ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Leveraging PCI compliance to improve security

Henning Horst at comforte AG argues that organisations cannot postpone compliance with evolving standards such as PCI DSS

 

Since 2018, when the PCI Council released the current version (3.2.1.) of the PCI Data Security Standard (PCI DSS) the threat landscape has undeniably changed, with more people relying on their computers for work and leisure due to the pandemic.

 

To reflect these changes, at the beginning of 2022, the PCI announced a newer DSS version, version 4.0. Some organisations may be comforted by the fact that immediate action is not necessary. Version 3.2.1 won’t be retired until the second quarter of 2023 and many of the newer requirements in version 4.0 are not considered best practice until March 2025.

 

This might tempt some organisations to delay or prolong the roll out period for the latest version, but delaying implementation is undeniably the strategy that involves the most risk.

 

The two-year transition period for version 4.0 allows organisations to take some time to thoroughly review their existing security program. The transition period also helps them understand how compliance can support rather than detract from their security objectives.

 

Plans can be drawn up from this that not only improve security, but also meet compliance requirements. It also allows time for organisations to become acquainted with the version and implement changes if necessary.

 

PCI DSS V4.0 has four key goals: to continue to meet the security needs of the payment industry, to promote security as continuous process, add flexibility for different methodologies, and enhance validation methods. These are positive goals that could, if compliance is achieved, enhance protection of payment data for consumers and companies.

 

PCI DSS 4.0 considers multi-factor authentication usage as standard practice, passwords being changed every 12 months, access privileges being reviewed bi-annually, and vendor or third-party accounts only enabled as needed and monitored when in use. PCI SSC have also partnered with Europay, Mastercard, and Visa to implement the use of the 3DS core security standard during transaction authorisation.

 

These changes have been carefully considered based on the current threat landscape. Sso delaying implementation may mean exposing your organisation to more risk. We must consider the security landscape as a continuous process, which means, in practical terms, that critical controls will be tested much more frequently.

 

The upgrade is bound to cause teething problems though, with technology not being fully understood and therefore, not properly implemented. This can cause a lot of risk. Unfortunately, data revolving around payments and finances are most highly sought after by cyber criminals. This makes retailers and merchants especially vulnerable to data theft and/or exposure because they are typically the first point of contact for consumer data.

 

This is just one of the reasons why the transition period to the new PCI requirements can pose a significant risk for organisations.

 

Some positive changes have been made to the standards to address secure configuration though. The update has been developed in collaboration with global industry and driven by industry feedback. There were also three requests for comment (RFC) periods, over 6000 items of feedback received and considered, and 200+ companies provided feedback. The 12 core PCI DSS requirements did not fundamentally change though.

 

The updated version is designed to make room for Zero Trust approaches to authentication and authorisation. Zero Trust is a collection of IT design principles attempting to eliminate or reduce the chances of the whole entity getting a hold of vital information or resources possessed by your organisation.

 

Implicit trust or privilege which might be granted to users or devices based on where those people/things are physically on the network are removed. PCI compliance doesn’t require a Zero Trust Architecture (ZTA), but the data suggests that by implementing a best practice ZTA security can be greatly enhanced.

 

Problems also arise when you consider the cost of addressing the changes as individual requirements. Whilst it is possible to take the full two years to implement these changes and remain fully compliant with PCI, this adds avoidable risk. You also don’t escape compliance completely in the meantime because you still have to remain compliant with version 3.2.1.

 

For those seeking the appropriate protection for financial information while remaining compliant, data-centric security has been the protection method of choice. Many retailers and financial organisations have met compliance, not just with PCI DSS, but also with a host of other data protections standards and regulations.

 

The benefit of data-centric security tools, like tokenisation, is that it protects the data itself, not simply the perimeter around information storage. Regardless, the security controls you choose to implement should protect your organisation and its data, even if PCI compliance ultimately aims to protect the card brands themselves.

 

Crucially, compliance should be seen as a vital security tool, rather than an inconvenience.

 


 

Henning Horst is CTO at comforte AG

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543