The payment card industry (PCI) has long been a Holy Grail target for bad actors for obvious reasons. Visa, Mastercard, and American Express account for the bulk of the consumer financial activity in the United States. Breaching them would be an unimaginable windfall for hackers--and, undoubtedly, an unmitigated disaster for the world’s economy.
So far these major companies have avoided such attacks that have impacted established networks, from larger retail breaches to individual stores and payment processing companies. Given the rising sophistication in attack methods and malicious actors’ understandable predilections for targeting the financial sector it’s likely only a matter of time before major credit card issuers and retailer partners become victims.
That’s why the PCI Security Standards Council was formed. As its name suggests, the Council outlines a clear set of PCI security standards it recommends both card vendors and retailers adhere to in order to ensure the security of cardholder data. The Council’s goal is to protect consumers, card issuers, and merchants.
What are the PCI security standards?
The 15 PCI security standards outline recommended security practices, technologies, and processes to protect card payment. They run the gamut from implementing effective PIN security, to card protection processes, software lifecycle management, and more.
PCI security standards can help turn the tide against rising cybersecurity threats. As recent security breaches at Capital One and other financial institutions prove, industrious hackers will diligently and continuously probe and attempt to thwart even the most stalwart security measures. And the biggest risk tends to come via third parties, proven again to the cybersecurity world by the recent and ongoing SolarWinds breach.