Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Banks blame merchants for data breaches

Execs note TJX breach caused by retailer, not banks

June 19, 2007 12:00 PM ET

Computerworld - LAS VEGAS -- A discussion of the ongoing tug of war between banks, credit card companies and retailers regarding the Payment Card Industry (PCI) Data Security Standard drew ire, frustration and organizational tips from a panel of users at the Symantec Vision user conference here last week.

Executives from JP Morgan Chase & Co., First Horizon Bank Holding Co., and AT&T Inc.'s compliance division offered details about their PCI deployment experiences, discussed the confusion surrounding evolving rules, and offered advice on how to deal with the auditing and IT overhaul pressures PCI can bring.

As some retail executives openly criticize the PCI standard,  for levying unfair costs and IT burdens upon their organizations, the financial services executives fired back by noting that high-profile data breaches at retailers like The TJX Companies Inc. are not originating from their side of the fence.

The TJX incident, said Christopher Leach, senior vice president and chief information security officer for First Horizon, "was not a JP Morgan [data breach], it wasn't at First Horizon or CitiGroup, it was at a merchant, and yet all the plans to remediate that have been with the banks. So we are seeing a shift right now for who's going to pay for that. At the end of the day, the breach wasn't at a bank, it was at a merchant."

First Horizon, which operates in 43 states and claims $5 billion in annual revenue, is currently going through a new round of PCI certification -- or, as Leach put it, "trying to build that airplane as we build the runway."

"We've discovered that PCI keeps changing," said Leach. "We went down the path to be certified at one point of time and did a great deal of due diligence, only to find out some of the requirements would change. One Visa analyst would say one thing and another Visa analyst would say something else very contradictory."

The PCI standards were enacted in June 2005 by five major credit card companies -- Visa International, MasterCard Worldwide, American Express Co., Discover Financial Services LLC and Tokyo-based JCB Co. -- to protect credit card data before, during and after transactions. The standards mandate an array of basic security controls, including encryption, authentication, logging and monitoring, for transactions processed using credit and debit cards. Failure to comply with the PCI standard could cause stiff fines and increased transactional rates starting later this year.
 
Vanessa Pegueros, director of compliance services for AT&T, said her organization was first threatened with PCI-related fines after the TJ Maxx data breach when the credit card group ordered that the company be compliant with the standard by September 2007 or face fines of $25,000 a month. "I think [after] the TJ Maxx incident, Visa came down with a much heavier hammer. [Merchants are] thumbing their nose at the PCI regulation, so we are paying the price," Pegueros contended.



Jump to comments

security

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs