# Managing compliance complexity will deliver security rewards
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-05
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Why Financial Organisations Must Focus on PCI DSS
Meta Description: Learn how financial services industry can enhance cybersecurity measures and ensure compliance with PCI DSS standards to protect against cyber threats.
URL: https://financedigest.com/managing-compliance-complexity-will-deliver-security-rewardshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/security-sbi-300195529-1736837711950-compressed.jpg)

_By_ **_Dave Waterson,_** _CEO,_ [_SentryBay_](http://www.sentrybay.com)

In the escalating battle against cyberthreats, financial services companies need to think beyond traditional defences. It is now time for enterprises to work closely with solution specialists who are addressing changed work environments if they are to stop being vulnerable to attack now and in the future. There is another imperative too, which for financial organisations is just as important – compliance with regulations and legislation. While this is developed with the best intentions of protecting customers, it has become, all too often, an irritant that seems to cause more difficulties than it solves.

Any organisation of any size that accepts card payments must comply with Payments Council Industry [Data Security](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") Standards, commonly known as PCI DSS. These are promoted by leading card brands like Visa, American Express and Mastercard and seek to protect cardholder data and [strengthen the adoption of consistent data security](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") measures around the world. The standard outlines an array of technical and operational requirements designed to [protect account data provided in an online](https://www.financedigest.com/uk-opposition-calls-for-better-online-protections-for-children.html "UK opposition calls for better online protections for children") purchase or other card-based transaction. These – subject to local or regional laws and other requirements – set a minimum standard that applies not only to [retailers but to anyone who handles either cardholder data](https://www.financedigest.com/investing-in-a-first-party-data-strategy-can-save-the-day-for-retailers.html "Investing in a first-party data strategy can save the day for retailers") or sensitive authentication data.

**Views on PCI**

Given the backdrop of the rise in cyberattacks, we were interested to know how security professionals viewed the [PCI DSS](https://www.financedigest.com/the-pci-dss-comes-of-age-with-v3-2.html "The PCI DSS comes of age with v3.2") standards. We carried out a poll on Twitter which found more than [half of respondents admitted that their current](https://www.financedigest.com/more-than-half-of-workers-are-open-to-leaving-their-current-employers.html "MORE THAN HALF OF WORKERS ARE OPEN TO LEAVING THEIR CURRENT EMPLOYERS") infrastructure had either failed Payments Council Industry assessments or the company was non-compliant with PCI DSS. In addition, over 50% told us they either believe PCI regulations are unfit for purpose or need adjusting for current [hybrid working](https://www.financedigest.com/how-has-hybrid-working-impacted-the-gender-gap.html "How has hybrid working impacted the gender gap?") models, which allow employees to work both at the office, or remotely.

The problem seems to lie in addressing numerous [security needs at the same time as the standards](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’"), which can be contradictory. Almost a quarter (24%) of the respondents to our poll cited process contradictions in applying the requirements of PCI DSS. This could be caused by incompatible technologies, services and solutions, or even attempting to satisfy the requirements of other regulations. Typically these issues can be exacerbated by staffing or other resourcing problems and nearly one in four of the people answering our poll pinpointed the education of [employees and other workers as a major challenge](https://www.financedigest.com/how-to-deal-with-challenging-employees.html "How to Deal With Challenging Employees?") when it came to ensuring PCI DSS compliance.

Onerous [security demands](https://www.financedigest.com/new-demands-on-network-security.html "NEW DEMANDS ON NETWORK SECURITY") in themselves cause critical issues when it comes to achieving and maintaining PCI DSS compliance, according to 22% of respondents. These challenges are not just cybersecurity theatre or a failure to tick a box. While correlation is not causation, some 15% revealed that their organisation in the past year experienced at least one [security breach that was most likely caused by mishandling payment card or related information](https://www.financedigest.com/privacy-vs-security-is-the-cybersecurity-information-sharing-act-beneficial.html "PRIVACY VS SECURITY: IS THE CYBERSECURITY INFORMATION SHARING ACT BENEFICIAL?"). Another 20% admitted that they do not know if their organisation has experienced such a breach.

**Compliance frameworks will help defend against cyberattack**

PCI DSS is constantly subject to further review and expansion, so it is essential that enterprises get on top of what it means for them and how they can address it. It will not become less complex, indeed is likely to become more so, and [needs addressing](https://www.financedigest.com/if-the-nation-backs-fintech-we-need-to-address-a-few-things.html "If the nation backs FinTech, we need to address a few things") with some urgency. However, despite the difficulties that organisations are experiencing, they should understand that compliance frameworks and legislation will help them combat cyberattacks, and by addressing requirements, they will improve their overall cybersecurity posture across all devices, applications, and systems whenever, and wherever, they are used.

**Getting on top of the problem**

Dealing with this means adopting a multi-layered approach that integrates complementary products and [services that can enable organisations to block cyberthreats and proactively address gaps](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER") in compliance.

