Comment: PCI DSS: Cutting through the compliance
 
Fri, 6th March 2009
 
 

Comment: PCI DSS: Cutting through the compliance

Comment: PCI DSS: Cutting through the compliance
Doug Hargrove

For retailers, the advantages of being able to offer payment by card are obvious.

By Doug Hargrove

For retailers, the advantages of being able to offer payment by card are obvious. Today's consumers are used to being able to pay for transactions using whichever method is the most convenient for them, and facilitating card payments ensures that no sales are lost due to customers not having access to a nearby cash machine. For independent store owners concerned about the encroachment of the supermarkets into the convenience store space, card payment facilities also present a crucial means of staying competitive and maintaining market share.

But as card payment technology becomes increasingly common, the number of data security breaches reported is rising, as thieves develop increasingly sophisticated methods of extracting sensitive payment data. It is therefore important for customers and retailers that stores arm themselves in the best possible way against the threat of a security lapse. The Payment Card Industry Data Security Standard (PCI DSS) rules, which are compulsory for all card-accepting retailers, are designed to achieve this.

Evolving from a number of separate initiatives set out by different card providers, the PCI DSS regulations were introduced in 2004 as a means of identifying the areas in which it is important for security to be maintained, and to clarify the role retailers had to play in ensuring this. An independent Security Standards Council (PCI DSS) was formed to oversee the implementation of these standards, including accrediting Qualified Security Assessors and to advise on any amendments or updates that were to be incorporated.

In theory, the creation of PCI DSS should have spelled the end of any uncertainty over retailers' responsibilities in ensuring the integrity of transactions. However, the reality is one of confusion. Since the introduction of the standards, there have been two revisions, with version 1.2 introduced last October, but it is estimated that still only 10% of transactions in the UK are currently processed on compliant systems.

It is important that retailers who accept card payments are aware that compliance with PCI DSS is a contractual obligation between them and the acquiring bank to protect the security of transactions. Compliance with the standards is not a cast-iron guarantee that a data breach cannot occur, but it does render the retailer free from liability in the eyes of the card providers. By contrast, if a retailer is found to be liable, they face the prospect of incurring a considerable fine, as well as having their right to accept card payments withdrawn.

This is in addition to the high cost of a 'clean up' following an incident, including legal fees and the necessary upgrading of in-store systems, as well as mitigating the impact on customers' perceptions of a store. Following a widely-publicised security breach at TK Maxx's US counterpart, analyst house Forrester estimated that it cost the company up to 0 per customer record leaked to resolve the incident. Such an amount could be enough to bankrupt a smaller retailer.

Whilst larger retailers can employ dedicated in-house staff to ensure they meet the PCI DSS requirements, gaining compliance does not have to be a prohibitively expensive and complex process for independent retailers. Instead, with advanced retail technology, stores can effectively 'buy' in compliance by choosing a solution that has already been assessed as meeting the PCI DSS regulations.

In order to ensure this, stores can work with a technology provider that understands the security requirements laid out in the PCI DSS. Responding to the challenges smaller retailers have faced in implementing the regulations, systems vendors have been able to enlist the guidance of Qualified Security Assessors when designing retail applications. This has enabled them to fully integrate the necessary security processes into the technology used at the point of sale. For example, the automatic end-to-end encryption of customer payment data can be applied as standard, ensuring that, even in the event of a leak, sensitive information cannot be easily read by an outside party.

As well as ensuring the integrity of the technical processes behind transactions, compliant applications can also provide useful support and consultancy for retailers looking to shore up their business processes. One requirement of the PCI DSS is that businesses create unique passwords for applications instead of leaving the default login details active. Compliant retail applications can enforce this by automatically requiring the user to create a new password, for example.

Compliant systems can offer store owners protection and peace-of-mind without the need to spend time and resources on keeping up-to-date with the latest updates to the PCI DSS rules. Instead, technology vendors can offer software updates to ensure the retailer's systems support the most recent version of the regulations, and provide advice on how best they can adapt their business to meet the requirements.

Choosing compliant systems also presents retailers with an opportunity to make additional improvements to bring their operations fully up-to-date with the latest innovations in retailing. Advanced retail technology such as business analysis tools and loyalty systems can help retailers offer customers the best service possible by identifying trends in shopper behaviour and offering customers individualised promotions based on their personal shopping habits, for example.

