Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > New Payment Security Standards Update Fails to Convey a Sense of Urgency for Security
    Technology

    New Payment Security Standards Update Fails to Convey a Sense of Urgency for Security

    New Payment Security Standards Update Fails to Convey a Sense of Urgency for Security

    Published by Jessica Weisman-Pitts

    Posted on August 22, 2022

    Featured image for article about Technology

    By Donnie MacColl, Senior Director of EMEA Technical Services at HelpSystems

    Since 2004, the Payment Card Industry Data Security Standard (PCI DSS) has ensured that organisations processing or storing credit card information do so securely.

    During the pandemic, when shops were either closed or no longer accepting cash as the preferred method of payment, the volume of payment card data increased dramatically. Since then, the volume of online transactions and use of point-of-sale machines continue to soar and, as most of the data is held in the cloud, so do the opportunities for cyber-attacks. These trends meant that the previous version of PCI DSS was no longer sufficient and a new version was required to update the guidance on security controls.

    Now that PCI DSS V4.0 has been announced, many financial businesses are getting ready to implement the changes it brings. Companies have two years to plan their implementation, but must have everything in place by March 2025. The risk of working to this single deadline, however, is that it fails to create a sense of urgency and many of the security updates included in the new standard are best practices that businesses should already have established.

    For instance, “8.3.6 – Minimum level of complexity for passwords when used as an authentication factor” or “5.4.1 – Mechanisms are in place to detect and protect personnel against phishing attacks” are listed as “non-urgent updates to implement in 36 months”. Considering the high level of cyber threat following events such as the Russian-Ukrainian conflict, this timeframe isn’t fast enough to raise the level of cyber protection needed by financial institutions and retail businesses today, posing a real threat to customer data and privacy.

    In a wider sense, there are some important and revealing numbers that illustrate both its scope and limitations:

    • 64 is the number of changes and updates between versions, representing positive progress.
    • 13 is the number of differences that are effective immediately for all V4.0 assessments. This is useful but doesn’t go far enough, particularly because:
    • 51 and 2025 – illustrate the core problems surrounding PCI DSS V4.0 in that 51 is the number of proposed changes that are classed as “best practice” between now and 2025 when they actually become effective – which is three years away.

    This isn’t without precedent, however, and I recall the threats of huge fines and the risk of having credit cards as a payment method withdrawn if organisations failed to comply with PCI standards. In reality, the imposition of penalties has been relatively few and far between, and waiting a further three years to implement the new requirements contained within V4.0 seems to imply a lack of ownership that some of the changes deserve.

    A phased approach?

    Granted, there are a lot of changes to implement, but a better strategy would be to adopt a phased approach, i.e. prioritise changes required immediately, in 12 months, 24 months and 36 months from now rather than say they must all be effective in three years’ time. Without this guidance, it’s likely some organisations will shelve these projects to be looked at in two years’ time when the implementation plan deadline approaches.

    Effective immediately for all V4.0 assessments includes items such as “Roles and responsibilities for performing activities are documented, assigned and understood”. These comprise 10 of the 13 immediate changes, so basically knowing what you should be doing already comprises the bulk of the “urgent updates”, whereas the following are updates that “need to be effective by March 2025”:

    • 3.3: Anti-malware scans are performed when removable electronic media is in use
    • 4.1: Mechanisms are in place to detect and protect personnel against phishing attacks.
    • 2.4: Review all user accounts and related access privileges appropriately.
    • 3.6: Minimum level of complexity for passwords when used as an authentication factor.
    • 4.2: Multi-factor authentication for all access into the CDE (Cardholder data environment)
    • 7.3: Failures of critical security control systems are responded to promptly

    These are just six of the 51 “non-urgent” updates, and I find it amazing that the detection of phishing attacks and use of anti-malware scans are considered so. Today, with phishing attacks at an all-time high, I would expect any global financial institution with sensitive data to protect to have these in place as essential requirements, not something to have in place in three years’ time.

    I do appreciate that just because they are specified in PCI 4.0 does not mean that companies have not already implemented some or all of the updates. I also appreciate that some updates require investment and planning, and for these purposes, PCI 4.0 needs to be more specific. For example, it states that security failures need to be responded to “promptly” which is simply too vague (does that mean 24 hours, 24 days or 24 months?). Stakeholders would be much better served with more specific deadlines.

    While PCI DSS V4.0 represents a good basis for moving the standard forward, much of what it includes would benefit all stakeholders if it was implemented with greater urgency. In an era when payment card crime continues to be a ubiquitous risk, there is little to be gained from delay.

    About Author:

    Donnie MacColl is Senior Director of EMEA Technical Services. He has worked for more than 25 years in the IT industry, initially specialising in the management of IBM systems in manufacturing and logistics companies, and later in his career developing expertise in network and enterprise management.

    A regular speaker at international events, he has worked with many industry sectors to help improve cost efficiencies and has implemented solutions across some of the largest data centres in the United States, Asia Pacific, and Europe. He specialises in cyber security, IT governance and compliance and advanced automation across multi-platform environments.

    Related Posts
    Treasury transformation must be built on accountability and trust
    Treasury transformation must be built on accountability and trust
    Financial services: a human-centric approach to managing risk
    Financial services: a human-centric approach to managing risk
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Technology PostHow Financial Organisations can Stay Protected from Financial Data Breaches
    Next Technology PostFive Ways Modern Multi Factor Authentication Secures and Protects Fintechs

    More from Technology

    Explore more articles in the Technology category

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Compliance Has Become an Engineering Problem

    Why Compliance Has Become an Engineering Problem

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    View All Technology Posts