# Payment security compliance declines &#8211; only 1 in 3 companies globally make the grade
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-01-07
Category: BANKING
Category URL: https://financedigest.com/category/banking
Meta Title: Verizon Report: Decline in Payment Security Compliance
Meta Description: Discover why payment security compliance is crucial and how Verizon&#039;s 9-5-4 Framework can help combat the downward trend. Learn more here.
URL: https://financedigest.com/payment-security-compliance-declines-only-1-in-3-companies-globally-make-the-gradehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/banking-2-1736838977517-compressed.jpg)

_Verizon’s 2019 Payment Security Report highlights why compliance matters, and offers measures to combat the downward compliance trend_

**What you need to know:**

- Companies that maintain full compliance with the Payment Card Industry Data Security Standard (PCI DSS) decrease for the second year in a row to 36.7 percent worldwide.
- Only 1-in-5 organizations in the Americas maintain full compliance; Companies in Asia-Pacific dominate.
- Verizon’s 9-5-4 Framework addresses elements to help develop and improve capability and process maturity across an entire [data protection compliance program](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks") (DPCP).

Payment security compliance has declined for the second year in a row, with organizations based in the Americas lagging behind worldwide counterparts, [Verizon’s 2019 Payment Security Report](https://enterprise.verizon.com/resources/reports/payment-security/) (2019 PSR) flags.

When Visa Inc. initially launched the PCI DSS in 2004, many assumed that organizations would achieve effective and [sustainable compliance within five years](https://www.financedigest.com/nfts-live-streams-sustainable-businesses-and-social-shopping-what-to-prioritise-in-commerce-this-year.html "NFTs, live streams, sustainable businesses and social shopping – what to prioritise in commerce this year"). Now, 15 years on, the number of businesses achieving and maintaining compliance has dropped from 52.5 percent (2018 PSR) to a low of just 36.7 percent worldwide. Geographically, organizations in the Asia-Pacific (APAC) region show a stronger ability to maintain full compliance at 69.6 percent, compared to 48 percent in Europe, Middle East and Africa (EMEA) and just 20.4 percent (1 in 5) in the Americas.

PCI DSS helps businesses that offer card payment facilities protect their payment systems from breaches and theft of cardholder data, as shown in the [Verizon Data Breach Investigations Report series](https://www.verizon.com/about/news/verizon-2019-data-breach-investigations). Compliance is [measured on an organization’s ability to meet — and importantly](https://www.financedigest.com/quality-control-measures-for-drug-development-are-of-utmost-importance-as-inadvertent-presence-of-unknown-pharmaceutical-ingredients-can-further-complicate-health-conditions-of-the-patients.html "Quality control measures for drug development are of utmost importance as inadvertent presence of unknown pharmaceutical ingredients can further complicate health conditions of the patients."), maintain — the standard.

“After witnessing a gradual increase in compliance from 2010 to 2016, we are now seeing a worrying downward trend and increasing geographical differences,” said RodolpheSimonetti, global [managing director](https://www.financedigest.com/tmwi-appoints-steve-hadfield-as-managing-director-as-the-agency-readies-itself-for-further-growth.html "tmwi appoints Steve Hadfield as Managing Director as the agency readies itself for further growth") for security consulting at Verizon. “We see an increasing number of organizations unable to obtain and maintain the required compliance for PCI DSS, which has a direct impact on the security of their [customers’ payment data](https://www.financedigest.com/understanding-the-realities-of-payment-data-monetisation.html "Understanding the realities of payment data monetisation"). With the latest version of the PCI DSS standard 4.0 launching soon, [businesses have an opportunity to turn this trend](https://www.financedigest.com/new-report-of-fuel-conditioning-system-market-with-size-growth-drivers-market-opportunities-business-trends-and-forecast-to-2028.html "New Report Of Fuel Conditioning System Market With Size, Growth Drivers, Market Opportunities, Business Trends And Forecast To 2028") around by rethinking how they implement and structure their compliance programs.”