With a compliant system, the PCI DSS regulations do not have to be a source of worry for retailers. Indeed, stores that can prove to shoppers that they care about keeping their data safe can benefit from increased customer trust and loyalty. With the right technology, it can present stores with an opportunity to boost sales and increase their market share by offering their customers the best possible service.

Doug Hargrove is Chief Marketing Officer at Torex


 
 
category Retail  |  source The Retail Bulletin
 
   
 
 
 
 
Fri, 10th February 2012
Mobile technology will decide who wins battle on the high street
A global KPMG survey has revealed that UK retailers are slower than other countries in adopting mobile technology.

more >
 
Fri, 10th February 2012
Comet to cut 450 jobs
OpCapita, the new owner of the Comet, is to axe around 450 jobs at the electrical chain as part of a plan to reduce investment in its UK-wide repair service.

more >
 
Fri, 10th February 2012
The emergence of click & collect as a real sales driver.
Arguably, the click & collect phenomenon emerged first in France. Much of this development has been driven by legal constraints such as zoning laws in France and high hurdles for the opening of new hypermarches.

more >
 
Fri, 10th February 2012
Hammerson plans redevelopment of Croydon's Centrale
Hammerson is planning to redevelop the Centrale shopping centre in Croydon.

more >
 
Fri, 10th February 2012
Tesco gets green light for new dot.com warehouse in Crawley
Tesco has secured planning permission for a 120,000 sq ft home shopping warehouse in Crawley. The warehouse will help to strengthen Tesco's dot.com home delivery business and create around 500 jobs.

more >
 
Fri, 10th February 2012
Businesses in the dark on electricity usage
Up to £1 in every £2 spent on electricity could be wasted - figures show 46% of business electricity is used when people aren't working.

more >
 
Fri, 10th February 2012
Morrisons lays out plans to open 300 convenience stores
Morrisons is understood to be targeting 300 M Local convenience store openings by 2014.

more >
 
Fri, 10th February 2012
John Lewis weekly sales up 6% in cold spell
John Lewis saw a 6% uplift in sales in the week ending 4 February compared to the same week last year.

more >
 
Fri, 10th February 2012
Sales of winter warmers drive John Lewis sales
John Lewis sales grew 6% to £52.5m in the week to February 4 as shoppers stocked up on winter warmers in the cold weather.

more >
 
Fri, 10th February 2012
Waitrose to use online personalised retargeting to drive customer relationships
Waitrose is to become the first UK supermarket to use online personalised retargeting for groceries to help drive relationships with its customers.

more >
 
Fri, 10th February 2012
Hut Group revenues rise 70%
Online retailer The Hut Group saw revenues increase by 70% to £143 million in the year to 31 December.

more >
 
Fri, 10th February 2012
White Stuff opens art gallery
Fashion retailer White Stuff has opened an art gallery in its Cardiff store in an innovative approach for driving footfall.

more >
 
Fri, 10th February 2012
Forever 21 boss sounds caution on UK expansion
US fast fashion giant Forever 21 is taking a cautious approach to UK expansion as the macro-environment remains volatile. 

more >
 
Fri, 10th February 2012
Hotel Chocolat to take dip in beauty market
Upmarket chocolatier Hotel Chocolat is mulling the launch of beauty products as it enters the European market for the first time.

more >
 
Fri, 10th February 2012
Store stocks rise as retailers refocus
Store stocks were on the up over the week as food and general merchandisers rose with the market, although the former still lagged the All Share index while the latter outperformed.

more >
 
Fri, 10th February 2012
Value retailer QD Stores targets online
Value retailer QD Stores will launch a fully transactional mobile-optimised website in time for Christmas.

more >
 
Thu, 9th February 2012
Edinburgh Woollen Mill pulls out of Peacocks talks
Edinburgh Woollen Mill has pulled out of the bidding process for Peacocks, Retail Week can reveal.

more >
 
Thu, 9th February 2012
Asda creates sustainability network for suppliers
Asda has signed a deal to increase sustainable practices in its supply chain.

more >
 
Thu, 9th February 2012
Co-op receives 64,000 enquiries for apprenticeship roles
The Co-operative Group has revealed that it has received 64,000 internet enquiries regarding its apprenticeship scheme.

more >
 
Thu, 9th February 2012
The Hut reports record sales
Online retailer The Hut group has posted soaring sales up 70% to £143m in the year to December 31, as the final quarter helped drive market share.

more >