know if they would meet the deadline. Furthermore, 25% of retailers did not know if they would be compliant, whilst only 9% of leisure companies were unsure about hitting the deadline.  

Commenting on the research results, Rob Warmack, Senior Director of International Marketing for Tripwire says, "As the evolution towards a cashless society continues to gain pace, every organisation from insurance companies to financial services, hospitality to retail is becoming reliant upon credit and debit cards. The research demonstrates that there is now a growing awareness of the importance of PCI DSS standards, however with only a small minority of companies currently certified as compliant many organisations are facing an uphill battle to meet the September 2010 deadline. In particular, Level 3 and 4 merchants lag Level 1 and 2 merchants in terms of PCI readiness, suggesting that many smaller businesses have to date perceived PCI standards to be the preserve of larger organisations." 

Guy Washer, Managing Director of Redshift Research, adds, "The results suggest that many companies could actually be taking a 'blind faith' approach to PCI compliance. Despite the fact that most companies remain confident of meeting the PCI deadline, only a small minority are currently audited and certified as compliant, and there is still confusion over PCI standards. There is also a huge divergence between large and small companies in terms of PCI readiness. Furthermore, whilst the importance of continuous compliance now seems to be hitting home, organisations are still not necessarily putting in place the processes or tools required to achieve that objective."

Warmack continues, "As many larger merchants who have gone first through the PCI compliance process have already realised, 'one-off' PCI DSS certification is not enough.  Simple system changes after an audit not only jeopardise PCI compliance but also create potentially significant security vulnerabilities. We are seeing clear evidence in the marketplace that companies face an ongoing struggle to collate volumes of change and event information across those systems charged with protecting cardholder data and then still maintain compliance between audits. Without automation through continuous monitoring and reporting, the process is both resource intensive and potentially valueless: why spend months achieving PCI DSS compliance only to slip out of compliance due to a system change within weeks?"


 
 
category Retail  |  source The Retail Bulletin
 
   
 
 
 
 
Tue, 7th February 2012
Jools Oliver to launch range with Mothercare
Jools Oliver, author and wife of celebrity chef Jamie, is to launch a clothing and nursery accessories range with mother and baby products retailer Mothercare.

more >
 
Tue, 7th February 2012
Argos, Comet and Dixons pledge action on extended warranties
Electrical retailers Argos, Comet and Dixons have offered legal undertakings to improve the way the extended warranties market works, the Office for Fair Trading said today.

more >
 
Tue, 7th February 2012
Jenny Packham to design collection for Debenhams
Jenny Packham, a designer favoured by the Duchess of Cornwall, is to design a collection for Debenhams.

more >
 
Tue, 7th February 2012
Retailers come to together to promote value of apprenticeships
The UK's leading retailers came together yesterday to promote the value of retail apprenticeships.

more >
 
Tue, 7th February 2012
M&S customers recycle their 100th million hanger for Unicef
Customers at Marks & Spencer have helped the retailer raise £370,000 for Unicef through the recycling of garment hangers.

more >
 
Tue, 7th February 2012
Sainsbury's to sponsor tree planting scheme to mark Queen's Diamond Jubilee
Sainsbury's is to become the lead corporate sponsor for the Woodland Trust's Jubilee Woods Project, which aims to plant six million native British trees to mark the Queen's Diamond Jubilee.

more >
 
Tue, 7th February 2012
Tesco expands Korean virtual stores
Tesco is to expand its virtual shopping walls in South Korea to target university students.

more >
 
Tue, 7th February 2012
Mothercare to launch range with Jools Oliver
Maternity retailer Mothercare is to launch a designer range with Jools Oliver, wife of celebrity chef Jamie.

more >
 
Tue, 7th February 2012
Amazon considers first physical store
Amazon is to open its first physical shop as it looks to showcase its Kindle.

more >
 
Tue, 7th February 2012
January retail sales like-for-like drop 'sobering'
January like-for-like sales fell by 0.3%, providing a sobering picture for 2012, according to the British Retail Consortium (BRC) KPMG Retail Sales Monitor.

more >
 
Tue, 7th February 2012
Empty shops on UK high streets set to rise in 2012
A new report has claimed that the number of empty shops on UK high streets is set to rise in 2012.

more >
 
Mon, 6th February 2012
UK retail sales values down 0.3% on a like-for-like basis from January 2011
Latest retail sales figures show consumer caution returns after Christmas celebrations.

more >
 
Mon, 6th February 2012
Gieves & Hawkes reduces stock levels after overhauling its IT systems
The Savile Row company said that it has set off a tailoring revolution with its new ready to wear and bespoke ranges whist stripping out £1 million in stock.

more >
 
Mon, 6th February 2012
Snow hampers grocery supplies
Poor weather conditions across the UK hit grocery supplies over the weekend as retailers battled the snow and ice.

more >
 
Mon, 6th February 2012
Boohoo.com owner reports 80% rise in profit
Pinstripe Clothing, owner of fashion website Boohoo.com, saw pre-tax profits climb 80% to £139,000 in 2011.

more >
 
Mon, 6th February 2012
350 jobs to be created through new Little Waitrose branches
Waitrose has marked the first anniversary of "little Waitrose" by announcing it is to create 350 jobs through opening six new convenience branches in central London this year.

more >
 
Mon, 6th February 2012
Research identifies top ten good practices for multi-channel retailers
New research by the Cranfield School of Management has identified ten 'good practices' for retailers operating across multi-channels.

more >
 
Mon, 6th February 2012
Nicole Vanderbilt to leave MyDeco
Nicole Vanderbilt has stood down from her role of CEO at MyDeco just three months after the company relaunched as a direct e-commerce store.

more >
 
Mon, 6th February 2012
Waitrose reports increase in veal sales following BBC TV programme
Waitrose has reported an 18% increase in sales of veal following a feature on a BBC Countryfile programme which aimed to dispel the myths about how veal is reared in the UK.

more >
 
Mon, 6th February 2012
Carrefour appoints Georges Plassat as new CEO
French supermarket giant Carrefour has appointed Georges Plassat as its new chairman and CEO. He will succeed current incumbent Lars Olofsson will stand down from the roles in June.

more >