The Green Sheet Online Edition

February 2, 2009 • 09:02:01

Get the FUD out of PCI

Merchants are being unnecessarily frightened by vendors trying to lock in the idea that the Payment Card Industry (PCI) Data Security Standard (DSS) is always horribly complicated, and the only way to tackle it is to buy expensive hardware, software or services.

And misrepresentations involving PCI compliance are not just affecting merchants: They hurt ISOs, merchant level salespeople (MLSs), acquirers and others in the payments industry as well.

Too many ISOs and acquirers are taken in by talk of unavoidable complications and costs and are reacting in counterproductive ways. Some are ignoring PCI, hoping it will go away. Some are going to the other extreme: hitting their merchants with aggressive and tone-deaf requirements to the point at which some merchants are threatening to move to other acquirers or service providers.

Match method to merchant

It is true that for many merchants - particularly larger merchants - PCI is complicated. However, this need not be the case for everyone else, especially for small merchants. ISOs and MLSs can and should offer these merchants relatively simple, painless and inexpensive routes to compliance.

This article provides simple steps that can significantly lighten the burden and expense of PCI compliance. It also offers tips on how to tell when a vendor is making life more complicated than it really needs to be by spreading fear, uncertainty and doubt (FUD).

The right perspective will help ISOs and MLSs steer the proper middle course, giving each merchant the right level of service, laying out the right set of compliance and validation obligations, and, most importantly, ensuring cardholder information is protected against identity theft.

This means a one-size-fits-all strategy for dealing with merchants in a portfolio is never going to work. Some merchants are designated high-risk because of the number of transactions they handle or because they store cardholder data or are accessible over the Internet. PCI imposes a higher validation burden on these types of merchants.

It is likely such merchants need, and might even appreciate, a broad range of services. However, most merchants live in a simpler world. Imposing the same broad range of services and costs on them is hard to justify.

Doing so might help vendors and simplify the decision-making process, but it also burdens merchants with unnecessary services and gives them the impression that PCI is an expensive, complicated process that is divorced from reality.

ISOs should therefore look for a solution package that recognizes, and gracefully handles, the diversity of merchant environments. For example, only merchants who use an Internet-accessible payment application need network scans, and only they should have to pay for them.

ISOs also need to help merchants adjust operations to deal with PCI in the smartest way possible - not by running headfirst into challenges and then hopefully overcoming them, but by avoiding them altogether.

This is almost always the most secure and cost-effective way to deal with security issues; it also causes the least disruption to business. I am not talking about trying to "trick" PCI by avoiding assessments but rather passing assessments with flying colors by avoiding exposure to risks in the first place.

Ease the compliance burden

Here are ways for merchants to make PCI compliance and validation a simpler, less expensive process. Not all are relevant to every merchant, but it's a checklist that all merchants should consider:

Many merchants already have the suggested practices in place and live in a world in which PCI compliance can be relatively simple and painless. It's critical that ISOs avoid clumsy moves that punish these merchants with unnecessary cost and confusion just because other merchants need additional expensive services.

ISOs who strike the right balance, giving "simple" merchants streamlined, low-cost solutions while offering "complicated" merchants a broad suite of affordable services, will have safer, more satisfied merchants.

So remember, every time a PCI vendor tries to use FUD to make life unnecessarily complicated and expensive for your merchants, use the points provided herein to dispel the nonsense. End of Story

Dr. Tim Cranny is an internationally recognized security and compliance expert and is Chief Executive Officer of Panoptic Security Inc. (www.panopticsecurity.com). He speaks and writes frequently for the national and international press on compliance and technology issues. Contact him at tim.cranny@panopticsecurity.com or 801-599 3454.

Whether you want to upgrade your POS offerings, find a payment gateway partner, bone up on fintech regs or PCI requirements, find an upcoming trade show, read about faster payments, or discover the latest innovations in merchant acquiring, The Green Sheet is the resource for you. Since 1983, we've helped empower and connect payments professionals, starting with the merchant level salespeople who bring tailored payment acceptance and digital commerce tools, along with a host of other business services to merchants across the globe. The Green Sheet Inc. is also a proud affiliate of Bankcard Life, a premier community that provides industry-leading training and resources for payment professionals.

Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.

skyscraper ad