Payment Card Mandates Vex Retailers
Small retailers are frustrated and bewildered by the complex requirements of Payment Card Industry Data Security Standards—and most don’t realize how easily a data hacker could put them out of business, according to a new survey conducted in part by the National Retail Federation (Washington).
Nearly nine out of 10 retailers surveyed (88 percent) list data security as a medium or high priority, according to the survey, and 86 percent feel familiar with data security standards. Simultaneously, however, respondents feel frustrated when it comes to understanding, implementing and paying to comply with these standards.
The survey, conducted in July by ControlScan (Atlanta), the PCI Knowledge Base (Highland Village, Texas) and the NRF, involved Level 4 merchants representing a mix of e-commerce, retail, mail order and telephone businesses.
“A year ago, there was little to no awareness of [payment card industry] compliance among small merchants,” said David Taylor, founder of the PCI Knowledge Base. Now, many sales organizations require mandatory compliance—and some even impose fines if a business can’t prove that it’s following the rules.
Retailers who’d never had a security breach weren’t too concerned that it could happen: 72 percent thought the risk of a compromise was “low” or “not possible.” Merchants whose data had been compromised were on the opposite end of the spectrum: 67 percent called the risk “high” or “medium,” and typically spent more money on security measures.
“Small merchants often do not understand the severe consequences of a data breach and are understandably overwhelmed with the intricacies of becoming compliant in the first place,” said David Hogan, chief information officer for the NRF. “Until industry service providers and the PCI Security Standards Council make compliance easier to understand and less complex to implement, many small merchants will likely continue to be frustrated and bewildered, causing some of them to abandon the idea of compliance altogether.”
Learn more about the survey and PCI compliance at www.nrf.com. [October 2009 PET AGE]
 |