**New Verizon framework helps businesses** [navigate payment security compliance](https://www.financedigest.com/unfolding-the-great-payments-disruption-how-consumers-can-navigate-this-new-financial-world-and-how-financial-institutions-can-rise-to-the-challenge.html "Unfolding the Great Payments Disruption – how consumers can navigate this new financial world and how financial institutions can rise to the challenge")

[Data protection](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches ") and compliance present daily challenges. Many organizations believe they can use a one-size-fits-all script to achieve [effective and sustainable data](https://www.financedigest.com/can-banks-compete-in-the-digitisation-race-without-effective-data-integrity.html "Can banks compete in the digitisation race without effective data integrity?") protection. However, in the real world, security is more complicated.

Simonetti continues, “Many organizations [spend a lot of time](https://www.financedigest.com/its-time-for-banks-to-spend-on-digital-mortgage-journeys.html "It’s time for banks to spend on digital mortgage journeys") and money creating data protection compliance programs, but often these are ineffective — looking good on paper but not able to withstand the scrutiny of a professional security assessment. We still see Chief Information Security Officers focusing on how to maintain baseline control [activities rather than looking at data](https://www.financedigest.com/oil-slips-on-china-covid-curbs-weak-factory-activity-data.html "Oil slips on China COVID curbs, weak factory activity data") protection competency and maturity. What is needed is a clear and easy-to-understand navigational guide to help them deliver measurable results and predictable outcomes.”

In previous [Payment Security Reports](https://enterprise.verizon.com/resources/reports/payment-security/2018/), Verizon developed methodology to help organizations manage their Data Protection Compliance Programs (DPCPs). These have now been combined to form the Verizon 9-5-4 Compliance Program [Performance Framework — a guideline which helps develop and improve capability and process maturity](https://www.financedigest.com/strong-performance-of-investec-lowes-structured-product-maturities.html "Strong performance of Investec / Lowes structured product maturities").

The 9-5-4 Framework is designed to help organizations achieve repeatable, consistent and predictable outcomes by offering guidance on how to map, monitor and report the status of sustainability and effectiveness for each of the 9 Factors of Control Effectiveness and Sustainability — including control environment, control design, control risk, control robustness, control resilience, control [lifecycle management](https://www.financedigest.com/service-lifecycle-management-applications-market-to-grow-at-a-cagr-of-6-9.html "Service Lifecycle Management Applications Market to grow at a CAGR of 6.9%"), performance management, maturity measurement and self-assessment. This is across each of the essential 4 lines of assurance — individual accountability, [risk management](https://www.financedigest.com/risk-management-redefined-navigating-post-covid-disruption.html "Risk Management redefined: navigating post-COVID disruption") and compliance teams, internal audit, external audit and regulators — and is achieved by evaluating the 5 Constraints of Organizational Proficiency  — capacity, capability, competence, commitment and communication.

**Link reinforced between lack of compliance and breaches**

The [report also includes data from the Verizon Threat Research](https://www.financedigest.com/fucoidan-extract-market-research-report-2022-global-forecast-till-2028.html "Fucoidan Extract Market Research Report 2022 – Global Forecast till 2028") Advisory Center (VTRAC), which demonstrates that a compliance program without the proper controls to protect data has a more than 95 percent probability of not being sustainable and is more likely to be a potential target of a cyber-attack.

“For years, we have discussed the close correlation between the lack of PCI DSS compliance and [cyber](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") breaches,” concludes Simonetti. “In this year’s report, we included even more [data from the Verizon VTRAC team, the authors of Verizon’s Data Breach](https://www.financedigest.com/outthink-raises-10-million-to-tackle-human-errors-behind-data-breaches.html "OutThink raises million to tackle human errors behind data breaches") Investigation series, to add more depth to this discussion. Our [data shows that we have never investigated a payment card security data breach](https://www.financedigest.com/amazons-twitch-hit-by-data-breach-due-to-configuration-error.html "Amazon’s Twitch hit by data breach due to configuration error") for a PCI DSS compliant organization. Compliance works! ”


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