Firstly, it’s [important to adopt a zero-trust approach to all endpoints on the network:](https://www.financedigest.com/the-importance-of-networking-for-smes.html "The Importance of Networking for SMEs") “Never trust, always verify.” It also means thinking past the old standards of internet security, anti-virus software and securing the wireless network with virtual private networking (VPN). Instead, enterprises should look to deploy dedicated software and solutions that can ‘wrap’ data and applications [securely to reduce the threat](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") of cyberattack via keyloggers, screen scrapers and similar malware.

For PCI DSS, following proper security measures for accepting, processing and [storing card payments and personal information includes annual](https://www.financedigest.com/ikea-stores-owner-ingkas-annual-operating-profit-rises-9.html "IKEA stores owner Ingka’s annual operating profit rises 9%") and quarterly validation requirements, including several reports by qualified independent experts and an attestation of compliance. The [exact standards depend on the merchant category and level of business](https://www.financedigest.com/exact-launches-practice-management-solution-to-help-transform-accountants-into-trusted-business-advisors.html "Exact launches Practice Management solution to help transform accountants into trusted business advisors") as described by PCI SCC.

Organisations can begin by auditing their own environments, determining what data is handled and by whom, and how it is processed and stored. The attack surface can be [reduced by isolating cardholder data](https://www.financedigest.com/durham-county-council-reduces-data-log-analysis-costs-by-50-with-real-time-analysis-and-security-tool.html "Durham County Council reduces data log analysis costs by 50% with real-time analysis and security tool") from other parts of the network, which makes compliance easier by reducing the scope of coverage. Once vulnerabilities have been identified, the required paperwork should be completed and sent to stakeholders in the company.

The next step is to [address all gaps found in the security](https://www.financedigest.com/infosecurity-europe-agenda-spotlights-innovation-as-security-leaders-address-cybersecurity-spend-in-the-face-of-economic-headwinds.html "Infosecurity Europe agenda spotlights innovation as security leaders address cybersecurity spend in the face of economic headwinds") posture, with special attention paid to the endpoint environment – endpoints are any device that is used to connect to the corporate network. Organisations should also regularly review, test and assess the assets and tools used to assure [compliance and handle payments](https://www.financedigest.com/payment-security-compliance-declines-only-1-in-3-companies-globally-make-the-grade.html "Payment security compliance declines – only 1 in 3 companies globally make the grade").

**Employee education**

Compliance requirements like penetration testing and vulnerability scans can also help satisfy additional security standards, along with password protection and identification, multifactor authentication, encryption, tokenisation, local and in-cloud automated system backups, email gateway security, endpoint threat detection and response, ransomware protection, monitoring and critical control testing – all of which must be done in conjunction with [strong ongoing employee education programmes](https://www.financedigest.com/reckon-one-builds-momentum-with-strong-backing-from-accountants-joining-the-cloud-advisor-programme.html "Reckon One builds momentum with strong backing from accountants joining the Cloud Advisor Programme").

[Keeping customer transactions safe](https://www.financedigest.com/five-ways-to-keep-your-personal-data-safe-from-hackers.html "Five ways to keep your personal data safe from hackers") from phishing, keylogging, spyware, screen scraping and more can be achieved with solutions built for purpose, which can also block employees from viewing or handling sensitive information. Contact centre agents and remote workers may be using virtualised desktop infrastructure (VDI) to connect to head office, using their own [devices via a portal – perhaps regularly processing contracts and payments](https://www.financedigest.com/emvco-streamlines-approval-process-for-mobile-payment-devices.html "EMVCo Streamlines Approval Process for Mobile Payment Devices") with another partner company, so this needs to be addressed.

**Get the right** [security solutions](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions")

[Security professionals](https://www.financedigest.com/private-equity-firms-hungry-for-investment-opportunities-but-business-owners-must-be-cautious.html "Half of Security Professionals Had No Contingency Plan in Place for COVID-19") should look for scalable solutions that can be quickly deployed, particularly to remote workers. In this industry they should at the very least [protect endpoints and devices, however security for commerce applications, or to protect customers when they access](https://www.financedigest.com/supporting-a-fair-and-resilient-society-by-protecting-access-to-cash.html "Supporting a fair and resilient society by protecting access to cash ") an online banking site, or specific assistance with threat intelligence or against ransomware will be equally important.

Good practice must be led by [managers and those responsible for security and risk](https://www.financedigest.com/early-detection-of-mismatched-trades-is-key-to-managing-risk-and-maximizing-profits-on-the-pl-desk.html "EARLY DETECTION OF MISMATCHED TRADES IS KEY TO MANAGING RISK AND MAXIMIZING PROFITS ON THE P&L DESK") need to engage regularly with other functions in the company, not just compliance stakeholders, but network managers, application owners, business unit managers, and legal teams. This multi-layered approach supports close alignment with the needs of the enterprise and facilitates the continual review and revision that must accompany the [understanding of security and regulations](https://www.financedigest.com/activision-aims-to-help-uk-regulator-better-understand-our-industry.html "Activision aims to help UK regulator ‘better understand our industry’") as a constantly changing, continuous process.

Further information on how organisations can connect their security strategies with compliance is available [here](https://www.sentrybay.com/news/connecting-security-strategies-with-pci-dss-compliance).


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

