Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Dispelling the Myths of PCI DSS
Articles

Dispelling the Myths of PCI DSS

ISBuzz TeamBy ISBuzz TeamDecember 28, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Dispelling the Myths of PCI DSS
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Almost a decade on from its original launch in 2006, the Payment Card Industry Data Security Standard (PCI DSS) continues to generate heated debate regarding its precise application and interpretation. Many of the issues stem from the wealth of misinformation out there about the standard, perpetuated by individuals and groups who do not properly understand the principles behind it or why it was originally created. At the centre of this is a number of PCI DSS myths that have no grounding in fact yet continue to arise time and time again. Below are five of the most common of these myths, which this article hopes to dispel once and for all.

  • If your business is non-PCI compliant, the card brands will fine you

This is incorrect. Whilst the global card brands such as MasterCard, VISA and American Express are the driving force behind PCI DSS, their relationship is with the acquiring banks (Barclays, HSBC etc), not the merchants themselves. As such, the card brands cannot directly fine the merchants for any breach where the merchant is found to be non-PCI DSS compliant.

However, that’s not to say merchants can’t be fined. Acquiring banks can levy fines in cases where merchants are the subject of a security breach and upon investigation are found to be non-compliant. Fines for a small merchant typically total around £15,000, which is payable on top of any forensic investigation and remediation costs (that can significantly increase the financial penalty).

  • PCI DSS compliance trumps FCA regulations

One of the most common myths encountered amongst regulated UK industries is that PCI DSS compliance is more important than compliance with the Financial Conduct Authority (FCA) regulations. It’s not hard to see where the confusion creeps in; the two sets of regulations create a compliance paradox, where the ‘correct’ answer is not immediately clear.

This is because under the current rules, it is a violation of the PCI DSS requirement for any merchant to store any sensitive payment authentication data after authorisation, even if encrypted. However, the FCA regulations demand that financial institutes keep sufficient detail of all their transactions, often for many years after the transaction took place. This is particularly vexing when considering phone payment recordings, where the two regulations appear to directly conflict with one another.

In truth, FCA trumps PCI DSS every time, however it is possible to be compliant with both regulations simultaneously. By deploying secure telephone payment platforms, in customer contact centres, merchants governed by FCA can maintain accurate transaction records whilst ensuring no sensitive payment data is captured as part of those calls. At the point of a payment, customers are re-routed through the platform, keying in their payment information via the telephone keypad where it is processed directly with the bank. If the information never enters the call centre, PCI compliance is achieved, while the merchant has the complete call recording required to meet FCA requirements.

  • Qualified Security Assessors and security advisors are the same

One of the more concerning myths out there is the notion that security advisors can do the same job as Qualified Security Assessors (QSAs). This is extremely innacurate. Whilst unscrupulous security advisors may try to convince merchants otherwise, only qualified QSAs are able to carry out an official PCI DSS audits. The full list of officially recognised PCI DSS QSAs can be found on the PCI standards website. All merchants should ensure the individual/company conducting their PCI assessment is on this list before engaging their services.  Failure to do so could leave the merchant with expensive bills for consultancy services, but no closer to being officially recognised as PCI compliant.

  • Once an auditor is satisfied you are PCI compliant, you are officially ‘PCI certified’

Many merchants and service providers like to promote themselves as ‘PCI DSS certified’ in marketing materials to entice new customers. However, this is false advertising. There is no such thing as being ‘PCI DSS certified’ and customers should be wary of any merchant/service provider stating they are.

PCI DSS compliance is a continuous process, not a snapshot in time. Too many merchants make the mistake of thinking that once they have passed the QSA audit, they can tick the box and not worry about PCI compliance again until the next annual review. More often than not, this mentality leads to merchants falling out of compliance shortly after certification has been achieved.

  • Outsourcing PCI compliance to a service provider makes it their problem

Many merchants choose to outsource PCI compliance to specialist third party providers, which can be a good strategy, particularly when they lack the necessary infrastructure and resources to attempt it in house. However, some make the mistake of assuming that all of the associated liability is transferred along with it. Whilst the assistance of a specialist third party can greatly reduce the burden of PCI compliance on a merchant, it does not remove it entirely. Furthermore, the reputational damage attached to any major data breach will always fall on the merchant itself, irrespective of which party was actually to blame.

Recent changes to the PCI DSS regulations mean Merchants must now ensure third parties sign an enforceable agreement acknowledging the responsibility they have to the security of the payment data under their control. However, merchants choosing this route must not lose sight of where the blame will lie in the eyes of their customers, irrespective of where the buck stops from a legal perspective.

The path to PCI compliance may not always be straightforward but it is a critical aspect of any effective data security strategy. The wealth of misinformation out there doesn’t help but it also shouldn’t be used as an excuse. With a little effort, merchants can quickly sort the fact from the fiction, giving them a clear path to achieving compliance and keeping their customer data safe.

[su_box title=”About Matthew Bryars” style=”noise” box_color=”#336588″]Matthew BryarsMatthew Bryars, CEO at Aeriandi, Shortly after completing a Masters degree in physics from University College London, Matthew was one of the first to see the potential for highly secure, cloud-based business services – and promptly co-founded Aeriandi. Matthew quickly applied his problem solving skills to the business world and has been responsible for building the company from a start-up to a well renowned business – running services for some of the world’s largest banks and contact centres.

Although the business has grown substantially, Matthew still takes a hands-on approach and remains actively involved in the development process, getting most fulfilment from delivery of high quality, relevant solutions based on the company’s hosted multi-channel platform.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}